Healthcare Compliance News

Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced that two settlements have been agreed to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA).

EMTALA was enacted by Congress in 1986 to ensure public access to emergency medical services. EMTALA requires Medicare-participating hospitals that offer emergency services to provide a medical screening examination (MSE) to patients who present to their emergency department requesting an examination or treatment for an emergency medical condition, regardless of the patient’s ability to pay.

A patient must be provided with stabilizing treatment if the MSE determines that they have an emergency medical condition. If the hospital lacks the capability to provide stabilizing treatment, or if requested by the patient, they must initiate an appropriate transfer.  The receiving hospital must have the available space and qualified personnel and must agree to accept the transfer. The transferring hospital must send all medical records related to the emergency condition that are available at the time of the transfer, and send all other records as soon as is practicable. Hospitals that violate EMTALA can face heavy civil monetary penalties, and individuals harmed may pursue legal action for EMTALA violations.

Merit Health Central Hospital

Merit Health Central Hospital in Jackson, Mississippi, formerly known as Central Mississippi Medical Center, has agreed to settle alleged EMTALA violations with HHS-OIG and will pay a $350,000 financial penalty. Unusually, the case relates to patients who presented at the hospital emergency room more than a decade ago. The delay in issuing the penalty was due to a False Claims Act lawsuit related to the alleged EMTALA violations that was working its way through the legal system. HHS-OIG’s investigation determined that the hospital failed to provide an adequate MSE and stabilizing treatment to fourteen patients who presented to its emergency room between January 2013 and April 2015 requesting an examination or treatment for a medical condition.

Out of the fourteen individuals, nine had emergency medical conditions and were transferred to another hospital between January 2013 and May 2013 without providing an appropriate MSE and treatment to stabilize the patients to minimize the risk of transfer, despite having staff within its facilities or available as on-call physicians who could have provided the necessary stabilizing treatment. In six cases, the transfers were based on its application of Central MS Trauma Region Trauma Activation Criteria and Destination Guidelines for the transfer of individuals with penetrating trauma to another hospital. Several of the patients had presented with gunshot wounds.

Four patients presented to the emergency room between March 2015 and April 2015 with a psychiatric emergency medical condition and were not provided with an appropriate MSE within the capabilities of the hospital or stabilizing treatment. The four individuals were transferred by taxi in an unstable condition to a homeless day shelter. One patient presented to the emergency room in March 2015 for treatment related to end-stage renal disease and had an emergency medical condition requiring dialysis, yet stabilizing treatment was not provided even though it was within the hospital’s capabilities.

NorthShore University Health System

NorthShore University Health System in Evanston, Illinois, agreed to settle alleged an EMTALA violation concerning a patient who presented to its emergency room in February 2025 complaining of leg pain and nausea.

The 64-year-old man presented to the emergency department at 10:53 a.m. and was triaged at 11:15 a.m. During triage, the patient’s vitals were taken. He had a heart rate of 126 bpm and was assigned an emergency severity index (ESI) level of 2 – high risk. The patient was placed in a wheelchair in a waiting room but was not reassessed, and his vitals were not rechecked. The patient was found slumped over and unresponsive in the wheelchair at 8:55 p.m – more than 9 hours after he was triaged. The patient was determined to be in cardiac arrest, and CPR was quickly initiated. HHS-OIG’s investigation determined that Northshore failed to provide an appropriate MSE. The case was settled with a $105,000 financial penalty.

The post Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations appeared first on The HIPAA Journal.

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the states of Utah and California over the company’s business and data sharing practices, which are alleged to violate the Federal Trade Act, Restore Online Shoppers’ Confidence Act, Utah Consumer Sales Practices Act, and California’s False Advertising and Unfair Competition Laws.

Him & Hers is a direct-to-consumer business that provides prescription and over-the-counter medications. According to the complaint, filed last week in the U.S. District Court for the Northern District of California, the company claims to maintain consumers’ privacy yet discloses their sensitive data to third-party advertising platforms, without consumers’ knowledge or consent. In addition, the complaint alleges that the company deceives consumers about its billing and cancellation policies.

Him & Hers used tracking technologies such as Meta Pixel and the Meta Conversions API, which automate the recording of user data based on the Him & Hers website and transmit that information to Meta in response to certain events. Him & Hers also used a variety of advertising tools from companies such as Snap, Microsoft, Google, Criteo, Pinterest, TikTok, Trade Desk, and X, which also collected sensitive consumer information and transferred the information to third-party companies for advertising purposes. Him & Hers is also alleged to have sent lists of certain customers to the Meta and Snap custom audience systems.

Oftentimes, consumers use Him & Hers to obtain medications for sensitive medical conditions such as mental health issues, erectile dysfunction, and premature ejaculation. According to the complaint, until at least mid-2023, Him & Hers claimed that “medical records and sensitive information are only accessed by the medical providers managing your care,” and has claimed in its online advertising that consumers are provided with a “100% online, private, and secure process,” yet sensitive information was being shared with third parties for advertising purposes.

