Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


96 entries · newest first · RSS · Atom · browse by tag

CareCloud breach: 3.7 million records exposed in hacking incident

CareCloud, Inc., a business associate based in New Jersey, reported a hacking/IT incident to HHS OCR on July 24, 2026. The breach affected 3,756,469 individuals, with data compromised on a network server. Because CareCloud is a business associate, any healthcare providers, health plans, or other covered entities that use its services may need to verify if their patient data was included in this incident. Organizations should review their contracts and communications from CareCloud to determine exposure. This filing date is when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered.

Saint Pete MRI reports hacking incident affecting 138,209 patients

A Florida-based healthcare provider, MRI Associates of St. Pete, Inc. d/b/a Saint Pete MRI, filed a breach report with HHS OCR on August 19, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 138,209 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

One Medical Group reports hacking incident affecting 153,174 patients

One Medical Group, Inc., a healthcare provider in California, filed a breach report with HHS OCR on July 17, 2026. The filing describes a hacking/IT incident that compromised the protected health information of 153,174 individuals. The breached data was located on a network server. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own vendor contracts and security protocols, as large-scale provider breaches often signal broader industry threats. While this specific incident involves One Medical Group, the scale highlights the ongoing risk of network server vulnerabilities in healthcare IT infrastructure.

Delta Dental of Virginia reports hacking incident affecting 126,953 individuals

A health plan, Delta Dental of Virginia, filed a breach notification with HHS OCR on November 21, 2025. The filing reports a hacking/IT incident that compromised the protected health information of 126,953 individuals. The breached data was located in email systems. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred or was discovered. As a covered entity, the health plan is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected individuals.

Persante Health Care reports hacking incident affecting 111,815 individuals

Persante Health Care, a business associate operating in New Jersey, filed a breach notification with HHS OCR on November 26, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 111,815 individuals. Because Persante is a business associate, this incident likely impacts the covered entities—such as hospitals, clinics, or health plans—that rely on its services. Healthcare administrators should check whether their organization uses Persante’s services and review any communications from the vendor regarding next steps for affected patients. The submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered.

Wound Technology Network reports hacking incident affecting 139,830 patients

A Florida healthcare provider, Wound Technology Network, Inc., filed a breach report with HHS OCR on January 28, 2026. The filing details a hacking/IT incident that compromised the protected health information of 139,830 individuals. The unauthorized access occurred on a network server. As a covered entity, the provider is required to report breaches affecting 500 or more individuals within 60 days of discovery. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape, particularly for providers managing sensitive wound care data. No further details on the specific nature of the data accessed or the timeline of the incident are provided in this summary.

Acadian Ambulance Service reports massive data breach — 2.9 million records affected

Acadian Ambulance Service, Inc., a healthcare provider in Louisiana, filed a report with HHS OCR on August 20, 2024, disclosing a hacking/IT incident. The breach exposed the protected health information of 2,896,985 individuals. The compromised data was stored on a network server. This filing date reflects when the report was submitted to the government, not necessarily when the incident occurred or was discovered. Healthcare administrators should note the scale of this incident as a reminder of the risks associated with network security. While this specific event involves an ambulance service, the underlying vulnerability type is relevant to any organization managing electronic health records.

Business associate Xsolis reports massive hacking incident affecting 1.4 million records

A business associate named Xsolis, Inc. filed a breach report with HHS OCR on June 5, 2026, disclosing a hacking/IT incident that compromised the data of 1,396,519 individuals. The unauthorized access occurred on a network server. Because Xsolis is a business associate, its clients—likely healthcare providers or health plans—may also have reporting obligations to their own patients or members. Administrators should verify if their organization uses Xsolis services and review internal protocols for handling third-party breach notifications. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered.

HealthEquity breach affects 4.3 million — Business Associate filing

HealthEquity, Inc., a Business Associate based in Utah, filed a report with HHS OCR on August 9, 2024, disclosing a hacking/IT incident. The breach impacted the protected health information of 4.3 million individuals. The compromised data was located on a network server. Because HealthEquity is a Business Associate, your organization may be affected if you use its services for health savings accounts or related benefits administration. Review your contracts and incident response plans to understand your obligations when a vendor experiences a security incident. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred.

Business associate breach affects 134,918 individuals — HHS OCR filing

A business associate named Kerber, Eck & Braeckel LLP filed a breach report with HHS OCR on August 16, 2024. The filing covers a hacking/IT incident that compromised data for 134,918 individuals. The breached information was located on a network server. Because this entity is a business associate, your organization may be affected if you contract with them for services handling protected health information. Review your vendor contracts and security logs to determine if you are among the impacted covered entities. This submission date reflects when the report was filed with HHS, not necessarily when the breach occurred or was discovered.

Delta Health System reports hacking incident affecting 216,532 individuals

Delta Health System, a healthcare provider in Mississippi, filed a breach notification with HHS OCR on March 29, 2024. The filing reports a hacking/IT incident that compromised the protected health information of 216,532 individuals. The unauthorized access occurred on a network server. This submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should note this incident as a reminder of the risks associated with network infrastructure vulnerabilities. While this specific event involves a provider in Mississippi, the scale of the breach highlights the importance of monitoring IT security across all covered entities and business associates.

HHS OCR filing: 1.06 million records affected at Connecticut community health center

A Community Health Center, Inc. in Connecticut filed a breach notification with HHS OCR on January 30, 2025. The filing reports that a hacking/IT incident compromised the protected health information of 1,060,936 individuals. The unauthorized access involved data stored on an electronic medical record system and a network server. This submission date marks when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor this case to understand the scale of recent incidents affecting community health providers in the region.

Western Orthopaedics reports hacking incident affecting 113,330 patients

Western Orthopaedics, P.C., a healthcare provider in Colorado, filed a breach notification with HHS OCR on May 1, 2026. The filing reports a hacking/IT incident that compromised the protected health information of 113,330 individuals. The unauthorized access occurred on the organization's network server. This submission date marks when the report was sent to the regulator, not necessarily when the breach occurred or was discovered. As a covered entity, Western Orthopaedics is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should monitor for similar IT incidents and ensure their own incident response plans are current.

