96 entries · newest first · RSS · Atom · browse by tag
2026-08-24
RECENT
Hacking/IT incident
CareCloud, Inc., a business associate based in New Jersey, reported a hacking/IT incident to HHS OCR on July 24, 2026. The breach affected 3,756,469 individuals, with data compromised on a network server. Because CareCloud is a business associate, any healthcare providers, health plans, or other covered entities that use its services may need to verify if their patient data was included in this incident. Organizations should review their contracts and communications from CareCloud to determine exposure. This filing date is when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered.
2026-08-24
RECENT
Hacking/IT incident
A Florida-based healthcare provider, MRI Associates of St. Pete, Inc. d/b/a Saint Pete MRI, filed a breach report with HHS OCR on August 19, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 138,209 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.
2026-08-17
RECENT
Hacking/IT incident
One Medical Group, Inc., a healthcare provider in California, filed a breach report with HHS OCR on July 17, 2026. The filing describes a hacking/IT incident that compromised the protected health information of 153,174 individuals. The breached data was located on a network server. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own vendor contracts and security protocols, as large-scale provider breaches often signal broader industry threats. While this specific incident involves One Medical Group, the scale highlights the ongoing risk of network server vulnerabilities in healthcare IT infrastructure.
2026-08-15
RECENT
Hacking/IT incident
A health plan, Delta Dental of Virginia, filed a breach notification with HHS OCR on November 21, 2025. The filing reports a hacking/IT incident that compromised the protected health information of 126,953 individuals. The breached data was located in email systems. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred or was discovered. As a covered entity, the health plan is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected individuals.
2026-08-15
RECENT
Hacking/IT incident
Persante Health Care, a business associate operating in New Jersey, filed a breach notification with HHS OCR on November 26, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 111,815 individuals. Because Persante is a business associate, this incident likely impacts the covered entities—such as hospitals, clinics, or health plans—that rely on its services. Healthcare administrators should check whether their organization uses Persante’s services and review any communications from the vendor regarding next steps for affected patients. The submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered.
2026-08-15
RECENT
Hacking/IT incident
A Florida healthcare provider, Wound Technology Network, Inc., filed a breach report with HHS OCR on January 28, 2026. The filing details a hacking/IT incident that compromised the protected health information of 139,830 individuals. The unauthorized access occurred on a network server. As a covered entity, the provider is required to report breaches affecting 500 or more individuals within 60 days of discovery. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape, particularly for providers managing sensitive wound care data. No further details on the specific nature of the data accessed or the timeline of the incident are provided in this summary.
2026-08-14
RECENT
Hacking/IT incident
Acadian Ambulance Service, Inc., a healthcare provider in Louisiana, filed a report with HHS OCR on August 20, 2024, disclosing a hacking/IT incident. The breach exposed the protected health information of 2,896,985 individuals. The compromised data was stored on a network server. This filing date reflects when the report was submitted to the government, not necessarily when the incident occurred or was discovered. Healthcare administrators should note the scale of this incident as a reminder of the risks associated with network security. While this specific event involves an ambulance service, the underlying vulnerability type is relevant to any organization managing electronic health records.
2026-08-14
RECENT
Hacking/IT incident
A business associate named Xsolis, Inc. filed a breach report with HHS OCR on June 5, 2026, disclosing a hacking/IT incident that compromised the data of 1,396,519 individuals. The unauthorized access occurred on a network server. Because Xsolis is a business associate, its clients—likely healthcare providers or health plans—may also have reporting obligations to their own patients or members. Administrators should verify if their organization uses Xsolis services and review internal protocols for handling third-party breach notifications. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered.
2026-08-13
RECENT
Hacking/IT incident
HealthEquity, Inc., a Business Associate based in Utah, filed a report with HHS OCR on August 9, 2024, disclosing a hacking/IT incident. The breach impacted the protected health information of 4.3 million individuals. The compromised data was located on a network server. Because HealthEquity is a Business Associate, your organization may be affected if you use its services for health savings accounts or related benefits administration. Review your contracts and incident response plans to understand your obligations when a vendor experiences a security incident. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred.
2026-08-12
RECENT
Hacking/IT incident
A business associate named Kerber, Eck & Braeckel LLP filed a breach report with HHS OCR on August 16, 2024. The filing covers a hacking/IT incident that compromised data for 134,918 individuals. The breached information was located on a network server. Because this entity is a business associate, your organization may be affected if you contract with them for services handling protected health information. Review your vendor contracts and security logs to determine if you are among the impacted covered entities. This submission date reflects when the report was filed with HHS, not necessarily when the breach occurred or was discovered.
2026-08-12
RECENT
Hacking/IT incident
Delta Health System, a healthcare provider in Mississippi, filed a breach notification with HHS OCR on March 29, 2024. The filing reports a hacking/IT incident that compromised the protected health information of 216,532 individuals. The unauthorized access occurred on a network server. This submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should note this incident as a reminder of the risks associated with network infrastructure vulnerabilities. While this specific event involves a provider in Mississippi, the scale of the breach highlights the importance of monitoring IT security across all covered entities and business associates.
2026-08-12
RECENT
Hacking/IT incident
A Community Health Center, Inc. in Connecticut filed a breach notification with HHS OCR on January 30, 2025. The filing reports that a hacking/IT incident compromised the protected health information of 1,060,936 individuals. The unauthorized access involved data stored on an electronic medical record system and a network server. This submission date marks when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor this case to understand the scale of recent incidents affecting community health providers in the region.
2026-08-12
RECENT
Hacking/IT incident
Western Orthopaedics, P.C., a healthcare provider in Colorado, filed a breach notification with HHS OCR on May 1, 2026. The filing reports a hacking/IT incident that compromised the protected health information of 113,330 individuals. The unauthorized access occurred on the organization's network server. This submission date marks when the report was sent to the regulator, not necessarily when the breach occurred or was discovered. As a covered entity, Western Orthopaedics is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should monitor for similar IT incidents and ensure their own incident response plans are current.