In addition to the unlawful data transfers, the complaint alleges that Him & Hers failed to clearly disclose that consumer prescriptions are charged almost immediately after completing an intake form. Consumers were informed that they could consult with a medical provider to find a suitable treatment and would not be charged unless and until their prescriptions are prescribed. The FTC alleges that Him & Hers rarely provides medical consultations, enrolls customers almost immediately into recurring subscription plans, and makes it difficult for consumers to cancel their subscriptions. For instance, consumers are not informed clearly and conspicuously when their recurring prescriptions will be refilled, which makes it difficult for them to cancel before the next billing cycle. Consumers are also not permitted to cancel subscriptions online, only via the phone, email, or chat, and the complaint alleges that consumers must navigate other hurdles, making it “extremely difficult” to cancel subscriptions.

The lawsuit seeks a permanent injunction preventing the company from engaging in unfair and deceptive business practices, civil penalties, and monetary awards. “The FTC’s complaint lays out a troubling scenario—consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers’ most private health information without their consent,” said Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection. “The FTC will not hesitate to act on behalf of consumers deprived of their ability to choose which products they want and whether to keep their most sensitive health information private.”

This is not the first time that the FTC has taken action against telehealth companies over the use of tracking technologies. Enforcement actions have previously been filed against the fertility tracking app Premom, BetterHelp, and GoodRx. In each case, the complaints were resolved with financial penalties.

The post FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices appeared first on The HIPAA Journal.

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred.

The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure. The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements.

The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential opportunities for harmonization. A recently published GAO report focuses on the potentially duplicative cybersecurity-related reporting requirements for critical infrastructure sectors. In some cases, the same types of information must be reported to different federal agencies, which requires multiple reports to be written about the same cybersecurity incident or compliance activity. That inevitably means resources are being diverted to compliance activities that could be better used for improving security.

Out of 117 regulations identified by GAO across 9 critical infrastructure sectors, 80 – approximately 70% – had the same kind of reporting requirement as another regulation. Across those 80 regulations, there were at least 125 total reporting requirements, as some regulations required multiple types of reporting – 48 required reporting of cybersecurity incidents, 52 required cybersecurity plans or other technical information, and 25 required reviews, audits, or assessments.

GAO believes that duplicative reporting requirements add an unnecessary administrative burden on critical infrastructure entities, which will soon face the additional reporting requirements of CIRCIA. While CIRCIA will improve federal visibility into cybersecurity incidents, it will certainly add to the reporting burden.

GAO is working on obtaining additional industry perspectives on federal cybersecurity regulations, such as where there are overlapping and duplicative reporting requirements, and it intends to issue an implementation plan to help streamline cybersecurity regulations for critical infrastructure entities.

The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal.

HHS Seeks Input on Potential Updates to the CLIA Regulations

The HHS’ Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have issued a request for information (RFI) on potential updates to the Clinical Laboratory Improvement Amendments (CLIA) of 1988. The RFI covers several topics, including breath testing, laboratory processes and procedures, emergency preparedness, cybersecurity, and the use of artificial intelligence. The feedback received in response to the RFI will advise future actions and rulemaking. Comments are being accepted through September 14, 2026.

The CLIA regulations were enacted on October 31, 1988, strengthening federal oversight of clinical laboratories and helping to ensure the accuracy and reliability of patient test results. The CLIA regulations were promulgated in 1992, and while certain elements of the CLIA regulations have been updated over the years, a substantial update may be required to better reflect current knowledge and advancements in laboratory testing.

One area where updates may be required is cybersecurity, as threats across the healthcare sector have expanded significantly in both scope and severity. “As clinical laboratories increasingly rely on digital systems and connected technologies—such as Laboratory Information System (LIS), Electronic Health Record (EHR) integration, automated diagnostic devices, and virtual or remote access to laboratory and patient data—new cybersecurity risks have emerged,” explained the CMS and CDC in the RFI.

Many U.S. laboratories are HIPAA-regulated entities and must therefore comply with the requirements of the HIPAA Security Rule; however, there are gaps that need to be addressed and threats that the current HIPAA Security Rule does not adequately protect against. The CMS is seeking non-proprietary/non-confidential information on current laboratory cybersecurity practices and experiences related to protecting patient data and lab operations; user identity and access; remote access to systems containing personal information from overseas entities; restrictions on ports and/or internet protocol (IP) addresses; cybersecurity response plans; and cybersecurity training.

One area where further regulation is likely required is artificial intelligence, as the CLIA regulations were enacted long before AI tools started to be used in clinical settings. Model corruption, hallucinations, and compromises could have serious implications for the accuracy and reliability of testing. The CMS and CDC are seeking information on postanalytic interpretation and the use of AI tools, specifically, the algorithms and AI tools used in postanalytic analysis; the circumstances where software and AI tools are being used to interpret test results, histopathology slides, and results; the methods used to verify the performance of those tools; and whether there are any additional technology considerations for high complexity tests that the CMS and CDC should consider incorporating into the CLIA regulations.

The post HHS Seeks Input on Potential Updates to the CLIA Regulations appeared first on The HIPAA Journal.

