HIPAA Compliance News

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U.S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures.

The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR), following its initial introduction in the 118th Congress 2D Session on September 25, 2024. When the bill was first introduced, 394 large hacking-related healthcare data breaches had been reported to the Department of Health and Human Services Office for Civil Rights (OCR), involving the protected health information of 43 million Americans.

At the time, the senators explained that cyberattacks are delaying and disrupting patient care, harming patient health and national security, and putting Americans at risk of identity theft and fraud. “These hacks are entirely preventable and are the direct result of lax cybersecurity practices by health care providers and their business partners,” explained the Senators.

The situation has only worsened in the two years since the bill was first introduced. The OCR breach portal lists year-to-date figures (Jan 1 – Aug 31) of 426 hacking-related breaches, involving the protected health information of 73 million Americans. That’s an 8% increase in hacking-related data breaches and a 70% increase in affected individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

On January 24, 2024, OCR published two sets of voluntary cybersecurity performance goals (CPGs) for the healthcare and public health (HPH) sector – Essential and Enhanced – that consist of high-impact measures that should be adopted by healthcare organizations to strengthen and mature their cybersecurity programs. As predicted by OCR at the time, voluntary goals alone would not be enough to drive the behavioral changes needed across the sector to improve cybersecurity.

The CPGs were followed by a proposed update to the HIPAA Security Rule, which mandates significant additional cybersecurity requirements. The proposed update has proven hugely unpopular, with industry groups and health systems calling for the proposed rule to be scrapped. A final rule has been delayed until July 2027, although a final decision about whether a final rule will actually be released has yet to be made by the Trump administration. Part of the problem, especially for rural and other low-resource healthcare providers, is a lack of funding to make the necessary cybersecurity improvements, which is something that the Health Infrastructure Security and Accountability Act seeks to address.

“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy,” explained Sen. Warner. “This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”

As the Senators explained, the U.S. health care system is particularly at risk for cyberattacks due to its size, technological dependence, collection of sensitive personal information, and unique vulnerability to disruptions. Healthcare organizations are viewed as low-hanging fruit, and attacks can be highly profitable for cybercriminals. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow,” said Sen. Wyden. “Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every American’s medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.”

The 2026 Health Infrastructure Security and Accountability Act remains largely unchanged from the 2024 version, other than shifting the timeline forward by two years. The key requirements of the bill are:

  • Mandatory minimum cybersecurity standards for covered entities and business associates, established, enforced, and updated by the HHS. Updates are required at least every two years.
  • Heightened cybersecurity standards for systemically important entities and entities critical to national security.
  • Continuity/recovery plans for all covered entities for technical failures, disruptive cyber events, and natural disasters, and stress tests to evaluate whether the entity has the capabilities to recover essential functions.
  • Written annual statements signed by the chief executive officer and chief information security officer attesting that the company is compliant with applicable security standards.
  • Mandatory annual security risk analyses, including specific assessments of the extent to which the entity is exposed to risk through its business associates.
  • Independent audits of covered entities’ security measures to assess compliance with the HHS’s CPGs.
  • Annual HHS audits of at least 20 HIPAA-regulated entities to assess data security practices, focused on those of systemic importance.
  • Increased financial penalties under HIPAA for failing to meet security requirements – A minimum $500 penalty for no knowledge; $5,000 for reasonable cause; $50,000 for willful neglect (corrected); and $250,000 for willful neglect (uncorrected).
  • A government investment of $1.3 billion to help hospitals strengthen cybersecurity: $800 million in up-front investment for hospitals in rural and underserved urban communities to adopt the essential cybersecurity goals, and $500 million in incentives available to all hospitals to adopt the enhanced CPGs.
  • Medicare accelerated and advanced payments in response to cybersecurity incidents.

The post Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act appeared first on The HIPAA Journal.

Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company Ambry Genetics Corporation have agreed to a settlement to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Ambry Genetics has agreed to pay a $700,000 financial penalty and adopt a corrective action plan to address the areas of noncompliance identified by OCR during its investigation of a breach of the electronic protected health information (ePHI) of 225,370 individuals.

The data breach was reported to OCR on March 22, 2020, initially as involving the protected health information of 232,772 individuals, although the total was later updated to 225,370 individuals. Ambry Genetics identified suspicious activity within its email environment on January 22, 2020, and its forensic investigation determined that an unauthorized third party gained access to an employee’s email account as a result of a response to a phishing email. The account was accessed by a criminal actor between January 22 and January 24, 2020, exposing names, addresses, dates of birth, driver’s license numbers, diagnosis/condition information, medications, treatment information, and some Social Security numbers.