2026-08-11
RECENT
Hacking/IT incident
A Florida healthcare provider, Medical Associates of Brevard, LLC, has filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on September 5, 2025, indicates that the personal information of 246,711 individuals was compromised. The breach occurred on a network server. As a covered entity, this provider is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.
2026-08-11
RECENT
Hacking/IT incident
A major hacking/IT incident at VITAS Hospice Services, LLC, a healthcare provider in Florida, has been reported to HHS OCR. The filing, submitted on November 24, 2025, indicates that the personal information of 319,177 individuals was compromised. The breach originated from a network server. As a covered entity, VITAS is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for further details regarding the specific data types exposed, as this large-scale incident highlights the ongoing risks to provider networks.
2026-08-10
RECENT
Hacking/IT incident
A healthcare provider in Massachusetts has filed a report with HHS OCR regarding a hacking/IT incident. The entity, operating as Brown Health Medical Group-MA, states that the breach impacted 311,760 individuals. The unauthorized access occurred on a network server. This filing was submitted to the government on July 16, 2026. Healthcare administrators should note that this is a covered entity report, distinct from a business associate filing. While the specific data elements are not detailed here, the scale suggests significant patient data exposure. Monitor for further disclosures from the provider regarding notification timelines and remediation steps.
2026-08-10
RECENT
Hacking/IT incident
A Business Associate named Unlimited Technology Systems, LLC reported a hacking/IT incident to HHS OCR on July 21, 2026. The filing indicates that 3,803,750 individuals were affected. The unauthorized access occurred on a network server. Because the entity is a Business Associate, your organization may be impacted if you contract with this vendor for services involving protected health information. Review your vendor contracts and security logs to determine if you are among the affected clients. This submission date is when the report was filed, not necessarily when the breach occurred or was discovered.
2026-08-10
RECENT
Hacking/IT incident
A healthcare provider, Texas Tech University Health Sciences Center El Paso, filed a breach report with HHS OCR on November 25, 2024. The filing details a hacking/IT incident involving data stored on a network server. The breach potentially affected 815,000 individuals. As a covered entity, the university health sciences center is required to report such incidents. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should note the scale of this incident as a benchmark for risk assessment in their own operations.
2026-08-09
RECENT
Hacking/IT incident
A healthcare provider in Alabama has filed a breach notification with HHS OCR. Alabama Ophthalmology Associates reported that a hacking/IT incident compromised the protected health information of 131,576 individuals. The unauthorized access occurred on a desktop computer and a network server. This filing was submitted on April 8, 2025, which is the date the report was received by the regulator, not necessarily the date the breach occurred. As a covered entity, the provider is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar incidents involving network servers and ensure their own incident response plans are current.
2026-08-09
RECENT
Hacking/IT incident
A healthcare provider in Kansas, Mid America Physician Services, filed a breach notification with HHS OCR on January 13, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 104,513 individuals. As a covered entity, the provider is required to report breaches affecting 500 or more people within 60 days of discovery. This submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape for cybersecurity risks targeting provider networks.
2026-08-09
RECENT
Hacking/IT incident
A healthcare provider in Illinois has reported a significant data breach to HHS OCR. Southern Illinois Dermatology filed a notice on April 2, 2026, stating that a hacking/IT incident compromised the personal information of 160,312 individuals. The unauthorized access occurred on a network server. This filing date represents when the report was submitted to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own systems for similar vulnerabilities and ensure their incident response plans are current, as large-scale provider breaches often signal broader industry threats.
2026-08-08
RECENT
Hacking/IT incident
A healthcare provider in Maryland has reported a significant security incident to HHS OCR. Anne Arundel Dermatology filed a breach notification on July 11, 2025, stating that a hacking/IT incident compromised data on a network server. The filing indicates that 1,905,000 individuals were affected. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. As a covered entity, the dermatology group is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should note the scale of this incident for risk assessment purposes.
2026-08-08
RECENT
Hacking/IT incident
A California radiology group, Expert MRI, filed a breach report with HHS OCR on October 31, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, affecting 209,560 individuals. As a healthcare provider, Expert MRI is a covered entity under HIPAA. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected patients.
2026-08-08
RECENT
Hacking/IT incident
A Florida-based business associate, Zumpano Patricios, P.A., filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 279,275 individuals, with unauthorized access occurring on a network server. The filing was submitted on July 3, 2025. As a business associate, this entity is bound by HIPAA obligations through its contracts with covered entities. Healthcare administrators should review their vendor contracts to ensure business associates have adequate security measures and breach notification protocols in place. This filing highlights the scale of potential exposure when network servers are compromised.
2026-08-08
RECENT
Hacking/IT incident
IPPC Inc., IPPC of New York LLC, and Innovative Pharmacy LLC (collectively IPPC) filed a breach report with HHS OCR on February 27, 2026. The New Jersey-based healthcare provider reported a hacking/IT incident involving its network server. The filing indicates that 133,862 individuals were affected by the unauthorized access. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own vendor relationships and security protocols, as large-scale provider breaches often signal broader industry threats.
2026-08-07
RECENT
Hacking/IT incident
A healthcare provider named Harbor has filed a report with HHS OCR regarding a hacking/IT incident. The breach involved unauthorized access to a network server, potentially exposing the protected health information of 216,000 individuals. The filing was submitted on September 30, 2025. As a covered entity, Harbor is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for notifications if their patients may be members of this organization, and review their own vendor contracts to ensure business associates have robust security measures for network servers.
2026-08-07
RECENT
Hacking/IT incident
A healthcare provider operating under the City of Long Beach, CA, reported a hacking/IT incident to HHS OCR on April 14, 2025. The breach affected 258,191 individuals, with data compromised on a network server. This filing date reflects when the report was submitted to regulators, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor this case to understand how large-scale municipal provider breaches are handled. While this specific incident involves a city-run entity, the scale highlights the ongoing risk of server-based attacks. Review your own incident response plans to ensure they can handle mass notification requirements if a similar event impacts your organization.