DOJ’s Using Advanced Data Analytics and AI Tools to Combat Healthcare Fraud Before Payment

The U.S. government has announced record-breaking Medicaid fraud charges as part of its 2026 National Health Care Fraud Takedown, with the enforcement action resulting in charges for 455 defendants, including more than 90 doctors and other licensed medical professionals, in connection with more than $6.5 billion in healthcare fraud and opioid abuse claims.

The enforcement action involved a whole-government approach, including U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG), HHS Centers for Medicare and Medicaid Services (CMS), and Drug Enforcement Administration (DEA), with cases in 56 federal districts, 45 U.S. states and territories, and 50 state Medicaid Fraud Control Units participated, more than ever before. There was also unprecedented international cooperation over the two-week takedown. The DOJ seized more than $182 million in cash, luxury vehicles, jewelry, and other assets.

“We are aggressively scaling our offensive against anyone using health care as a front to steal from the American people,” said Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division. “As today’s cases and arrests show, there is no case too big, no scheme too complex, and no hiding place too remote for our relentless fraud-fighting team. Our message is simple: if you put profit over patients, you should expect to be put in prison.”

Advanced Algorithms and AI Tools Used to Shift from Pay-and-Chase to Pre-Payment Detection

The takedown involved the use of cutting-edge data analytics algorithms and artificial intelligence tools to identify potential fraud before criminals cash out, rather than the reactive pay-and-chase approach of previous years. The use of AI tools for fraud prevention is set to expand significantly moving forward. AI tools were used to identify suspicious activity in many of the fraud schemes, including the first-ever criminal prosecution under the Data Fusion Center that was formed last year.

The Data Fusion Center was established to track, identify, and prevent fraudulent billing and medical scams and combines traditional data analytics with financial analysis and comprises experts from the Health Care Fraud Unit’s Data Analytics Team, HHS-OIG, FBI, and other agencies, supported by data sharing agreements between a wide range of government agencies. “Prosecuting criminals who steal from American patients is necessary—but stopping them before a single dollar leaves the building is smarter,” said CMS Administrator Dr. Mehmet Oz.

The Data Fusion Center helped identify a $67 million fraud scheme involving the billing of Illinois Medicaid for behavioral health services that were never provided. The defendant allegedly billed more than 500 hours a day for counselling and therapy services, which could not have been provided even if all providers on staff had been working 24 hours per day. The data analysis showed that patients were hospitalized at other institutions on days when the defendant billed for behavioral health services. Prosecutors opened the case within 5 days of the completion of the data analysis, and the defendant was arrested within 7 months while attempting to flee the country.

Actions by the CMS resulted in the suspension of 1,079 providers and the revocation of billing privileges for 1,403 providers. More than $73 million was obtained in 48 Civil Monetary Payment settlements accompanied by more than 1,400 exclusions, while 25 actions by HHS-OIG are seeking more than $10 billion in payments to the Medicare Trust Fund from payments identified by CMS and blocked before the funds were paid in fraudulent claims. CMS has announced that under a new arrangement, it will provide cloud computing space within its integrated data repository to support the DOJ fraud division’s data analysis algorithms and AI tools to combat health care fraud. Civil charges have been filed against 13 defendants for $14.8 million in health care fraud schemes, along with $23 million in civil settlements with 31 defendants. There have also been 928 administrative cases by the DEA seeking the revocation of authority to handle and prescribe controlled substances since October 1, 2025.

Fraud Costs Taxpayers and Causes Significant Patient Harm

Healthcare fraud costs U.S. taxpayers, exploits vulnerable patients and puts lives at risk, causing considerable patient harm, including death. In one case, the medical director of a cardiovascular testing and treatment practice in Florida was charged in connection with an $89 million fraud scheme to bill for medically unnecessary cardiovascular tests on student athletes. The director falsified diagnoses to defraud health care benefit programs for the testing and is alleged to have rubber-stamped test results as normal without checking them, in some cases stamping test results as normal within seconds.

Student athletes with cardiac abnormalities were not made aware that they were at high risk of sudden cardiac arrest. In one case, a patient’s test results showed an enlarged heart, but the results were signed off as normal. The patient died from complications from his enlarged heart within 24 hours of the test results being signed off as normal.

The DOJ highlighted fraud cases involving wound care, especially allografts, and hospice providers in its announcement, where fraud cases have increased significantly, and these are likely to remain key enforcement areas moving forward. Medicare billing for wound care more than doubled from $3.4 billion in 2023 to $7.5 billion in 2024 and almost doubled again in 2025 to $14.4 billion. The increase in payments was not due to medical necessity; rather, it was driven by illegal kickback and healthcare fraud schemes. Charges were filed in 6 districts for fraudulent claims for amniotic wound allografts against 11 defendants, including a company executive and 8 medical professionals.

In one scheme, a company that did not manufacture allografts obtained them from another firm, added a 2,000% mark-up, paid 40% of that in illegal kickbacks to marketers, and targeted hospice patients, providing medically unnecessary allografts, far exceeding the size of the wound, which were often provided without coordinating with the individual’s treating physician, without proper treatment for infection, and for superficial wounds that did not require the treatment, The defendant was paid more than $24 million by the company, with the marketers and medical professionals involved often paid between $500 and $600 per square centimeter of graft.

