How to Become HIPAA Compliant
How to become HIPAA compliant is one of the biggest challenges for many businesses operating in the healthcare and health…
The HIPAA Journal legal news section contains details of the latest enforcement activities by the Department of Health and Human Services’ Office for Civil Rights, including settlements and civil monetary penalties, and legal actions taken against covered entities by state attorneys general.
You will also find brief details of class action lawsuits and other legal actions filed against covered entities for HIPAA violations, privacy violations, and data breaches, along with other legal news specifically relating to HIPAA or other legal matters of particular relevance to the healthcare industry.
Changes to HIPAA Rules are detailed in the HIPAA Updates category, although this section does include updates to state legislation, in particular any changes to breach notification and cybersecurity laws that are relevant to healthcare organizations.
The Federal Trade Commission (FTC) has proposed changes to the Health Breach Notification Rule to strengthen the applicability of the...
A healthcare data breach of 1 million+ records is certain to result in multiple lawsuits, and the data breach experienced...
In June 2020, the Luxottica Group PIVA-owned vision insurance company, EyeMed Vision Care, experienced a data breach involving the protected...
A settlement has been proposed by Maxim HealthCare Services to resolve all claims related to a 2020 cyberattack and data...
The Californian home care service provider, SuperCare, has proposed a $2.25 million settlement to resolve a class action lawsuit filed...
A lawsuit has been filed in the U.S. District Court for the Southern District of Iowa that alleges University of...
How to become HIPAA compliant is one of the biggest challenges for many businesses operating in the healthcare and health…
Free Expert HIPAA Risk Assessment Your risk assessment is part of your mandatory annual HIPAA requirements. Book a complimentary session…
A complaint filed by the Federal Trade Commission (FTC) against the mobile app attribution and analytics company, Kochava, has been...
The HHS’ Office for Civil Rights has announced its 44th enforcement action under its HIPAA Right of Access initiative with...
There has been an update to a lawsuit filed against Lehigh Valley Health Network over a ransomware attack that involved...
A lawsuit has been filed against 90 Degree Benefits over a breach of the protected health information of 181,543 individuals....
One Brooklyn Health, a New York City-based network of three acute care hospitals – Brookdale Hospital Medical Center, Interfaith Medical...
Five former Methodist Hospital employees have pleaded guilty to criminal violations of HIPAA for accessing and disclosing the information of...
Mount Nittany Health, a community healthcare provider and operator of the 260-baed Mount Nittany Medical Center in State College, Pennsylvania,...
A class action lawsuit has been filed against Conifer and Tenet Healthcare over a breach of the protected health information...
Insight Global LLC has agreed to settle a class action lawsuit that was filed in response to an April 2021...
The Manchester, New Hampshire-based medical equipment company, NuLife Med, has agreed to settle a class action lawsuit that was filed...
A U.S. District Court Judge has denied class certification in a long-running legal battle against CareFirst BlueCross BlueShield over its...
Illinois Gastroenterology Group (IGG) has agreed to settle a class action lawsuit that stemmed from a 2021 data breach that...
A Georgia physician has avoided jail time for a HIPAA violation as part of a plea deal after illegally accessing...
A lawsuit has been filed against the digital marketing agency, Rise Interactive Media & Analytics, over a cyberattack in which...
At least two class action lawsuits have been filed against the online health insurance marketplace, DC Health Link, over a...
The Federal Bureau of Investigation (FBI) has published its 2022 Internet Crime Report, which shows at least $10.3 billion was...
Cardiovascular Associates in Alabama is facing a class action lawsuit over a recently reported hacking incident in which patients protected...
It has only been a few days since the Miami-based healthcare administration and managed care solutions provider, Independent Living Systems...
Multiple class action lawsuits have been filed against two healthcare providers in Arkansas – Mena Regional Health System (MRHS) and...
The United States Department of Justice has agreed to settle alleged False Claims Act violations with Jelly Bean Communications Design...
A lawsuit has been filed against Lehigh Valley Health Network (LVHN) over its recent BlackCat ransomware attack. The attack saw...
Revenetics is facing a class action lawsuit over its December 2022 cyberattack and data breach that affected more than 250,000...
A lawsuit has been filed against Maternal & Family Health Services (MFHS) in Pennsylvania which alleges the healthcare provider failed...
Three Democratic Senators have introduced a bill that seeks to improve personal health data privacy by preventing companies from disclosing...
Four Californian medical groups have been named in a class action lawsuit that alleges a failure to implement reasonable and...
Two individuals suspected of being core members of the DoppelPaymer ransomware gang have been arrested by police officers in Germany...
The Department of Justice has announced one of its first prosecutions under the Medicare Access and CHIP Reauthorization Act of...
