NCH Corporation Employee Benefits Plan Member Data Stolen
Personal and protected health information has been compromised in security incidents affecting NCH Corporation Employee Benefits Plan members, and patients of Foundation Health Partners in Alaska and One Community Health in California. NCH Corporation The global industrial solutions provider, NCH Corporation, has announced a breach of the protected health information of 3,098 members of its Employee Benefits Plan. Like many organizations of its size, NCH Corporation uses Oracle’s E-Business Suite (EBS) software to help with the management of its operations. A previously unknown vulnerability in the software – CVE-2025-61882 – was exploited by a threat actor to gain access to the Oracle EBS application, and sensitive data was exfiltrated. NCH Corporation was one of several organizations to be attacked in this manner in mid to late 2025. While not stated by NCH Corporation in its data breach notification letters, this was a mass exploitation by the Cl0p ransomware group, which specializes in exploiting zero-day vulnerabilities. Assisted by third-party cybersecurity...
Data Breach Affects Patients of Multiple Fyzical Therapy & Balance Centers
Fyzical Acquisition Holdings LLC, the parent company of Fyzical Therapy & Balance Centers, has announced a security incident involving unauthorized access to the personal and protected health information of its patients. Fyzical Therapy & Balance Centers is a large physical therapy franchise with more than 500 locations in 46 U.S. states. On or around December 9, 2024, suspicious activity was identified within its email environment. An investigation was launched to determine the cause of the activity, and it was confirmed that there had been unauthorized access to its email environment. The substitute data breach notice does not state for how long its email environment was compromised, only that during that time, emails and attached files may have been viewed or acquired. The review of the affected data has taken almost a year to complete, concluding on November 25, 2025, when it was confirmed that the affected data included names, dates of birth, Social Security numbers, driver’s license numbers, state IDs, financial account information, credit card information, medical...
New York Attorney General Fines Capital Region Orthopedic Practice $500K for 2023 Data Breach
Orthopedics NY LLP (aka OrthoNY; OrthopedicsNY), a New York orthopedic medicine practice, has been fined $500,000 by the New York Attorney General over a December 2023 ransomware attack and data breach, according to several media outlets serving the Capital District in New York State. OrthopedicsNY operates almost 20 orthopedic, physical therapy, MRI Imaging, and surgery clinics in the Capital Region in New York State. On or around December 28, 2023, OrthopedicsNY fell victim to an INC Ransom ransomware attack. The investigation took around 9 months and revealed on September 5, 2024, that the personal and protected health information of current and former patients and employees was compromised in the incident. The data breach was initially reported as affecting around 5,100 individuals, but the total was later updated to 656,086 individuals. Those individuals had to wait 10 months to discover their information had been stolen in the attack. While the ransomware attack occurred in late December 2023, the affected individuals did not start to be notified until October 30, 2024....
HIPAA Compliance for Nursing Homes
HIPAA compliance for nursing homes requires controlled use, disclosure, safeguarding, and breach response for protected health information under the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule across resident care, facility operations, and external coordination. HIPAA-Covered Functions in Nursing Home Operations Nursing homes create and maintain protected health information during admissions, assessments, care planning, medication administration, therapy services, dietary services, social services, and discharge planning. Protected health information also exists in documentation used for reimbursement, quality reporting, and regulatory oversight. The compliance scope includes electronic health records, paper charts, resident rosters, and communications used by clinical and administrative staff. Nursing homes that operate as part of a health system or that share services with affiliates should define where protected health information flows across entities, departments, and shared platforms. Access and disclosure controls should match those defined...
HIPAA Training for Administrators
Healthcare administrators must receive documented HIPAA training covering the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule during onboarding and refreshed annually as an industry best practice, supported by security awareness training so administrative functions involving protected health information, electronic systems access, and incident reporting are performed in accordance with HIPAA training requirements and organizational policies. Administrative roles often have broad system access and handle protected health information across multiple functions, including registration, scheduling, billing, eligibility verification, authorizations, records management, contracting, compliance coordination, vendor management, and quality reporting. Training must reflect the operational reality that administrators frequently initiate disclosures, process requests, and control access to systems that contain protected health information. HIPAA training should be provided during onboarding within a reasonable period after hire, assignment, or access authorization....