“Today’s historic enforcement action sends a clear message: if you use our health care system to enrich yourself at the expense of patients or the American people, we will find you, we will prosecute you, and we will hold you accountable,” said HHS Secretary Robert F. Kennedy, Jr. “HHS will continue working with our law enforcement partners to protect patients, safeguard taxpayer dollars, and restore integrity to our health care system.”

The post DOJ’s Using Advanced Data Analytics and AI Tools to Combat Healthcare Fraud Before Payment appeared first on The HIPAA Journal.

California AG Files Lawsuit Over 23andMe Data Breach

California Attorney General Rob Bonta has filed a lawsuit against the genetic testing company formerly known as 23andMe over its 2023 data breach that affected almost 7 million Americans. The lawsuit alleges multiple violations of state consumer privacy and data protection laws.

23andMe is a provider of direct-to-consumer DNA testing services. Consumers purchase kits for collecting saliva samples, which are sent to the company for DNA analysis. Consumers are given a report detailing their ancestry, ethnicity, and genetic health predispositions, and can access a platform that allows them to trace their biological relatives.

In 2023, 23andMe discovered that around 14,000 accounts had been subject to unauthorized access over a period of around 5 months, resulting in a breach of the personal and genetic information of 6.9 million individuals, including 855,541 California residents. Access to the accounts was gained using a technique known as credential stuffing. Credentials obtained in a data breach on one platform are used to try to access accounts another platform. The technique only works if users reuse their usernames and passwords on multiple platforms. In the case of the 23andMe attack, some of the credentials were stolen from MyHeritage, a separate genealogy site that 23andMe encouraged its users to set up an account with.

The data breach was discovered when the threat actor offered the stolen data for sale on a dark web hacking forum in October 2023. Initially, 23andMe downplayed the incident, maintaining that there had been no breach of its systems, placing the blame on customers for the poor security practice of re-using credentials on multiple platforms. 23andMe also said the breach involved data from its DNA Relatives feature, which was essentially publicly available information. 23andMe paid the threat actor to remove data that had been posted online, stop any sale of stolen data, and to receive information about the vulnerabilities that were exploited by the threat actor to access data.

23andMe, which filed for Chapter 11 bankruptcy protection in March 2025, faced class action litigation over the data breach and agreed to pay $30 million to settle claims related to the data breach, then increased the settlement fund to up to $50 million. The settlement received final approval from a judge in January 2026.

The California Department of Justice, part of a multistate coalition that investigated the data breach, determined that security vulnerabilities were exploited that should not have existed, and that the company’s handing of the breach was “entirely unacceptable.” The investigation determined that there was a well-known risk of unauthorized account access through credential stuffing, yet 23and Me failed to implement reasonable and appropriate security procedures to reduce risk. The data breach was only detected when the threat actor offered stolen data for sale in October 2023. AG Bonta alleged that 23andMe missed several opportunities to detect the credential stuffing attack, such as a suspicious spike in login attempts in July 2023, and a Reddit post discussing a potential 23andMe data breach in August 2023.

A coding error in the DNA Relatives feature meant doctored queries could be sent to the 23andMe database, and when creating and implementing its data security protocols, 23andMe failed to properly account for genetic data and its high level of sensitivity. 23andMe informed its customers that it adhered to the highest industry standards for data security; when its security practices were far below industry standards. Further, when the breach was announced, AG Bonta alleges that 23andMe made misleading statements, repeatedly stating that there had been no breach of 23andMe systems, despite the threat actor informing the company of multiple exploitable vulnerabilities within its systems, some of which were exploited in the attack.

The state Attorney General’s lawsuit was filed in the San Francisco Superior Court, California, and alleges that the company failed to implement and maintain reasonable and appropriate security procedures and practices, made untrue and misleading statements regarding its security measures and practices prior to the data breach, as well as misleading statements about the circumstances of the breach. Those failures are alleged to have violated the California Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act. The lawsuit seeks millions of dollars in civil fines to resolve the alleged violations.

The California Attorney General has also challenged 23andMe’s sale of consumers’ genetic information and materials in bankruptcy. That lawsuit is pending in the in U.S. Bankruptcy Court for the Eastern District of Missouri.

The post California AG Files Lawsuit Over 23andMe Data Breach appeared first on The HIPAA Journal.

CISA Announces Rescheduled CIRCIA Virtual Town Hall Meetings

The Cybersecurity and Infrastructure Security Agency (CISA) has announced a revised schedule of virtual town hall meetings for its Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”) rulemaking.

CISA was affected by the failure of lawmakers to agree on funding for the Department of Homeland Security (DHS), which resulted in a 76-day partial shutdown that ended on April 30, 2026. The shutdown significantly reduced CISA’s operational capacity, with only 38% of its staff remaining on the job over that period. While CISA’s core cyber defense operations were maintained during the partial shutdown, CISA’s outreach activities were a casualty. The CIRCIA virtual town hall meetings initially scheduled for March and April 2026 had to be delayed.