AssistCare Home Health Services has agreed to settle a class action lawsuit, filed on behalf of individuals affected by a...
The Albuquerque, NM-based health insurance provider, True Health New Mexico, has proposed a settlement to resolve claims related to a...
Several class action lawsuits have been filed against Regal Medical Group and affiliated healthcare providers following the February 1, 2023,...
A lawsuit has been filed against Freehold Township, NJ-based CentraState Healthcare System over its December 2022 ransomware attack, a few...
HIPAA certification is defined as either a point in time accreditation demonstrating an organization has passed a HIPAA compliance audit,...
The American Civil Liberties Union of Rhode Island (ACLU of RI) has amended its complaint against the Rhode Island Public...
The Nashville, TN-based health system, Advent Health Partners, has proposed a $500,000 settlement to resolve claims related to a September...
Two Louisiana health are being sued over the use of pixels on their websites, which allegedly captured and impermissibly disclose...
The medical device manufacturer Electromed has proposed an $850,000 settlement to resolve claims related to a June 2021 ransomware attack...
Umass Memorial Health has proposed a $1.2 million settlement to resolve a class action lawsuit that was filed on behalf...
Another lawsuit has been filed against Connexin Software over its August 2022 ransomware attack and data breach, which affected more...
iCare Acquisitions has proposed a $3 million settlement to resolve claims from individuals affected by a 2021 data breach that...
A lawsuit has been filed against Cedars-Sinai Medical Center alleging impermissible disclosures of patient data to Google, Meta, and other...
Last week, the Federal Trade Commission (FTC) announced its first-ever financial penalty for a violation of the FTC Health Breach...
The HHS’ Office for Civil Rights has announced its second financial penalty of 2023 to resolve alleged violations of the...
The Federal Trade Commission’s Health Breach Notification Rule requires vendors of personal health records and related entities to issue notifications...
The Department of Health and Human Services’ Office for Civil Rights is the main enforcer of HIPAA compliance; however, state...
San Andreas Regional Center has agreed to settle a class action lawsuit that was filed in response to a July...
Katherine Shaw Bethea (KSB) Hospital in Dixon, IL, has proposed a $380,000 settlement to resolve claims related to a September...
Earlier this month, a lawsuit was filed against The Christ Hospital in Cincinnati, OH, alleging third-party tracking code had been...
Logan Health has agreed to settle a class action lawsuit related to a 2021 hacking incident that exposed the protected...
Another lawsuit has been filed against CommonSpirit Health over its 2022 ransomware attack and data breach that alleges the nation’s...
Mayo Clinic has settled another lawsuit that stemmed from a data breach involving a former employee, who was discovered to...
A settlement proposed by Rehoboth McKinley Christian Health Care Services to resolve claims related to February 2021 cyberattack has been...
Multiple lawsuits have been filed against Massachusetts-based Shields Health Care Group, which suffered one of the largest healthcare data breaches...
Washington Attorney General Bob Ferguson is suing a plastic surgery provider for falsely inflating online ratings, bribing, and threatening patients,...
The Chicago, IL-based health system, CommonSpirit Health, is facing a class action lawsuit over its October 2022 ransomware attack. Malicious...
Fertility Centers of Illinois has proposed a $450,000 settlement to resolve a lawsuit filed on behalf of patients and employees...
A settlement has been proposed by Scripps Health to resolve a consolidated class action lawsuit – In Re: Scripps Health...
Can a patient sue for a HIPAA violation? There is no private cause of action in HIPAA, so it is...
Plaintiffs in a consolidated class action lawsuit against Meta recently sought an injunction to stop the company from collecting and...
Cyber insurance policies can help to cover the cost of losses from ransomware attacks, but these policies are becoming more...
Morley Companies has agreed to settle a class action lawsuit filed on behalf of individuals affected by a major data...
A former nurse employed by the Roswell Park Comprehensive Cancer Center in Buffalo, NY, has been sentenced to 37 months...
Two healthcare organizations in Massachusetts have chosen to settle class action lawsuits that were filed by patients whose protected health...
Conway Regional Medical Center, a non-profit healthcare system in north central Arkansas, has proposed a $295,000 settlement to resolve a...
Developers of mobile health apps may be required to comply with certain federal laws such as the FTC Act, FTC...
The New York ambulance service, Empress EMS, is facing multiple class action lawsuits over a ransomware attack that was detected...
San Juan Regional Medical Center (SJRMC) in Farmington, New Mexico, has proposed a settlement to resolve a class action lawsuit...
The Department of Health and Human Services (HHS) and the Substance Abuse and Mental Health Services Administration (SAMHSA) have issued...
It is now common for class action lawsuits to be filed in response to a healthcare data breach. While the...
