How to Become HIPAA Compliant
One of the simplest ways how to become HIPAA compliant is to adapt HHS’ “The Seven Fundamentals of an Effective Compliance Program” to address compliance challenges identified in a HIPAA risk assessment. It can also be beneficial to take advantage of HIPAA compliance software that is built around The Seven Fundamentals in order to maintain a compliant workplace. 7 Steps for HIPAA Compliance In 2011, HHS published “The Seven Fundamental Elements Of An Effective Compliance Program”. We have slightly amended it to be more relevant to HIPAA compliance in 2026. Here is a summary of the elements, which we outline in more detail in this guide. Develop policies and procedures so that day-to-day activities comply with the HIPAA Privacy Rule. Designate a privacy officer and a security officer. Implement effective training programs. Ensure channels of communication exist to report violations and breaches. Monitor compliance at floor level so poor compliance practices can be nipped in the bud. Enforce sanctions policies fairly and equally. Respond promptly to identified or...
November 2025 Healthcare Data Breach Report
Based on breach reports submitted to the U.S. Department of Health and Human Services (HHS), November saw relatively low numbers of healthcare data breaches. On average in 2025, 57 healthcare data breaches affecting 500 or more individuals were reported to the HHS’ Office for Civil Rights (OCR) each month. In fact, for the past six years, data breaches have been reported at a rate of around 60 per month. The OCR breach portal currently lists 32 large healthcare data breaches for November, and a similar number were reported in October (28) – numbers that have not been regularly seen since 2018. Compared to previous Novembers, data breaches have decreased substantially, with a 54% reduction from November 2024 and a 56% reduction from November 2023. While data breaches appear to have halved in October and November, it coincides with the U.S. government shutdown due to Congress failing to pass appropriations legislation for the 2026 fiscal year. The shutdown lasted from October 1, 2025, to November 12, 2025, and during that time, no data breaches were added to the OCR data breach...
Central Maine Healthcare Data Breach Affects 145,000 Individuals
Data breaches have recently been announced by Central Maine Healthcare, Dermatology Associates in Kentucky, and Reproductive Medicine Associates of Michigan. The Central Maine Healthcare data breach has affected 145,000 individuals. Central Maine Healthcare Central Maine Healthcare, an integrated nonprofit healthcare system serving around 400,000 residents in central and western Maine, has announced a major data breach involving the electronic protected health information of up to 145,000 patients. Suspicious activity was identified within its IT systems on June 1, 2025, and immediate action was taken to secure its systems while an investigation sought to determine the nature and scope of the activity. The investigation determined that between March 19, 2025, and June 1, 2025, an unauthorized third party had access to its network and accessed or acquired files containing sensitive patient data. The file review confirmed that names and Social Security numbers were compromised, in combination with one or more of the following: address, date(s) of service, provider names, treatment...
HIPAA Training for Pharmacy Staff
HIPAA training for pharmacy staff is required because pharmacies routinely create, access, and share protected health information through prescriptions, insurance claims, medication therapy management, patient counseling, and coordination with prescribers and other providers, and training is one of the most practical ways to reduce avoidable disclosures, improve incident reporting, and keep workflows compliant. In most healthcare settings, annual HIPAA training is a widely followed best practice, and all workforce members should receive training that matches their role and the way they interact with patient information. Why HIPAA Training Matters in a Pharmacy Setting Pharmacies handle PHI in high volume and at high speed. The risk is not only unauthorized access to prescription profiles, but also everyday situations such as conversations at the counter, voicemail messages, delivery logistics, prior authorization paperwork, and sharing information with caregivers. HIPAA training helps staff recognize what information is sensitive, when a disclosure is permitted, and what to do when...
Complying with HIPAA California Law
The difficulty in complying with HIPAA California law is that there are several significant Acts of state privacy legislation that healthcare organizations and their Business Associates have to comply with that overlay provisions of the Health Insurance Portability and Accountability Act (HIPAA). In the context of complying with HIPAA California law as a healthcare organization – or as a Business Associate of a healthcare organization – one of the primary areas of difficulty is understanding the differences between the Acts and where overlaying provisions apply. HIPAA HIPAA provides a federal floor of privacy protections that applies to healthcare organizations who conduct electronic transactions for which the Department of Health and Human Services (HHS) has published standards. Under HIPAA, “Covered Entities” are required to protect the privacy of individually identifiable health information (“Protected Health Information” or “PHI”) and safeguard the confidentiality, integrity, and availability of electronic PHI. HIPAA also applies to Business Associates who receive,...



