HIPAA Breach News

Drug and Alcohol Treatment Services Settles Data Breach Litigation

Drug and Alcohol Treatment Services, Inc., a Scranton, Pennsylvania-based provider of drug and alcohol addiction services, has agreed to settle class action litigation stemming from an October 2024 ransomware attack.

The attack resulted in the theft of the personal and protected health information of employees and patients. The HHS’ Office for Civil Rights was informed that 22,215 patients were affected. Data exposed or stolen in the incident included names, dates of birth, Social Security numbers, health insurance information, medical billing/claims information, patient account numbers, prescription/medication information, and diagnosis/treatment information.

Eight class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint – Leo Woytach, et al v. Drug and Alcohol Treatment Services, Inc. – in the Court of Common Pleas of Lackawanna County, Pennsylvania. The consolidated lawsuit asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of confidence, and unjust enrichment. The defendant denies all claims and contentions in the lawsuit and maintains there was no wrongdoing.

Following negotiations about a potential settlement and a full day of mediation, settlement terms were agreed upon that were acceptable to all parties. By settling, all parties avoid the costs, distraction, burden, and risks of a trial and related appeals. The defendant will establish a $549,000 settlement fund, from which attorneys’ fees and expenses, settlement administration/notification costs, and service awards for the eight class representatives will be paid. The remainder will be used to pay benefits to the class members.

The settlement covers individuals who were notified about the data breach and provides cash payments to individuals who submit a valid claim. Claims may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member, or a claim may be submitted for a pro rata cash payment. The value of the cash payments will be determined by the number of valid claims received.  In addition, class members qualify for a free 12-month membership to a medical data monitoring service.

The deadline for filing an objection and opting out of the settlement is August 25, 2026. Claims must be submitted by September 24, 2026, and the final fairness hearing has been scheduled for November 24, 2026.

June 9, 2025: Drug and Alcohol Treatment Services Facing Multiple Class Action Data Breach Lawsuits

A Pennsylvania non-profit provider of drug and alcohol addiction services is facing multiple class action lawsuits over an October 2024 ransomware attack. Drug and Alcohol Treatment Services, Inc. (DATS), based at 441 Wyoming Avenue in Scranton, PA, identified unauthorized access to its computer network on October 6, 2024. The forensic investigation confirmed that an unauthorized third party had access to the protected health information of 22,215 individuals between October 5 and October 6, 2024. Data compromised in the incident included patient names, dates of birth, medical histories, treatment information, health insurance information, medical claims information, billing information, Social Security numbers, and financial information.

The data breach was confirmed by DATS on December 5, 2024; however, notification letters were not sent to the affected individuals until May 2, 2025. DATS said it was unaware of any misuse of the stolen data at the time of issuing notification letters and offered the affected individual complimentary credit monitoring and identity theft protection services. The notification letters did not state the exact nature of the cyberattack; however, the Interlock ransomware group claimed responsibility for the attack and said 150 GB of data was stolen. The ransom was not paid, so the group published the stolen data on its data leak site. The group claims the leaked files include the personal data of employees and patients.

Currently, at least eight class action lawsuits have been filed against DATS over the data breach. The lawsuits make similar claims, including negligence for failing to protect its information technology systems and sensitive patient and employee data. The lawsuits claim the data breach could have been prevented if DATS had implemented reasonable security measures and adhered to industry-standard data security practices. The lawsuits also claim that DATS did not provide timely notifications to the affected individuals, who were informed that their sensitive data had been stolen seven months after the data breach. The lawsuits claim the notification delay deprived the plaintiffs and class members of the opportunity to take action to mitigate the harmful effects of the data breach. The lawsuits also assert claims of breach of confidence, breach of implied contract, breach of fiduciary duty, unjust enrichment, and invasion of privacy.

The lawsuits seek class certification, a jury trial, damages, attorneys’ fees, reimbursement of legal costs and expenses, and injunctive relief, including an order from the court compelling DATS to implement measures to improve security.

The post Drug and Alcohol Treatment Services Settles Data Breach Litigation appeared first on The HIPAA Journal.

ERMI; McLeod Physician Associates; Centers for Dialysis Care Announce Data Breaches

Data breaches have been announced by the Georgia-based medical equipment company ERMI, McLeod Physician Associates in South Carolina, and the Centers for Dialysis Care in Ohio. More than 101,000 individuals have been affected by these three incidents.