2026-08-07
RECENT
Hacking/IT incident
A healthcare provider, Retina Group of Florida, filed a breach report with HHS OCR on September 3, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server. The breach affected 152,691 individuals. This submission date is when the report was filed with the regulator, not necessarily when the incident occurred or was discovered. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators at other organizations should note the scale of this incident involving a specialist group. Review your own incident response plans to ensure they address server-level compromises. Monitor for further details from the provider regarding the specific types of data exposed.
2026-08-06
RECENT
Hacking/IT incident
Business Associate Modernizing Medicine, Inc. filed a breach report with HHS OCR on October 17, 2025, describing a hacking/IT incident involving data on a network server. The filing covers 198,795 individuals. As a Business Associate, Modernizing Medicine provides services to covered entities; if your organisation uses their software, you should verify whether your patient data was among those affected. The submission date is when the report was filed with HHS, not necessarily when the breach occurred or was discovered. This is a reportable event under HIPAA breach notification rules.
2026-08-05
RECENT
Hacking/IT incident
Madera Community Hospital, a healthcare provider in California, filed a breach report with HHS OCR on July 13, 2026. The filing describes a hacking/IT incident involving a network server. The breach potentially exposed the protected health information of 150,810 individuals. This submission date marks when the report was sent to regulators, not when the incident occurred. Healthcare administrators should note the scale of this exposure as a reminder of the risks associated with network server vulnerabilities. While this specific event affects a single provider, it highlights the ongoing threat of cyberattacks in the healthcare sector. Monitor your own systems for similar indicators of compromise.
2026-08-05
RECENT
Hacking/IT incident
University of Iowa Health Care, a healthcare provider in Iowa, filed a breach notification with HHS OCR on August 29, 2025. The filing reports a hacking/IT incident involving data stored on a network server. The breach potentially affected 101,875 individuals. This submission date marks when the report was sent to the regulator, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor such filings to understand the scale of recent cyber threats facing large provider systems. While this specific incident involves a university health system, it highlights the ongoing risk of server-based attacks that can expose large volumes of patient records. No further details on the specific data types or remediation steps are provided in this summary record.
2026-08-04
RECENT
Hacking/IT incident
Alera Group, Inc., a business associate in Illinois, reported a hacking/IT incident to HHS OCR on July 29, 2025. The breach involved unauthorized access to a network server, exposing the protected health information of 155,567 individuals. As a business associate, Alera Group is required to notify its covered entity clients, who in turn must notify affected patients. Healthcare administrators should verify if their organization contracts with Alera Group and review any notifications received. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered. Monitor communications from vendors to ensure compliance with notification timelines.
2026-08-04
RECENT
Hacking/IT incident
A Florida-based business associate, Operation PAR, Inc., filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on June 25, 2026, indicates that 145,714 individuals were affected. The breach occurred on a network server. Because this entity is a business associate, its covered entities (such as health plans or providers) may need to verify their own notification obligations. Administrators should check if they contract with this vendor and review their business associate agreements for specific reporting requirements.
2026-08-04
RECENT
Hacking/IT incident
A healthcare provider, North Texas Behavioral Health Authority, filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on March 6, 2026, indicates that 285,086 individuals were affected. The breach occurred on a network server. As a covered entity, the authority is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.
2026-08-04
RECENT
Hacking/IT incident
SimonMed Imaging, a healthcare provider in Arizona, filed a report with HHS OCR on March 27, 2025, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,275,669 individuals. The unauthorized access occurred on a network server. As a covered entity, SimonMed is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.
2026-08-03
RECENT
Hacking/IT incident
A dental service organization, Chord Specialty Dental Partners (operated by CDHA Management, LLC and Spark DSO, LLC), filed a breach report with HHS OCR on March 14, 2025. The filing covers a hacking/IT incident involving email systems that exposed the protected health information of 173,430 individuals. As a healthcare provider in Tennessee, the entity is a Covered Entity under HIPAA. Administrators should note that this submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. This incident highlights the ongoing risks associated with email security in dental and specialty care settings.
2026-08-03
RECENT
Hacking/IT incident
United of Omaha Life Insurance Company, a health plan based in Nebraska, filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 107,894 individuals. According to the filing, the compromised information was located in email. The report was submitted to HHS OCR on July 26, 2024. As a covered entity, the health plan is required to report breaches of unsecured protected health information affecting 500 or more individuals. This filing confirms the incident met that threshold. Healthcare administrators should note that email remains a common vector for data exposure. While this specific breach involves a health plan, the incident highlights the ongoing risks associated with email security across the healthcare ecosystem.
2026-08-02
RECENT
Hacking/IT incident
Cierant Corporation, a Business Associate based in Connecticut, filed a breach report with HHS OCR on July 3, 2025. The filing describes a hacking/IT incident involving a network server that exposed the protected health information of 232,506 individuals. Because Cierant is a Business Associate, this incident likely impacts the healthcare providers and health plans that contract with them. Your organisation should check whether you have a business relationship with Cierant Corporation. If you do, contact their compliance team immediately to understand the specific data involved and any required next steps for your own breach notification obligations.
2026-08-02
RECENT
Hacking/IT incident
Escambia Community Clinics, Inc., operating as Community Health Northwest Florida, filed a breach report with HHS OCR on February 3, 2025. The healthcare provider disclosed that a hacking/IT incident compromised data stored on a network server. The filing indicates that 143,969 individuals were affected by this unauthorized access. As a covered entity, the clinic is required to report breaches of this scale. Administrators at similar community health centers and clinics should review their own server security protocols and incident response plans, noting that submission dates reflect when the report was filed, not necessarily when the breach occurred or was discovered.
2026-08-02
RECENT
Hacking/IT incident
Medical Express Ambulance Inc., operating as Medex Ambulance in Illinois, filed a breach report with HHS OCR on May 2, 2024. The filing describes a hacking/IT incident where unauthorized access occurred on a network server. The breach potentially exposed the protected health information of 121,190 individuals. As a healthcare provider, Medex is a covered entity under HIPAA. This submission date reflects when the report was sent to regulators, not necessarily when the incident occurred or was discovered. Healthcare administrators should review their own vendor contracts and security protocols to ensure similar network vulnerabilities are addressed.