The U.S. Department of Justice has charged 10 individuals over business email compromise scams that have resulted in more than...
The Wisconsin-based dermatology practice, Forefront Dermatology, has agreed to settle a class action lawsuit filed on behalf of patients whose...
A former employee of Axia Women’s Health in Pennsylvania has been charged in a 39-count indictment for stealing patient information...
The Governor of Pennsylvania, Tom Wolf, has signed Senate Bill 696 into law, which expands the definition of personal information...
Five former employees of Methodist Hospital in Tennessee have been indicted by a federal grand jury in Memphis for criminal...
A New York-based physician-owned provider of administrative services to anesthesiology firms is facing several class action lawsuits over a cyberattack...
Ann & Robert H. Lurie Children’s Hospital has proposed a settlement to resolve a class action lawsuit filed in response...
Oakbend Medical Center in Richmond, TX, and Keystone Health in Chambersburg, PA, are facing class action lawsuits over recent hacking...
Two class action lawsuits have been filed on behalf of patients whose protected health information (PHI) was impermissibly disclosed to...
Aveanna Healthcare has agreed to pay a $425,000 financial penalty to the Office of the Attorney General of Massachusetts for...
A Californian appellate court has recently confirmed the decision of the lower court to deny class action status for a...
The American Civil Liberties Union of Rhode Island (ACLU of RI) is taking legal action against the Rhode Island Public...
A pharmaceutical sales rep has pleaded guilty to conspiring to commit healthcare fraud and wrongfully disclosing and obtaining patients’ protected...
FINRA compliance is often mentioned in relation to the securities industry, but what is FINRA and what does FINRA compliance...
United Health Centers of the San Joaquin Valley (UNC) has proposed a settlement to resolve a class action lawsuit filed...
A former physician with practices in New Jersey, New York, and Florida has pleaded guilty to criminal violations of HIPAA...
An affiliate of the infamous Netwalker ransomware gang has been sentenced to serve 20 years in jail for his role...
Mon Health is facing a class action lawsuit over a hacking incident that allowed unauthorized individuals to gain access to...
LifeBridge Health Inc. has agreed to settle a class action lawsuit to resolve claims from patients affected by a data...
Magellan Health has agreed to settle a class action data breach lawsuit and will create a $1.43 million fund to...
The HHS’ Office for Civil Rights (OCR) has agreed to settle three HIPAA investigations of potential HIPAA Right of Access...
The Ohio law firm, Bricker & Eckler LLP, has agreed to settle a class action data breach lawsuit filed on...
Ambry Genetics has agreed to settle a class action lawsuit that stemmed from a breach of the protected health information...
The Urology Center of Colorado has agreed to settle a class action lawsuit that was filed in response to a...
The Morristown, VT-based healthcare provider, Lamoille Health Partners, is facing a class action lawsuit over a June 2022 ransomware attack...
Democrats from the Committee on Energy and Commerce wrote to the Meta CEO, Mark Zuckerberg, on August 31, 2022, to...
The Californian legislature has passed a bill (AB-1242) that prohibits companies in the state from complying with warrants from other...
The Federal Trade Commission (FTC) has sued the Idaho-based data broker Kochava for unlawfully collecting and selling the sensitive data...
The Wilsonville, OR-based home health care service provider and nursing home operator, Avamere Holdings, is facing a class action lawsuit...
Humana & Cotiviti have agreed to settle a class action lawsuit to resolve claims from individuals affected by a 2020...
A lawsuit has been filed against the Federal Trade Commission by an Idaho-based digital marketing and analytics company, which is...
Florida Orthopaedic Institute has proposed a $4 million settlement to resolve claims from patients affected by a 2020 data breach....
Novant Health has recently notified 1,362,296 patients about a breach of their protected health information due to the incorrect configuration of...
Salinas Valley Memorial Healthcare System in California has agreed to settle a class action lawsuit for $340,000 to resolve claims...
Dental Care Alliance has agreed to settle a class action lawsuit filed in response to a data breach that affected...
Meta is facing another class action lawsuit over the unlawful collection and sharing of health data without content. The lawsuit...
The U.S Department of Justice has announced that around $500,000 in Bitcoin has been seized from North Korean threat actors...
The Methodist Hospitals Inc. has agreed to settle a class action lawsuit and has created a fund of $425,000 to...
BJC HealthCare has agreed to settle a class action lawsuit to resolve claims it failed to adequately protect patient data...
Tenet Healthcare and Baptist Health are facing a class action lawsuit over a recently reported data breach that affected 1.2...
Health Aid of Ohio has agreed to settle a class action lawsuit to resolve claims that it failed to protect...
Multiple class action lawsuits have been filed against the Seattle-based Hearst Health subsidiary, MCG Health, over a data breach that...