Florida medical group reports hacking incident affecting 246,711 patients

A Florida healthcare provider, Medical Associates of Brevard, LLC, has filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on September 5, 2025, indicates that the personal information of 246,711 individuals was compromised. The breach occurred on a network server. As a covered entity, this provider is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

VITAS Hospice reports massive data breach affecting 319,177 individuals

A major hacking/IT incident at VITAS Hospice Services, LLC, a healthcare provider in Florida, has been reported to HHS OCR. The filing, submitted on November 24, 2025, indicates that the personal information of 319,177 individuals was compromised. The breach originated from a network server. As a covered entity, VITAS is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for further details regarding the specific data types exposed, as this large-scale incident highlights the ongoing risks to provider networks.

Brown Health Medical Group-MA reports massive hacking incident affecting 311,760 patients

A healthcare provider in Massachusetts has filed a report with HHS OCR regarding a hacking/IT incident. The entity, operating as Brown Health Medical Group-MA, states that the breach impacted 311,760 individuals. The unauthorized access occurred on a network server. This filing was submitted to the government on July 16, 2026. Healthcare administrators should note that this is a covered entity report, distinct from a business associate filing. While the specific data elements are not detailed here, the scale suggests significant patient data exposure. Monitor for further disclosures from the provider regarding notification timelines and remediation steps.

Business associate breach affects 3.8 million records — Ohio

A Business Associate named Unlimited Technology Systems, LLC reported a hacking/IT incident to HHS OCR on July 21, 2026. The filing indicates that 3,803,750 individuals were affected. The unauthorized access occurred on a network server. Because the entity is a Business Associate, your organization may be impacted if you contract with this vendor for services involving protected health information. Review your vendor contracts and security logs to determine if you are among the affected clients. This submission date is when the report was filed, not necessarily when the breach occurred or was discovered.

Texas Tech El Paso reports hacking incident affecting 815,000 records

A healthcare provider, Texas Tech University Health Sciences Center El Paso, filed a breach report with HHS OCR on November 25, 2024. The filing details a hacking/IT incident involving data stored on a network server. The breach potentially affected 815,000 individuals. As a covered entity, the university health sciences center is required to report such incidents. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should note the scale of this incident as a benchmark for risk assessment in their own operations.

Alabama Ophthalmology Associates reports hacking incident affecting 131,576 patients

A healthcare provider in Alabama has filed a breach notification with HHS OCR. Alabama Ophthalmology Associates reported that a hacking/IT incident compromised the protected health information of 131,576 individuals. The unauthorized access occurred on a desktop computer and a network server. This filing was submitted on April 8, 2025, which is the date the report was received by the regulator, not necessarily the date the breach occurred. As a covered entity, the provider is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar incidents involving network servers and ensure their own incident response plans are current.

Mid America Physician Services reports hacking incident affecting 104,513 individuals

A healthcare provider in Kansas, Mid America Physician Services, filed a breach notification with HHS OCR on January 13, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 104,513 individuals. As a covered entity, the provider is required to report breaches affecting 500 or more people within 60 days of discovery. This submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape for cybersecurity risks targeting provider networks.

Southern Illinois Dermatology reports hacking incident affecting 160,312 patients

A healthcare provider in Illinois has reported a significant data breach to HHS OCR. Southern Illinois Dermatology filed a notice on April 2, 2026, stating that a hacking/IT incident compromised the personal information of 160,312 individuals. The unauthorized access occurred on a network server. This filing date represents when the report was submitted to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own systems for similar vulnerabilities and ensure their incident response plans are current, as large-scale provider breaches often signal broader industry threats.

Anne Arundel Dermatology reports massive data breach — 1.9 million records affected

A healthcare provider in Maryland has reported a significant security incident to HHS OCR. Anne Arundel Dermatology filed a breach notification on July 11, 2025, stating that a hacking/IT incident compromised data on a network server. The filing indicates that 1,905,000 individuals were affected. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. As a covered entity, the dermatology group is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should note the scale of this incident for risk assessment purposes.

Expert MRI reports hacking incident affecting 209,560 patients

A California radiology group, Expert MRI, filed a breach report with HHS OCR on October 31, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, affecting 209,560 individuals. As a healthcare provider, Expert MRI is a covered entity under HIPAA. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected patients.

Florida business associate reports massive hacking breach affecting 279,275 individuals

A Florida-based business associate, Zumpano Patricios, P.A., filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 279,275 individuals, with unauthorized access occurring on a network server. The filing was submitted on July 3, 2025. As a business associate, this entity is bound by HIPAA obligations through its contracts with covered entities. Healthcare administrators should review their vendor contracts to ensure business associates have adequate security measures and breach notification protocols in place. This filing highlights the scale of potential exposure when network servers are compromised.

IPPC Inc. reports hacking incident affecting 133,862 patients

IPPC Inc., IPPC of New York LLC, and Innovative Pharmacy LLC (collectively IPPC) filed a breach report with HHS OCR on February 27, 2026. The New Jersey-based healthcare provider reported a hacking/IT incident involving its network server. The filing indicates that 133,862 individuals were affected by the unauthorized access. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own vendor relationships and security protocols, as large-scale provider breaches often signal broader industry threats.

Harbor healthcare provider reports hacking incident affecting 216,000 patients

A healthcare provider named Harbor has filed a report with HHS OCR regarding a hacking/IT incident. The breach involved unauthorized access to a network server, potentially exposing the protected health information of 216,000 individuals. The filing was submitted on September 30, 2025. As a covered entity, Harbor is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for notifications if their patients may be members of this organization, and review their own vendor contracts to ensure business associates have robust security measures for network servers.

Long Beach City breach: 258,191 records exposed in hacking incident

A healthcare provider operating under the City of Long Beach, CA, reported a hacking/IT incident to HHS OCR on April 14, 2025. The breach affected 258,191 individuals, with data compromised on a network server. This filing date reflects when the report was submitted to regulators, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor this case to understand how large-scale municipal provider breaches are handled. While this specific incident involves a city-run entity, the scale highlights the ongoing risk of server-based attacks. Review your own incident response plans to ensure they can handle mass notification requirements if a similar event impacts your organization.

Retina Group of Florida reports hacking incident affecting 152,691 patients

A healthcare provider, Retina Group of Florida, filed a breach report with HHS OCR on September 3, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server. The breach affected 152,691 individuals. This submission date is when the report was filed with the regulator, not necessarily when the incident occurred or was discovered. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators at other organizations should note the scale of this incident involving a specialist group. Review your own incident response plans to ensure they address server-level compromises. Monitor for further details from the provider regarding the specific types of data exposed.