2026-08-02
RECENT
Hacking/IT incident
Healthcare administrators should note that PIH Health, Inc., a healthcare provider in California, filed a report with HHS OCR for a significant data breach. The filing, submitted on January 31, 2025, indicates that a hacking/IT incident compromised the personal information of 2,947,264 individuals. The unauthorized access occurred on a network server. While this specific filing details the scope of the incident at PIH Health, it serves as a reminder for all covered entities to review their own cybersecurity protocols. This report reflects the submission date to the regulator, not necessarily the date the breach was discovered or announced to patients.
2026-08-02
RECENT
Hacking/IT incident
TriZetto Provider Solutions, a business associate serving healthcare providers, reported a hacking/IT incident to HHS OCR. The filing, submitted on February 6, 2026, states that 3,433,965 individuals were affected. The breach occurred on a network server. Because TriZetto is a business associate, your organization may be impacted if you use their services for claims processing or other administrative functions. Review your contracts and contact your vendor management team to confirm whether your entity is among those affected and to understand any required next steps.
2026-08-02
RECENT
Hacking/IT incident
A New York radiology group, University Diagnostic Medical Imaging, PC, filed a report with HHS OCR on January 21, 2025, disclosing a hacking/IT incident. The breach involved unauthorized access to a network server, exposing the protected health information of 138,080 individuals. As a healthcare provider, the entity is directly responsible for this disclosure. Administrators at imaging centers and hospitals should note the scale of this incident as a benchmark for risk assessment. While the filing date is January 21, 2025, this does not indicate when the breach occurred or was discovered. Monitor for further details on the nature of the data exposed.
2026-08-01
RECENT
Hacking/IT incident
Wisconsin-based ambulance provider Bell Ambulance, Inc. filed a breach report with HHS OCR on April 14, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, potentially affecting 237,830 individuals. As a healthcare provider, Bell Ambulance is a covered entity under HIPAA. This submission date reflects when the report was filed, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data types involved and any required notifications to affected individuals.
2026-08-01
RECENT
Settled
Deer Oaks – The Behavioral Health Solution, a healthcare provider in Texas, has reached a $225,000 HIPAA settlement with HHS OCR. The agency announced the agreement on July 7, 2025, resolving a case covering two separate incidents: an earlier online exposure of patient discharge summaries caused by a coding error (35 individuals), and a later hacking/IT incident affecting 171,871 individuals. The larger breach filing was submitted on July 31, 2024. OCR's risk-analysis-failure finding spanned both incidents. As part of the resolution, the provider agreed to a two-year corrective action plan. Administrators should review their incident response protocols to ensure they meet regulatory expectations for breach notification and remediation.
2026-08-01
RECENT
Hacking/IT incident
Insightin Health, Inc., a business associate based in Maryland, filed a report with HHS OCR on January 16, 2026, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,949,534 individuals. The unauthorized access occurred on a network server. Because Insightin Health is a business associate, your organization may be impacted if you contract with them for services such as claims processing or data analytics. Review your vendor contracts and assess whether you receive data from this entity. If so, contact your legal and compliance teams to determine if you need to notify your own patients or take additional risk mitigation steps.
2026-08-01
RECENT
Hacking/IT incident
Summit Pathology and Summit Pathology Laboratories, Inc., a healthcare provider in Colorado, filed a breach report with HHS OCR on October 18, 2024. The filing covers a hacking/IT incident involving a network server that exposed the protected health information of 1,813,538 individuals. This submission date is when the report was filed with the government, not necessarily when the breach occurred. As a covered entity, Summit Pathology is responsible for notifying affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for notification letters if their patients or staff received pathology services from this organization, as the scale of this incident suggests widespread exposure of sensitive medical data.
2026-08-01
RECENT
Hacking/IT incident
A Washington-based healthcare provider, Northwest Radiologists, Inc./Mount Baker Imaging, filed a report with HHS OCR regarding a hacking/IT incident. The submission, dated October 28, 2025, indicates that 362,713 individuals were affected. The breach involved unauthorized access to a network server. As a covered entity, this radiology group is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar incidents involving healthcare providers and review their own cybersecurity protocols, though no specific remediation steps are detailed in this filing.
2026-07-31
RECENT
Hacking/IT incident
Centers for Medicare & Medicaid Services (CMS) filed a report with HHS OCR on June 30, 2025, disclosing a hacking/IT incident that compromised the data of 107,154 individuals. The breach occurred on a network server. CMS is classified as a Health Plan under HIPAA. Healthcare administrators should note the scale of this federal breach as a benchmark for potential risks to their own systems.
2026-07-31
RECENT
Hacking/IT incident
Doctors Imaging Group, a healthcare provider in Florida, filed a breach report with HHS OCR on September 24, 2025. The filing covers a hacking/IT incident that compromised the personal health information of 171,862 individuals. The unauthorized access occurred on a network server. While this specific incident involves an imaging group, administrators at hospitals, clinics, and health plans should review their own vendor contracts and security monitoring protocols. The submission date marks when the report was filed, not necessarily when the breach occurred or was discovered. Organizations should verify if they share data with this entity or similar providers to assess potential downstream risks.
2026-07-31
RECENT
Hacking/IT incident
A Pennsylvania-based eye care provider, Tri Century Eye Care PC, filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on October 31, 2025, indicates that the personal information of 200,000 individuals was compromised. The breach originated from a network server. As a healthcare provider, this entity is a covered entity under HIPAA. Administrators should note this as a significant data security event in the ophthalmology sector. The submission date marks when the report was filed with the government, not necessarily when the incident occurred or was discovered. No further details on the specific data types or remediation steps are provided in this initial filing.
2026-07-31
RECENT
Hacking/IT incident
University of Iowa Community Home Care, a healthcare provider, filed a breach report with HHS OCR on August 29, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 109,029 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. This submission date marks when the report was filed, not necessarily when the breach occurred. Healthcare administrators should monitor for similar IT security risks within their own networks and ensure their incident response plans are current.
