23 Healthcare Workers Are Sharing Their Most Baffling “HIPAA-Compliant” Patient Stories – BuzzFeed
23 Truly Baffling “HIPAA-Compliant” Patient Stories From Healthcare Workers – Yahoo
23 Truly Baffling “HIPAA-Compliant” Patient Stories From Healthcare Workers – Yahoo Lifestyle Canada
Data Breaches Announced by Five HIPAA-Regulated Entities
Data breaches have recently been announced by the Women’s Center for Radiology in Florida, Optalis Management Solutions in Michigan, the Association for Neurologically Impaired Brain Injured in New York, the Cardiovascular Institute of New England in Rhode Island, and the Kubota Tractor Corporation in Texas.
Women’s Center for Radiology, Florida
Women’s Center for Radiology, a Florida-based women’s radiology practice with two centers in Orlando, has notified 66,422 patients about a data security incident identified on April 29, 2026. Assisted by third-party cybersecurity specialists, the Women’s Center for Radiology determined that an unauthorized third party had access to its network between April 26, 2026, and April 28, 2026, and accessed or downloaded files containing patient information.
After securing its network, the files were reviewed and found to contain patient information such as names, addresses, dates of birth, contact information, diagnosis/condition information, lab test results, treating/referring physician names, medical record numbers, driver’s license numbers, and health insurance information. Data privacy and security policies, procedures, and processes are being reviewed to reduce the likelihood of similar incidents in the future. While data misuse has not been identified, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.
Optalis Management Solutions, Michigan
Optalis Management Solutions, a Michigan-based management company that operates Optalis Health & Rehabilitation’s skilled nursing, rehabilitation, assisted living, and independent living facilities, has notified 13,723 individuals about a breach of some of their protected health information. Suspicious activity was identified within its computer network, and the investigation confirmed unauthorized access occurred between April 14, 2025, and April 19, 2025. After a breach was confirmed by third-party cybersecurity specialists, a document review was initiated to determine the individuals and data types involved. That process concluded on June 10, 2026.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Data potentially viewed or obtained in the incident included full names in combination with one or more of the following: Social Security number, driver’s license number/state ID number, credit/debit card information, financial account information, diagnosis and treatment information, and/or health insurance policy number. Notifications were mailed to the affected individuals on June 29, 2026, and individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services.
Kubota Tractor Corporation, Texas
Kubota Tractor Corporation, a Japanese company that makes agricultural and construction equipment, has recently confirmed that hackers gained access to certain parts of its network earlier this year. The forensic investigation determined that its network was first compromised on March 16, 2026, and the hackers maintained access for more than a month. The unauthorized access was detected and blocked on April 20, 2026. The company, which has its U.S. HQ in Grapevine, Texas, determined that this was a reportable breach under HIPAA, as the incident involved unauthorized access to the protected health information of beneficiaries of its Employee Welfare Benefit Plan.
Employee data potentially compromised in the incident includes names in combination with one or more of the following: Social Security number, date of birth, taxpayer identification number, driver’s license or other government-issued identification number, financial account information for direct deposit, payment card information for corporate cards, benefit enrollment information, and limited claims information. For dependents of employees, the exposed data may have included names in combination with one or more of the following: Social Security number, date of birth, benefit enrollment information, and limited claims information. Notification letters were mailed to the 5,891 affected individuals on June 30, 2026, and complimentary identity monitoring services have been offered.
Cardiovascular Institute of New England, Rhode Island
The Cardiovascular Institute of New England, a heart care practice with seven locations in Rhode Island, started mailing notification letters to patients on July 28, 2026, about a data security incident identified on or around February 12, 2026. Suspicious activity was identified within its email environment, and the investigation confirmed unauthorized email access, which may have resulted in patient data being viewed or acquired.
The review of the affected email accounts was completed on or around July 14, 2026, when the practice learned that names, phone numbers, dates of birth, financial account numbers, medical information, medical diagnoses, treatment information, treatment locations, clinical information, prescription information, and medical insurance provider information had been exposed. No evidence has been found to suggest that any patient data has been misused.
Email security policies, procedures, and security measures are being reviewed, and steps are being taken to reduce the risk of similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.
