Data Breach
U.K.-based healthcare billing software maker Craneware disclosed that hackers stole a significant volume of customer, employee, and partner data from its systems. Here is what compliance officers need to know now.
Updated Jul 21, 20266 min read
Data Breach
The Qilin ransomware group listed Hillebrand Home Health on its dark web leak site on July 14, 2026. Here is what compliance officers and home health administrators need to know right now.
Updated Jul 15, 20265 min read
Data Breach
A Minnesota hospital system notified patients more than 14 months after an unauthorized party accessed its network, exposing Social Security numbers, medical records, and financial data. Here is what compliance teams need to know.
Updated Jul 14, 20266 min read
Data Breach
Family Health Centers of Southern Indiana disclosed a January 2026 network intrusion that exposed patient names, dates of birth, Social Security numbers, medical information, and health insurance data. The five-month gap between detection and public disclosure raises serious questions about HIPAA breach notification compliance.
Updated Jul 7, 20265 min read
Data Breach
The Texas Hearing Institute in Houston notified at least 29,498 individuals after the Interlock ransomware group claimed a March 2026 attack exfiltrated 540 GB of data including Social Security numbers, financial records, and medical information.
Updated Jul 7, 20265 min read
Data Breach
Wisconsin DHS reported a HIPAA breach to OCR after benefit increase letters for 8,157 Medicaid SSI recipients were mailed to outdated addresses. Learn what this means for HIPAA breach notification obligations at government-run health programs.
Updated Jul 7, 20265 min read
Data Breach
ShinyHunters claimed responsibility for a June 2026 breach of One Medical Seniors legacy systems, threatening to expose a reported 8.8 terabytes of archived patient records. Here is what compliance officers need to know about HIPAA obligations that survive acquisitions.
Updated Jun 28, 20267 min read
Data Breach
OpenLoop Health, a white-label telehealth infrastructure vendor and business associate to numerous digital health companies, disclosed a January 2026 breach in which an unauthorized party removed data from its systems. Here is what covered entities and their compliance teams need to know.
Updated Jun 25, 20268 min read
Data Breach
A January 2026 phishing attack on AI utilization management vendor Xsolis exposed 1.4 million patient records across seven hospital systems. The breach also raises a serious HIPAA notification timing question: Xsolis reportedly waited 135 days before notifying HHS, well beyond the 60-day rule for business associates.
Updated Jun 24, 20267 min read
Analysis
OCR's HIPAA breach portal is running months behind schedule, still posting March 2026 breaches in late June. Here is what the lag means for covered entities tracking business associate risk.
Updated Jun 19, 20265 min read
OCR Enforcement
Deer Oaks, a behavioral health provider, made patient discharge summaries publicly accessible online, exposing names, dates of birth, and diagnoses. OCR's $225,000 settlement is a warning about accidental public exposure and the special sensitivity of behavioral health data.
Updated Jun 18, 20266 min read
Data Breach
Kettering Health declined to pay the Interlock ransomware group. The attackers leaked the stolen data, exposing roughly 1.7 million people, including passports and plaintext credentials. Why refusing to pay does not change your HIPAA obligations, and what the breach reveals.
Updated Jun 18, 20267 min read
OCR Enforcement
OCR reached a $450,000 settlement with an employer-sponsored group health plan after a 2021 ransomware attack exposed PHI for more than 10,000 plan members. Here is what HR leaders and benefits plan administrators need to know.
Updated Jun 18, 20267 min read
Analysis
The share of healthcare breaches involving a business associate doubled in a year, from 15% to 30%. Halfway through 2026, the data explains why the biggest breaches keep starting at vendors, and what covered entities should do about it.
Updated Jun 17, 20267 min read
Data Breach
A ransomware attack on Conduent, a business process vendor serving health plans and government programs, started as a 4-million-person breach and grew into one of the largest in U.S. history. What it means for every health plan and covered entity that relies on a vendor.