2026-07-30
RECENT
Hacking/IT incident
If your organisation uses Ciox Health LLC (doing business as Datavant Group) for data services, you may be affected by a significant security incident. This Business Associate reported a hacking/IT incident to HHS OCR on 10/07/2024. The filing lists 320,702 individuals affected. Protected health information was exposed via email. Because Datavant is a Business Associate, your own compliance obligations depend on your specific contract and data flow. Verify if you share data with this entity and review your Business Associate Agreement for notification requirements.
2026-07-30
RECENT
Hacking/IT incident
Fieldtex Products, Inc., a Business Associate, filed an HHS OCR breach report on December 12, 2025, citing 104,071 individuals affected by a hacking/IT incident on a network server. This entry reflects the single OCR filing cited below; additional related filings have been reported elsewhere but are not covered by this record. If your organization uses Fieldtex services, review your contracts to understand notification obligations and monitor the OCR portal for further filings.
2026-07-30
RECENT
Hacking/IT incident
A healthcare provider in South Carolina, Innovative Scientific Solutions, LLC, reported a hacking/IT incident to HHS OCR on April 17, 2026. The breach affected 143,842 individuals after unauthorized access to a network server. This filing date reflects when the report was submitted, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data compromised and any required notifications to affected patients or partners.
2026-07-30
RECENT
Hacking/IT incident
Highlands Oncology Group PA, an oncology practice in Arkansas, filed a breach report with HHS OCR on August 1, 2025. The filing covers a hacking/IT incident involving data stored on a network server. The breach potentially affected 111,766 individuals. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators should note the scale of this incident for risk assessment purposes. The submission date is when the report was filed, not necessarily when the breach occurred or was discovered. No further details were provided in the initial filing.
2026-07-30
RECENT
Hacking/IT incident
Nacogdoches Memorial Hospital, a healthcare provider in Texas, filed a breach report with HHS OCR on March 30, 2026, regarding a hacking/IT incident. The OCR portal lists 2,507,073 individuals affected. While some secondary sources cite a lower figure of 257,073, the federal record stands at 2.5 million with no documented correction. The breach involved data stored on a network server. As a covered entity, the hospital is responsible for notifying affected individuals. Healthcare administrators should monitor official notifications from the hospital to understand the specific scope of exposure for their own patients or partners, as the federal filing does not detail the specific types of data compromised.
2026-07-29
RECENT
Hacking/IT incident
Brightstar Global Solutions Corporation, a health plan based in Rhode Island, filed a report with HHS OCR on October 3, 2025, regarding a hacking/IT incident. The breach compromised the protected health information of 103,879 individuals. The unauthorized access occurred on a network server. As a covered entity, Brightstar is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor this case to understand how large-scale cyber incidents are handled by health plans. This filing confirms the breach was reported to regulators; it does not indicate when the incident originally occurred or was discovered.
2026-07-29
RECENT
Hacking/IT incident
A Florida-based healthcare provider named Florida Physician Specialists has filed a report with HHS OCR regarding a significant data breach. The incident, classified as a hacking/IT incident, compromised information stored on a network server. The filing indicates that 276,498 individuals were affected by this security failure. The report was submitted on April 24, 2026. Healthcare administrators should note the scale of this breach, which underscores the risks associated with network server vulnerabilities. While this specific event involves a provider group, the implications for data security practices are relevant to all entities handling protected health information. Monitor your own network defenses and review incident response protocols to ensure preparedness against similar threats.
2026-07-29
RECENT
Hacking/IT incident
A significant security incident has been reported by Philadelphia Corporation for Aging (PCA), a Business Associate operating in Pennsylvania. The organization filed a report with HHS OCR on September 23, 2025, disclosing a hacking/IT incident that compromised data stored on a network server. This breach affects a substantial number of individuals, with 410,491 people impacted. Because PCA is a Business Associate, this incident likely involves the health data of patients from various covered entities, such as clinics or health plans, that contract with them. Healthcare administrators should review their vendor contracts and security protocols to ensure their own Business Associates are maintaining adequate safeguards against cyber threats.
2026-07-29
RECENT
Hacking/IT incident
A Virginia-based radiology group, Radiology Associates of Richmond, has filed a report with HHS OCR regarding a significant security incident. The filing, submitted on May 21, 2026, indicates that a hacking/IT incident compromised data stored on a network server. This breach affects a substantial number of individuals, with 266,183 people impacted. As a healthcare provider, the entity is a Covered Entity under HIPAA rules. Administrators should note that this submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered. Given the scale of the incident, this serves as a reminder of the risks associated with network server vulnerabilities in medical imaging and diagnostic settings.
2026-07-29
RECENT
Hacking/IT incident
A Colorado-based gastroenterology practice has filed a report with HHS OCR regarding a significant data security incident. The filing, submitted on November 13, 2024, indicates that a hacking or IT incident compromised information stored on a network server. This breach affects approximately 366,491 individuals. As a healthcare provider, the entity is required to notify affected patients and report the incident to the government. Healthcare administrators should note the scale of this exposure, which highlights the risks associated with network server vulnerabilities. While this specific event involves a specialty practice, the underlying threat vector is relevant to any organization managing electronic health records.
2026-07-28
RECENT
Hacking/IT incident
A major healthcare provider, Centers Lab NJ LLC, has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking/IT incident targeting a network server, compromising the records of 542,377 individuals. The breach was officially filed on June 18, 2026. Hospital administrators should monitor this case closely as a reminder of the risks associated with network security vulnerabilities. While this specific report does not detail immediate operational changes for other facilities, it underscores the critical need for robust cybersecurity measures to protect patient data from unauthorized access.
2026-07-28
RECENT
Hacking/IT incident
Mainline Health Systems Inc in Arkansas has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking or IT incident that compromised information stored on a network server. A total of 101,104 individuals were affected by this security failure. The breach was officially reported on June 23, 2025. Hospital administrators should monitor their own network security protocols and ensure incident response plans are up to date. While this specific event affects Mainline Health Systems, it serves as a reminder of the risks associated with server vulnerabilities. No further details were provided in the initial filing.