The aim of CIRCIA is to help the government respond quickly to cyber threats and disseminate key information to critical infrastructure sectors in response to those threats. When a final rule is issued, CIRCIA will require critical infrastructure entities to rapidly report significant cybersecurity incidents and ransomware payments to CISA. Covered critical infrastructure entities will be required to notify CISA of any ransom payment within 24 hours and certain cyber incidents within 72 hours.

The rapid reporting required under CIRCIA will allow CISA to quickly deploy resources and provide emergency assistance; build a comprehensive, coordinated, and centralized approach to understanding cyber risks across different critical infrastructure sectors; and identify cyber trends and rapidly share threat intelligence with network defenders and warn potential victims about threats.

Ahead of the publication of a final rule, CISA is seeking stakeholder feedback on the requirements of the CIRCIA Notice of Proposed Rulemaking (NPRM). The aim is to ensure that national cybersecurity is strengthened while minimizing the compliance burden on critical infrastructure entities.

The special topics of interest that were due to be covered in the town hall meetings have not been changed; however, the schedule differs from the original proposal. CISA will be hosting four four-hour virtual town hall meetings, starting on June 15, 2026.

A general session will be hosted on June 15, 2026, followed by a June 16, 2026, virtual meeting for Group A critical infrastructure sectors. These will be followed by a general session on June 17, 2026, and a virtual meeting for Group B critical infrastructure sectors.

  • The Group A session is for the communications, dams, emergency services, food and agriculture, government facilities, healthcare and public health, transportation systems, and water and wastewater sectors.
  • The Group B session is for the chemical, commercial facilities, critical manufacturing, defense industrial base, energy, financial services, information technology, and nuclear reactors, materials, and waste sectors.

While initially tentatively scheduled for 13:30 a.m. to 3:30 p.m, they have since been moved to 4:30 p.m. to 8:30 p.m. Advance registration is required, and registration will close two business days before the meeting, although early registration is recommended. The sessions will be recorded, and transcripts will be published in the CISA docket for CIRCIA rulemaking.

“CISA is working to maximize the impact of CIRCIA to significantly improve our Nation’s cybersecurity posture. At the same time, CISA values the interest and concern our stakeholders have that CIRCIA will be implemented with minimal unnecessary burden to entities in critical infrastructure sectors,” said Nick Andersen, acting director, CISA. “CISA appreciates our stakeholders’ patience with waiting for our rescheduled town hall meetings to provide their critical input as we finalize this rule. As an agency built on collaboration and coordination, CISA is committed to hearing from the American people, critical infrastructure owners and operators, and other community members.”

The post CISA Announces Rescheduled CIRCIA Virtual Town Hall Meetings appeared first on The HIPAA Journal.

Rhode Island Finalizes $12 Million Settlement With Deloitte Consulting Over RIBridges Cyberattack

An agreement has been reached between the state of Rhode Island and Deloitte Consulting LLP that will see the professional services firm pay an additional $7 million in financial support to the state following the 2024 cyberattack on the state’s benefits administration system – RIBridges. RIBRidges is Rhode Island’s one-stop shop for public benefits for state residents, including applications and management of Medicaid, food stamps, and other benefits. In November 2024, Deloitte Consulting identified the intrusion and took steps to secure the system. The state was notified about the hack in early December.

The investigation confirmed that hackers had access to the system for around 5 months, during which time they gained access to around 28 of the 338 backend environments of the system and exfiltrated sensitive data, including the data of almost 650,000 Rhode Island benefits applicants and recipients – around 59% of the population of the state. The Brain Cipher ransomware group claimed responsibility for the attack, boasting that access was gained by cracking an 8-character password to gain access to a domain controller – a process Brain Cipher claimed took just 5 minutes. The stolen data was subsequently leaked on the dark web.

In early 2025, the state secured a $5 million payment from Deloitte Consulting to cover immediate costs associated with the incident, and now a settlement agreement has been finalized that will see the total financial recovery increase to $12 million. Deloitte Consulting has also agreed to invest $6 million to cover security enhancements, operational support, and business continuity services that were not covered by its contract with the state. The settlement brings the legal wrangles between the state and Deloitte Consulting to an end.

Deloitte Consulting also faced class action litigation over the data breach and opted to settle the litigation in October 2025. Deloitte Consulting agreed to pay $6.3 million to resolve all claims related to the cyberattack and data breach, with no admission of wrongdoing or liability. Class members were eligible to claim up to $5,000 as reimbursement for out-of-pocket losses and a pro rata cash payment.

May 20, 2025: Rhode Island Releases Details of RIBridges Hacking Investigation

The state of Rhode Island has released a summary of the findings of an investigation by the cybersecurity firm CrowdStrike into the hacking of the Rhode Island state benefit system, known as RIBridges, by the Brain Cipher threat group.

