HIPAA Compliance for Urgent Care Clinics
Due to the emotions that can manifest during emergency events, HIPAA compliance and urgent care do not go hand-in-hand, providing a challenge for urgent care clinics. It can also be the case that shortcuts are taken with compliance during emergency events in order to administer urgent care as quickly as possible. These factors can lead to multiple HIPAA violations, and staff dealing with emergencies need standard HIPAA training and also additional HIPAA training for emergency situations. There has been an increasing amount of research done into the role of emotions in clinical decision-making and patient safety in urgent care settings. The conclusions tend to be that more needs to be done via training initiatives “to promote awareness of emotional influences and consider strategies for managing these influences”. While HIPAA compliance does not have the same importance as optimizing patient safety, it too can be influenced by emotions. This is especially true in the context of HIPAA compliance and urgent care due to the serious nature of injuries treated in urgent care environments...
Main Line Fertility Center Settles Tracking Technology Lawsuit
Main Line Fertility Center in Pennsylvania will pay cash payments to individuals whose sensitive data may have been disclosed to third parties via website tracking technologies. Like many healthcare providers, Main Line Fertility Center deployed third-party tracking tools and analytics code on its public website, including Meta Pixel. While these tools can provide valuable data to website owners, their use is problematic in healthcare due to the potential for sensitive data to be transferred to the providers of those tools. Depending on how and where these tools are deployed, they can potentially transfer personally identifiable and health information to those third parties. In the case of Main Line Fertility Center, it was alleged to have used these tools without patients’ knowledge or consent, resulting in individually identifiable information being transferred to third parties, such as Meta. Anonymous plaintiff Jane Doe filed a lawsuit – Jane Doe v. Main Line Fertility, Ltd. – in the Court of Common Pleas of Philadelphia County, Pennsylvania, alleging the use of these...
Data Breaches Announced by Ennoble Care & Circa Health; Dermatology Associates of Concord
Data breaches have recently been announced by Ennoble Care & Circa Health in New Jersey and Dermatology Associates of Concord in Massachusetts. Ennoble Care/Circa Health, New Jersey Ennoble Care & Circa Health, LLC, a Hackensack, NJ-based provider of primary care, palliative care, and hospice services to individuals in Georgia, Kansas, Maryland, New York, New Jersey, Oklahoma, Pennsylvania, Virginia, and Washington, D.C., has announced an email account breach that was identified on April 17, 2025. Ennoble Care said the investigation into the incident is ongoing; however, it has been determined that patient information has been exposed and may have been obtained by an unauthorized individual. The types of information involved include names, addresses, dates of birth, hospice status, status dates, and orders status (CTI, SN, MSW, CH, HHA, etc.). No evidence was found to indicate that its cloud-based electronic health record was compromised. While no evidence has been found to indicate misuse of the exposed data, the affected individuals have been advised to remain vigilant...
Data Breaches Announced by Heritage Communities & Metrocare Services
The senior living company Heritage Communities and the Dallas mental health care company Metrocare Services have announced security incidents that exposed sensitive patient data. Heritage Communities, Nebraska Heritage Communities, a senior living company based in Omaha, Nebraska, has recently announced a breach of the personal and protected health information of current and former residents. The data breach affected the company Heritage Holdings LP, a business associate of Heritage Communities, Orchard Pointe, and OnCare Health. On or around September 16, 2025, a network intrusion was identified, and third-party cybersecurity experts were engaged to investigate the incident. The investigation confirmed that an unauthorized actor gained access to its network and a limited amount of protected health information. The forensic investigation could not rule out the possibility that sensitive data was exfiltrated from its network. The review of the affected data confirmed that a range of data types were exposed, including first and last names, Social Security numbers, driver’s license...
North Kansas City Hospital Patients Affected by Cerner Hacking Incident
North Kansas City Hospital has notified patients about a January 2025 data breach at its EHR vendor Cerner. Data breaches have also been announced by Shasta County Health and Human Services and OncoHealth in Georgia. North Kansas City Hospital, Missouri North Kansas City (NKC) Hospital in Missouri issued a substitute breach notice on November 25, 2025, announcing a data breach at its electronic medical record (EHR) vendor. A hacker gained access to a legacy Cerner (now Oracle Health) server that was awaiting migration to the Oracle Cloud infrastructure. According to Oracle Health, the hacker gained access to the server as early as January 22, 2025, and exfiltrated data, including the personal health information of NKC Hospital patients. NKC Hospital stressed that none of its own systems were compromised in the incident, as the breach was limited to two legacy Cerner servers. The HIPAA Journal first reported on the Oracle Health data breach in March 2025, and in the months following the announcement, several healthcare providers have issued notifications confirming that they have...