2026-07-28
RECENT
Hacking/IT incident
A significant data breach has been reported involving ATSG, Inc., a business associate operating in New York. This incident, classified as a hacking/IT event, compromised the protected health information of 909,469 individuals. The breach occurred on a network server and was reported to the HHS Office for Civil Rights on October 4, 2024. Hospital administrators should review their own business associate agreements to ensure vendors have robust cybersecurity measures. While this specific incident affects ATSG, it serves as a stark reminder of the risks associated with third-party data handling. Monitor your own systems for unusual activity and verify that your partners are compliant with security standards.
2026-07-28
RECENT
Hacking/IT incident
Navia Benefit Solutions, Inc., a Washington-based business associate for employee benefits (FSA, HSA, HRA, COBRA, DCAP), reported a hacking/IT incident to HHS OCR on March 18, 2026. The filing lists 2,151,330 individuals affected, but external reports from the Maine Attorney General and other sources cite a total of approximately 2,697,540 individuals. The breach involved data on a network server and other locations. Because Navia serves employers rather than hospitals, health plans, self-insured employers, and benefits administrators should verify if they use Navia. If so, review your vendor contracts and assess potential exposure to your members or employees. This filing date is when the report was submitted to OCR, not when the breach occurred.
2026-07-28
RECENT
Hacking/IT incident
VectraRx Mail Pharmacy Services, LLC, a Healthcare Provider based in Arizona, reported a hacking/IT incident affecting 109,383 individuals. The breach involved data stored on a network server. The report was submitted to HHS OCR on February 6, 2025. This filing is relevant to healthcare administrators and vendors who interact with mail-order pharmacies or share data with similar entities. Because VectraRx is classified as a Covered Entity, this incident highlights risks for providers managing their own patient data systems. Administrators should review their own vendor management protocols to ensure partners maintain robust cybersecurity measures, particularly for systems handling large volumes of patient data. The primary source record does not confirm whether patient notifications have been sent or if credit monitoring was offered, nor does it indicate the incident is resolved.
2026-07-27
RECENT
Hacking/IT incident
Central Kentucky Radiology, a physician-owned radiology group in Kentucky, filed a breach notification with HHS OCR on June 13, 2025. The filing reports a hacking/IT incident that compromised a network server, exposing the protected health information of 166,953 individuals. While the submission date is June 2025, secondary sources indicate the underlying incident occurred in October 2024. Healthcare administrators, particularly those running imaging practices, diagnostic labs, or provider networks, should note this risk profile. This event highlights the vulnerability of network servers to unauthorized access. Review your own incident response plans and ensure your IT teams are monitoring for similar vulnerabilities. Verify that your security protocols align with current best practices for protecting patient data in digital health environments.
2026-07-27
RECENT
Hacking/IT incident
Coastal Carolina Health Care, PA in North Carolina has reported a significant data breach to the Department of Health and Human Services. The incident involved a hacking or IT incident targeting a network server. This breach affects 110,304 individuals, exposing their protected health information. The report was submitted on March 24, 2026. Hospital administrators should review their own cybersecurity protocols to ensure similar vulnerabilities are not present in their systems. While this specific incident is contained to Coastal Carolina Health Care, it serves as a reminder of the ongoing risks posed by cyber threats to healthcare networks. Ensure your IT teams are monitoring for unusual activity and that incident response plans are up to date.
2026-07-27
RECENT
Hacking/IT incident
Frederick Health in Maryland has reported a significant cybersecurity incident to the Department of Health and Human Services. The breach involved a hacking or IT incident targeting a network server, exposing the protected health information of 934,326 individuals. This filing was submitted on March 28, 2025. Hospital administrators should monitor this case closely as a benchmark for large-scale incident response. While this specific event is reported, it serves as a reminder to review your own network security protocols and ensure your incident response plans are current and tested.
2026-07-27
RECENT
Hacking/IT incident
Laurel Eye Clinic in Pennsylvania has reported a significant cybersecurity incident to the HHS Office for Civil Rights. The breach involved a hacking or IT incident targeting the clinic's network server. This event potentially exposed the protected health information of 145,221 individuals. The report was submitted on April 22, 2026. Hospital administrators should review their own network security protocols to ensure similar vulnerabilities are addressed. While this specific incident is contained to one provider, it highlights the ongoing risk of server-based attacks in healthcare settings. Ensure your IT teams are monitoring for unauthorized access and that incident response plans are up to date.
2026-07-27
RECENT
Hacking/IT incident
Liberty Resources, Inc., a healthcare provider in New York, submitted a breach report to HHS OCR on March 4, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server, affecting 103,711 individuals. As a covered entity, Liberty Resources must notify affected individuals and HHS OCR. This incident highlights the risk of server-based attacks for any organization handling protected health information. Healthcare administrators should review their own cybersecurity protocols to ensure network servers are secure against similar attacks.
2026-07-27
RECENT
Hacking/IT incident
Radiology Associates of Richmond, Inc., a Virginia-based healthcare provider, filed a breach notification with HHS OCR on July 1, 2025, reporting a hacking/IT incident affecting 1,419,091 individuals. The data was accessed from a network server. This entity has since disclosed a second, separate breach involving 266,183 individuals, stemming from an incident on or about July 25, 2025. This subsequent disclosure was reported to the Maine Attorney General on May 21, 2026. However, claims that this second breach has appeared on HHS OCR's public breach portal are unsupported by primary sources and contradicted by contemporaneous reporting stating it had not yet appeared. The HHS OCR record for the initial filing indicates no business associate was involved. Administrators should monitor the OCR portal for updates on both incidents.
2026-07-27
RECENT
Hacking/IT incident
Richmond Behavioral Health Authority in Virginia has reported a significant data breach affecting 113,232 individuals. The incident, classified as a hacking or IT incident, involved unauthorized access to a network server. The report was submitted to HHS OCR on November 28, 2025. Hospital administrators should monitor this case to understand how large-scale server breaches are being handled and reported. While this specific event affects a behavioral health provider, the scale highlights the ongoing risk to network infrastructure across all healthcare sectors. Ensure your own IT security protocols are robust and that your breach response plan is current.