ERMI LLC, Georgia

ERMI LLC, A Georgia manufacturer of medical equipment for orthopedic patients, has experienced a significant data breach involving unauthorized access to systems containing the electronic protected health information of 74,074 patients. Unauthorized access to its systems was identified on or around August 14, 2025. Assisted by third-party cybersecurity experts, ERMI determined that certain systems had been accessed by an unauthorized third party between February 15, 2025, and August 14, 2025, during which time files containing patient information may have been viewed or acquired.

An extensive manual review of the affected data was completed on or around April 17, 2026, and confirmed that the exposed data included names in combination with one or more of the following: Social Security number, driver’s license number, veteran identification number, passport number, username and password, email address with password and security question, date of birth, date of death, taxpayer/employer identification number, financial account information, payment card information, medical information, and health insurance information. The affected individuals have been notified and informed about the steps that can be taken to reduce the risk of data misuse, and complimentary credit monitoring services have been offered to individuals whose Social Security numbers were impacted.

McLeod Physician Associates Li, South Carolina

McLeod Physician Associates li, a Florence, SC-based healthcare group practice, has recently reported a data breach to the HHS’ Office for Civil Rights involving unauthorized access to the protected health information of up to 19,553 patients. The affected patients started to be notified about the incident on June 4, 2026. According to the substitute breach notice on the McLeod Health website, on March 5, 2026, a suspicious file was found on a Dillon Family Medicine server that was in the process of being decommissioned. An investigation was launched, which determined that an unauthorized party had accessed the server between October 17 and October 18, 2025.

The investigation confirmed that the incident was limited to the single server, and no McLeod Health systems were involved, including the practice’s current electronic medical record system. The server was reviewed and found to contain patient information such as names, dates of birth, Social Security numbers, and information related to patient care, which may have included diagnoses, medications, test results, medical images, treatment information, and health insurance information.

Steps have been taken to prevent similar incidents in the future, and the practice will continue to implement and evaluate enhanced safeguards. McLeod Health has confirmed that the affected server has been decommissioned and is no longer in use.

Centers for Dialysis Care, Ohio

Centers for Dialysis Care in Shaker Heights, Ohio, has identified a data security incident that potentially involved unauthorized access to the protected health information of up to 8,000 individuals.  Suspicious activity was identified within its computer network on or around March 20, 2026. Assisted by third-party cybersecurity experts, Centers for Dialysis Care confirmed on April 11, 2026, that there had been unauthorized access to its network, and files containing personal and protected health information had been accessed.

The personal and protected health information of current and former patients and employees was involved, including names, dates of birth, Social Security numbers, medical and health information, diagnostic and treatment information, health insurance information, and/or tax/financial information. Centers for Dialysis Care said additional security measures have been implemented to reduce the risk of similar incidents in the future.

The post ERMI; McLeod Physician Associates; Centers for Dialysis Care Announce Data Breaches appeared first on The HIPAA Journal.

Data Security Incidents Announced by Park Dental Research Corp; Wabi Sabi Behavioral Health Center

Employee data has been compromised in data security incidents at Park Dental Research Corporation in Oklahoma and Wabi Sabi Behavioral Health Center in Nebraska.

Park Dental Research Corporation

Park Dental Research Corporation, an Ardmore, OK-based dental implant company, has notified individuals about a security incident it experienced on or around April 29, 2026. The investigation confirmed that an unauthorized third party had access to systems containing information such as names, dates of birth, addresses, Social Security numbers, driver’s license numbers, bank account information, passports, and I-9 forms.

There has been no known misuse of the affected information; however, as a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services, which include a $1,000,000 identity theft insurance policy. Notification letters were mailed to the affected individuals on June 24, 2026.

While ransomware was not mentioned in the notification letters, a ransomware group called Interlock took responsibility for the cyberattack and claimed to have exfiltrated 260 gigabytes of data from the company’s systems.