Brain Cipher members were able to gain access to 28 of the 338 environments that comprise the RIBridges system and stole sensitive data such as names, addresses, birth dates, Social Security numbers, and health information. The affected individuals had previously signed up to receive public benefits such as food stamps or private health insurance through the HealthSource RI portal. The state issued notification letters to around 657,000 individuals in January informing them that their sensitive data may have been compromised in the incident.

The forensic investigation determined that 114,879 individuals who received the notifications in January had not in fact been affected, although an additional 107,757 individuals had been affected but were not notified in January. They include approximately 30,000 individuals whose data was collected during employment checks or verifications through the child support system and the Department of Children, Youth, and Families. Notification letters are now being sent to those 107,757 individuals. The final total stands at 644,401 affected individuals, who have been offered complimentary credit monitoring and identity theft protection services for 5 years.

The investigation started on December 16, 2024, and concluded on January 31, 2025. According to state officials, Brain Cipher actors gained access to the RIBridges system through the RIBridges Virtual Private Network (VPN) using the credentials of a Deloitte employee. Deloitte is the vendor used by the state of Rhode Island to manage the RIBridges system. CrowdStrike was unable to determine how the credentials were obtained and whether multifactor authentication was bypassed or if it was in place.

Brain Cipher first accessed a non-production environment within the RIBRidges system on July 2, 2024; however, the intrusion was not detected until November 28, 2024. After authenticating with the RIBridges VPN, the threat actor performed initial reconnaissance and lateral movement from an application server to six other systems. Privileges were escalated on two systems via Image File Execution Options (IFEO) injection, and credential harvesting was performed on six systems within the RIBridges environment.

Commercially available remote monitoring and management (RMM) tools were used along with a reverse proxy tool to maintain access to the environment. During the five months of access, Brain Cipher performed data access, staging, and data exfiltration from 28 systems. Large data transfers were performed by Brain Cipher out of the RIBridges system in November.

It was not the data transfers that alerted Deloitte to the hack, but rather a post on the Brain Cipher data leak site on December 4, 2024, claiming data had been stolen. Deloitte investigated the claim and identified suspicious activity, although it took until December 13, 2024, for the breach of the RIBridges system to be confirmed. When it was confirmed that the RIBridges systems had been compromised, it was shut down and remained offline for around a month. No evidence was found of any ransomware on the system.

According to the Crowdstrike investigation, the RIBridges firewall denied traffic from an external cloud storage provider IP address to an internal IP address on September 10, 2024, and between November 11, 2024 and November 28, 2024, the firewall management portal generated 397 alerts from 15 systems about large data transfers to an external cloud storage provider. “Deloitte missed some issues that we certainly hold them responsible for,” said state Governor Dan McKee. “That this would be undetected for that period of time is something that is just unacceptable.” Governor McKee confirmed that the state will be pursuing all avenues in our efforts to ensure accountability and is considering legal action against Deloitte.

The state plans to choose a vendor to modernize the RIBridges system, but it is likely to take between 18 and 24 months to roll out the new system. In the meantime, Deloitte will continue to manage the RIBridges system. The state is also planning on increasing the size of its IT workforce and has requested the budget for an additional 15 hires, including an RIBridges Technical Lead.

February 5, 2025: Deloitte to Pay $5 Million to Rhode Island to Cover Ransomware Attack Expenses

Rhode Island Governor Dan McKee has announced that Deloitte has agreed to pay $5 million to the state of Rhode Island to cover expenses incurred as a result of a December 2024 ransomware attack. The ransomware attack caused a prolonged outage of the state’s RI Bridges system, which is used to manage eligibility for public benefits, including programs such as Medicaid, SNAP, HealthSource RI, and RI Works.

The cyberattack was detected on December 5, 2024, and resulted in the prolonged outage of the RI Bridges system. The personal information of more than 650,000 Rhode Islanders was stolen in the attack, and the data was added to the ransomware group’s data leak site when the ransom was not paid. Information stolen and published included names, contact information, employment details, and Social Security numbers.

For around 2 months, the outage of the RI Bridges system prevented approximately 2,000 Rhode Islanders from enrolling in state-paid healthcare coverage by Blue Cross & Blue Shield and Neighborhood Health. Lindsay Musser Hough, Principal at Deloitte Consulting, said the commitment to pay $5 million to the state was not an admission of wrongdoing or fault and is being provided “in the spirit of supporting the state and its constituents in their response to the bad actor’s cyberattack.” Announcing the payment, Governor McKee said, “Deloitte has recognized that the state has immediate and unexpected expenses related to the breach, and we appreciate their willingness to lend financial support.”

Deloitte has also paid for credit monitoring and identity theft protection services for the 650,000+ individuals who had their data stolen in the ransomware attack, and is also covering the cost of the data breach call center.

January 13, 2025: Rhode Island Starts Notifying Individuals Affected by RI Bridges Ransomware Attack

Rhode Island Governor Dan McKee has confirmed that individual notification letters started to be mailed to the individuals whose personal data was stolen in the December 2024 ransomware attack on the RI Bridges system on January 10, 2025.  Individuals affected by the incident have been offered 5 years of complimentary credit monitoring services through Experian and are being encouraged to take advantage of those services as soon as possible. The deadline for signing up for those free services is April 30, 2025.