2026-07-27
RECENT
Hacking/IT incident
Sandhills Medical Foundation, a healthcare provider in South Carolina, reported a data breach to HHS OCR. The incident is classified as a hacking/IT incident, with data compromised on a network server. A total of 169,017 individuals were affected. The report was submitted on September 14, 2025. This filing highlights risks for providers and other covered entities. Administrators should review their own incident response plans. Ensure your breach notification procedures are current and ready for immediate deployment if a similar incident occurs at your organisation.
2026-07-27
RECENT
Hacking/IT incident
Veradigm LLC, a healthcare IT vendor classified as a Business Associate, reported a hacking/IT incident affecting 2,672,036 individuals. The HHS OCR record lists the submission date as September 22, 2025. Because Veradigm is a Business Associate, your organization’s obligations depend on your specific Business Associate Agreement and whether your patients’ data was involved. Review your contracts to understand liability and support responsibilities. Do not assume automatic notification duties; verify if your facility uses Veradigm services. Note that the related class action Goodrum v. Veradigm, Inc. has reached a final settlement. Payments for approved claims were issued on June 12, 2026, and uncashed checks void after September 10, 2026. Crucially, the OCR filing names Veradigm LLC, while the lawsuit names Veradigm, Inc.. These are distinct legal entities. Check your contracts for the exact legal entity name to ensure proper compliance.
2026-07-11
UPCOMING
Hacking/IT incident
A filing for Absolute Dental Group, LLC in Nevada lists the entity as a Business Associate. The HHS OCR record, submitted on May 2, 2025, reports 1,223,635 individuals affected by a hacking/IT incident on a network server. A $3.3 million class action settlement received preliminary court approval on March 6, 2026. The Final Approval Hearing is set for Thursday, July 30, 2026, per the official settlement administrator site. (The court docket entry, Doc. 92, reads "Thursday, July 31" — July 31 is a Friday, and every other source gives July 30, so the docket appears to contain a clerical error.) If your organization contracts with this dental group, confirm the date with the settlement administrator.
2026-07-11
RECENT
Hacking/IT incident
Dameron Hospital in California has reported a significant data breach to HHS OCR. The incident involved a hacking or IT incident that compromised information stored on a network server. This breach affects 210,706 individuals, making it a large-scale event that hospital administrators should monitor for potential industry-wide trends. The filing was submitted on April 2, 2025. While this specific report does not detail the exact data types exposed, the scale suggests a serious security failure. Administrators should review their own server security protocols and ensure incident response plans are current. This is a confirmed breach, not a proposal, and highlights the ongoing risk of cyberattacks on healthcare infrastructure.
2026-07-11
RECENT
Hacking/IT incident
A significant hacking/IT incident has been reported involving Specialty Networks, Inc., a business associate located in Tennessee. The breach affected the personal health information of 411,037 individuals. The compromised data was stored on a network server. This incident was reported to the HHS Office for Civil Rights on August 15, 2024. Hospital administrators should review their contracts with business associates to ensure robust cybersecurity measures are in place. If your facility uses Specialty Networks, verify their security protocols and confirm that any shared data was protected. This is a confirmed breach, not a proposal, highlighting the ongoing risks of digital health records.
2026-07-11
RECENT
Hacking/IT incident
A major breach has been reported involving Conduent Business Services LLC, a business associate operating in New Jersey. This incident, classified as a hacking/IT incident, compromised the data of approximately 62.2 million individuals. The unauthorized access occurred on a network server. Hospital administrators should verify if their organization uses Conduent for services such as billing, claims processing, or other administrative support. If you do, contact your vendor management team immediately to assess potential risks to your patient data. Even if you are not a direct client, the scale of this breach highlights the critical need to review your own cybersecurity protocols and ensure all business associates have robust security measures in place to protect sensitive health information.
2026-07-11
RECENT
Hacking/IT incident
A hacking/IT incident at Hillcrest Convalescent Center, Inc., a healthcare provider in North Carolina, has been reported to HHS OCR. The filing, submitted on March 4, 2025, indicates that data stored on a network server was compromised. This breach affects 106,194 individuals. Because the source record provides no web description, the specific types of data involved are not detailed here. Healthcare administrators should note this incident as a reminder to verify their own incident response plans and server security protocols. This is a confirmed report from a covered entity classified as a healthcare provider.
2026-07-11
HOT
In force — repeal proposed
Two things every hospital should know about the AI built into their EHR. First: under
a federal rule (HTI-1) that became fully enforceable this past February,
your certified EHR vendor must disclose how its predictive AI tools work — what data
trained them, who they're meant for, known risks, and how they were validated. That's
31 required disclosure items, often called an "AI model card." You can ask your vendor
for this today, and they're required to have it. Second: the same federal office has
proposed repealing exactly that requirement (the HTI-5 proposal,
December 2025), arguing there's no evidence the disclosures improved care. Public
comments closed February 27, 2026; no final decision has been published yet. Practical
advice: if these model cards are useful to your AI purchasing decisions, request them
from your vendors now, while the requirement is still in force.
2026-07-09
UPCOMING
Takes effect Oct 1, 2026
Alabama's new law (signed April 17, 2026, effective October 1, 2026)
says a health insurer can't rely only on AI to decide whether care gets covered — any
decision to deny or reduce coverage has to be made by a qualified healthcare professional.
Insurers must also tell enrollees that AI is used in coverage decisions, base prior-auth
determinations on the individual patient's medical history rather than group data alone,
and certify annually to the state that their AI is monitored for accuracy and doesn't
discriminate. If you're in Alabama, this is leverage: after October 1, an AI-only denial
is something you can push back on by law.
2026-07-09
WATCHING
EO signed Dec 11, 2025 — litigation pending
A December 2025 executive order (EO 14365) directs the federal government to push back
on state AI laws it considers burdensome — including a Justice Department task force to
challenge them in court, and reviews by Commerce and the FTC identifying which state laws
conflict with federal policy. What this means for you: the state AI rules covered in this
feed (Texas, Colorado, Indiana, Alabama, and others) are valid law today and you should
keep complying — but some may end up challenged in court over the next year or two. Don't
un-build your compliance program based on headlines; do expect uncertainty about which
state rules survive.