Updated Jun 12, 20267 min read
Data Breach
A third-party vendor breach at NYC Health + Hospitals exposed roughly 1.8 million records from late November 2025 through February 2026, including biometric data such as fingerprints and palm prints. The Senate HELP Committee is now pressing the health system for answers.
Updated Jun 9, 20266 min read
Data Breach
NYC Health + Hospitals, Erie Family Health, and other large breaches recently posted to the HHS 'Wall of Shame' share one root cause: a third-party vendor. What the supply-chain breach pattern means for your practice, and what to do about it.
Updated Jun 9, 20267 min read
Business Associates
Cloud storage, email, EHR software, billing, AI tools, IT support: which of your vendors actually require a HIPAA Business Associate Agreement? A clear, plain-English decision guide with a vendor-by-vendor breakdown.
Updated Jun 8, 20266 min read
OCR Enforcement
Cadia Healthcare posted patient names, photos, and treatment details as 'success stories' on their public website without HIPAA authorization. OCR's investigation found 150 patients affected and fined the facility group $182,000. Here is what every healthcare marketing team needs to know.
Updated Jun 1, 20267 min read
OCR Enforcement
BST and Co. CPAs, a New York public accounting firm, settled with OCR for a ransomware breach affecting patient financial data. The case is a warning for every professional services firm that handles healthcare client data.
Updated May 31, 20266 min read
OCR Enforcement
OCR fined MMG Fusion just $10,000 for exposing 15 million patients' data — the company has since dissolved. The real story is what this means for every dental practice that trusted them with patient data.
Updated May 31, 20266 min read
Rule Update
OCR announced new offices focused on religious discrimination and anti-Christian bias on May 19, 2026 — raising serious questions about whether HIPAA breach enforcement will receive less attention as resources shift to administration priorities.
Updated May 22, 20266 min read
Rule Update
OCR's director told HIMSS 2026 that inaction is the real risk. The enforcement signals from the address and what they mean for your compliance program.
Updated May 20, 20264 min read
Rule Update
A HITECH Act provision requires HHS to share HIPAA civil money penalties with individuals harmed by violations. OCR is now seeking comment on how to implement it. Here is what the proposed program would mean for patients, covered entities, and compliance programs.
Updated May 19, 20267 min read
Rule Update
OCR reorganized into three new divisions. What the restructuring means for HIPAA enforcement priorities and what healthcare organizations should expect.
Updated May 15, 20264 min read
OCR Enforcement
Top of the World Ranch Treatment Center paid $103,000 to settle HIPAA violations after a 2023 phishing attack exposed patient records. OCR found the center had never completed a HIPAA Security Rule risk analysis.
Updated May 15, 20264 min read
OCR Enforcement
OCR's 54th Right of Access enforcement action settled with Concentra Inc. for $112,500 after a patient had to make six separate records requests over more than a year before receiving access to his health information.
Updated May 14, 20266 min read
Rule Update
OCR's regulatory agenda listed May 2026 as the target for the HIPAA Security Rule final rule. The month is here and no announcement has been made. Here is where things stand and what covered entities should do right now.
Updated May 14, 20265 min read
Rule Update
What the reproductive health privacy rule requires, who it affects, and where it stands now after the latest legal developments. Plain-English breakdown with citations.
Updated May 12, 20266 min read
OCR Enforcement
Warby Parker's HIPAA penalty came down to one overlooked requirement. Here is what happened, what OCR actually fined them for, and how to avoid the same mistake.
Updated May 12, 20266 min read
Data Breach
A complete guide to HIPAA breach response — from the moment of discovery through notification to HHS, individuals, and media. Includes the four-factor risk assessment, deadlines, and role-specific responsibilities.
Updated May 11, 202612 min read
Data Breach
When a breach happens, the clock starts immediately. A plain-English guide to who you must notify, the 60-day deadline, and the four-factor risk assessment, with CFR citations.