The notification letters provide instructions for signing up for the credit monitoring services, including a required activation code. State residents can sign up for the credit monitoring services online or over the phone (833-918-6603). The phone lines are manned Monday through Friday from 9 a.m. to 9 p.m., and on weekends from 11 a.m. to 8 p.m.

The data breach is still being investigated by Deloitte and more individuals may have been affected than the initial review suggests. In such cases, notification letters will be promptly sent to those individuals. “We understand the concerns this breach has caused for our residents,” said Governor McKee. “We appreciate everyone’s patience as these letters are delivered.” State officials are confident that the source of the intrusion has been identified and steps have been taken to ensure the RI Bridges systems can be safely restored. The first phase of that process has been completed and the second phase is underway to restore the public-facing part of the system, which is expected to be brought back online in mid-January.

The state has yet to confirm exactly how many individuals have been affected but has previously indicated approximately 650,000 state residents had their personal data exposed or stolen in the ransomware attack.

December 31, 2025: Ransomware Group Behind RI Bridges Attack Starts Leaking Stolen Data

The ransomware group (Brain Cipher) behind the cyberattack on Rhode Island’s online health and human services platform has started to leak stolen files on the dark web, according to State Governor Daniel McKee. Deloitte has been monitoring the dark web and informed the state Attorney General about the data leak.

The Brain Cipher group promised to leak the stolen data if the ransom was not paid, and the data leak indicates the ransom has not been paid. Brain Ciper allegedly demanded a ransom payment of $23 million in cryptocurrency to prevent the stolen data from being leaked. “This is a scenario that the State has been preparing for, which is why earlier this month we launched a statewide outreach strategy to encourage potentially impacted Rhode Islanders to protect their personal information,” said AG McKee.

McKee said Deloitte is investigating and reviewing the impacted files to determine which individuals have been affected and is also looking to analyze the leaked data; however, the analysis of the leaked data has not yet been completed. The HIPAA Journal has been periodically monitoring the Brain Cipher dark web data leak site to determine if data has been released. The site has been largely inaccessible, which will limit the potential for unauthorized individuals to obtain the leaked data.

Dissent from databreaches.net reached out to the Brain Cipher group after receiving no response from Deloitte. The group confirmed they were behind the attack and provided a preview of the data they would be leaking, and said they have been experiencing a DDoS attack on their data leak site, indicating someone is trying to prevent the group from leaking the data. The identity of the third party or third parties is unknown.

December 27, 2024: Rhode Island Ransomware Attack May Affect Half of State Residents

The cyberattack that forced the shutdown of Rhode Island’s public benefits system (RI Bridges) has potentially exposed the personal data of more than half of the population of the state – approximately 650,000 individuals, according to state Governor Daniel McKee.

McKee said conversations between Deloitte and the Brain Cipher group are ongoing, he is being kept informed of any progress, and no sensitive data appears to have been publicly released so far. He did not provide any information about how much the attackers are demanding to prevent the release of the stolen data, or if there is any intention to pay the ransom. Deloitte is working on restoring the crippled RI Bridges system as soon as possible, although it is not expected to be brought back online until some point in January.

December 17, 2024: Brain Cipher Group Claims Responsibility for Rhode Island Ransomware Attack

The Brain Cipher ransomware group has claimed responsibility for the Rhode Island RI Bridges ransomware attack and is threatening to publish the stolen data if the ransom demand is not paid. Brain Cipher is a relatively new ransomware operation that first appeared in June 2024. The group has already conducted some major attacks, including an attack on the National Data Center in Indonesia, which disrupted operations at more than 200 government agencies and saw the group demand a $8 million ransom payment. The group engages in double extortion and maintains a data leak site where stolen data is published if the ransom is not paid.

Countdown clock on the Brain Ciper data leak siteBrain Cipher claimed responsibility for a ransomware attack earlier this month and added Deloitte to its data leak site. Deloitte has issued a statement confirming that only the RI Bridges system was affected by the ransomware attack. The Deloitte listing on the Brain Cipher data leak site has a countdown clock that indicated the data leak would occur on December 17, 2024, if the ransom was not paid; however, on December 19, 2024, the countdown clock was still ticking down and showed 13 hours remaining, after having been reset. The ransomware group appears to still be holding out for a ransom payment.

On December 16, 2024, State Governor Daniel McKee issued a public service announcement encouraging all state residents who have used any of the affected systems in the past to take immediate action to protect themselves against identity theft and fraud. The RI Bridges hack will almost certainly lead to attempted data misuse by cyber criminals if the ransomware group releases the stolen data.

December 15, 2024: Hundreds of Thousands of Rhode Island Residents Affected by RI Bridges Data Breach

Hundreds of thousands of Rhode Island residents have had their data stolen in a cyberattack on the state government’s RI Bridges system, an online portal used by state residents to obtain social services and health insurance. Vendor Deloitte identified a potential RI Bridges system breach on December 5, 2024, and after confirming the unauthorized access, the portal was shut down on December 13 as a precaution. Deloitte has been working with state officials, IT experts, and law enforcement to investigate the cyberattack and data breach and limit its impact.

