Precipio; Pit River Health Service; Tulane University Medical Group Confirm Data Breaches
Data breaches have been announced by the Connecticut diagnostic laboratory Precipio, Pit River Health Service in California, and Tulane University Medical Group in Louisiana. Precipio, Inc. Precipio, Inc., a Connecticut-based laboratory specializing in advanced hematopathology diagnostics, has discovered unauthorized access to an employee’s cloud-based storage account. Suspicious activity was identified within the email account on or around November 25, 2025, and the investigation confirmed that an unauthorized third party accessed the employee’s account from November 23, 2025, to November 25, 2025, during which time, files were copied from the account. The affected files are currently being reviewed to determine the information involved, and that process is currently ongoing. Precipio has yet to disclose a final list of the affected data, but said that, based on its investigation so far, information compromised in the incident includes names, addresses, dates of birth, medical record numbers, clinical/treatment information, medical procedure information, medical provider names,...
Is Paubox HIPAA Compliant?
Paubox is HIPAA compliant and as an email encryption solution supports HIPAA compliance and can be used by Covered Entities and Business Associates to communicate Protected Health Information in emails without violating the standards of the HIPAA Privacy or Security Rules. Contents What is Paubox? What are the HIPAA Email Requirements? Privacy Rule Challenges to HIPAA Email Compliance Security Rule Challenges to HIPAA Email Compliance How Paubox Can Help Overcome the Challenges Making Paubox HIPAA Compliant Conclusion: Paubox is HIPAA Compliant What is Paubox? Paubox Inc. is a Californian provider of email encryption products with varying levels of capabilities and is the market lead in HIPAA-compliant email. At the entry level, Paubox works in the background to encrypt outbound emails to prevent Protected Health Information (PHI) from being impermissibly disclosed during the transit of emails. Further up the product suite, Paubox offers AI-powered inbound email security to stop phishing attacks, business email compromise attacks and email spoofing. Along with standard email...
McLaren Health Care Pays $14 Million to Settle Litigation Over Ransomware Attacks
McLaren Health Care has agreed to pay $14 million to settle class action litigation stemming from two ransomware attacks in 2023 and 2024 that affected more than 2.8 million patients and employees. McLaren Health Care is a Grand Rapids, Michigan-based integrated healthcare delivery system that operates 12 hospitals and many healthcare facilities in Michigan, Indiana, and Ohio, and also a health plan. Over the space of a year, McLaren Health Care experienced two ransomware attacks. The first attack was conducted by the ALPHV/BlackCat ransomware group, which had access to its computer network from July 28, 2023, to August 23, 2023. The second attack was conducted by the Inc Ransom ransomware group, which accessed its network between July 17, 2024, and August 3, 2024. The ALPHV/BlackCat ransomware attack affected 2,103,881 individuals, and the Inc Ransom ransomware attack affected 743,131 individuals. Data compromised in the attacks included names, Social Security numbers, information about past, present, or future physical, mental, or behavioral health or conditions, the provision of...
Jefferson-Blount-St. Clair Mental Health Authority Data Breach Affects 30,000 Patients
Jefferson-Blount-St. Clair Mental Health Authority in Alabama, Cottage Hospital in New Hampshire, WindRose Health Network in Indiana, and Iroquois Memorial Hospital in Illinois have announced that patient data has been exposed in hacking incidents. Jefferson-Blount-St. Clair Mental Health Authority, Alabama Jefferson-Blount-St. Clair (JBS) Mental Health Authority in Alabama has notified more than 30,000 individuals that some of their personal and protected health information was exposed and potentially acquired in a ransomware attack. Suspicious activity was identified within its computer network on or around November 25, 2026. The investigation confirmed that hackers gained access to its network on November 25, 2026, and potentially viewed or acquired information relating to individuals who were patients or employees between 2011 and 2025. The file review has recently concluded and confirmed that the exposed data included names, Social Security numbers, health insurance information, dates of birth, and medical information, which may have included diagnoses, physician information,...
HIPAA Compliant Email: Best Practice To Avoid Violations & Breaches
This practical guide to HIPAA compliant email services explains how to achieve best practice compliance by avoiding the common misunderstandings and implementation errors that cause the preventable email violations that lead to breaches and fines. It has become increasingly clear that many aspects of HIPAA compliant email are either not understood or badly implemented, leaving a large number of healthcare organizations of all sizes wrongly believing their email is both secure and HIPAA compliant. Unfortunately, many easily preventable issues only come to light after it is too late and a breach has taken place. The Office for Civil Rights receives around 60,000 notifications of data breaches each year, of which many are wrongful disclosures of Protected Health Information (PHI) attributable to email violations. What Is Required For HIPAA Email Compliance? From an organizational perspective, when looking into HIPAA email compliance services there are three areas that should be considered, each of which is covered in more detail below: 1. HIPAA Compliance: What is required for...



