Data Breach
U.K.-based healthcare billing software maker Craneware disclosed that hackers stole a significant volume of customer, employee, and partner data from its systems. Here is what compliance officers need to know now.
Updated Jul 21, 20266 min read
Data Breach
The Qilin ransomware group listed Hillebrand Home Health on its dark web leak site on July 14, 2026. Here is what compliance officers and home health administrators need to know right now.
Updated Jul 15, 20265 min read
Data Breach
A Minnesota hospital system notified patients more than 14 months after an unauthorized party accessed its network, exposing Social Security numbers, medical records, and financial data. Here is what compliance teams need to know.
Updated Jul 14, 20266 min read
Data Breach
Family Health Centers of Southern Indiana disclosed a January 2026 network intrusion that exposed patient names, dates of birth, Social Security numbers, medical information, and health insurance data. The five-month gap between detection and public disclosure raises serious questions about HIPAA breach notification compliance.
Updated Jul 7, 20265 min read
Data Breach
The Texas Hearing Institute in Houston notified at least 29,498 individuals after the Interlock ransomware group claimed a March 2026 attack exfiltrated 540 GB of data including Social Security numbers, financial records, and medical information.
Updated Jul 7, 20265 min read
Data Breach
Wisconsin DHS reported a HIPAA breach to OCR after benefit increase letters for 8,157 Medicaid SSI recipients were mailed to outdated addresses. Learn what this means for HIPAA breach notification obligations at government-run health programs.
Updated Jul 7, 20265 min read
Data Breach
ShinyHunters claimed responsibility for a June 2026 breach of One Medical Seniors legacy systems, threatening to expose a reported 8.8 terabytes of archived patient records. Here is what compliance officers need to know about HIPAA obligations that survive acquisitions.
Updated Jun 28, 20267 min read
Data Breach
OpenLoop Health, a white-label telehealth infrastructure vendor and business associate to numerous digital health companies, disclosed a January 2026 breach in which an unauthorized party removed data from its systems. Here is what covered entities and their compliance teams need to know.
Updated Jun 25, 20268 min read
Data Breach
A January 2026 phishing attack on AI utilization management vendor Xsolis exposed 1.4 million patient records across seven hospital systems. The breach also raises a serious HIPAA notification timing question: Xsolis reportedly waited 135 days before notifying HHS, well beyond the 60-day rule for business associates.
Updated Jun 24, 20267 min read
Data Breach
Kettering Health declined to pay the Interlock ransomware group. The attackers leaked the stolen data, exposing roughly 1.7 million people, including passports and plaintext credentials. Why refusing to pay does not change your HIPAA obligations, and what the breach reveals.
Updated Jun 18, 20267 min read
Data Breach
A ransomware attack on Conduent, a business process vendor serving health plans and government programs, started as a 4-million-person breach and grew into one of the largest in U.S. history. What it means for every health plan and covered entity that relies on a vendor.
Updated Jun 12, 20267 min read
Data Breach
A third-party vendor breach at NYC Health + Hospitals exposed roughly 1.8 million records from late November 2025 through February 2026, including biometric data such as fingerprints and palm prints. The Senate HELP Committee is now pressing the health system for answers.
Updated Jun 9, 20266 min read
Data Breach
NYC Health + Hospitals, Erie Family Health, and other large breaches recently posted to the HHS 'Wall of Shame' share one root cause: a third-party vendor. What the supply-chain breach pattern means for your practice, and what to do about it.
Updated Jun 9, 20267 min read
Data Breach
A complete guide to HIPAA breach response — from the moment of discovery through notification to HHS, individuals, and media. Includes the four-factor risk assessment, deadlines, and role-specific responsibilities.
Updated May 11, 202612 min read
Data Breach
When a breach happens, the clock starts immediately. A plain-English guide to who you must notify, the 60-day deadline, and the four-factor risk assessment, with CFR citations.
Updated May 11, 202610 min read
Data Breach
What to do in the first 60 days after a breach: assess, document, notify individuals and HHS, and avoid the mistakes that turn a breach into a penalty.
Updated May 11, 20261 min read