Is Saying Someone Died a HIPAA Violation?
In answer to the question is saying someone died a HIPAA violation, it depends on who is making the statement, who the statement is made to, and what other information is disclosed with the statement. Saying someone died can be a HIPAA violation, but – as this blog discusses – in most cases it is not. Among other purposes, the HIPAA Privacy Rule protects the privacy of individually identifiable health information relating to the past, present, or future health condition of an individual. Organizations subject to the HIPAA Privacy Rule – and their workforces – must comply with this requirement with respect to a deceased individual “for a period of 50 years following the death of the individual”. However, not all organizations are subject to the HIPAA Privacy Rule. If, for example, an employee of a private nursing home which does not qualify as a HIPAA “covered entity” revealed somebody had died, it is not a HIPAA violation because the nursing home is not required to protect the privacy of individually identifiable health information (Note: although this might not be a violation of...
Monroe University: 320,000 Individuals Affected by December 2024 Cyberattack
Monroe University, a for-profit university with campuses in the Bronx and La Rochelle in New York, and Saint Lucia in the Caribbean, has recently confirmed that a cyberattack has resulted in unauthorized access to the personal and health information of approximately 320,973 individuals. The cyberattack was detected more than a year ago on December 23, 2024. When the intrusion was detected, immediate action was taken to secure its systems to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized third party had access to its network from December 9, 2024, to December 23, 2024, and exfiltrated files containing sensitive data. It has taken nine months to review the affected files to determine the individuals affected and the types of data involved. On September 30, 2025, Monroe University confirmed that the data compromised in the incident included names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, government...
HIPAA for Therapists
When discussing HIPAA for therapists, it is important to be aware that a therapist can be a solo covered entity, a hybrid covered entity, part of an affiliated covered entity, part of an Organized Health Care Arrangement, a business associate to a covered entity, or an employee of any of the above. Even when none of these options apply, therapists may still need to comply with HIPAA-style privacy, security, and breach notification requirements mandated by state legislation. When is a Therapist a Solo Covered Entity? A therapist is a solo covered entity under HIPAA when they work independently of other healthcare providers and conduct transactions electronically for which the Department of Health and Human Services (HHS) has adopted standards. The standards can be found in Part 162 of the HIPAA Administrative Simplification Regulations and relate to processes such as eligibility checks for treatment, authorizations for treatment, and billing for treatment when payment is made by a health plan. A therapist qualifies as a solo covered entity whether or not they conduct the...
Tens of Thousands of Patients Affected by Two Business Associate Data Breaches
Mid Michigan Medical Billing Service, a Flint, MI-based revenue cycle management company that provides billing support services to HIPAA-covered entities, has fallen victim to a cyberattack that exposed the sensitive data of patients of its healthcare clients. Suspicious network activity was identified on March 27, 2025, and the forensic investigation confirmed that an unauthorized third party accessed and copied data from its network. The affected data was reviewed to determine the types of information involved and the affected individuals. Mid Michigan Medical Billing Service then notified the affected covered entity clients and worked with them to provide notice to the affected individuals. The Qilin ransomware group claimed responsibility for the attack. The file review confirmed that the protected health information of 28,185 individuals had been exposed in the cyberattack. The compromised data varied from individual to individual and may have included names in combination with one or more of the following: date of birth, driver’s license/ government issued identification...
Is Google Workspace HIPAA Compliant?
Google Workspace is HIPAA compliant for services that have “included functionality”, provided HIPAA-covered organizations subscribe to a Workspace Plan that supports HIPAA compliance and configure the services to comply with the HIPAA Security Rule. To make Google Workspace HIPAA compliant, it is also necessary to agree to Google’s Business Associate Addendum (BAA) to the Terms of Service Agreement. Google Workspace – formally known as G Suite – is a collection of productivity and communication services. The services can be used independently or integrated with each other to streamline workflows and enhance collaboration. Workspace is a popular choice for organizations in the healthcare industry because most users already have experience of services such as Gmail and Drive. Most other Workspace services have familiar controls and are intuitive to use. However, most organizations in the healthcare industry are required to comply with HIPAA. HIPAA is a federal law which led to the development of privacy and security standards for “Protected Health Information” (PHI). The...



