Veradigm to Pay $10.5M to Settle Class Action Data Breach Lawsuit
The healthcare technology company Veradigm Inc. (formerly Allscripts) has agreed to settle a class action lawsuit that was filed in response to a 2024 data breach that compromised sensitive patient data. The Illinois-based company provides software tools to healthcare organizations, including electronic medical record software and practice management tools. In December 2024, cybercriminals accessed its network and potentially obtained patient data belonging to its healthcare clients. More than 2 million patients were affected. Data compromised in the incident included names, contact information, dates of birth, health record information, insurance claim data, payment information, and other identifiers, such as Social Security numbers and copies of their driver’s licenses. The first class action lawsuit in response to the data breach was filed in June 2025 by plaintiffs Tony Goodrum and Jason Mixton, individually and on behalf of similarly situated individuals. A second class action lawsuit was subsequently filed, and the two actions were consolidated into a single action in the...
Valley Eye Associates Confirms Patient Data Stolen in Ransomware Attack
Valley Eye Associates has fallen victim to a ransomware attack in which sensitive patient data was exfiltrated from its network. Imperial Beach Community Clinic has started notifying patients about unauthorized access to its email environment. Valley Eye Associates, Wisconsin Valley Eye Associates, an ophthalmology, optometry, and LASIK eye surgery center in Appleton, WI, has recently announced that it fell victim to a ransomware attack on or around October 8, 2025. Third-party cybersecurity specialists were engaged to assist with the investigation and determined that the ransomware group had access to its network between October 8, 2025, and October 9, 2025, during which time files were exfiltrated from its network. While data was stolen, Valley Eye Associates said there are no indications that the stolen data has been or will be used inappropriately. It is unclear how that determination was made. The ransomware group behind the attack was not mentioned in the breach notice, although the Qilin ransomware group claimed responsibility for the attack and published the stolen data,...
How Often is HIPAA Training Required?
HIPAA training is required when a new staff member joins the workforce, when there is a material change to their role or the policies and procedures that apply to their role, when a risk analysis identifies a need for HIPAA training, and when a staff member violates a policy or procedure for which the sanction is further training. HIPAA training may also be required as part of a corrective action plan agreed with the HHS’ Office for Civil Rights. In addition, HIPAA security and awareness training must be ongoing and provided to all members of the workforce at regular intervals. The training must be provided in accordance with the HIPAA Security Rule’s General Requirements and developed to protect against any reasonably anticipated uses and disclosures of Protected Health Information (PHI) not permitted by the HIPAA Privacy Rule. Training topics must be reinforced between training sessions via periodic security reminders. HIPAA Training for Employees Our training provides employees with a clear and practical understanding of what to do and why in real-world HIPAA scenarios. View...
What is HIPAA Incident Management?
HIPAA incident management is the process of tracking, responding to, and documenting HIPAA security incidents as they are detected by automated security tools or reported by members of the workforce. An effective HIPAA incident management process not only supports compliance with the Administrative Safeguards of the HIPAA Security Rule, but it can also help identify gaps in an organization’s security defenses. All HIPAA covered entities and business associates are required to have procedures in place for identifying and responding to suspected or known security incidents, mitigating any harmful effects of the incidents, and documenting the incidents and their outcomes (§164.308(a)(6)). It is also necessary for covered entities and business associates to implement procedures to regularly review security incident tracking reports (§164.308(a)(1)). However, the HIPAA Security Rule allows covered entities and business associates to be flexible in how they comply with these Administrative Safeguards. The degree of flexibility depends on an organization’s size, complexity, and...
What are the Duties of a HIPAA Compliance Officer?
A HIPAA Compliance Officer is an individual who has been designated the role of HIPAA Privacy Officer and/or assigned responsibility for compliance with the HIPAA Security Rule. The individual may be an existing employee, a new member of the workforce, or an outsourced partner assigned the role of HIPAA Compliance Officer on a temporary or permanent basis. The duties of the HIPAA Compliance Officer depend on multiple factors. These factors include whether the HIPAA Compliance Officer has been designated the HIPAA Privacy Officer, the HIPAA Security Officer, or both. The duties also depend on the size of the organization, the nature of its operations, other roles performed by the individual, and whether duties are delegated to members of a Compliance Team. The following sections outline the duties of each role and provide a consolidated job description suitable for covered entities, business associates, and compliance leaders. It is recommended to implement HIPAA compliance software at smaller organizations where responsibility for HIPAA normally falls to an administrator or...