While the cyberattack was not initially described as a ransomware attack, Rhode Island’s Chief Digital Officer, Brian Tardiff, confirmed that a threat actor had installed malware and issued a ransom demand, payment of which was required to prevent the publication of the stolen data. It has yet to be confirmed how many individuals have been affected or the exact types of data stolen in the attack. Deloitte said it is still evaluating the data theft incident and said it is likely that information such as names, addresses, dates of birth, Social Security numbers, and potentially bank account information was involved.

Any individuals who applied for or received benefits or health insurance through the RI Bridges system may have been affected. The programs and benefits managed through the RI Bridges system include ,but are not limited to:

  • Medicaid
  • Supplemental Nutrition Assistance Program (SNAP)
  • Temporary Assistance for Needy Families (TANF)
  • Child Care Assistance Program (CCAP)
  • Health insurance purchased through HealthSource RI
  • Rhode Island Works (RIW),
  • Long-Term Services and Supports (LTSS)
  • General Public Assistance (GPA) Program

Rhode Island Governor Daniel McKee confirmed on Friday that the number of Rhode Islanders potentially affected was in the hundreds of thousands. Individual notifications will be mailed to all individuals affected by the Rhode Island data breach when the data breach investigation is concluded. Due to the sensitivity of the data stolen in the ransomware attack, anyone who applied for or obtained benefits or health insurance through any of the above programs should be vigilant against identity theft and fraud, monitor the accounts closely, and take advantage of any available free credit monitoring services. They have also been advised to consider placing a credit freeze or fraud alert with one of the three main credit bureaus and to change any common or reused passwords. State officials have not detected any misuse of the impacted data so far. The hackers are still holding out for a ransom payment and are likely to release the stolen data in the coming week if the ransom is not paid. The state has set up a helpline for state residents to find out more about the Rhode Island data breach. The helpline – 833-918-6603 – will be added Mondays through Fridays from 9 a.m. to 9 p.m.

The post Rhode Island Finalizes $12 Million Settlement With Deloitte Consulting Over RIBridges Cyberattack appeared first on The HIPAA Journal.

Delta Dental Fined $2.25 Million Over 2023 MOVEit Transfer Hack

Delta Dental Insurance and Delta Dental of New York (Delta Dental) have agreed to pay a fine of $2.25 million to the New York Department of Financial Services to settle alleged violations of New York cybersecurity regulations. The violations were discovered during an investigation of a 2023 hacking incident that affected almost 7.1 million of its customers.

The incident in question occurred over the Memorial Day weekend in 2023 and was detected by Delta Dental on June 1, 2023. A Russian-speaking cybercriminal group called Clop (aka Cl0p) exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer managed file transfer solution, accessed the solution between May 27 and May 30, 2023, and exfiltrated approximately 60,000 files. The group then demanded a ransom to prevent the publication of the stolen files.

By July 6, 2023, Delta Dental confirmed that a range of sensitive personal and protected health information had been stolen, including names, addresses, Social Security numbers, driver’s license numbers, financial account information, and health information. Delta Dental was one of around 2,700 companies to fall victim to the automated mass exploitation attacks.

Delta Dental Insurance, a dental insurance underwriter, and its subsidiary, Delta Dental of New York, were investigated by the New York Department of Financial Services after being notified about the data breach on December 15, 2023. The Department of Financial Services identified several violations of state laws, including the failure to provide timely notice about the data breach. Under N.Y. Comp. Codes R. & Regs. Tit. 23 § 500.17(a)(1), covered entities are required to notify the superintendent about a cybersecurity incident within 72 hours of discovery.

According to the consent order, Delta Dental did not implement and maintain a written policy addressing incident response, in breach of the New York Cybersecurity regulations for financial services companies – 23 NYCRR § 500.3(n), and did not have a written incident response plan that sufficiently addressed its reporting obligations to regulators, in violation of 500.16(b)(6). Further, Delta Dental did not implement policies and procedures for the secure disposal of data no longer required for business purposes, as required by § 500.13.

The investigation found that most of the data stolen in the attack had been on the server for more than 30 days. By default, MOVEit Transfer sets the data retention period as 30 days; however, Delta Dental had changed the retention period first to 45 days, and then to 60 days for many folders. Some folders had data retention settings disabled and there were no written policies regarding requesting, reviewing, or approving changes to the data retention settings.

Delta Dental is required to pay the financial penalty, although there are no corrective actions required by the order. Provided Delta Dental complies with the consent order, the New York Department of Financial Services will take no further action. “The Department’s nation-leading cybersecurity regulation requires financial institutions to have robust policies in place to protect the personal information of New Yorkers,” said Kaitlin Asrow, acting superintendent of the New York Department of Financial Services. “As cybersecurity threats continue to grow, the Department is committed to holding institutions accountable.”

The post Delta Dental Fined $2.25 Million Over 2023 MOVEit Transfer Hack appeared first on The HIPAA Journal.