Modernizing Medicine reports hacking incident affecting nearly 200,000 patients

Business Associate Modernizing Medicine, Inc. filed a breach report with HHS OCR on October 17, 2025, describing a hacking/IT incident involving data on a network server. The filing covers 198,795 individuals. As a Business Associate, Modernizing Medicine provides services to covered entities; if your organisation uses their software, you should verify whether your patient data was among those affected. The submission date is when the report was filed with HHS, not necessarily when the breach occurred or was discovered. This is a reportable event under HIPAA breach notification rules.

Madera Community Hospital reports hacking incident affecting over 150,000 patients

Madera Community Hospital, a healthcare provider in California, filed a breach report with HHS OCR on July 13, 2026. The filing describes a hacking/IT incident involving a network server. The breach potentially exposed the protected health information of 150,810 individuals. This submission date marks when the report was sent to regulators, not when the incident occurred. Healthcare administrators should note the scale of this exposure as a reminder of the risks associated with network server vulnerabilities. While this specific event affects a single provider, it highlights the ongoing threat of cyberattacks in the healthcare sector. Monitor your own systems for similar indicators of compromise.

University of Iowa Health Care reports hacking incident affecting 101,875 individuals

University of Iowa Health Care, a healthcare provider in Iowa, filed a breach notification with HHS OCR on August 29, 2025. The filing reports a hacking/IT incident involving data stored on a network server. The breach potentially affected 101,875 individuals. This submission date marks when the report was sent to the regulator, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor such filings to understand the scale of recent cyber threats facing large provider systems. While this specific incident involves a university health system, it highlights the ongoing risk of server-based attacks that can expose large volumes of patient records. No further details on the specific data types or remediation steps are provided in this summary record.

Alera Group reports hacking incident affecting 155,567 records

Alera Group, Inc., a business associate in Illinois, reported a hacking/IT incident to HHS OCR on July 29, 2025. The breach involved unauthorized access to a network server, exposing the protected health information of 155,567 individuals. As a business associate, Alera Group is required to notify its covered entity clients, who in turn must notify affected patients. Healthcare administrators should verify if their organization contracts with Alera Group and review any notifications received. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered. Monitor communications from vendors to ensure compliance with notification timelines.

Florida business associate reports hacking incident affecting 145,714 individuals

A Florida-based business associate, Operation PAR, Inc., filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on June 25, 2026, indicates that 145,714 individuals were affected. The breach occurred on a network server. Because this entity is a business associate, its covered entities (such as health plans or providers) may need to verify their own notification obligations. Administrators should check if they contract with this vendor and review their business associate agreements for specific reporting requirements.

North Texas Behavioral Health Authority reports hacking incident affecting 285,086 individuals

A healthcare provider, North Texas Behavioral Health Authority, filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on March 6, 2026, indicates that 285,086 individuals were affected. The breach occurred on a network server. As a covered entity, the authority is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

SimonMed Imaging reports massive data breach affecting 1.2 million patients

SimonMed Imaging, a healthcare provider in Arizona, filed a report with HHS OCR on March 27, 2025, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,275,669 individuals. The unauthorized access occurred on a network server. As a covered entity, SimonMed is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

Chord Specialty Dental Partners reports hacking incident affecting 173,430 patients

A dental service organization, Chord Specialty Dental Partners (operated by CDHA Management, LLC and Spark DSO, LLC), filed a breach report with HHS OCR on March 14, 2025. The filing covers a hacking/IT incident involving email systems that exposed the protected health information of 173,430 individuals. As a healthcare provider in Tennessee, the entity is a Covered Entity under HIPAA. Administrators should note that this submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. This incident highlights the ongoing risks associated with email security in dental and specialty care settings.

United of Omaha Life Insurance reports hacking breach affecting 107,894 individuals

United of Omaha Life Insurance Company, a health plan based in Nebraska, filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 107,894 individuals. According to the filing, the compromised information was located in email. The report was submitted to HHS OCR on July 26, 2024. As a covered entity, the health plan is required to report breaches of unsecured protected health information affecting 500 or more individuals. This filing confirms the incident met that threshold. Healthcare administrators should note that email remains a common vector for data exposure. While this specific breach involves a health plan, the incident highlights the ongoing risks associated with email security across the healthcare ecosystem.

Cierant Corporation reports major data breach affecting 232,506 individuals

Cierant Corporation, a Business Associate based in Connecticut, filed a breach report with HHS OCR on July 3, 2025. The filing describes a hacking/IT incident involving a network server that exposed the protected health information of 232,506 individuals. Because Cierant is a Business Associate, this incident likely impacts the healthcare providers and health plans that contract with them. Your organisation should check whether you have a business relationship with Cierant Corporation. If you do, contact their compliance team immediately to understand the specific data involved and any required next steps for your own breach notification obligations.

Escambia Community Clinics reports hacking incident affecting 143,969 patients

Escambia Community Clinics, Inc., operating as Community Health Northwest Florida, filed a breach report with HHS OCR on February 3, 2025. The healthcare provider disclosed that a hacking/IT incident compromised data stored on a network server. The filing indicates that 143,969 individuals were affected by this unauthorized access. As a covered entity, the clinic is required to report breaches of this scale. Administrators at similar community health centers and clinics should review their own server security protocols and incident response plans, noting that submission dates reflect when the report was filed, not necessarily when the breach occurred or was discovered.

Medex Ambulance reports hacking incident affecting 121,190 patients

Medical Express Ambulance Inc., operating as Medex Ambulance in Illinois, filed a breach report with HHS OCR on May 2, 2024. The filing describes a hacking/IT incident where unauthorized access occurred on a network server. The breach potentially exposed the protected health information of 121,190 individuals. As a healthcare provider, Medex is a covered entity under HIPAA. This submission date reflects when the report was sent to regulators, not necessarily when the incident occurred or was discovered. Healthcare administrators should review their own vendor contracts and security protocols to ensure similar network vulnerabilities are addressed.

