News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

All insights

HIPAA compliance insights

Deep dives mapped to the Privacy, Security, and Breach Notification Rules, written for operators who need plain-English explanations, CFR citations, and practical checklists.

Try: BAA, Security Rule, breach notification, PHI, OCR enforcement

Data Breach

Optalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands

Optalis Management Solutions, a Michigan-based skilled nursing and rehabilitation management company, notified 13,723 individuals of unauthorized network access occurring April 14–19, 2025. At least one additional entity disclosed an email breach exposing sensitive patient data. Neither incident is an OCR enforcement action, and no fines have been announced.

Updated Aug 14, 20265 min read

Data Breach

Family Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers

Family Health Centers of Southern Indiana disclosed a January 2026 network intrusion that exposed patient names, dates of birth, Social Security numbers, medical information, and health insurance data. The five-month gap between detection and public disclosure raises serious questions about HIPAA breach notification compliance.

Updated Jul 7, 20265 min read

Data Breach

How to Respond to a HIPAA Breach — A Step-by-Step Guide

A complete guide to HIPAA breach response — from the moment of discovery through notification to HHS, individuals, and media. Includes the four-factor risk assessment, deadlines, and role-specific responsibilities.

Updated May 11, 202612 min read

Data Breach

HIPAA Breach Notification Overview

What to do in the first 60 days after a breach: assess, document, notify individuals and HHS, and avoid the mistakes that turn a breach into a penalty.

Updated May 11, 20261 min read

Security Rule

The HIPAA Security Rule: A Complete Guide for 2026

Everything covered entities and business associates need to know about the HIPAA Security Rule: administrative, physical, and technical safeguards explained.

Updated Apr 21, 20266 min read

SaaS & Technology

HIPAA for SaaS and technology vendors

When HIPAA applies to software companies, how BAAs fit product roadmaps, and which Security Rule themes customers audit most often.

Updated Apr 13, 20264 min read

Security Rule

HIPAA Security Rule overview for compliance teams

A structured overview of the HIPAA Security Rule, administrative, physical, and technical safeguards, with CFR anchors and practical implementation notes.

Updated Apr 12, 20265 min read

Privacy Rule

What counts as PHI under HIPAA?

Understand Protected Health Information (PHI), the 18 identifiers, limited data sets, and the Safe Harbor method for de-identification, with regulatory citations.

Updated Apr 10, 20265 min read