News
CareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachOhio Healthcare Software Vendor Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients — Largest HHS Report of 2026 · Data BreachAmgen Patient PHI Stolen via Third-Party Cloud Vendors; Pharmaceutical Giant Discloses Breach in SEC 8-K Filing · Data BreachFour Surgical Centers and Hospitals Disclose Patient Data Breaches: Wildwood, Michigan Surgical, Penobscot Valley, and Whitfield Regional · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachOhio Healthcare Software Vendor Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients — Largest HHS Report of 2026 · Data BreachAmgen Patient PHI Stolen via Third-Party Cloud Vendors; Pharmaceutical Giant Discloses Breach in SEC 8-K Filing · Data BreachFour Surgical Centers and Hospitals Disclose Patient Data Breaches: Wildwood, Michigan Surgical, Penobscot Valley, and Whitfield Regional · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data Breach
resolution agreement

Health Information Privacy: Corrective action / RA

Resolution ,

Penalty

Corrective action / RA

Action type

Resolution agreement

Entity profile

Case number

What went wrong

Health Information Privacy

  • Health Information Privacy I would like info on ... Parental AccessHIPAA Security Rule NPRMConfidentiality of Substance Use Disorder (SUD) Patient RecordsChange Healthcare Cybersecurity Incident-FAQs HIPAA for Individuals We offer information about your rights under HIPAA and answers to frequently asked questions about the HIPAA Rules. Filing a Health Information Privacy Complaint You may file a c

Full description

Health Information Privacy I would like info on ... Parental AccessHIPAA Security Rule NPRMConfidentiality of Substance Use Disorder (SUD) Patient RecordsChange Healthcare Cybersecurity Incident-FAQs HIPAA for Individuals We offer information about your rights under HIPAA and answers to frequently asked questions about the HIPAA Rules. Filing a Health Information Privacy Complaint You may file a complaint with OCR if you believe your health information privacy rights under the HIPAA Rules or the regulations protecting confidentiality of substance use disorder patient records were violated. Substance Use Disorder Patient Confidentiality Find information about the requirements to protect confidentiality of substance use disorder patient records, patient rights, and more. HIPAA for Professionals Find information about the HIPAA Rules, guidance on compliance, OCR's enforcement activities, frequently asked questions, and more. Conscience and Religious Freedom HHS enforces federal laws that protect conscience and the free exercise of religion and prohibit coercion and religious discrimination in health and human services. Civil Rights HHS enforces federal civil rights laws that protect the rights of individuals and entities from unlawful discrimination on the basis of race, color, national origin, disability, age, or sex in health and human services. Office for Civil Rights The Office for Civil Rights (OCR) ensures equal access to certain health and human services and protects the privacy and security of health information. Newsroom Read the latest HIPAA news and bulletins, and an archive of past releases. Other Languages Español (Spanish), 繁體中文 (Chinese - Traditional), 简体中文 (Chinese – Simplified), Tiếng Việt (Vietnamese), 한국어 (Korean), Tagalog (Tagalog), Русский (Russian), العربية (Arabic), Français (French), Português (Portuguese), Kreyòl Ayisyen (French Creole), Polski (Polish), Italiano (Italian), Deutsch (German), 日本語 (Japanese), فارسی (Farsi)

Timeline

  • Resolution,
  • Incident and investigation milestones are not consistently published by OCR in machine-readable form.

Key takeaways for your organization

  • Treat internet-facing systems and vendor-hosted environments as in-scope for HIPAA risk analysis and technical safeguards testing.
  • Pair technical access controls with workforce training, sanctions, and proactive audit reviews for inappropriate access patterns.
  • Maintain an actionable risk analysis tied to remediation milestones; evidence should map to Security Rule implementation specifications.
  • Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.

Related actions

Source

U.S. Department of Health and Human Services release

Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use, not legal advice.