Paubox Opens HIPAA Compliant Forms to AI Agents – Business Wire
ChatGPT Integrates Epic EHR with Public Health Data Access – blockchain.news
Hacking Incidents Announced by Rehabilitative Care Providers and Senior Living Facilities – The HIPAA Journal
Hacking Incidents Announced by Rehabilitative Care Providers and Senior Living Facilities
Data breaches have been announced by multiple North Carolina rehabilitative care practices, senior living and skilled nursing care providers in Ohio and Washington, and the California-based nonprofit foundation The Health Trust and its subsidiary, FASS.
North Carolina Rehabilitation Practices Notify Patients About November Hacking Incident
The operator of multiple clinical, long-term, and rehabilitative care practices in North Carolina has reported a data security incident that has affected almost 4,000 patients of Elevate Health & Rehabilitation, Bear Mountain Health and Rehabilitation, and Swannanoa Valley Health and Rehabilitation.
On June 1, 2026, the operator learned that there had been unauthorized access to files maintained by an unnamed third-party vendor, and some of those files had been copied by a bad actor. The unauthorized third party used stolen credentials to log in to its system between November 25, 2025, and November 28, 2025. The obtained files contained patient information such as names, addresses, email addresses, dates of birth, Social Security numbers, driver’s license numbers, patient account numbers, diagnoses, and other health information.
Assurances were received that the stolen data has been deleted and was not published online, which suggests that the vendor paid a ransom. The compromised credentials have been disabled, passwords reset, and additional steps have been taken to strengthen security and the privacy of patient information. The data breach was reported to the HHS’ Office for Civil Rights by Asheville Victoria NC Opco LLC as affecting 1,551 patients of Elevate Health & Rehabilitation; Asheville Beaverdam NC Opco LLC, as affecting 1,397 patients of Bear Mountain Health and Rehabilitation; and Asheville US Seventy NC Opco LLC, as affecting 1,045 patients of Swannanoa Valley Health and Rehabilitation.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Ohio Skilled Nursing Care Provider Hit with Medusa Ransomware Attack
Atrium Centers Inc., a Columbus, Ohio-based skilled nursing and rehabilitation care provider, has alerted patients about an October 2025 cybersecurity incident. Unusual activity was identified within certain computer systems on or around October 13, 2026. Assisted by third-party cybersecurity experts, Atrium Centers determined that an unauthorized third party had accessed certain computer systems between October 8, 2025, and October 12, 2025. During that time, files containing patient and employee data were viewed or copied.
The files were reviewed and found to contain names, contact information, demographic information, dates of birth, Social Security numbers, driver’s license numbers, patient ID numbers, medical record numbers, medical information, health insurance information, financial account information, claims information. The file review is ongoing, and the number of affected individuals has yet to be publicly disclosed. Notification letters will be mailed to the affected individuals when that process is completed. Atrium Centers said it is enhancing its technical safeguards to prevent similar incidents in the future.
Rockwood Retirement Communities Discloses February 2026 Hacking Incident
Spokane United Methodist Homes, doing business as Rockwood Retirement Communities, a Spokane, Washington-based senior living organization, has started notifying individuals impacted by a February 2026 hacking incident. Suspicious network activity was identified on or around February 16, 2026. Immediate action was taken to secure its systems, and third-party cybersecurity and digital forensics experts were engaged to investigate the activity. The investigation confirmed unauthorized network access and the exfiltration of files from its network.
Third-party data review experts conducted a comprehensive and time-consuming review of the affected data, contact information was verified, and notification letters were sent to the affected individuals. Those processes were completed on July 27, 2026. Data compromised in the incident included personal and protected health information such as names, Social Security numbers, dates of birth, driver’s license numbers/state identification numbers, passport numbers, financial account information, Medicaid/Medicare numbers, medical information, and/or health insurance information. Rockwood Retirement Communities is unaware of any actual or attempted misuse of that data.
The HHS’ Office for Civil Rights (OCR) has been informed, but the data breach has yet to be added to the OCR data breach portal, so it is currently unclear how many individuals have been affected.
Qilin Claims Responsibility for The Health Trust Hacking Incident
The Health Trust, a San Jose, California-based nonprofit foundation that provides services to governmental and non-governmental organizations to help build health equity and improve health outcomes, has identified a hacking incident that also affected its subsidiary, Financial Administrative Support Services (FASS).
On May 26, 2025, FASS identified suspicious activity within its computer network. Steps were immediately taken to secure its network; however, on June 11, 2025, further suspicious activity was identified. All systems were immediately taken offline while security was assessed and the activity was investigated. The forensic investigation determined that there had been unauthorized access to certain systems prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025.
Files on the compromised parts of the network were accessed or copied. The review determined that they contained names, Social Security numbers, financial account information, government-issued identification numbers, medical information, and health insurance information. Internal data privacy and security policies, procedures, and protocols have been reviewed, and additional security measures have been implemented to prevent similar incidents in the future. The affected individuals have been offered complimentary credit monitoring services. The Qilin threat group claimed responsibility for the incident and said it exfiltrated 408 gigabytes of data.
The post Hacking Incidents Announced by Rehabilitative Care Providers and Senior Living Facilities appeared first on The HIPAA Journal.
HHS Convenes Leaders at the Live Real Life Symposium to Address Harms of Screen Use in Children – HHS.gov
DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation
In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some of the affected individuals took legal action in response to the data breach, which they claim has put them at risk of identity theft and fraud. Following extensive negotiations, a $15 million settlement has been proposed to bring the litigation to an end.
DaVita operates more than 3,000 kidney dialysis centers in the United States and 14 other countries. On April 12, 2025, the Interlock ransomware group accessed its network, exfiltrated data, and encrypted files, causing temporary disruption to operations. The forensic investigation determined that the electronic protected health information of 2,689,826 individuals was compromised in the incident, including names, contact information, Social Security numbers, health insurance information, clinical information, and tax information. Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not paid.
Multiple class action lawsuits were filed in response to the data breach that alleged that it occurred as a result of the defendant’s failure to implement reasonable and appropriate cybersecurity measures. The lawsuits were consolidated – Julian Jenkins, et al v. DaVita Inc. – in the United States District Court for the District of Colorado as they had overlapping claims.
The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and violations of state consumer protection statutes. The lawsuit alleged that the plaintiffs face a current, imminent, and ongoing risk of fraud and identity theft as a result of the theft of their personal and health information, and the publication of that information on the dark web. The defendant denies the claims and contentions in the lawsuit, including claims of negligence, fault, and liability.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
All parties were able to negotiate a settlement to resolve the litigation, with no admission of liability or wrongdoing by DaVita. The proposed $15,000,000 settlement covers attorneys’ fees and expenses, settlement administration costs, service awards for the five class representatives, and a $10,000,000 non-revisionary settlement fund to pay relief to the class members.
Class members may submit a claim for up to $2,500 as reimbursement for documented, unreimbursed out-of-pocket losses due to the data breach. All class members, including those who submit a claim for reimbursement of losses, may claim a pro rata cash payment. The amount will depend on the number of valid claims received. The class consists of approximately 2.3 million individuals, and if everyone submits a claim, that would amount to around $4.17 per class member; however, based on the expected response rate, the cash payments are anticipated to be around $50 per class member.
The post DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation appeared first on The HIPAA Journal.