Updated May 11, 202610 min read
Data Breach
What to do in the first 60 days after a breach: assess, document, notify individuals and HHS, and avoid the mistakes that turn a breach into a penalty.
Updated May 11, 20261 min read
Analysis
Every HIPAA requirement in one checklist: risk assessment, training, BAAs, breach procedures, and safeguards. Built for small practices that need to get compliant without the legalese.
Updated May 11, 20269 min read
OCR Enforcement
OCR has now resolved more than 50 HIPAA enforcement actions in 2026 under its Risk Analysis and Right of Access initiatives. A new enforcement focus on parental access to minor records adds a third priority area every practice must understand.
Updated May 11, 20266 min read
OCR Enforcement
What OCR actually asks for in an audit, the documents to have ready now, and the gaps that trigger findings. A practical preparation guide for healthcare organizations.
Updated May 11, 20269 min read
Rule Update
A complete guide to all eight patient rights under the HIPAA Privacy Rule — what each right requires, how to respond correctly, and the timelines your practice must meet.
Updated May 11, 20268 min read
Rule Update
OCR's proposed HIPAA Security Rule overhaul faces fierce industry opposition — including a coalition of over 100 hospital systems calling for its withdrawal. Here is the full picture of what is proposed, who is fighting it, and what covered entities should actually do while the outcome remains uncertain.
Updated May 11, 20267 min read
Analysis
A complete guide to HIPAA workforce training requirements under the Privacy Rule and Security Rule — who must be trained, what training must cover, how often it must occur, and how to document it for OCR.
Updated May 11, 20267 min read
Rule Update
The most significant update to the HIPAA Security Rule since 2013 is on the verge of finalization. Here is what the proposed changes require and what every covered entity and business associate must do to prepare.
Updated May 8, 20267 min read
OCR Enforcement
HHS published updated HIPAA civil money penalty amounts effective January 2026. Here are the current figures for all four violation tiers and what they mean for your compliance program.
Updated May 8, 20266 min read
OCR Enforcement
An employer health plan drew a $245K HIPAA penalty. What went wrong, why employee PHI is a blind spot, and what plan sponsors need to know.
Updated May 5, 20266 min read
OCR Enforcement
OCR's settlement with Assured Imaging highlights two compounding violations: no risk analysis ever conducted and delayed breach notification. Here is what every covered entity must learn from this case.
Updated May 3, 20265 min read
Rule Update
OCR's new authority over 42 CFR Part 2 changes the rules for substance use disorder records. What providers must do differently, and the first enforcement signals.
Updated May 3, 20266 min read
Rule Update
OCR has formally expanded its enforcement initiative beyond risk analysis to include risk management. Here is exactly what changed, what OCR is now looking for, and the specific steps every covered entity and business associate must take.
Updated Apr 30, 20266 min read
OCR Enforcement
OCR announced four simultaneous HIPAA settlements on April 23, 2026 totaling $1.165 million following ransomware investigations. All four failed the same requirement.
Updated Apr 30, 20265 min read
Security Rule
Everything covered entities and business associates need to know about the HIPAA Security Rule: administrative, physical, and technical safeguards explained.
Updated Apr 21, 20266 min read
SaaS & Technology
When HIPAA applies to software companies, how BAAs fit product roadmaps, and which Security Rule themes customers audit most often.
Updated Apr 13, 20264 min read
Security Rule
A structured overview of the HIPAA Security Rule, administrative, physical, and technical safeguards, with CFR anchors and practical implementation notes.
Updated Apr 12, 20265 min read
Privacy Rule
Understand Protected Health Information (PHI), the 18 identifiers, limited data sets, and the Safe Harbor method for de-identification, with regulatory citations.
Updated Apr 10, 20265 min read
BAA
A complete guide to HIPAA Business Associate Agreements, who needs one, what it must include, and how to get one signed.
Updated Apr 11, 20266 min read