Is It a HIPAA Violation to Send to Collections?
It is not a HIPAA violation to send to collections provided the minimum necessary Protected Health Information is disclosed and – if using an external collection agency – a Business Associate Agreement is in place with the collection agency. However, before sending medical bills to collections, it is important to consider state and local laws relating to medical debt relief. The HIPAA Privacy Rule stipulates when uses and disclosures of Protected Health Information (PHI) are required, permitted, require consent, or require authorization. Permitted uses and disclosures of PHI include “Treatment, Payment, or Healthcare Operations” (§164.506). This section of the Privacy Rule states: “A covered entity may use or disclose protected health information for its own treatment, payment, or health care operations”. By reviewing how TPO in HIPAA is defined – particularly how the word payment is defined – it is possible to determine if it is a HIPAA violation to send to collections. §2(iii) of the definition of payment includes “Billing, claims management, collection activities, obtaining...
AHA: Understand Your Risk Environment to Better Protect Patient Data
In the first part of its 2025 review of healthcare cybersecurity, the American Hospital Association (AHA) reports that in the year to October 3, 2025, the health records of 33 million Americans were compromised in 364 hacking incidents. While the figures are appalling, they are at least better than last year, when a new record was set, with 259 million Americans having had their sensitive health data stolen, 190 million of whom had their data stolen in a single incident – the ransomware attack on Change Healthcare. It is too early to tell how bad this year will be in terms of data breaches, but over the previous four years, more than 700 large data breaches have been reported each year, the majority of which were due to hacking incidents. As the AHA points out in the report, 100% of breached records were unencrypted. Had the records been encrypted, there would not have been a data breach, as data breaches only ever involve unencrypted records unless decryption keys are stolen in addition to encrypted data. The AHA analysis revealed that over the past few years, the majority of...
Data Breaches Announced by North Atlantic States Carpenters Health Benefits Fund & Millcreek Pediatrics
Data breaches have recently been announced by the North Atlantic States Carpenters Health Benefits Fund in Massachusetts and Millcreek Pediatrics in Delaware. Millcreek Pediatrics, Delaware Millcreek Pediatrics, a Wilmington, Delaware-based pediatric medical practice, has recently reported a data security incident to the HHS Office for Civil Rights involving the protected health information of 14,095 individuals. Unauthorized access to its network was detected on or around February 25, 2025. A leading digital forensics firm was engaged to investigate the activity, which confirmed unauthorized network access between February 17, 2025, and February 25, 2025. On October 27, 2025, the file review confirmed that protected health information had been exposed, including full names, birth dates, medical record numbers, patient identification numbers, driver’s license numbers/state identification numbers, dates of service, claims information, provider information, and clinical/treatment information. A limited number of the affected individuals also had their Social Security numbers exposed....
Davies, McFarland & Carroll; Awakenings Center Data Breaches Impact 72,500 Individuals
Data breaches have been announced by the medical malpractice law firm Davies, McFarland & Carroll, the sex therapy and couples counseling provider Awakenings Center, and the Maryland healthcare provider, Adventist HealthCare. Davies, McFarland & Carroll, Pennsylvania Davies, McFarland & Carroll LLC, a Pittsburgh, PA-based law firm specializing in medical malpractice, has experienced a significant data breach involving unauthorized access to the sensitive information of 54,712 individuals. Davies, McFarland & Carroll is a business associate of HIPAA-covered entities and is provided with access to protected health information to provide its legal services. On or around May 22, 2025, a network intrusion was detected. External cybersecurity experts were engaged to investigate the incident and confirmed that an unauthorized third party had access to its network from May 19, 2025, to May 22, 2025, during which time files containing sensitive data were either viewed or acquired. The forensic investigation and file review concluded on September 25, 2025, when it was...
Data Breaches Announced by Morton Drug Company & Physicians to Children & Adolescents
Data breaches have been announced by Morton Drug Company in Wisconsin, Physicians to Children & Adolescents in Kentucky, and the Center for Urologic Care of Berks County in Pennsylvania. Across the three incidents, the protected health information of more than 50,000 patients was exposed. Morton Drug Company, Wisconsin Morton Drug Company (Morton LTC), a Wisconsin-based pharmacy specializing in long-term care, has recently disclosed a security incident that has affected 40,051 individuals. The incident impacted its IT systems and was detected on or around August 20, 2025. Third-party cybersecurity experts were engaged to investigate, contain, and remediate the incident, and law enforcement was notified. Unauthorized network access was confirmed, and a review was conducted to determine the extent to which sensitive data had been exposed. On or around October 21, 2025, Morton LTC determined that patient data had been exposed and may have been stolen. The types of data involved vary from individual to individual and may include name in combination with address, prescription...



