Healthcare Interactive: More Than 3 Million Individuals Affected by July 2025 Security Incident
Healthcare Interactive, better known as HCIactive, reported a data breach to the HHS’ Office for Civil Rights on September 22, 2025, using a placeholder figure of 501 affected individuals. At the time, the extent of the data breach had not been determined as the review of affected data was ongoing. While the Maine Attorney General was informed in September that 87,565 individuals had been affected, it has now been confirmed that the data breach was far more extensive. The Oregon Attorney General was informed on January 7, 2026, that the personal and protected health information of 3,056,950 individuals was compromised in the incident, which makes it one of the largest healthcare data breaches of 2025. As of January 30, 2026, it is the 5th largest healthcare data breach of 2025. Healthcare Interactive is an Ellicott City, MD-based provider of AI-powered software solutions for insurance enrollment and benefits administration. On or around July 22, 2025, suspicious activity was identified within its computer network. According to its substitute data breach notice, the forensic...
U.S. Data Compromises Hit Record Breaches in 2025
An unwanted new record was set in 2025 for data compromises, which increased by 4% from the record-breaking total in 2024, according to the Identity Theft Resource Center (ITRC). The ITRC is a non-profit organization dedicated to helping victims of data breaches, scams, and identity theft. ITRC also offers education to help consumers protect themselves against identity theft and fraud. ITRC tracks data compromises, which include data breaches, data leaks, and accidental exposures of sensitive consumer data. The record total of 3,332 data compromises in a year represents a 79% increase in just five years, and the third successive year when more than 3,000 data compromises have been identified. While the historic high is concerning, there is at least some good news, as the number of individuals affected by data compromises has fallen sharply to the lowest annual total since 2014. Across the 3,332 data compromises, 278.8 million individuals were affected, down from 2024’s shockingly high total of 1.36 billion. The relatively low total is due to a lack of mega data breaches, which have...
Northwell Health & Northbay Healthcare Settle Litigation Over Website Pixel Use
Northwell Health & Northbay Healthcare were sued over the use of tracking tools on their websites, which are alleged to have illegally disclosed sensitive data to unauthorized third parties. Both healthcare providers have agreed to settle the lawsuits. Northwell Health Data Breach Settlement Northwell Health has agreed to settle litigation over its use of tracking software on its website. According to the lawsuit, tracking tools such as Meta Pixel and Google Analytics code were added to its website and were configured in a manner that resulted in protected health information being transmitted to third parties, without the consent of website visitors. The lawsuit – Kaplan v. Northwell Health, Inc. – was filed in the New York State Supreme Court, Kings County, and alleged that information about website users’ past, present, or future health conditions, including the type and date of a medical appointment, was collected and transmitted to third parties. That information could be tied to individuals via identifiers such as the their Facebook ID and IP address. The...
HIPAA Security Rule
The HIPAA Security Rule contains the security standards for the protection of electronic Protected Health Information (ePHI) that apply when a HIPAA covered entity or business associate creates, receives, transmits, or maintains ePHI in connection with an activity or function regulated by the HIPAA Administrative Simplification Regulations. Rather than being a one-size-fits-all set of security standards, the HIPAA Security Rule allows a degree of flexibility with regard to what standards are implemented and how they are applied. It is also important to be aware that because ePHI is a subset of Protected Health Information, the HIPAA Privacy Rule still governs how ePHI can be used and disclosed. Details of these variables are published in the General Requirements of the HIPAA Security Rule. Thereafter, the main standards and implementation specifications are listed in the Administrative, Physical, and Technical Safeguards, while other security-related HIPAA compliance standards appear in the Organizational and Documentation Requirements. General Security Requirements The General...
Comstar to Pay State AGs $515,000 to Settle Alleged HIPAA Violations
Comstar, a Massachusetts-based ambulance billing and collections company, has been investigated by the Massachusetts Attorney General and found to have violated the Health Insurance Portability and Accountability Act (HIPAA) and the Massachusetts Data Security Regulations. Comstar will pay a $515,000 penalty to resolve the alleged violations. Comstar was investigated over a March 2022 cyberattack and data breach. A cyber threat actor breached its network, exfiltrated files, and used ransomware to encrypt data on its network. While the attack was detected on March 26, 2022, the ransomware group gained access to its network on March 19, 2026. The forensic investigation confirmed that protected health information (PHI) had been stolen, including names, Social Security numbers, driver’s license numbers, financial information, and medical assessment information. The PHI of 585,621 individuals was compromised in the ransomware attack, including 326,426 Massachusetts residents and 22,829 Connecticut residents. The Rowley, Massachusetts-based company faced an investigation by the...