Wabi Sabi Behavioral Health Center

Hastings, NE-based Wabi Sabi Behavioral Health Center, a multidisciplinary mental health provider serving patients in South Central Nebraska, has identified unauthorized access to parts of its network containing employee payroll records. On June 15, 2026, an unauthorized third party gained access to a QuickBooks Online account using compromised credentials. The purpose of the attack was to make changes to employees’ account details in order to divert payments to attacker-controlled accounts. The unauthorized access was detected on the same day, and changes to payroll were identified.

While the affected accounts have been secured, employee information such as names, addresses, and Social Security numbers may have been viewed or copied. The affected individuals have been notified and offered complimentary credit monitoring and identity theft protection services. No misuse of employee data has been identified as a result of the incident. The Nebraska Attorney General has been informed about the data breach, but the number of affected individuals has not been publicly disclosed.

The post Data Security Incidents Announced by Park Dental Research Corp; Wabi Sabi Behavioral Health Center appeared first on The HIPAA Journal.

North Los Angeles County Regional Center Notifies Individuals About November 2024 Ransomware Attack

North Los Angeles County Regional Center has started mailing notification letters to individuals affected by a November 2024 ransomware attack, and Midland Care Connection in Kansas has announced a March 2026 hacking incident.

North Los Angeles County Regional Center

North Los Angeles County Regional Center has started notifying individuals about a cybersecurity incident and data breach that was first identified 17 months ago on November 28, 2024. Suspicious activity was identified within its computer network, and the forensic investigation confirmed unauthorized access from November 20, 2024, to December 1, 2024.

North Los Angeles County Regional Center determined that sensitive data was exfiltrated from its systems before ransomware was used to encrypt files. The files exfiltrated from its systems included names, addresses, dates of birth, telephone numbers, Social Security numbers, passport numbers, driver’s license or other state-issued ID numbers, U.S. federal issued ID numbers, email addresses, usernames/passwords, financial account information, payment card information, health plan information, CI and patient ID numbers, medical record numbers, lab results, medications, physical and/or mental conditions, diagnosis and/or treatment information, prescription or medication information, treatment cost information, disability codes, certificate/license numbers, and certain other medical and health insurance-related information.

North Los Angeles County Regional Center said it first announced the incident on its website on January 6, 2025, to allow individuals to take steps to protect themselves against data misuse; however, it has taken time to review the affected data to allow notification letters to be issued. North Los Angeles County Regional Center said it implemented additional technical security measures shortly after the attack and is continuing to work with data security experts to further enhance the security of its systems. The Medusa ransomware group claimed responsibility for the attack, in which more than 600 gigabytes of data was allegedly stolen.

The incident is shown on the HHS’ Office for Civil Rights website as affecting 500 individuals. That is a placeholder figure, as the breach was reported to OCR on January 6, 2025, well before the investigation had concluded.  The total should be updated in the coming days, now that the data review has concluded.

Midland Care Connection

Midland Care Connection Inc., a Topeka, Kansas-based non-profit provider of patient care, hospice, and community health support services, has experienced a cybersecurity incident that may have resulted in the theft of sensitive data. Suspicious network activity was identified on March 31, 2026, and legal counsel and third-party digital forensics experts were engaged to investigate the activity. They confirmed network access by an unauthorized third party starting on March 30, 2026, and initiated a data review to determine the individuals affected and the types of information. The data review was completed on June 12, 2026.

The affected information varied from individual to individual and may have included names, birth dates, medical treatment information, medical health information, health insurance information, financial account information, and, for certain individuals, Social Security numbers. Data privacy and security policies have been reviewed and enhanced to reduce the risk of similar incidents in the future, and the affected individuals have been notified by mail and offered 12 months of complimentary single-bureau credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

The post North Los Angeles County Regional Center Notifies Individuals About November 2024 Ransomware Attack appeared first on The HIPAA Journal.

Almost 30,000 Texas Residents Affected by Data Breach at The Texas Hearing Institute

The Texas Hearing Institute has notified the Texas Attorney General about a data breach impacting more than 29, 000 state residents. Data breaches have also been announced by Family Health Centers of Southern Indiana, the Wisconsin Department of Health Services, and Stephen W. Brown & Radiology Associates of Augusta.

Texas Hearing Institute

The Texas Hearing Institute, a pediatric hearing center in Houston, Texas, has started notifying at least 29,498 individuals about a March 2026 cyberattack that resulted in unauthorized access to its network and the exposure of patients’ personal and health data.

