Atrium Health & Interim HealthCare Affected by Business Associate Data Breaches
Atrium Health Navicent and Interim HealthCare of Lubbock/Amarillo have recently announced that they have been affected by data breaches at third-party vendors. Atrium Health Navicent Atrium Health Navicent is the latest healthcare provider to announce that it has been affected by the January 2025 data breach at Oracle Health. Oracle Health acquired the electronic medical record company Cerner, and was due to migrate patient records from legacy Cerner servers to Oracle Health’s systems. As early as January 22, 2025, a hacker gained access to two legacy servers and exfiltrated patient data. Oracle Health detected the breach in February 2025. Many healthcare providers were affected and issued notification letters last year. According to Atrium Health Navicent, the delay in notification is due to the complexity of the data review, which has taken many months to complete. Atrium Health Navicent said it only recently learned from Oracle Health that it had been affected, and the review of the impacted data was not completed until March 12, 2026. The data compromised in the incident was...
What are the HIPAA Training Requirements for New Hires?
The HIPAA training requirements for new hires are that “a covered entity must provide training […] to each new member of the workforce within a reasonable period of time after the person joins the covered entity’s workforce” (45 CFR 164.530(b)(2)). What a “reasonable period of time” is may depend on the new hire’s role and their existing HIPAA knowledge but the best practice in the healthcare sector is to provide HIPAA training and HIPAA security awareness training as soon as possible. All healthcare students on clinical placements are new hire that should immediately be provided with HIPAA training. Because HIPAA applies to many different types of organizations, it is important the HIPAA training requirements for new hires are put into context rather than taken in isolation. This is because HIPAA requires covered entities and business associates to identify risks to the privacy of Protected Health Information (PHI) and mitigate the risks to a reasonably acceptable level. If a covered entity conducts a risk assessment, and identifies a risk to the privacy of PHI by allowing an...
Gandara Mental Health Center Settles Class Action Data Breach Lawsuit
Gandara Mental Health Center in Springfield, Massachusetts, has agreed to settle class action litigation stemming from a June 2024 cyberattack and data breach that affected 17,543 individuals. The cyberattack was detected on June 20, 2024, and Gandara Mental Health Center determined that personal and protected health information, such as names, addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnoses, treatment information, and health insurance information, had been compromised. The hackers claimed to have exfiltrated approximately 450 GB of data. A class action lawsuit was filed in the Court in the Commonwealth of Massachusetts, Hampden County – Eugene Mitchell v. Gandara Mental Health Center, Inc. – in response to the data breach that alleged that the defendant failed to properly secure its network, leading to the theft of the plaintiffs’ personal and protected health information. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and breach of fiduciary duty. Gandara Mental Health...
Mt. Spokane Pediatrics Data Breach Affects 32,000 Patients
A cyberattack on Mt. Spokane Pediatrics exposed the data of more than 32,000 patients. Data breaches have also been announced by Cornerstone Care Center in California and Michigan Medicine. Mt. Spokane Pediatrics Mt. Spokane Pediatrics in Washington state has started notifying 32,021 individuals about the theft of some of their personal and protected health information in a January 2026 cyberattack. According to its website breach notice, the attack occurred on or around January 1, 2026, and the threat actor was found to have exfiltrated files containing patients’ protected health information. The forensic investigation determined on April 22, 2026, that the data exfiltrated in the attack included full names, dates of birth, Social Security numbers, diagnoses, treatment information, patient numbers, medical record numbers, health plan beneficiary numbers, and dates of service. Mt. Spokane Pediatrics said it is unaware of any actual or attempted fraud as a result of the data breach. Complementary single-bureau credit monitoring services have been offered to the affected individuals...
Rhode Island Finalizes $12 Million Settlement With Deloitte Consulting Over RIBridges Cyberattack
An agreement has been reached between the state of Rhode Island and Deloitte Consulting LLP that will see the professional services firm pay an additional $7 million in financial support to the state following the 2024 cyberattack on the state’s benefits administration system – RIBridges. RIBRidges is Rhode Island’s one-stop shop for public benefits for state residents, including applications and management of Medicaid, food stamps, and other benefits. In November 2024, Deloitte Consulting identified the intrusion and took steps to secure the system. The state was notified about the hack in early December. The investigation confirmed that hackers had access to the system for around 5 months, during which time they gained access to around 28 of the 338 backend environments of the system and exfiltrated sensitive data, including the data of almost 650,000 Rhode Island benefits applicants and recipients – around 59% of the population of the state. The Brain Cipher ransomware group claimed responsibility for the attack, boasting that access was gained by cracking an 8-character...



