HIPAA Training for IT Professionals
HIPAA training for IT professionals is required for IT workforce members who support systems that create, receive, maintain, or transmit protected health information (PHI), because HIPAA compliance depends on administrative, physical, and technical safeguards being implemented and followed consistently. Why HIPAA Training is Necessary for IT Professionals IT professionals influence how PHI is protected more directly than most job functions because they design, configure, administer, and monitor the systems that store and move electronic protected health information (ePHI). Even when an IT role is not clinical, IT staff may access logs, databases, backups, ticketing systems, and troubleshooting data that contain PHI. HIPAA training helps IT teams understand the privacy and security expectations that apply to their work, the consequences of misconfiguration or improper access, and the operational behaviors that reduce the risk of unauthorized access, improper disclosure, or data loss. HIPAA training for IT should connect the HIPAA Privacy Rule and the HIPAA Security Rule to real...
Four Healthcare Providers Settle Class Action Lawsuits Over Data Breaches
Settlements have been agreed to resolve class action lawsuits over healthcare data breaches experienced by Alabama Cardiovascular Group, Carolina Arthritis Associates, Rocky Mountain Gastroenterology Associates, and Regional Obstetrical Consultants. Alabama Cardiovascular Group Data Breach Settlement Alabama Cardiovascular Group has settled a class-action data breach lawsuit arising from a data security incident detected on July 2, 2024. The investigation confirmed that an unauthorized third party accessed its network between June 6, 2024, and July 2, 2024, and exfiltrated files containing patient and employee information. Data compromised in the incident included names, contact information, Social Security numbers, health insurance information, and medical information. The data breach affected 280,534 individuals. Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – Tammy Brown et al., v. Alabama Cardiology Group P.C. d/b/a Alabama Cardiovascular Group – in the Circuit Court for Jefferson County, Alabama....
What is the HHS OIG Exclusions List?
The HHS OIG Exclusions List is a database of individuals and organizations that are prohibited from participating in federal health care programs, and healthcare providers participating in federal healthcare programs are advised to regularly check the HHS OIG Exclusions List to avoid penalties for non-compliance with §1128 of the Social Security Act. This article answers the following: What is the HHS Office of Inspector General? What is the HHS OIG Exclusions List? How is the OIG Exclusions List populated? Why check the OIG list for exclusions? What are the penalties for engaging excluded entities? How can providers mitigate the risk of a penalty? What other lists should be checked for exclusions? Conclusion: The importance of regularly checking for exclusions Addendum: Synonyms for the HHS OIG Exclusions List What is the HHS Office of Inspector General? The HHS Office of Inspector General (OIG) is a team of investigators, auditors, analysts, attorneys and cybersecurity specialists within the Department of Health and Human Services (HHS). The team’s roles are to investigate and...
Mitchell County Dept. Social Services; 360 Dental; GiaCare Announce Data Breaches
Protected health information has been exposed in data security incidents at Mitchell County Department of Social Services in North Carolina, 360 Dental in Pennsylvania, and GiaCare in Florida. Mitchell County Department of Social Services Individuals who received services from Mitchell County Department of Social Services in North Carolina have had their sensitive information stolen in a ransomware attack. The investigation into the October 2025 ransomware attack on Mitchell County was initiated on October 20, 2025, following the encryption of files. The attack caused email and phone outages that lasted for several days. The forensic investigation confirmed that there had been unauthorized network access between October 16, 2025, and October 20, 2025, during which time files were exfiltrated. The data review and investigation are ongoing to determine the types of information involved and the individuals affected. After that information has been confirmed and up-to-date contact information has been obtained, notification letters will be mailed to the affected individuals....
Texas & New Jersey Dermatology Practices Settle Class Action Data Breach Lawsuits
Two U.S. dermatology practices have agreed to settle class action lawsuits stemming from cybersecurity incidents that exposed patient data. The settlements provide cash benefits to class members and credit monitoring and identity theft protection services. Affiliated Dermatologists & Dermatologic Surgeons Class Action Settlement Affiliated Dermatologists & Dermatologic Surgeons, a dermatology practice based in Morristown, New Jersey, learned about a cybersecurity incident on March 4, 2025. The forensic investigation determined that an unauthorized third party had access to its computer network from December 19, 2023, to March 5, 2024. The review of the exposed files determined that they contained the protected health information of 373,630 individuals, including names, mailing addresses, birth dates, Social Security numbers, medical treatment information, and health insurance claims information. Compromised employee information includes names, mailing addresses, birth dates, Social Security numbers, driver’s license numbers, and passport numbers. Notification letters were...