Unauthorized network access was identified on March 20, 2026, and immediate steps were taken to contain the incident and secure its systems. Assisted by third-party digital forensics experts, the Texas Hearing Institute determined on April 22, 2026, that there had been unauthorized access to personal information on its systems. The data review confirmed that names, Social Security numbers, financial information, and medical records were compromised in the incident.

The affected individuals have been offered 24 months of complimentary credit monitoring and identity theft protection services. While the notification letters do not provide further information about the nature of the attack, this appears to have been a ransomware incident. The interlock ransomware group added the Texas Hearing Institute to its dark web data leak site in early April, claiming to have stolen 540 gigabytes of data. As such, the affected individuals should ensure that they take advantage of the free identity theft protection services being offered. The Texas Attorney General was informed that 29,498 Texas residents were affected. It is currently unclear how many individuals were affected in total.

Family Health Centers of Southern Indiana

Family Health Centers of Southern Indiana, a network of health centers in Jeffersonville, New Albany, Corydon, and Clarksville in Indiana, announced a data security incident on June 22, 2026, that may have resulted in unauthorized access to patient data.

Unauthorized network activity was identified on or around January 16, 2026. Its incident response plan was immediately initiated, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed that an unauthorized third party had access to parts of its network containing patient data, including names, dates of birth, contact information, demographic information, Social Security numbers, medical information, and health insurance information.

Family Health Centers of Southern Indiana has implemented additional technical safeguards, enhanced security measures, and updated its procedures related to data privacy and security. Complimentary credit monitoring and identity theft protection services have been offered to individuals whose Social Security numbers were involved.

The data breach is not yet shown on the HHS’ Office for Civil Rights website; however, the Indiana Attorney General was informed that the protected health information of 7,037 Indiana residents was compromised in the incident. The Termine threat group took responsibility for the incident and added Family Health Centers of Southern Indiana to its dark web data leak site, including samples of the stolen data. The group claims to have exfiltrated around 250 gigabytes of data.

Stephen W. Brown & Radiology Associates of Augusta

Stephen W. Brown & Radiology Associates of Augusta have been affected by a data breach at their third-party billing vendor, MCBS, LLC. MCBS was provided with patient information as part of its contracted duties, and discovered on or around September 26, 2025, that an unauthorized third party had gained access to systems containing that information.

After an extensive forensic analysis, MCBS determined that its systems were accessed by an unauthorized third party between September 22 and September 26, 2025. Individuals affected by the incident may have had some or all of the following data stolen in the incident: name, address, date of birth, Social Security number, diagnosis, treatment information, mental or physical condition, medical history, health plan beneficiary number, health insurance policy number/subscriber identification number, and other health insurance information.

MCBS said it is unaware of any misuse of the affected data; however, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. It is currently unclear how many patients of Stephen W. Brown & Radiology Associates of Augusta have been affected, or how many individuals were affected in total.

Wisconsin Department of Health Services

The Wisconsin Department of Health Services has recently reported a HIPAA breach to the HHS’ Office for Civil Rights that involved unauthorized access to the protected health information of 8,157 individuals. The affected individuals were Medicaid recipients who received benefits from the Wisconsin Supplementary Security Income program.

Letters were mailed to those individuals that contained personal and private information regarding an increase in their benefits. Some of those letters were inadvertently sent to outdated addresses. The error was identified on April 30, 2026, and further mailings to the incorrect addresses have been prevented. Up to 8,157 individuals were affected and have now been notified that their information may have been accessed by unauthorized individuals as a result of the error. Complimentary credit monitoring services have been offered to those individuals for 12 months.

The post Almost 30,000 Texas Residents Affected by Data Breach at The Texas Hearing Institute appeared first on The HIPAA Journal.

AdaptHealth Reports Material Cybersecurity Incident and Theft of Patient Data

AdaptHealth, a publicly traded healthcare company that provides home medical equipment, diabetes supplies, and sleep therapy products, has informed the U.S. Securities and Exchange Commission (SEC) that it is investigating a material cybersecurity incident involving unauthorized access to patient data.

