HHS Updates Security Risk Assessment Tool
The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited…
Get The FREE
HIPAA Checklist
Discover everything you need to become HIPAA compliant
Get Free ChecklistThe HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited…
A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to…
Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data…
Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting,…
The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in…
In early July, we reported that AdaptHealth had notified the U.S. Securities and Exchange Commission that it had experienced a…
Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit…
The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as…
A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information…
The healthcare industry has the highest rate of third-party data breaches out of any sector, according to the Verizon Data…
A final rule updating the HIPAA Security Rule was due for release as early as May 2026; however, the time…
Artificial intelligence is rapidly reshaping healthcare, offering new ways to analyze data, support clinical decisions, streamline operations, and improve patient…
The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in…
In early July, we reported that AdaptHealth had notified the U.S. Securities and Exchange Commission that it had experienced a…
Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by…
It has been two weeks since a cyberattack on the Massachusetts-based medical device manufacturer Boston Scientific prevented access to critical…
The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited…
In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more…
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of…
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training...
Why AI Tools are Problem for HIPAA Compliance and how training can help.
Organizations must take care how social media is used to avoid HIPAA violations.
Why healthcare students need additional targeted HIPAA training.
First identify which standards your organization needs to comply with HIPAA compliant, then implement these.
HIPAA security training is required for all members of the workforce regardless of whether they have access to PHI or not.
Changes to HIPAA in 2025, including expected upcoming updates.
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
A New York business associate has chosen to settle an alleged violation of the Health Insurance Portability and Accountability Act…
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced new additions to its List of…
Two hospitals have entered into settlement agreements with the Department of Health and Human Services (HHS) Office of Inspector General…
Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data…
Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit…
Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating…
The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack…
Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident…
Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma,…
In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some…
Medical Management Resource Group LLC (MMRC), doing business as American Vision Partners, has agreed to settle class action litigation stemming…
A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to…
Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting,…
The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as…
In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more…
The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has…
A lawsuit has been filed in the U.S. District Court for the Northern District of California against two healthcare organizations over their use of an AI-based tool that records conversations…
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has launched the first wave of Health Tech Ecosystem tools as part of its initiative…
See what an investigation actually looks like and learn where organizations fail so you can avoid government fines and drawn…
Free Webinar: HIPAA Compliant Email - What you Actually Need (Without an IT Team)
Artificial intelligence has tremendous potential in healthcare, and healthcare organizations have embraced AI tools in all areas of their operation;…
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced…
On April 10, 2026, two days after the Occupational Safety and Health Administration’s (OSHA) Heat National Emphasis Program (NEP) expired, OSHA announced an update to the NEP. The updated NEP…
The Department of Labor Office of Inspector General will be conducting a federal audit to determine how well the Occupational Safety and Health Administration (OSHA) is addressing the growing problem…
The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI…
The HIPAA Journal has compiled healthcare data breach statistics from October 2009, when the Department of Health and Human Services…
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
Mandatory HIPAA training explained.
Medical spas that qualify as HIPAA-Covered Entities should provide all members of their workforce with HIPAA training that covers foundational…
5-part guide to choosing HIPAA training