University of Pittsburgh Medical Center has agreed to settle a class action data breach lawsuit and will make $450,000 available...
A lawsuit has been filed against Meta that alleges the social media giant has been knowingly collecting patient data from...
A new bill has been introduced by Sen. Elizabeth Warren (D-MA) that seeks to ban data brokers from selling the...
San Diego Family Care, a Californian provider of medical, dental, & mental health services, has agreed to settle a class...
A class action lawsuit has been filed against Shields Health Care Group over its recently announced 2 million-record data breach...
A class action lawsuit has been filed in the U.S. District Court for the District of Massachusetts by the law...
A class action lawsuit filed against NorthEast Radiology PC and Alliance HealthCare Services over a data breach that exposed the...
A $9.76 million settlement proposed by Solara Medical Supplies to resolve a class action lawsuit related to a 2019 data...
On July 1, 2022, updated data breach notification laws (HB 1351) will take effect in Indiana that require notifications to...
Class action lawsuits have recently been filed against Partnership Health Plan in Northern California and Oregon Anesthesiology Group in response...
A preliminary settlement has recently been approved by a California Federal court to resolve a consolidated class action lawsuit against...
A lawsuit has been filed against the in-home respiratory care provider, SuperCare Health, over a cyberattack and data breach that...
The law firm BakerHostetler has published its 8th Annual Data Security Incident Response (DSIR) Report, which provides insights based on...
The Department of Health and Human Services’ Office for Civil Rights has released a Request for information (RFI) related to...
A woman has been sentenced to serve 15 months in federal prison for her role in a scheme to defraud...
Arkansas Attorney General Leslie Rutledge announced this week that legal action is being taken against Country Medical Services Inc., the...
The U.S. Department of Justice (DOJ) has announced a settlement has been reached with the Cape Canaveral, FL-based healthcare services...
Legal action is being taken against Logan Health and subsidiary, sister, and related entities over a data breach that occurred...
Seattle, WA-based Sea Mar Community Health Centers is facing a class action lawsuit over a cyberattack in which the protected...
CaptureRx has proposed a $4.75 million settlement to resolve claims related to a 2021 data breach that affected approximately 2.4...
Inmediata, a provider of clearinghouse services and business process software, has agreed to settle a class action lawsuit filed by...
The U.S. District Court for the Western District of New York has recommended a class action lawsuit against Practicefirst Medical...
The Rhode Island Attorney General is investigating UnitedHealthcare and the Rhode Island Public Transit Authority (RIPTA) over a cyberattack and...
Marietta Area Health Care Inc., doing business as Memorial Health System, is facing a class action lawsuit over a cyberattack...
Excellus Health Plan Inc., its affiliated companies, and the Blue Cross Blue Shield Association (BCBSA) have reached a settlement to...
The first settlement of 2022 to resolve a healthcare data breach has been announced by New York Attorney General Letitia...
An $18.4 million settlement has been approved that resolves a class action lawsuit against Mass General Brigham over the use...
The Palo Alto, CA-based technology firm Accellion has proposed an $8.1 million settlement to resolve a class action data breach...
QRS, a Tennessee-based healthcare technology services company and EHR vendor, is facing a class action lawsuit over an August 2021 cyberattack...
A Florida specialty pharmacy is facing a class action lawsuit over an October 2021 cyberattack in which the personally identifiable...
The Rhode Island Public Transit Authority (RIPTA) has recently notified the Department of Health and Human Services’ Office for Civil...
Avalon Healthcare has agreed to settle alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) and state laws...
The Chicago, IN-based certified public accounting firm Bansley & Kiener LLP is facing a class action lawsuit over a data...
The New Jersey Division of Consumer Affairs has agreed to settle a data breach investigation that uncovered violations of the...
Planned Parenthood Los Angeles (PPLA) is facing a class action lawsuit over a ransomware attack that was discovered on October...
A medical biller in the Tampa Bay area of Florida has pleaded guilty to four counts of healthcare fraud, four...
San Juan Regional Medical Center in Farmington, New Mexico is facing a class action lawsuit over a data breach that...
An Eskenazi Health patient whose protected health information was stolen in an August 2021 ransomware attack is suing the healthcare...
A lawsuit has been filed in the US District Court for the District of Massachusetts against Quest Diagnostics and its...
The HHS’ Office for Civil Rights (OCR) is continuing with its enforcement of compliance with the HIPAA Right of Access...
A class action lawsuit filed against West Virginia University Health System over a breach of the protected health information of...
The United States Department of Justice (DoJ) has unsealed indictments charging two individuals for their roles in multiple REvil/Sodinokibi ransomware...
A federal judge has ruled in favor of University of Mississippi Medical Center (UMMC) in an unauthorized access and data...