According to the company’s Form 8-K filing, a threat actor contacted the company on June 15, 2026, claiming to have obtained files containing patient data. AdaptHealth launched an investigation, engaged third-party cybersecurity experts, and notified law enforcement. AdaptHealth has determined that certain cloud-based business applications were accessed by the threat actor, including internal patient management systems and document storage platforms. Files containing patients’ personally identifiable information (PII) and protected health information were exfiltrated by the threat actor.

The investigation is ongoing; however, AdaptHealth has determined that the unauthorized access occurred as a result of a response to a social engineering attack on a third-party contractor, which allowed the contractor’s credentials to be obtained. The threat actor obtained a stored password file tied to insurance billing and access to external electronic health record portals.

The affected account has been disabled, credentials have been reset, and additional access controls have been implemented. The incident has not had an impact on its operations or patient services, and a review is ongoing to determine the extent of data theft. The types of data involved have yet to be determined, and the number of affected individuals is currently unknown. AdaptHealth said it does not collect patients’ Social Security numbers, and financial account information and payment card information are not stored in the compromised systems.

AdaptHealth said it considers this to be a material cybersecurity incident due to the nature and potential volume of data at risk. The financial impact of the incident is still being assessed, with the company potentially having to cover costs associated with forensics, breach notification, legal and regulatory responses, and any remediation measures. The company holds a cybersecurity insurance policy, which may cover certain losses associated with the incident.

While AdaptHealth has not named the threat actor behind the attack, this appears to have been a data theft and extortion attempt by the ShinyHunters threat group. ShinyHunters added AdaptHealth to its data leak site and has threatened to leak the stolen data if the ransom is not paid, giving the company a final warning to pay or face a data leak.

The post AdaptHealth Reports Material Cybersecurity Incident and Theft of Patient Data appeared first on The HIPAA Journal.

Delaware & Florida Women’s Health Centers Announce Data Breaches

Two women’s healthcare providers have announced data privacy incidents. Women’s Wellness of Southern Delaware recently learned about unauthorized retention of patient data by a former provider of aesthetic services, and Women’s Center for Radiology has identified a hacking incident.

Women’s Wellness of Southern Delaware

Women’s Wellness of Southern Delaware, a Lewes, DE-based provider of obstetrics, gynecology, and facial aesthetic services, has recently learned that a former provider who rendered aesthetic services for the practice retained the protected health information of patients after engagement with the practice had terminated. Women’s Wellness of Southern Delaware was made aware of the data retention on April 28, 2026. The provider retained patients’ contact information and other patient-related information and is believed to have contacted certain patients to offer similar services at a new practice.

The information retained relates to certain recipients of aesthetic services and clinical services patients. For the aesthetic services patients, the information included their name, birth date, gender, email address, physical address, phone number, allergies, medications, supplements, and information related to the services received, which may include photographs, intake records, aesthetics-related medical history, face maps, dates of services and purchases, and descriptions of services or items purchased. For the clinical services recipients, the impacted data included name, phone number, dates of purchases, and descriptions of the items/medications purchased. The former provider did not have access to electronic medical records.

Women’s Wellness of Southern Delaware said it is in communication with the former provider and is seeking to obtain assurances that the data is returned or destroyed, and steps have been taken to enhance its data privacy and security measures to prevent similar incidents in the future. The incident is not currently shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

Women’s Center for Radiology

Women’s Center for Radiology, a provider of medical imaging services at three locations in Orlando, Florida, has identified unauthorized access to parts of its network containing patient data. The unauthorized access was identified on or around April 28, 2026, and the forensic investigation determined that an unauthorized third party gained access to a limited part of its computer network. Files containing patient information were viewed or downloaded by the unauthorized third party.

Assisted by third-party specialists, Women’s Center for Radiology determined that the exposed files contained patient information such as names, addresses, dates of birth, contact information, diagnosis or condition, lab results, treating physician, medical record number, health insurance information, and driver’s license numbers.

Women’s Center for Radiology has started notifying the affected individuals, who have been offered complimentary credit monitoring and identity theft protection services. Women’s Center for Radiology is reviewing its policies, procedures, and protocols related to data privacy and security. Regulators have been notified about the incident; however, the number of affected individuals has not yet been publicly disclosed.

The post Delaware & Florida Women’s Health Centers Announce Data Breaches appeared first on The HIPAA Journal.

