OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2023
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has submitted a pair of reports to Congress on the state of compliance with the Health Insurance Portability and Accountability (HIPAA) Privacy, Security, and Breach Notification Rules, and breaches of unsecured protected health information for calendar year 2023, as required by Section 13424(a) of the Health Information Technology for Economic and Clinical Health (HITECH) Act. OCR maintains a data breach portal, through which HIPAA-regulated entities must submit their reports of breaches of unsecured protected health information, and a web page through which individuals may submit a health information privacy complaint. There has been a general trend of increasing data breaches and complaints, which is placing greater pressure on OCR’s limited resources; however, OCR made progress in decreasing the backlog of complaint and data breach investigations in 2023. The reports show data breaches affecting fewer than 500 individuals increased by 7% year-over-year, data breaches affecting 500 or more...
March 2026 Healthcare Data Breach Report
In March 2026, 66 healthcare data breaches affecting 500 or more individuals were reported to the HHS’ Office for Civil Rights (OCR). More than 8.7 million individuals had their personal and protected health information exposed, stolen, or otherwise impermissibly disclosed. Under the HITECH Act of 2009, OCR is required to publish a summary of large healthcare data breaches – incidents involving the exposure, theft, or impermissible disclosure of the electronic protected health information of 500 or more individuals. OCR checks all breach reports submitted through its data breach portal, then adds the data breaches to the public-facing section of the portal. Typically, there is a delay of up to 2 weeks from the receipt of a breach report to its addition to the breach portal. During the month of March, no data breaches were added to the portal for March. March data breaches started to be added to the portal in mid-April, hence the delay in publication of this breach report. Since this breach report was first published on May 11, 2026, a further 22 data breaches were added to the...
5 HIPAA Compliance Tips for Medical Office Managers
Article Content What HIPAA requires from medical office managers Tip 1: Treat policies as living documents, not binders on a shelf Tip 2: Build HIPAA training into the practice calendar Tip 3: Review access permissions regularly Tip 4: Establish clear security incident procedures Tip 5: Track Business Associate Agreements HIPAA compliance software for office managers Medical Office Manager’s Central Role Medical office managers sit at the center of every operational workflow in a small or mid-sized practice. They are the people who translate HIPAA’s legal requirements into the daily routines that keep patient information protected, staff aligned with the practice’s workflows, and the practice out of regulatory trouble. Unlike large health systems with compliance departments, privacy teams, and dedicated security personnel, medical practices often rely on a single individual to oversee both the structural elements of a HIPAA compliance program and the practical application of HIPAA in daily operations across reception, billing, clinical support, and administrative...
OpenLoop Health Data Breach Affects 716,000 Individuals
On March 24, 2026, The HIPAA Journal reported on a data breach at the telehealth platform provider Open Loop Health (see below). The data breach had been reported to regulators, but it can take weeks for the incident to be added to the HHS Office for Civil Rights breach portal and for the scale of the breach to become clear. While the data breach was reported to OCR on March 17, 2026, it has only recently been added to the breach portal. That listing shows that the protected health information of up to 716,000 individuals was compromised in the incident. March 24, 2026: Telehealth Platform Provider OpenLoop Health Discloses Data Breach A major data breach has been reported by the telehealth platform provider OpenLoop Health Inc. While the total number of affected individuals has yet to be publicly disclosed, it could well be one of the largest healthcare data breaches of the year to date. According to the breach notice provided to the California Attorney General, OpenLoop Health learned on January 7, 2026, that an unauthorized third party had gained access to some of its systems...
CISA Launches Initiative to Improve Critical Infrastructure Resilience During Geopolitical Conflicts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced a new initiative aimed at improving critical infrastructure cyber resilience during geopolitical conflicts, and is urging critical infrastructure operators to improve their defenses against disruptive and destructive cyberattacks through proactive isolation and recovery planning. CISA warns that adversaries have already embedded themselves in critical systems and are positioning themselves to cripple operational technology in the event of a wider geopolitical conflict. During geopolitical conflicts, critical infrastructure entities face an increased risk of cyberattacks, where nation-state actors may attempt to disrupt and destroy the operational technology running the United States. Attacks may target healthcare providers to disrupt patient care, telecommunications infrastructure to damage phone and internet services, food production facilities, and energy and wastewater entities. At all times, critical infrastructure entities must continue to deliver crucial services to Americans. They must therefore...