The Association for Neurologically Impaired Brain Injured, New York
The Association for Neurologically Impaired Brain Injured (ANIBIC), a New York-based not-for-profit agency that provides services to individuals with developmental and neurological disabilities, has recently informed the HHS’ Office for Civil Rights about a breach of the protected health information of 1,918 individuals. According to its substitute breach notice, suspicious activity was identified within its computer network on or around March 8, 2026. The investigation determined that an unauthorized third party accessed files containing program member information between March 7, 2026, and March 8, 2026.
The compromised information included names, contact information, Social Security numbers, dates of birth, health insurance information, and service details such as diagnoses, treatment information, and prescriptions. Notification letters were mailed to the affected individuals on July 17, 2026, and complimentary identity monitoring services have been offered to individuals whose Social Security numbers were involved.
The post Data Breaches Announced by Five HIPAA-Regulated Entities appeared first on The HIPAA Journal.
OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits
Individuals affected by data breaches at OnePoint Patient Care and Clay-Platte Family Medicine may be entitled to claim benefits after settlements have been agreed to resolve class action lawsuits. The lawsuit against OnePoint Patient Care has been settled for $2,115,000, and the Clay-Platte Family Medicine lawsuit has been settled for $1,000,000.
OnePoint Patient Care Data Breach Settlement
OP Pharmacy, LLC, also known as OnePoint Patient Care, LLC, a Kentucky-based hospice-dedicated pharmacy and pharmacy benefits manager, was sued in response to a 2024 data breach. The lawsuit relates to a security incident detected by OnePoint on August 8, 2024. Hackers gained access to systems containing the protected health information of 1,741,152 individuals and copied files from its network between August 6 and August 8, 2024. At the time the lawsuit was filed, approximately 528,000 patients were living. Notification letters were mailed to the affected individuals in October and November, 2024
The lawsuit alleged that the defendant willfully, recklessly, or negligently maintained patient data, as it failed to implement appropriate cybersecurity measures and did not keep its systems free of vulnerabilities. Two lawsuits were filed in response to the breach, which were consolidated as they had overlapping claims. The consolidated lawsuit – Christopher Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC – was filed in the District Court for the Western District of Kentucky, Louisville Division. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, breach of fiduciary duty, and for declaratory and injunctive relief.
The defendant disagrees with the claims and contentions in the lawsuit; however, a settlement was negotiated to avoid the cost and risks associated with a trial and related appeals. OnePoint will establish a $2,115,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remaining funds will pay for class member benefits.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
A claim may be submitted for one of two cash payments: reimbursement of documented, unreimbursed losses due to the data breach up to $3,500 per class member, or an alternative pro rata cash payment, estimated to be $100 per claimant. The cash payments will be subject to a pro rata increase or decrease, depending on the number of valid claims received. In addition, OnePoint has agreed to implement additional security measures to reduce the risk of similar breaches in the future. The deadline for exclusion and opting out is August 24, 2026. The deadline for submitting a claim is October 8, 2026, and the final fairness hearing is scheduled for September 23, 2026.
Clay-Platte Family Medicine Data Breach Settlement
Clay-Platte Family Medicine and Barry Pointe Family Care in Kansas City, Missouri, and Cobblestone Family Medicine Clinic dba Clay Platte Family Medicine Clinic and Nathan D. Granger, dba Summit Family and Sports Medicine in Harrisonville, Missouri, were sued in response to a June 2024 data breach involving the electronic protected health information of patients. Hackers gained access to its network on or around June 26, 2024, and potentially viewed or obtained patient data such as names, contact information, dates of birth, Social Security numbers, and medical information.
Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – Highfill, et al. v. Clay-Platte Family Medicine Clinic, P.C., et al – in the U.S. District Court for the Western District of Missouri. The consolidated lawsuit alleged that the defendants failed to implement reasonable and appropriate safeguards to ensure the privacy of patient data, such as the encryption of data on its network. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, invasion of privacy by public disclosure of private facts, breach of fiduciary duty of confidentiality, negligent training and supervision, invasion of privacy, and violations of the Missouri Merchandising Practices Act.
The defendants deny any wrongdoing and sought to have the lawsuit dismissed. The motion to dismiss was granted in part, although certain claims were allowed to proceed. Following mediation and continued negotiations, a settlement was agreed to by all parties. The settlement class consists of the 53,916 individuals who were notified about the data breach. A $1,000,000 settlement fund will be established to pay for court-approved costs and benefits for the class members.
