House Committee Advances Bill Preventing OSHA From Implementing Heat Standard
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard…
Get The FREE
HIPAA Checklist
Discover everything you need to become HIPAA compliant
Get Free ChecklistA bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard…
Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have…
AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced…
MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the…
Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital. Wildwood…
Anatomic and Clinical Laboratory Associates is notifying almost 170,000 patients about a recent cybersecurity incident. Data breaches have also been…
At smaller organizations with under 100 employees, responsibility for HIPAA compliance normally falls to an administrator or practice manager who usually won’t have deep knowledge of compliance matters. For these multitasking individuals, the best HIPAA compliance software reduces the administrative burden and lessens the likelihood of an expensive HIPAA breach. In this article we discuss how to choose a suitable HIPAA compliance software tool.
There has been a general trend of increasing data breaches over the past decade, with this year on track to…
The healthcare industry has the highest rate of third-party data breaches out of any sector, according to the Verizon Data…
A final rule updating the HIPAA Security Rule is due for release as early as May 2026. According to HHS/OCR,…
Artificial intelligence is rapidly reshaping healthcare, offering new ways to analyze data, support clinical decisions, streamline operations, and improve patient…
Hackers focus on medical records because the combination of demographic data, insurance details, clinical information, and financial identifiers creates a…
Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have…
AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced…
MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the…
Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital. Wildwood…
Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting…
There has been some good news for the HIPAA-regulated entities that feel unprepared for the proposed changes to the HIPAA…
In April 2026, 47 healthcare data breaches affecting 500 or more individuals were reported to the HHS’ Office for Civil…
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training...
Why AI Tools are Problem for HIPAA Compliance and how training can help.
Organizations must take care how social media is used to avoid HIPAA violations.
Why healthcare students need additional targeted HIPAA training.
First identify which standards your organization needs to comply with HIPAA compliant, then implement these.
HIPAA security training is required for all members of the workforce regardless of whether they have access to PHI or not.
Changes to HIPAA in 2025, including expected upcoming updates.
New legislation – the Health Information Privacy Reform Act – has been introduced to improve privacy protections for health information…
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
A New York business associate has chosen to settle an alleged violation of the Health Insurance Portability and Accountability Act…
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced new additions to its List of…
Two hospitals have entered into settlement agreements with the Department of Health and Human Services (HHS) Office of Inspector General…
Healthcare providers participating in federal healthcare programs are advised to regularly check the HHS OIG Exclusions List to avoid penalties…
Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved…
ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle…
A coalition of 42 state attorneys general has agreed to a $18 million settlement with 23andMe (now Chrome Holding Co.)…
Charlotte-Mecklenburg Hospital Authority, doing business as Atrium Health, has agreed to pay up to $1,800,000 to settle a class action…
Settlements have been agreed to resolve class action lawsuits against two vision care providers: Total Vision in California and Naper…
Physicians Primary Care of Southwest Florida was the victim of a targeted cyberattack in September 2024 that exposed patient data….
A settlement has been agreed to resolve a class action lawsuit against the Nashville, TN-based health plan administration service provider,…
A settlement has been agreed to resolve a class action lawsuit against the Pinehurst, North Carolina-based molecular, cytology, and pathology…
A recent analysis of healthcare websites has revealed that the majority use marketing and analytics tools that could potentially disclose…
Accenture, one of the world’s largest consulting firms, has confirmed it has experienced a security breach, shortly after a hacker…
Researchers have identified what they believe to be the first agentic ransomware attack. An autonomous large language model (LLM) agent…
The Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) has announced the formation of the Alliance of…
The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has…
A lawsuit has been filed in the U.S. District Court for the Northern District of California against two healthcare organizations over their use of an AI-based tool that records conversations…
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has launched the first wave of Health Tech Ecosystem tools as part of its initiative…
Small healthcare practices often assume their emails are HIPAA-compliant; however, security gaps are often found to exist that threaten patient…
Join Bradley King, a senior compliance consultant, as he provides a clear explanation for small medical practices on what they…
Artificial intelligence has tremendous potential in healthcare, and healthcare organizations have embraced AI tools in all areas of their operation;…
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced…
On April 10, 2026, two days after the Occupational Safety and Health Administration’s (OSHA) Heat National Emphasis Program (NEP) expired, OSHA announced an update to the NEP. The updated NEP…
The Department of Labor Office of Inspector General will be conducting a federal audit to determine how well the Occupational Safety and Health Administration (OSHA) is addressing the growing problem…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident…
The HHS’ Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have issued…
The U.S. government has announced record-breaking Medicaid fraud charges as part of its 2026 National Health Care Fraud Takedown, with…
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
Medical spas that qualify as HIPAA-Covered Entities should provide all members of their workforce with HIPAA training that covers foundational…
The HIPAA training requirements apply to any individual or organization with access to Protected Health Information that perform a regulated activity as a Covered Entity or as a Business Associate. The Administrative Simplification Regulations (§160.102) make it clear that Business Associates must follow the HIPAA Privacy Rule standard when working with Covered Entities, i.e, they are obliged to meet the same training requirements as a Covered Entity.
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training. However, it…