PIH Health reports massive data breach affecting nearly 3 million patients

Healthcare administrators should note that PIH Health, Inc., a healthcare provider in California, filed a report with HHS OCR for a significant data breach. The filing, submitted on January 31, 2025, indicates that a hacking/IT incident compromised the personal information of 2,947,264 individuals. The unauthorized access occurred on a network server. While this specific filing details the scope of the incident at PIH Health, it serves as a reminder for all covered entities to review their own cybersecurity protocols. This report reflects the submission date to the regulator, not necessarily the date the breach was discovered or announced to patients.

TriZetto Provider Solutions reports massive data breach affecting 3.4 million records

TriZetto Provider Solutions, a business associate serving healthcare providers, reported a hacking/IT incident to HHS OCR. The filing, submitted on February 6, 2026, states that 3,433,965 individuals were affected. The breach occurred on a network server. Because TriZetto is a business associate, your organization may be impacted if you use their services for claims processing or other administrative functions. Review your contracts and contact your vendor management team to confirm whether your entity is among those affected and to understand any required next steps.

University Diagnostic Medical Imaging reports hacking breach affecting 138,080 patients

A New York radiology group, University Diagnostic Medical Imaging, PC, filed a report with HHS OCR on January 21, 2025, disclosing a hacking/IT incident. The breach involved unauthorized access to a network server, exposing the protected health information of 138,080 individuals. As a healthcare provider, the entity is directly responsible for this disclosure. Administrators at imaging centers and hospitals should note the scale of this incident as a benchmark for risk assessment. While the filing date is January 21, 2025, this does not indicate when the breach occurred or was discovered. Monitor for further details on the nature of the data exposed.

Bell Ambulance reports hacking incident affecting 237,830 individuals

Wisconsin-based ambulance provider Bell Ambulance, Inc. filed a breach report with HHS OCR on April 14, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, potentially affecting 237,830 individuals. As a healthcare provider, Bell Ambulance is a covered entity under HIPAA. This submission date reflects when the report was filed, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data types involved and any required notifications to affected individuals.

Deer Oaks Behavioral Health settles HIPAA case for $225,000 after ransomware breach

Deer Oaks – The Behavioral Health Solution, a healthcare provider in Texas, has reached a $225,000 HIPAA settlement with HHS OCR. The agency announced the agreement on July 7, 2025, resolving a case covering two separate incidents: an earlier online exposure of patient discharge summaries caused by a coding error (35 individuals), and a later hacking/IT incident affecting 171,871 individuals. The larger breach filing was submitted on July 31, 2024. OCR's risk-analysis-failure finding spanned both incidents. As part of the resolution, the provider agreed to a two-year corrective action plan. Administrators should review their incident response protocols to ensure they meet regulatory expectations for breach notification and remediation.

#hipaa-settlement#ransomware#enforcement#behavioral-health#data-breach

Insightin Health reports massive data breach affecting nearly 2 million records

Insightin Health, Inc., a business associate based in Maryland, filed a report with HHS OCR on January 16, 2026, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,949,534 individuals. The unauthorized access occurred on a network server. Because Insightin Health is a business associate, your organization may be impacted if you contract with them for services such as claims processing or data analytics. Review your vendor contracts and assess whether you receive data from this entity. If so, contact your legal and compliance teams to determine if you need to notify your own patients or take additional risk mitigation steps.

Summit Pathology reports massive hacking incident affecting 1.8 million patients

Summit Pathology and Summit Pathology Laboratories, Inc., a healthcare provider in Colorado, filed a breach report with HHS OCR on October 18, 2024. The filing covers a hacking/IT incident involving a network server that exposed the protected health information of 1,813,538 individuals. This submission date is when the report was filed with the government, not necessarily when the breach occurred. As a covered entity, Summit Pathology is responsible for notifying affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for notification letters if their patients or staff received pathology services from this organization, as the scale of this incident suggests widespread exposure of sensitive medical data.

Washington radiology group reports massive data breach — 362,713 individuals affected

A Washington-based healthcare provider, Northwest Radiologists, Inc./Mount Baker Imaging, filed a report with HHS OCR regarding a hacking/IT incident. The submission, dated October 28, 2025, indicates that 362,713 individuals were affected. The breach involved unauthorized access to a network server. As a covered entity, this radiology group is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar incidents involving healthcare providers and review their own cybersecurity protocols, though no specific remediation steps are detailed in this filing.

CMS reports hacking incident affecting over 100,000 records

Centers for Medicare & Medicaid Services (CMS) filed a report with HHS OCR on June 30, 2025, disclosing a hacking/IT incident that compromised the data of 107,154 individuals. The breach occurred on a network server. CMS is classified as a Health Plan under HIPAA. Healthcare administrators should note the scale of this federal breach as a benchmark for potential risks to their own systems.

Florida imaging group reports hacking incident affecting 171,862 patients

Doctors Imaging Group, a healthcare provider in Florida, filed a breach report with HHS OCR on September 24, 2025. The filing covers a hacking/IT incident that compromised the personal health information of 171,862 individuals. The unauthorized access occurred on a network server. While this specific incident involves an imaging group, administrators at hospitals, clinics, and health plans should review their own vendor contracts and security monitoring protocols. The submission date marks when the report was filed, not necessarily when the breach occurred or was discovered. Organizations should verify if they share data with this entity or similar providers to assess potential downstream risks.

Pennsylvania eye care group reports hacking incident affecting 200,000 patients

A Pennsylvania-based eye care provider, Tri Century Eye Care PC, filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on October 31, 2025, indicates that the personal information of 200,000 individuals was compromised. The breach originated from a network server. As a healthcare provider, this entity is a covered entity under HIPAA. Administrators should note this as a significant data security event in the ophthalmology sector. The submission date marks when the report was filed with the government, not necessarily when the incident occurred or was discovered. No further details on the specific data types or remediation steps are provided in this initial filing.

University of Iowa Community Home Care reports hacking incident affecting 109,029 individuals

University of Iowa Community Home Care, a healthcare provider, filed a breach report with HHS OCR on August 29, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 109,029 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. This submission date marks when the report was filed, not necessarily when the breach occurred. Healthcare administrators should monitor for similar IT security risks within their own networks and ensure their incident response plans are current.

Ciox Health (Datavant Group) breach: 320,702 individuals affected — email data exposed

If your organisation uses Ciox Health LLC (doing business as Datavant Group) for data services, you may be affected by a significant security incident. This Business Associate reported a hacking/IT incident to HHS OCR on 10/07/2024. The filing lists 320,702 individuals affected. Protected health information was exposed via email. Because Datavant is a Business Associate, your own compliance obligations depend on your specific contract and data flow. Verify if you share data with this entity and review your Business Associate Agreement for notification requirements.