All class members are entitled to enroll in three years of free medical and credit monitoring services. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses or an alternative cash payment. Claims for reimbursement of documented losses have been capped at $15,000 per class member. The remainder of the settlement fund will be paid pro rata to individuals who claim an alternative cash payment. The deadline for exclusion and opting out is September 6, 2026. The deadline for submitting a claim is September 30, 2026, and the final fairness hearing is scheduled for September 29, 2026.
The post OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits appeared first on The HIPAA Journal.
OSF Healthcare pays $552,250 for HIPAA violations from ransomware breach – Compliance Week
Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits – The HIPAA Journal
Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits
Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants that stem from breaches of patient data.
Highland Health Systems Data Breach Settlement
A settlement has been agreed to resolve a class action lawsuit against the nonprofit healthcare organization Highland Health Systems, CEO Mickey Turner, and Director of Finance Allen Stokes, stemming from a July 2023 data breach.
A security incident was identified in early July 2023, in which sensitive patient data was accessed and stolen by hackers. Data compromised in the incident included patient and employee data, including names, contact information, birth dates, Social Security numbers, account numbers, payment card information, medical information, health Insurance Information, tax IDs, and other sensitive data. The affected individuals were notified about the data breach on June 13, 2024, and the data breach was reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 83,543 individuals.
Two class action lawsuits were filed in response to the data breach, which were combined into a single action –Weyerman, et al. v. Highland Health Systems et al.– which is pending in the Circuit Court for Calhoun County, Alabama. The lawsuit alleges that the data breach was the result of the defendants’ negligence and could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit asserted claims for negligence/negligence per se, breach of express and/or implied contract, wantonness, breach of fiduciary duty, breach of confidence, and unjust enrichment.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The defendants denied all claims and contentions in the lawsuit and sought to have the lawsuit dismissed; however, the court rejected the motion to dismiss in its entirety. Mediation proved unsuccessful; however, a settlement agreement was subsequently negotiated that was acceptable to all parties. Highland Health Systems has agreed to establish a $650,000 settlement fund to cover the costs of litigation, attorneys’ fees, administration costs, and benefits for the class members.
Those benefits include a two-year membership to a medical identity protection service and one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a one-time pro rata cash payment may be claimed, which is expected to be $85 per class member, but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 28, 2026. Claims must be submitted by October 28, 2026, and the final approval hearing has been scheduled for November 30, 2026.
Albany Gastroenterology Consultants Data Breach Settlement
Albany Gastroenterology Consultants, PLLC, a New York gastroenterology practice, has agreed to settle litigation stemming from a November 2024 security incident. The incident occurred on or around November 10, 2024. Hackers gained access to its network, where the personally identifiable information and protected health information of 57,751 individuals was stored. Data potentially compromised in the incident included names, addresses, Social Security numbers, medical information, and health insurance information. The affected individuals started to be notified on January 28, 2025.
Multiple class action lawsuits were filed in response to the data breach in the Supreme Court of the State of New York, County of Albany. The defendant filed a motion to dismiss, and the plaintiffs filed their response. All parties agreed to engage in settlement discussions, and during those discussions, the parties agreed that the Circuit Court for the Eleventh Judicial Circuit in and for Miami-Dade County, Florida, was the proper venue and the New York state actions were voluntarily dismissed. The amended lawsuit was filed in Florida – Clements v. Albany Gastroenterology Consultants, PLLC. The negotiated settlement has received preliminary approval from the court.
The defendant will pay attorneys’ fees and expenses, service awards for the class representatives, and will establish a $200,00 settlement fund to pay benefits to the class members. Class members may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $2,500 per class member. Alternatively, a claim may be submitted for a one-time cash payment, expected to be around $10 per class member. In addition, class members are eligible to enrol in a 2-year membership to a credit monitoring and medical data monitoring service. The $200,000 settlement fund will be divided equally between the two cash payments. If the $100,000 for either is exceeded, claims will be paid pro rata. The deadline for objection and opting out is August 21, 2026. Claims must be submitted by October 5, 2026, and the final approval hearing has been scheduled for September 22, 2026.
The post Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits appeared first on The HIPAA Journal.