2026-07-09
WATCHING
Draft guidance — not final
The FDA has authorized over a thousand AI-enabled medical devices, but its first
comprehensive rulebook for how these devices should be designed, validated, and monitored
over their whole life — published as a draft in January 2025 — has still not been
finalized. Why a hospital should care: once final, it will shape what documentation and
ongoing performance monitoring you can demand from device vendors, especially for AI
tools whose behavior changes with updates. Reasonable ask of vendors today: whether
they're already building to the draft guidance rather than waiting.
2026-07-09
UPCOMING
Takes effect Jan 1, 2027
Georgia's SB 444, effective January 1, 2027, draws a clean line:
insurers may use AI in prior authorization to automate paperwork and reduce administrative
burden — but an adverse decision (denying or reducing care) can't be issued until a
qualified clinical peer has actually conducted the review and participated in the decision.
The AI also can't override that clinician's judgment. If you operate in Georgia, nothing
changes today, but this is worth having on your 2027 compliance calendar now.
2026-07-09
RECENT
In effect May 6, 2026
Utah's SB 319, in effect since May 6, 2026, requires insurers to
publicly post their preauthorization requirements on their website and to disclose
whether AI is used when reviewing authorization requests. It also sets a maximum time
insurers can take to answer an authorization request, and sets minimum periods an
approval stays valid. Practical upshot for your utilization and scheduling teams:
approvals should be faster to get and harder to have silently expire — and you can
now find out whether a Utah payer is using AI on your requests just by asking.
2026-07-03
RECENT
Deadline shift
Colorado's AI law (requirements around AI systems not discriminating against patients)
now takes effect June 30, 2026 — pushed back from its original February
date. A companion healthcare-specific rule adds a plain but important protection: your
staff can't let an AI system be the sole reason a patient's coverage or care is denied.
A human still has to be involved in that decision.
2026-07-03
HOT
In effect
The federal government's rulebook for approving cloud software (FedRAMP) got a major
overhaul, and it's already active as of July 4, 2026 — not something
coming later this year. The old "Low/Moderate/High" security tiers are gone, replaced
by new tiers called Classes A through D. If any of your software vendors handle
government-adjacent data or claim FedRAMP approval, it's worth asking them directly
whether they've moved to the new system, since some requirements become mandatory
before January 1, 2027.
2026-07-03
WATCHING
NPRM — not final
You may have heard that HIPAA now requires encrypting all patient data. It doesn't —
not yet. Federal regulators proposed making encryption mandatory (it's currently just
"recommended"), but that proposal has not been finalized into law as of this writing.
There's no deadline to comply with yet. Once it is finalized, organizations would get
60 days before it takes effect and 240 days after that to actually comply — so there
will be advance warning. Worth watching, not worth panicking about yet.
2026-07-03
RECENT
In effect
If you operate in Texas, there are two separate AI laws to know about, not one.
The first, HB 149, is the broad rulebook for how AI systems can be used —
it's been in effect since January 1, 2026. The second, SB 1188,
is narrower but easy to overlook: it requires your staff to tell patients when AI was used
in their diagnosis or treatment. That one has actually been in effect longer, since
September 1, 2025. If your compliance team only checked the first law, you
may already be missing a disclosure requirement that's been live for almost a year.
2026-07-01
HOT
In effect July 1, 2026
As of July 1, 2026, health insurers in Indiana can no longer use AI as
the only basis to downcode a claim (pay it at a lower level than billed) — a human must
review the patient's medical record first. Insurers also now have to disclose, in plain
view, whenever AI was used to deny a prior authorization or downcode a claim. Two things
for your team: your billing office should start watching downcoded claims for the required
disclosures, and note the law cuts both ways — providers also can't submit claims generated
by AI without a person involved in the claim reviewing them. Appeals get at least 180 days.
2026-07-01
HOT
Unauthorized disclosure — paper/films
The most recent breach filed with federal regulators, on July 1, 2026,
affected 8,157 people at the Wisconsin Department of Health Services —
and it wasn't a computer hack at all. It involved paper and film records. Easy to
forget when most breach news is about hackers: mishandled physical records are still
a reportable breach, and still something your front-desk and records-handling
procedures need to guard against.
2026-06-05
RECENT
Hacking/IT incident
Minnesota Epilepsy Group, a single-specialty outpatient practice, reported a hacking
incident affecting 80,061 patients on June 5, 2026. The takeaway for
any smaller or specialty practice: attackers aren't only targeting big hospital networks
or national insurers. If your organization is smaller, that is not protection — you're
still a target, and this-size breach is common.
2026-06-05
RECENT
Hacking/IT incident
Xsolis — a company whose AI software helps hospitals and health plans decide whether
a patient's stay or treatment gets approved — reported a hacking incident affecting
1,396,519 people on June 5, 2026. Why this one matters
beyond the number: this isn't just a generic IT vendor, it's a vendor making decisions
about patient care. If your hospital uses Xsolis or a similar utilization-review AI
tool, this is worth a direct conversation with that vendor about what happened and
whether your patients' data was involved.
2026-06-02
RECENT
EO signed Jun 2, 2026 — directives rolling out
A second AI executive order (EO 14409, signed June 2, 2026 — separate
from the December order about overriding state laws) focuses on AI and cybersecurity.
The part that matters for hospitals: the federal cyber agency CISA was given 30 days to
expand AI-powered defensive tools and make them easier to access for critical
infrastructure operators — which includes healthcare. Treasury is also standing
up a clearinghouse for coordinating vulnerability detection and fixes. Nothing here
requires you to do anything; it's a potential resource. Worth having your IT/security
lead watch CISA's announcements over the coming weeks for new tools or programs your
organization can enroll in. The order does not add licensing requirements for AI, and
it says nothing about healthcare regulation or state-law preemption.