The hacker who gained access to the databases of University of Pittsburgh Medical Center (UPMC) and stole the personally identifiable...
A New Jersey infertility clinic accused of violating HIPAA and New Jersey laws by failing to implement appropriate cybersecurity measures...
A new bill has been introduced that, if passed, will require victims of ransomware attacks to disclose any payments made...
A lawsuit has been filed on behalf of a former patient of Northwestern Memorial HealthCare (NMHC) against Elekta Inc. over...
A medical malpractice lawsuit has been filed against an Alabama hospital alleging vital information that could have prevented the death...
A lawsuit has been filed in U.S. District Court in Minnesota on behalf of 180 healthcare workers over the COVID-19...
Multiple class action lawsuits have been filed against the Californian healthcare provider San Diego Health over a data breach involving...
Healthcare organizations that are required to comply with the California Consumer Privacy Act (CCPA) are facing challenges achieving compliance, according...
A class action lawsuit has been filed against St. Joseph’s/Candler Hospital Health System in response to a ransomware attack that...
Two DuPage Medical Group patients are taking legal action against the healthcare provider following a July 2021 ransomware attack in...
The Department of Health and Human Services’ Office for Civil Rights (OCR) has imposed its 20th financial penalty under the...
The Breach Notification Rule of the Health Insurance Portability and Accountability Act (HIPAA) requires covered entities and business associates to...
The U.S. Department of Justice has announced a Texas woman has been sentenced by a federal court in the Eastern...
Overlake Hospital Medical Center in Bellevue, WA has proposed a settlement to resolve a class action lawsuit filed by victims...
The healthcare administrative services provider CaptureRx is facing multiple class action lawsuits for failing to protect patient data, which was...
The Department of Justice has announced nine San Diego residents have been charged in two separate indictments in connection with...
UPMC has proposed a $2.65 million settlement to resolve a data breach lawsuit filed by employees affected by a February...
In June, a bipartisan group of senators circulated a draft federal breach notification bill – the Cyber Incident Notification Act...
A comprehensive new privacy framework has been introduced in Ohio to better protect the privacy of Ohioans. The Ohio Personal...
Colorado has joined California and Virginia in passing a comprehensive data privacy law to protect state residents. It has taken...
A class action lawsuit has been filed in the New York Southern District Court against a radiology company and its...
A Texas man has been sentenced to 48 months in prison after pleading guilty to one count of conspiracy to...
The pharmacy and supermarket chain Kroger has proposed a $5 million settlement to resolve lawsuits filed by victims of data...
Plaintiffs in a class action lawsuit against Blackbaud sufficiently demonstrated they have standing, and the lawsuit has survived Blackbaud’s motion...
A class action lawsuit has been filed against Amazon by four healthcare workers who allege their Amazon Alexa devices may...
A class action lawsuit filed by two former patients against BJC HealthCare over a March 2020 email data breach has...
Dominion National, a Virginia-based insurer, health plan administrator, and administrator of dental and vision benefits, has agreed to settle a...
The U.S. Court of Appeals for the Fourth Circuit has ruled that there is no private cause of action in the...
In October 2020, Mayo Clinic announced a former employee was discovered to have impermissibly accessed the medical records of approximately...
A former Cedar Rapids Hospital employee has been sentenced to 5 years’ probation for wrongfully accessing and distributing the protected...
San Diego-based Scripps Health is facing multiple class action lawsuits over an April 29, 2021 ransomware attack that affected 147,267...
The Connecticut legislature has enhanced its data breach notification law, expanding the definition of personal information and shortening the maximum...
Many U.S. employers have implemented a policy that requires their workers to be vaccinated against COVID-19, including several major healthcare...
The Chief Operating Officer of an IT security firm has been charged over a financially motivated cyberattack on Gwinnett Medical...
The Texas Legislature has followed in the footsteps of California and Maine and has passed a bill that requires the...
The Louisville, KY-based health insurance and healthcare provider Humana and its business associate Cotiviti are facing legal action over a...
In September 2020, Nebraska Medicine and the University of Nebraska Medical Center discovered their systems had been hacked and malware...
The National Institute of Standards and Technology (NIST) has published a new report on the use of biometric authentication on...
A Michigan man has pleaded guilty to hacking into University of Pittsburgh Medical Center human resources databases in 2013 and...
A lawsuit filed against Universal Health Services (UHS) following a 2020 data breach has been allowed to proceed; however, only...
The Pennsylvania Department of Health and its COVID-19 contact tracing vendor are being sued over a breach of the personal...
The Philadelphia-based health system, Einstein Healthcare Network, is facing a class action lawsuit over an August 2020 phishing attack that...
Tension is growing between Russia and the United States over the continuous cyberattacks on the U.S. government and public and...