Fieldtex Products breach filing: 104,071 individuals affected

Fieldtex Products, Inc., a Business Associate, filed an HHS OCR breach report on December 12, 2025, citing 104,071 individuals affected by a hacking/IT incident on a network server. This entry reflects the single OCR filing cited below; additional related filings have been reported elsewhere but are not covered by this record. If your organization uses Fieldtex services, review your contracts to understand notification obligations and monitor the OCR portal for further filings.

Hacking incident at South Carolina healthcare provider affects 143,842 individuals

A healthcare provider in South Carolina, Innovative Scientific Solutions, LLC, reported a hacking/IT incident to HHS OCR on April 17, 2026. The breach affected 143,842 individuals after unauthorized access to a network server. This filing date reflects when the report was submitted, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data compromised and any required notifications to affected patients or partners.

Highlands Oncology Group reports hacking breach affecting 111,766 patients

Highlands Oncology Group PA, an oncology practice in Arkansas, filed a breach report with HHS OCR on August 1, 2025. The filing covers a hacking/IT incident involving data stored on a network server. The breach potentially affected 111,766 individuals. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators should note the scale of this incident for risk assessment purposes. The submission date is when the report was filed, not necessarily when the breach occurred or was discovered. No further details were provided in the initial filing.

Nacogdoches Memorial Hospital breach: 2.5M affected per federal record

Nacogdoches Memorial Hospital, a healthcare provider in Texas, filed a breach report with HHS OCR on March 30, 2026, regarding a hacking/IT incident. The OCR portal lists 2,507,073 individuals affected. While some secondary sources cite a lower figure of 257,073, the federal record stands at 2.5 million with no documented correction. The breach involved data stored on a network server. As a covered entity, the hospital is responsible for notifying affected individuals. Healthcare administrators should monitor official notifications from the hospital to understand the specific scope of exposure for their own patients or partners, as the federal filing does not detail the specific types of data compromised.

Brightstar Global Solutions reports massive data breach affecting over 100,000 individuals

Brightstar Global Solutions Corporation, a health plan based in Rhode Island, filed a report with HHS OCR on October 3, 2025, regarding a hacking/IT incident. The breach compromised the protected health information of 103,879 individuals. The unauthorized access occurred on a network server. As a covered entity, Brightstar is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor this case to understand how large-scale cyber incidents are handled by health plans. This filing confirms the breach was reported to regulators; it does not indicate when the incident originally occurred or was discovered.

Florida Physician Specialists reports massive data breach affecting nearly 276,500 patients

A Florida-based healthcare provider named Florida Physician Specialists has filed a report with HHS OCR regarding a significant data breach. The incident, classified as a hacking/IT incident, compromised information stored on a network server. The filing indicates that 276,498 individuals were affected by this security failure. The report was submitted on April 24, 2026. Healthcare administrators should note the scale of this breach, which underscores the risks associated with network server vulnerabilities. While this specific event involves a provider group, the implications for data security practices are relevant to all entities handling protected health information. Monitor your own network defenses and review incident response protocols to ensure preparedness against similar threats.

Philadelphia Corporation for Aging reports massive data breach affecting over 400,000 individuals

A significant security incident has been reported by Philadelphia Corporation for Aging (PCA), a Business Associate operating in Pennsylvania. The organization filed a report with HHS OCR on September 23, 2025, disclosing a hacking/IT incident that compromised data stored on a network server. This breach affects a substantial number of individuals, with 410,491 people impacted. Because PCA is a Business Associate, this incident likely involves the health data of patients from various covered entities, such as clinics or health plans, that contract with them. Healthcare administrators should review their vendor contracts and security protocols to ensure their own Business Associates are maintaining adequate safeguards against cyber threats.

Radiology Associates of Richmond reports massive data breach affecting 266,183 patients

A Virginia-based radiology group, Radiology Associates of Richmond, has filed a report with HHS OCR regarding a significant security incident. The filing, submitted on May 21, 2026, indicates that a hacking/IT incident compromised data stored on a network server. This breach affects a substantial number of individuals, with 266,183 people impacted. As a healthcare provider, the entity is a Covered Entity under HIPAA rules. Administrators should note that this submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered. Given the scale of the incident, this serves as a reminder of the risks associated with network server vulnerabilities in medical imaging and diagnostic settings.

Rocky Mountain Gastroenterology Associates reports massive data breach

A Colorado-based gastroenterology practice has filed a report with HHS OCR regarding a significant data security incident. The filing, submitted on November 13, 2024, indicates that a hacking or IT incident compromised information stored on a network server. This breach affects approximately 366,491 individuals. As a healthcare provider, the entity is required to notify affected patients and report the incident to the government. Healthcare administrators should note the scale of this exposure, which highlights the risks associated with network server vulnerabilities. While this specific event involves a specialty practice, the underlying threat vector is relevant to any organization managing electronic health records.

Centers Lab NJ reports massive data breach affecting over 540,000 patients

A major healthcare provider, Centers Lab NJ LLC, has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking/IT incident targeting a network server, compromising the records of 542,377 individuals. The breach was officially filed on June 18, 2026. Hospital administrators should monitor this case closely as a reminder of the risks associated with network security vulnerabilities. While this specific report does not detail immediate operational changes for other facilities, it underscores the critical need for robust cybersecurity measures to protect patient data from unauthorized access.

Mainline Health Systems reports major data breach affecting over 100,000 patients

Mainline Health Systems Inc in Arkansas has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking or IT incident that compromised information stored on a network server. A total of 101,104 individuals were affected by this security failure. The breach was officially reported on June 23, 2025. Hospital administrators should monitor their own network security protocols and ensure incident response plans are up to date. While this specific event affects Mainline Health Systems, it serves as a reminder of the risks associated with server vulnerabilities. No further details were provided in the initial filing.

Major Data Breach at ATSG, Inc. — Nearly 1 Million Records Compromised

A significant data breach has been reported involving ATSG, Inc., a business associate operating in New York. This incident, classified as a hacking/IT event, compromised the protected health information of 909,469 individuals. The breach occurred on a network server and was reported to the HHS Office for Civil Rights on October 4, 2024. Hospital administrators should review their own business associate agreements to ensure vendors have robust cybersecurity measures. While this specific incident affects ATSG, it serves as a stark reminder of the risks associated with third-party data handling. Monitor your own systems for unusual activity and verify that your partners are compliant with security standards.