Data Breaches Reported by Amicus Solutions: Huntsville Hospital Health System

Amicus Solutions (Fedora Solutions) has been affected by a cybersecurity incident, and Huntsville Hospital has confirmed it was affected by a January 2025 breach at Cerner (Oracle Health).

Amicus Solutions

Amicus Solutions, Inc., doing business as Fedora Solutions, a provider of managed IT and revenue cycle management services, has experienced a cybersecurity incident involving the protected health information of 1,137 individuals. According to the breach notification to the Massachusetts Office of Consumer Affairs and Business Regulation, the breach affected patients of medical practices managed by OneOncology, LLC, including New York Cancer and Blood Specialists.

Suspicious activity was identified within the Amicus Solutions network on April 2, 2026, with the unauthorized access believed to have occurred between February 2, 2026, and February 18, 2026. During that time, a threat actor exfiltrated data from its systems, and some of that data was posted to the threat actor’s website, including personally identifiable information and protected health information.

The data review confirmed that the threat actor obtained patient data such as first and last names, phone numbers, email addresses, birth dates, gender information, Social Security numbers, medical information, and health insurance information. Amicus Solutions confirmed that there was no unauthorized access to its clients’ networks. No misuse of that data had been identified at the time of issuing notifications. Amicus Solutions said additional safeguards have been implemented to harden security, and 24 months of complementary credit monitoring and identity theft protection services have been offered to the affected individuals.

Huntsville Hospital

Huntsville Hospital Health System in Alabama has recently announced that it has been affected by the January 2025 data breach at electronic health record vendor Cerner, now Oracle Health. The data breach affected approximately 90 healthcare providers, and many of those providers announced the data breach last year. Hackers gained access to two legacy Cerner servers as early as January 22, 2025, and Huntsville Hospital was informed that it was affected on August 12, 2025. The hospital said law enforcement requested delaying notifying the affected individuals and additional providers so as not to impede the investigation.

According to the hospital, the breach was confined to Cerner systems, which contained names, Social Security numbers, and details from medical records, including medical record numbers, doctors’ names, diagnoses, medications, test results, images, and treatment information. The affected individuals have been offered complementary credit monitoring services for 24 months. It is currently unclear how many Huntsville Hospital patients have been affected.

The post Data Breaches Reported by Amicus Solutions: Huntsville Hospital Health System appeared first on The HIPAA Journal.

Washington Dept. Health & Social Services Insider Breach Affects 8,600 Individuals

The Washington Department of Social and Health Services (DSHS) has identified an insider data breach involving unauthorized access to the protected health information of approximately 8,600 individuals.

Insider threats are a major problem in healthcare, more so than in other sectors. While most insider incidents are unintentional, and snooping on medical records is a common cause of healthcare data breaches. Patient records may also be obtained for financial gain. Regular workforce HIPAA training is important to remind employees of their responsibilities with respect to patient privacy, and employee access logs should be routinely monitored. Without active monitoring, these privacy violations can persist for long periods before unauthorized access is identified.

In this case, a DSHS employee was discovered to have accessed a DSHS internal client data system without authorization and viewed records containing full names, dates of birth, Social Security numbers, DSHS client numbers, and information about DSHS program enrollment.

The DSHS investigation found no evidence that health information was accessed, such as diagnoses, test results, treatments, claims, or chart notes. The DSHS said the employee was found to have accessed records for “reasons unrelated to their job duties,” but did not elaborate further on the individual’s reasons for access. It is also unclear when the unauthorized access was detected, or for how long the employee had been accessing records for non-work purposes.

DSHS confirmed that action was immediately taken when the privacy violations were identified, preventing further unauthorized access. DSHS has confirmed that the individual is no longer working for the department. It is unclear whether the employee was terminated over the HIPAA violation or if they left voluntarily.

DSHS said it is issuing notification letters by mail to all affected individuals and encourages them to monitor their account statements and credit reports for unauthorized activity. DSHS is cooperating with state and local law enforcement in their ongoing investigation. DSHS said steps are being taken to implement additional safeguards, and internal policies and procedures related to data privacy and security are being reviewed.

The post Washington Dept. Health & Social Services Insider Breach Affects 8,600 Individuals appeared first on The HIPAA Journal.