Adventist Health Physicians Network in Simi Valley, California has been ordered to pay $40,000 in civil momentary penalties by the...
Roper St Francis Healthcare is facing a class action lawsuit over an October 2020 data breach in which patient data...
SalusCare, a provider of behavioral healthcare services in Southwest Florida, experienced a cyberattack in March that saw patient and employee...
The former CEO of Novus and Optimum Health Services, which operates two hospices in Texas, has pleaded guilty in a...
University of Pittsburgh Medical Center (UPMC) and the law firm Charles Hilton and Associates are facing a class action lawsuit...
The Swiss hacktivist who gained access to the security cameras of the California startup Verkada in March 2021 has been...
The number of healthcare organizations to announced they have been affected by the ransomware attack on Accellion has been increasing,...
A former Roswell Park Comprehensive Cancer Center nurse has pleaded guilty to tampering with a consumer product in a case...
A coalition of 41 state Attorneys General has agreed to settle an investigation into Retrieval-Masters Creditors Bureau dba American Medical...
On March 4, 2021, Senator Robert Menendez (D-New Jersey), and Reps. Bonnie Watson Coleman (D-New Jersey) and Mikie Sherrill (D-New...
This week, the Arizona Supreme Court revived a HIPAA violation lawsuit filed by a Phoenix man over a privacy violation...
The Virginia Consumer Data Protection Act (CDPA) has been signed into law by Governor Ralph Northam. CDPA requires persons conducting...
A Georgia man who falsely claimed a former acquaintance had violated patient privacy and breached the HIPAA Rules has been...
Wilmington Surgical Associates in North Carolina is facing a class action lawsuit over a Netwalker ransomware attack and data breach...
A settlement proposed by 21st Century Oncology to resolve a November 2020 class action lawsuit has received preliminary approval from...
US Fertility is facing a class action lawsuit over a September 2020 ransomware attack and data breach that affected 878,550...
A woman who worked in a medical research lab at the Nationwide Children’s Hospital in Columbus, OH has been jailed...
A lawsuit filed on behalf of victims of a Brandywine Urology Consultants data breach has been dismissed by the Delaware...
On January 28, 2021, Democratic senators introduced the Public Health Emergency Privacy Act to protect the privacy of Americans and...
A lawsuit has been filed against Burr Ridge, IL-based Easy Healthcare Corp. over the alleged sharing of sensitive user data...
In May 2020, the cloud software company Blackbaud suffered a ransomware attack. As is common in human operated ransomware attacks,...
The U.S. Court of Appeals for the Fifth Circuit has overturned a $4,348,000 HIPAA violation penalty imposed on University of...
The Nevada-based emergency services provider SkyMed has reached a settlement with the Federal Trade Commission (FTC) following an audit of...
A seasonal employee at a Virginia-based tech company that supported the Centers for Medicare & Medicaid Services (CMS) by operating contact...
The Montana-based healthcare provider Kalispell Regional Healthcare has proposed a $4.2 million settlement to resolve a lawsuit filed on behalf...
Mayo Clinic is facing multiple class action lawsuits over an insider data breach reported in October 2020. Mayo Clinic discovered...
A lawsuit has been filed in the US District Court in Massachusetts by the medical device vendor Zoll which alleges...
A $350,000 settlement has been reached between Saint Francis Healthcare System and patients impacted by a September 2019 ransomware attack...
A healthcare worker who was accused of violating Health Insurance Portability and Accountability Act (HIPAA) Rules and patient privacy by...
The Indianapolis, IN-based health insurer Anthem Inc. has settled a multi-state investigation by state attorneys general over its 78.8 million...
Individuals impacted by the recent data breaches at Blackbaud, Assured Imaging, and BJC Healthcare have taken legal action over the...
The Department of Health and Human Services’ Office for Civil Rights has announced its 10th HIPAA violation fine of 2020....
The U.S. Department of Justice has announced that a member of the notorious hacking group, The Dark Overlord, has been...
In 2019, a lawsuit was filed against Express Scripts by five independent pharmacies alleging improper use of patient data in...
A lawsuit has been filed against HealthAlliance Hospital and Ciox Health, its health record management vendor, for denying a widow...
A potential class action lawsuit filed against the University of Chicago, UChicago Medicine, and Google over an alleged privacy and...
Konica Minolta Healthcare Americas Inc. has agreed to pay a $500,000 financial penalty to settle a case against its former...
In 2019, Beaver, PA-based Heritage Valley Health System filed a lawsuit against its vendor Nuance Communications over its NotPetya malware...
A lawsuit filed against Sarrell Regional Dental Center for Public Health Inc. over a July 2019 ransomware attack has been...
Two Chinese nationals have been indicted by the U.S. Department of Justice (DOJ) for targeting and hacking US companies, government...