Navia Benefit Solutions Breach — 2.15 Million in OCR Filing, ~2.7 Million Total

Navia Benefit Solutions, Inc., a Washington-based business associate for employee benefits (FSA, HSA, HRA, COBRA, DCAP), reported a hacking/IT incident to HHS OCR on March 18, 2026. The filing lists 2,151,330 individuals affected, but external reports from the Maine Attorney General and other sources cite a total of approximately 2,697,540 individuals. The breach involved data on a network server and other locations. Because Navia serves employers rather than hospitals, health plans, self-insured employers, and benefits administrators should verify if they use Navia. If so, review your vendor contracts and assess potential exposure to your members or employees. This filing date is when the report was submitted to OCR, not when the breach occurred.

VectraRx Mail Pharmacy Breach — 109,383 Affected, Hacking Incident

VectraRx Mail Pharmacy Services, LLC, a Healthcare Provider based in Arizona, reported a hacking/IT incident affecting 109,383 individuals. The breach involved data stored on a network server. The report was submitted to HHS OCR on February 6, 2025. This filing is relevant to healthcare administrators and vendors who interact with mail-order pharmacies or share data with similar entities. Because VectraRx is classified as a Covered Entity, this incident highlights risks for providers managing their own patient data systems. Administrators should review their own vendor management protocols to ensure partners maintain robust cybersecurity measures, particularly for systems handling large volumes of patient data. The primary source record does not confirm whether patient notifications have been sent or if credit monitoring was offered, nor does it indicate the incident is resolved.

#data-breach#hacking#mail-pharmacy#covered-entity#cybersecurity

Central Kentucky Radiology reports hacking incident affecting 166,953 individuals

Central Kentucky Radiology, a physician-owned radiology group in Kentucky, filed a breach notification with HHS OCR on June 13, 2025. The filing reports a hacking/IT incident that compromised a network server, exposing the protected health information of 166,953 individuals. While the submission date is June 2025, secondary sources indicate the underlying incident occurred in October 2024. Healthcare administrators, particularly those running imaging practices, diagnostic labs, or provider networks, should note this risk profile. This event highlights the vulnerability of network servers to unauthorized access. Review your own incident response plans and ensure your IT teams are monitoring for similar vulnerabilities. Verify that your security protocols align with current best practices for protecting patient data in digital health environments.

Primary source: HHS OCR Breach Portal

Coastal Carolina Health Care reports major data breach affecting over 110,000 patients

Coastal Carolina Health Care, PA in North Carolina has reported a significant data breach to the Department of Health and Human Services. The incident involved a hacking or IT incident targeting a network server. This breach affects 110,304 individuals, exposing their protected health information. The report was submitted on March 24, 2026. Hospital administrators should review their own cybersecurity protocols to ensure similar vulnerabilities are not present in their systems. While this specific incident is contained to Coastal Carolina Health Care, it serves as a reminder of the ongoing risks posed by cyber threats to healthcare networks. Ensure your IT teams are monitoring for unusual activity and that incident response plans are up to date.

Frederick Health reports massive data breach affecting nearly 1 million patients

Frederick Health in Maryland has reported a significant cybersecurity incident to the Department of Health and Human Services. The breach involved a hacking or IT incident targeting a network server, exposing the protected health information of 934,326 individuals. This filing was submitted on March 28, 2025. Hospital administrators should monitor this case closely as a benchmark for large-scale incident response. While this specific event is reported, it serves as a reminder to review your own network security protocols and ensure your incident response plans are current and tested.

Primary source: HHS OCR Breach Portal

Laurel Eye Clinic reports massive data breach affecting over 145,000 patients

Laurel Eye Clinic in Pennsylvania has reported a significant cybersecurity incident to the HHS Office for Civil Rights. The breach involved a hacking or IT incident targeting the clinic's network server. This event potentially exposed the protected health information of 145,221 individuals. The report was submitted on April 22, 2026. Hospital administrators should review their own network security protocols to ensure similar vulnerabilities are addressed. While this specific incident is contained to one provider, it highlights the ongoing risk of server-based attacks in healthcare settings. Ensure your IT teams are monitoring for unauthorized access and that incident response plans are up to date.

Liberty Resources reports hacking incident affecting 103,711 individuals

Liberty Resources, Inc., a healthcare provider in New York, submitted a breach report to HHS OCR on March 4, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server, affecting 103,711 individuals. As a covered entity, Liberty Resources must notify affected individuals and HHS OCR. This incident highlights the risk of server-based attacks for any organization handling protected health information. Healthcare administrators should review their own cybersecurity protocols to ensure network servers are secure against similar attacks.

Primary source: HHS OCR Breach Portal

Radiology group reports 1.4M-record breach; second incident status unclear

Radiology Associates of Richmond, Inc., a Virginia-based healthcare provider, filed a breach notification with HHS OCR on July 1, 2025, reporting a hacking/IT incident affecting 1,419,091 individuals. The data was accessed from a network server. This entity has since disclosed a second, separate breach involving 266,183 individuals, stemming from an incident on or about July 25, 2025. This subsequent disclosure was reported to the Maine Attorney General on May 21, 2026. However, claims that this second breach has appeared on HHS OCR's public breach portal are unsupported by primary sources and contradicted by contemporaneous reporting stating it had not yet appeared. The HHS OCR record for the initial filing indicates no business associate was involved. Administrators should monitor the OCR portal for updates on both incidents.

Richmond Behavioral Health Authority reports major data breach — 113,232 records compromised

Richmond Behavioral Health Authority in Virginia has reported a significant data breach affecting 113,232 individuals. The incident, classified as a hacking or IT incident, involved unauthorized access to a network server. The report was submitted to HHS OCR on November 28, 2025. Hospital administrators should monitor this case to understand how large-scale server breaches are being handled and reported. While this specific event affects a behavioral health provider, the scale highlights the ongoing risk to network infrastructure across all healthcare sectors. Ensure your own IT security protocols are robust and that your breach response plan is current.

