How Employees Can Help Prevent HIPAA Violations
Employees can help prevent HIPAA violations by fully understanding what PHI is, knowing when PHI can permissibly be used and disclosed, and by following their employers’ policies on the compliant use of healthcare technologies and communication devices. Employees can also help prevent HIPAA violations by reporting poor practices they identify to a manager or compliance officer. One of the key goals of compliance officers is to prevent HIPAA compliance violations whenever possible. To achieve this goal, many compliance officers rely on technological solutions or sanctions policies to deter employees from noncompliant behaviors. However, by taking a more positive approach, employees can help prevent HIPAA violations. Use the article in conjunction with our free HIPAA Violations Checklist to understand what is required to ensure full compliance. Please use the form on this page to arrange for your copy. Most Frequent Complaints According to the Department of Health and Human Services’ Enforcement Highlights web page, the most frequent complaint received by HHS’ Office for...
Epic Sues Health Information Exchange Network Alleging Improper Record Access
Epic Systems, the market-leading electronic medical record system provider, has filed a lawsuit against the health information network Health Gorilla and several of its clients, alleging improper access to the records of 300,000 patients. The lawsuit, which also names OCHIN Inc, Reid Hospital & Health Care Services Inc. (Reid Health), Trinity Health Corporation, and UMass Memorial Health Care Inc., as plaintiffs, alleges bad actors have fraudulently obtained access to patient data and are abusing access for financial gain. The lawsuit seeks to put an end to the exploitation of health information exchange frameworks for obtaining and monetizing patient data. The lawsuit alleges that certain Health Gorilla clients are turning nationwide interoperability frameworks into data marts, where sensitive patient data can be bought and sold without patients’ or physicians’ knowledge or consent, including patient data stored in Epic’s interoperability framework. Two national frameworks – Carequality and TEFCA – are responsible for almost one billion patient-record exchanges each...
Ransomware Attacks Increased by 58% in 2025
The threat from ransomware is greater than ever, according to a new report from GuidePoint Security. The cybersecurity firm recorded a 58% year-over-year increase in victims, making 2025 the most active year ever reported by GuidePoint Security. In 2025, GuidePoint Security tracked 2,287 unique victims in Q4, 2025 alone – the largest number of victims in any quarter tracked by the GuidePoint Research and Intelligence Team (GRIT). December was the most active month in terms of claimed victims, which increased 42% year-over-year to 814 attacks. On average, 145 new victims were added to dark web data leak sites every week in 2025, with the year ending with 7,515 claimed victims. Law enforcement operations have targeted the most active groups, and there have been notable successes; however, they have had little effect on the number of victims, which continues to increase. Rather than the ransomware-as-a-service (RaaS) landscape being dominated by one or two major actors, law enforcement operations have helped create a highly fragmented ecosystem, with smaller groups conducting attacks...
PharMerica Pays Over $5.2 Million to Settle Class Action Data Breach Lawsuit
PharMerica has agreed to settle a class action lawsuit over a 2023 hacking incident and data breach that affected 5.8 million individuals. In addition to paying $5.2 million to cover costs and benefits, PharMerica has committed to investing millions to strengthen its security posture. PharMerica, a Fortune 1000 pharmacy services provider, experienced a cyberattack in March 2023 for which the Money Message ransomware group took credit. The group claimed to have exfiltrated 4.7 terabytes of data in the attack, and it proceeded to leak the stolen data on its dark web data leak site, including files containing patient information. Data compromised in the attack included names, addresses, birth dates, medications, Social Security numbers, and health insurance information. Several class action lawsuits were filed against PharMerica in response to the data breach, alleging negligent collection and storage of patient data. The lawsuits had overlapping claims and were consolidated into a single complaint – Lurry v. PharMerica Corporation – in the United States District Court for...
HIPAA and HITECH
The relationship between HIPAA and HITECH began in 2009 with the American Recovery and Reinvestment Act – an Act introduced by the Obama administration to stimulate the economy by incentivizing investment in infrastructure, education, health, and renewable energy. Division A Title XIII and Division B Title IV of the American Recovery and Reinvestment Act – together known to as the Health Information Technology for Economic and Clinical Health Act (HITECH) – set aside funds for the creation of a nationwide network of Health Information Exchanges and signaled the start of the Meaningful Use program. As the Meaningful Use program incentivized healthcare providers to adopt technology in the provision of healthcare, HITECH had to take into account the HIPAA Privacy and Security Rules. Subtitle D of HITECH addressed concerns about the electronic transmission and storage of medical records, strengthened existing HIPAA Privacy and Security Rule provisions and introduced measures for the effective enforcement of HIPAA. Subsequent updates to both HIPAA and HITECH frequently...