It is becoming increasingly common for healthcare organizations to face legal action after experiencing a ransomware attack in which patient...
On July 1, 2020, enforcement of the California Consumer Privacy Act (CCPA) of 2018 began. The CCPA took effect on...
A proposed settlement has been agreed between Grays Harbor Community Hospital and Harbor Medical Group and the representative plaintiff in...
Des Moines, Iowa-based UnityPoint Health has agreed to settle a proposed class action lawsuit filed by victims of two phishing...
A lawsuit filed by patients of Uniondale, N.Y-based Episcopal Health Services Inc., whose personal and protected health information was compromised...
The United States Attorney’s Office of the Western District of Pennsylvania has announced a suspect has been arrested and charged...
Patients whose protected health information was stolen in a manual ransomware attack on the New York accounting firm BST &...
The Atlanta, GA-based healthcare provider Aveanna Healthcare is facing a class action lawsuit over a data breach that occurred in...
On May 19, 2020, legislative changes to the Washington D.C. data breach notification law took effect. The changes were introduced...
A patient who sued Parkview Health System Inc. after a medical assistant accessed her medical records and shared sensitive information...
Lurie Children’s Hospital of Chicago is facing legal action over two privacy breaches involving employees accessing the medical records of...
A LabCorp shareholder is taking legal action against LabCorp and its executives and directors over the loss in share value...
A settlement proposed by Banner Health to resolve a class action lawsuit filed on behalf of victims of its 3.7...
The San Diego medical device manufacturer, Tandem Diabetes Care Inc., is facing a class action lawsuit in California over a...
The McHenry County Health Department in Illinois has been refusing to provide the names of COVID-19 patients to 911 dispatchers...
A $1 million settlement proposed by American HomePatient to resolve a class action lawsuit filed on behalf of victims of...
A law firm is taking legal action against the healthcare release-of-information solution provider, Medical Records Online (MRO), for alleged overcharging...
A federal judge has given final approval of a settlement to resolve a class action lawsuit filed against the New...
Several lawsuits filed against healthcare organizations over data breaches in recent weeks, with University of Washington Medicine the latest to...
A former employee of ACM Global Laboratories, part of Rochester Regional Health, has been accused of accessing the medical records...
A lawsuit has been filed against the New Jersey Healthcare provider, Hackensack Meridian Health, over a December 2, 2019 ransomware...
A former medical clinic worker in Florida who impermissibly accessed the protected health information of patients and sold the information...
A Georgia man has been charged over an elaborate scheme to frame an acquaintance for violations of the Health Insurance...
A second lawsuit has been filed against Kalispell Regional Healthcare in Montana over a May 2019 phishing attack that saw...
A lawsuit filed against Athens Orthopedic Clinic over a June 2016 cyberattack by TheDarkOverlord has been revived by the Georgia...
A lawsuit has been filed in the Western Division of U.S. District Court for the Northern District of Alabama against...
In June 2016, Banner Health suffered a data breach in which the protected health information of 2.9 million individuals was...
Kalispell Regional Healthcare in Montana is being sued over a phishing attack in which hackers gained access to employee email...
Solara Medical Supplies is facing legal action over a June 2019 data breach that saw the protected health information of...
Compensation is being sought by former Facebook content moderators who claim to have suffered psychological injuries as a direct result...
Following a November 2016 cyberattack at Quest Diagnostics that resulted in an unauthorized individual accessing and stealing the personal information...
California Governor Gov. Gavin Newsom has signed a new bill that updates data breach notification law in California, expanding the...
From October 1, 2019, providers of health insurance and associated services are required to notify the Maryland Insurance Administration (MIA)...
On June 26, a patient of University of Chicago Medical Center (UCMC) filed a lawsuit against the medical center and...
A class action lawsuit filed by victims of a June 2016 cyberattack on Athens Orthopedic in Georgia has gone before...
A lawsuit has been filed against University of Missouri Health Care (MU Health) over an April 2019 phishing attack. On...
A preliminary settlement has been proposed by Allscripts Healthcare Solutions to resolve alleged violations of HIPAA, the HITECH Act’s electronic...
A class-action data breach lawsuit filed against UnityPoint Health has been partially dismissed by the US District Court for the...
A Federal District Judge has given preliminary approval to a proposed $74 million settlement to resolve a consolidated class action...
The Stop Hacks and Improve Electronic Data Security (SHIELD) Act has been signed into state law by New York Governor...
Equifax has agreed to settle its federal data breach case for a minimum of $575 million. The settlement will potentially...
The GDPR data protection authority in the Netherlands – Authoriteit Persoonsgegevens – has issued its first GDPR data breach fine....