Sandhills Medical Foundation reports hacking incident — 169,017 individuals affected

Sandhills Medical Foundation, a healthcare provider in South Carolina, reported a data breach to HHS OCR. The incident is classified as a hacking/IT incident, with data compromised on a network server. A total of 169,017 individuals were affected. The report was submitted on September 14, 2025. This filing highlights risks for providers and other covered entities. Administrators should review their own incident response plans. Ensure your breach notification procedures are current and ready for immediate deployment if a similar incident occurs at your organisation.

Veradigm breach filing — settlement finalized, but check entity names

Veradigm LLC, a healthcare IT vendor classified as a Business Associate, reported a hacking/IT incident affecting 2,672,036 individuals. The HHS OCR record lists the submission date as September 22, 2025. Because Veradigm is a Business Associate, your organization’s obligations depend on your specific Business Associate Agreement and whether your patients’ data was involved. Review your contracts to understand liability and support responsibilities. Do not assume automatic notification duties; verify if your facility uses Veradigm services. Note that the related class action Goodrum v. Veradigm, Inc. has reached a final settlement. Payments for approved claims were issued on June 12, 2026, and uncashed checks void after September 10, 2026. Crucially, the OCR filing names Veradigm LLC, while the lawsuit names Veradigm, Inc.. These are distinct legal entities. Check your contracts for the exact legal entity name to ensure proper compliance.

#breach#business-associate#hacking#settlement#entity-name

Absolute Dental Group breach — $3.3M settlement, final hearing July 30

A filing for Absolute Dental Group, LLC in Nevada lists the entity as a Business Associate. The HHS OCR record, submitted on May 2, 2025, reports 1,223,635 individuals affected by a hacking/IT incident on a network server. A $3.3 million class action settlement received preliminary court approval on March 6, 2026. The Final Approval Hearing is set for Thursday, July 30, 2026, per the official settlement administrator site. (The court docket entry, Doc. 92, reads "Thursday, July 31" — July 31 is a Friday, and every other source gives July 30, so the docket appears to contain a clerical error.) If your organization contracts with this dental group, confirm the date with the settlement administrator.

#breach#business-associate#class-action-settlement#dental-services#hacking-incident

Dameron Hospital reports major data breach affecting over 210,000 patients

Dameron Hospital in California has reported a significant data breach to HHS OCR. The incident involved a hacking or IT incident that compromised information stored on a network server. This breach affects 210,706 individuals, making it a large-scale event that hospital administrators should monitor for potential industry-wide trends. The filing was submitted on April 2, 2025. While this specific report does not detail the exact data types exposed, the scale suggests a serious security failure. Administrators should review their own server security protocols and ensure incident response plans are current. This is a confirmed breach, not a proposal, and highlights the ongoing risk of cyberattacks on healthcare infrastructure.

Major Data Breach at Specialty Networks — Over 411,000 Records Compromised

A significant hacking/IT incident has been reported involving Specialty Networks, Inc., a business associate located in Tennessee. The breach affected the personal health information of 411,037 individuals. The compromised data was stored on a network server. This incident was reported to the HHS Office for Civil Rights on August 15, 2024. Hospital administrators should review their contracts with business associates to ensure robust cybersecurity measures are in place. If your facility uses Specialty Networks, verify their security protocols and confirm that any shared data was protected. This is a confirmed breach, not a proposal, highlighting the ongoing risks of digital health records.

Massive Data Breach at Conduent Business Services — 62 Million Records Compromised

A major breach has been reported involving Conduent Business Services LLC, a business associate operating in New Jersey. This incident, classified as a hacking/IT incident, compromised the data of approximately 62.2 million individuals. The unauthorized access occurred on a network server. Hospital administrators should verify if their organization uses Conduent for services such as billing, claims processing, or other administrative support. If you do, contact your vendor management team immediately to assess potential risks to your patient data. Even if you are not a direct client, the scale of this breach highlights the critical need to review your own cybersecurity protocols and ensure all business associates have robust security measures in place to protect sensitive health information.

Hacking incident at NC healthcare provider affects 106,194 individuals

A hacking/IT incident at Hillcrest Convalescent Center, Inc., a healthcare provider in North Carolina, has been reported to HHS OCR. The filing, submitted on March 4, 2025, indicates that data stored on a network server was compromised. This breach affects 106,194 individuals. Because the source record provides no web description, the specific types of data involved are not detailed here. Healthcare administrators should note this incident as a reminder to verify their own incident response plans and server security protocols. This is a confirmed report from a covered entity classified as a healthcare provider.

Primary source: HHS OCR Breach Portal

Right now you can demand an 'AI model card' from your EHR vendor — but that right may be going away

Two things every hospital should know about the AI built into their EHR. First: under a federal rule (HTI-1) that became fully enforceable this past February, your certified EHR vendor must disclose how its predictive AI tools work — what data trained them, who they're meant for, known risks, and how they were validated. That's 31 required disclosure items, often called an "AI model card." You can ask your vendor for this today, and they're required to have it. Second: the same federal office has proposed repealing exactly that requirement (the HTI-5 proposal, December 2025), arguing there's no evidence the disclosures improved care. Public comments closed February 27, 2026; no final decision has been published yet. Practical advice: if these model cards are useful to your AI purchasing decisions, request them from your vendors now, while the requirement is still in force.

#federal#onc#ehr#decision-support#transparency#nprm

Alabama: starting October 1, AI can't be the one denying coverage — a clinician must decide

Alabama's new law (signed April 17, 2026, effective October 1, 2026) says a health insurer can't rely only on AI to decide whether care gets covered — any decision to deny or reduce coverage has to be made by a qualified healthcare professional. Insurers must also tell enrollees that AI is used in coverage decisions, base prior-auth determinations on the individual patient's medical history rather than group data alone, and certify annually to the state that their AI is monitored for accuracy and doesn't discriminate. If you're in Alabama, this is leverage: after October 1, an AI-only denial is something you can push back on by law.

The White House wants to override state AI laws — the state rules you follow may be challenged

A December 2025 executive order (EO 14365) directs the federal government to push back on state AI laws it considers burdensome — including a Justice Department task force to challenge them in court, and reviews by Commerce and the FTC identifying which state laws conflict with federal policy. What this means for you: the state AI rules covered in this feed (Texas, Colorado, Indiana, Alabama, and others) are valid law today and you should keep complying — but some may end up challenged in court over the next year or two. Don't un-build your compliance program based on headlines; do expect uncertainty about which state rules survive.

If you buy AI-powered medical devices: the FDA's big rulebook for them is still in draft

The FDA has authorized over a thousand AI-enabled medical devices, but its first comprehensive rulebook for how these devices should be designed, validated, and monitored over their whole life — published as a draft in January 2025 — has still not been finalized. Why a hospital should care: once final, it will shape what documentation and ongoing performance monitoring you can demand from device vendors, especially for AI tools whose behavior changes with updates. Reasonable ask of vendors today: whether they're already building to the draft guidance rather than waiting.

#fda#federal#medical-devices#samd

Georgia (from January 2027): AI can help insurers process paperwork, but can't say no to care

Georgia's SB 444, effective January 1, 2027, draws a clean line: insurers may use AI in prior authorization to automate paperwork and reduce administrative burden — but an adverse decision (denying or reducing care) can't be issued until a qualified clinical peer has actually conducted the review and participated in the decision. The AI also can't override that clinician's judgment. If you operate in Georgia, nothing changes today, but this is worth having on your 2027 compliance calendar now.

Primary source: SB 444 — legis.ga.gov

Utah now requires insurers to say when AI reviews your preauthorization requests

Utah's SB 319, in effect since May 6, 2026, requires insurers to publicly post their preauthorization requirements on their website and to disclose whether AI is used when reviewing authorization requests. It also sets a maximum time insurers can take to answer an authorization request, and sets minimum periods an approval stays valid. Practical upshot for your utilization and scheduling teams: approvals should be faster to get and harder to have silently expire — and you can now find out whether a Utah payer is using AI on your requests just by asking.

Colorado pushed back its AI law deadline again — here's the date that matters now

Colorado's AI law (requirements around AI systems not discriminating against patients) now takes effect June 30, 2026 — pushed back from its original February date. A companion healthcare-specific rule adds a plain but important protection: your staff can't let an AI system be the sole reason a patient's coverage or care is denied. A human still has to be involved in that decision.

A federal cloud-security update is already in effect — check your vendor contracts

The federal government's rulebook for approving cloud software (FedRAMP) got a major overhaul, and it's already active as of July 4, 2026 — not something coming later this year. The old "Low/Moderate/High" security tiers are gone, replaced by new tiers called Classes A through D. If any of your software vendors handle government-adjacent data or claim FedRAMP approval, it's worth asking them directly whether they've moved to the new system, since some requirements become mandatory before January 1, 2027.

#fedramp#federal#cloud-compliance
Primary source: fedramp.gov/2026

No, HIPAA does not yet require encryption everywhere — that's still just a proposal

You may have heard that HIPAA now requires encrypting all patient data. It doesn't — not yet. Federal regulators proposed making encryption mandatory (it's currently just "recommended"), but that proposal has not been finalized into law as of this writing. There's no deadline to comply with yet. Once it is finalized, organizations would get 60 days before it takes effect and 240 days after that to actually comply — so there will be advance warning. Worth watching, not worth panicking about yet.

Texas actually has two AI laws, not one — and it's easy to miss the second

If you operate in Texas, there are two separate AI laws to know about, not one. The first, HB 149, is the broad rulebook for how AI systems can be used — it's been in effect since January 1, 2026. The second, SB 1188, is narrower but easy to overlook: it requires your staff to tell patients when AI was used in their diagnosis or treatment. That one has actually been in effect longer, since September 1, 2025. If your compliance team only checked the first law, you may already be missing a disclosure requirement that's been live for almost a year.

Indiana's new AI insurance law just took effect — insurers can't downcode your claims by AI alone

As of July 1, 2026, health insurers in Indiana can no longer use AI as the only basis to downcode a claim (pay it at a lower level than billed) — a human must review the patient's medical record first. Insurers also now have to disclose, in plain view, whenever AI was used to deny a prior authorization or downcode a claim. Two things for your team: your billing office should start watching downcoded claims for the required disclosures, and note the law cuts both ways — providers also can't submit claims generated by AI without a person involved in the claim reviewing them. Appeals get at least 180 days.

#indiana#state-law#claims#downcoding#prior-authorization
Primary source: HB 1271 — iga.in.gov

Reminder: paper records still count as a reportable breach, not just hacking

The most recent breach filed with federal regulators, on July 1, 2026, affected 8,157 people at the Wisconsin Department of Health Services — and it wasn't a computer hack at all. It involved paper and film records. Easy to forget when most breach news is about hackers: mishandled physical records are still a reportable breach, and still something your front-desk and records-handling procedures need to guard against.

#data-breach#paper-records#wisconsin#state-agency

Even small specialty clinics are being hacked — not just big hospital systems

Minnesota Epilepsy Group, a single-specialty outpatient practice, reported a hacking incident affecting 80,061 patients on June 5, 2026. The takeaway for any smaller or specialty practice: attackers aren't only targeting big hospital networks or national insurers. If your organization is smaller, that is not protection — you're still a target, and this-size breach is common.

#data-breach#hacking#specialty-practice#minnesota

A major AI vendor used for hospital coverage decisions was hacked — 1.4 million patients affected

Xsolis — a company whose AI software helps hospitals and health plans decide whether a patient's stay or treatment gets approved — reported a hacking incident affecting 1,396,519 people on June 5, 2026. Why this one matters beyond the number: this isn't just a generic IT vendor, it's a vendor making decisions about patient care. If your hospital uses Xsolis or a similar utilization-review AI tool, this is worth a direct conversation with that vendor about what happened and whether your patients' data was involved.

#data-breach#hacking#ai-vendor#utilization-management#tennessee

New federal AI-security order: free cyber-defense tools may be coming to hospitals

A second AI executive order (EO 14409, signed June 2, 2026 — separate from the December order about overriding state laws) focuses on AI and cybersecurity. The part that matters for hospitals: the federal cyber agency CISA was given 30 days to expand AI-powered defensive tools and make them easier to access for critical infrastructure operators — which includes healthcare. Treasury is also standing up a clearinghouse for coordinating vulnerability detection and fixes. Nothing here requires you to do anything; it's a potential resource. Worth having your IT/security lead watch CISA's announcements over the coming weeks for new tools or programs your organization can enroll in. The order does not add licensing requirements for AI, and it says nothing about healthcare regulation or state-law preemption.