New rules for hospitals have been implemented in Idaho that give patients new rights. The rules were implemented by the...
Premera Blue Cross has agreed to a $10 million settlement to resolve a multi-state data breach lawsuit involving 30 state...
A medical student is suing Marshall University and Cabell Huntington Hospital over the impermissible disclosure of some of his protected...
A lawsuit has been filed by a former patient of UChicago Medicine who claims his medical records – and those...
A former patient care coordinator at University of Pittsburgh Medical Center (UPMC) has received a 1-year jail term for accessing the medical...
Following the massive data breach at American Medical Collection Agency (AMCA) which saw more than 20 million records compromised, AMCA’s...
A woman in Alabama has been awarded $300,000 in damages after a doctor illegally accessed and disclosed her protected health...
The dust has barely settled after the news of the massive data breach at American Medical Collection Agency (AMCA) broke...
Oregon has updated its breach notification laws and has broadened the definition of consumer information, updated the definition of covered...
Coffey Health System has agreed to a $250,000 settlement with the U.S. Department of Justice to resolve alleged violations of...
The Supreme Court in Vermont has ruled that a patient can sue a hospital and one of its employees for...
In March 2015, the Seattle-based health insurer Premera Blue Cross announced it had experienced a major data breach that impacted...
Since the Department of Health and Human Services implemented the requirements of the Health Information Technology for Economic and Clinical...
A lawsuit has been filed against Atchison Hospital in Kansas by a rape victim who alleges an x-ray technician at...
Two Chinese nationals who were allegedly behind the 2015 hacking of Anthem Inc., have been charged by the U.S. Department...
An Arizona man who sued Costco over a privacy violation and had the lawsuit dismissed by the trial court has...
In February 2019, Baystate Health experienced a phishing attack that resulted in the exposure of the protected health information (PHI)...
A new data breach notification law (HB 1071 / SB 5064) has been unanimously passed by the Washington legislature and...
A $4.7 million settlement has recently been approved by the King County Superior Court to reimburse individuals whose personal information...
A lawsuit has been filed against Sharp HealthCare and Sharp Grossmont Hospital which alleges the hospital secretly recorded video footage...
A settlement has been reached to resolve a class action lawsuit filed on behalf of victims of an alleged data...
A class action lawsuit has been proposed which seeks to recover damages for patients whose protected health information (PHI) was...
Washington D.C. Attorney General Karl. A. Racine is looking to strengthen data breach notification laws to provide greater protection for...
UCLA Health has settled a class action lawsuit filed on behalf of victims of HIPAA compliance data breach that was...
Northwestern Medicine Regional Medical Group is being sued by a patient whose sensitive medial information was disclosed on Twitter and...
Senator Gary Farmer (D-FL) and Representative Bobby DuBose (D-FL) have proposed new bills (SB 1270 /HB 1153) that require all...
A former employee of an affiliate of University of Pittsburgh Medical Center (UPMC) who was discovered to have accessed the...
The New Jersey Assembly has unanimously passed a bill that expands the types of personal information that require notifications to...
From March 20, 2019, insurance companies in Ohio will be subject to a new law (Senate Bill 273) that requires...
The data breach notification laws in California are already some of the toughest in the United States, although they could...
Following a spate of ransomware attacks on businesses and hospitals in Maryland, a new bill (Senate Bill 151) has been...
The Department of Health and Human Services’ Office for Civil Rights (OCR) has agreed to settle a HIPAA violation case...
Community Health Systems’ (CHS) patients whose protected health information (PHI) was stolen in a cyberattack in 2014 have been offered...
The Illinois Supreme Court has ruled that individuals whose privacy has been violated through a breach of the Illinois Biometric...
Hartford, CT-based health insurer Aetna has agreed to pay the California Attorney General $935,000 to resolve alleged violations of state...
The Oregon Health Information Property Act proposes patients should be allowed to authorize their healthcare providers to sell their health...
Following an increase in data breaches affecting North Carolina residents in 2017, state Attorney General Josh Stein and state representative...
A physician who pleaded guilty to a criminal violation of HIPAA Rules has received 6 months’ probation and has escaped...
A new Massachusetts data breach notification law has been enacted. The new legislation was signed into law by Massachusetts governor...
The hacker behind a Distributed Denial of Service (DDoS) attack on Boston Children’s Hospital in 2014 has been handed a...
A class action data breach lawsuit filed against Flowers Hospital in Dothan, AL, in 2014 has finally been settled. In...
A lawsuit has been filed on behalf of patients who had their protected health information stolen as a result of...
An 11-year lawsuit that was filed following the release of a woman’s medical records to her former boyfriend has finally...
Is Your Organization HIPAA Compliant?
Find Out With Our Free HIPAA Compliance Checklist
Get Free Checklist