OCR investigates all data breaches affecting 500 or more individuals and launched an investigation after being informed about the phishing-related data breach. OCR determined that Ambry Genetics failed to conduct an accurate and thorough risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

In addition, there was a failure to implement policies and procedures for terminating access to ePHI when the employment of members of the workforce was terminated, or access to ePHI was otherwise no longer required. Unique usernames had not been assigned to all members of the workforce who required access to ePHI to allow them to be identified and their interactions with ePHI to be tracked.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

OCR notified Ambry Genetics of the findings of the investigation and the intention to impose a financial penalty, along with an offer to settle the alleged HIPAA violations informally. Ambry Genetics accepted and agreed to settle the alleged HIPAA violations with a $700,000 financial penalty and a corrective action plan to ensure full compliance with the HIPAA Rules. Ambry Genetics will be monitored for compliance with the corrective action plan for a period of two years.

The corrective action plan requires Ambry Genetics to conduct a comprehensive and accurate risk analysis and develop and implement a risk management program to reduce and mitigate the risks identified by the risk analysis. Policies and procedures must be developed to ensure compliance with the HIPAA Security Rule and other HIPAA policies and procedures, and all members of the workforce must be assigned unique identification to allow their activity to be tracked in information systems containing ePHI. All workforce members must receive HIPAA training on the policies and procedures.  The phishing attack has proven costly for Ambry Genetics. Ambry Genetics faced class action litigation over the data breach and settled the lawsuit for $12.25 million.

“Email phishing is a common cyberattack that can lead to a breach of PHI and reveal HIPAA Security Rule deficiencies,” said OCR Director Paula M. Stannard. “Conducting a compliant risk analysis, engaging in risk management, and full implementation of the Security Rule provisions continue to be the foundation for effective cybersecurity and the best cyber defense.” This is the 10th financial penalty to be imposed by OCR this year to resolve alleged violations of the HIPAA Rules, and its 188th penalty to date. All but one of this year’s penalties have resolved risk analysis failures. So far this year, OCR has collected $3,030,250 in HIPAA fines.

The post Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations appeared first on The HIPAA Journal.

HHS Updates Security Risk Assessment Tool

The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.

The SRA Tool was developed by the Department of Health and Human Services Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the Office for Civil Rights (OCR). The downloadable tool was first released in March 2014 to help small- and medium-sized HIPAA-regulated entities navigate the risk analysis requirement of the HIPAA Security Rule.

The tool guides regulated entities through the process of conducting and documenting risk analyses, the aim of which is to identify potential weaknesses and gaps in security policies and all risks and vulnerabilities to ePHI. Only by conducting a comprehensive and accurate risk analysis will HIPAA- regulated entities be able to identify all risks and vulnerabilities to ePHI. If risks and vulnerabilities remain unknown, regulated entities will not be able to take the necessary steps to reduce them to a low and acceptable level and comply with the Risk Management standard of the HIPAA Security Rule.

The SRA Tool has received many upgrades over the years to improve usability and add compliance features. The latest release –September 2026 –includes content improvements in questions, responses, and education, expanding the tool to make it more comprehensive and ensure it remains relevant in an evolving cybersecurity environment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key updates include the addition of new technologies that have been adopted by regulated entities; a new assessment-scope question to ensure that risk assessments account for every location that creates, receives, maintains, or transmits ePHI; new remote access and telework questions; modernization of the asset inventory to cover technologies that practices are now using; and an update to the system-activity logging question to reflect the varied systems used by regulated entities.  The new version also includes updated software libraries, bug fixes, and tweaks in response to feedback to make the application and Excel workbook easier to use.

OCR Actively Enforcing Risk Analysis and Risk Management Compliance

HIPAA-regulated entities have long struggled with conducting risk analyses, and 12 years after the tool was first released, OCR still frequently identifies noncompliance in this area. OCR often finds that risk analyses have never been completed, that they are incomplete or inaccurate, or that there is a lack of documentation of risk analysis processes and procedures.

Widespread noncompliance with this vital Security Rule implementation specification prompted OCR to launch a new risk analysis enforcement initiative in 2024 to encourage and improve compliance. To date, OCR has imposed 14 financial penalties under this initiative, which remains a key enforcement priority for OCR. Further, the planned update to the HIPAA Security Rule, which now has a July 2027 proposed release date, will increase the risk analysis requirements further.

The risk analysis is only the first step in the risk management process. HIPAA-regulated entities must ensure that the identified risks and vulnerabilities are managed effectively and reduced to a low and acceptable level. At the 2026 NIST/OCR conference, Safeguarding Health Information: Building Assurance through HIPAA Security 2026, OCR Director Paula Stannard explained that many regulated entities appear to be confusing risk management with the cybersecurity performance goals (CPGs) issued by OCR in January 2024.

While the CPGs can be adopted by regulated entities to improve their security posture and prevent cyberattacks and data breaches, simply implementing those measures does not satisfy the risk management requirements of the HIPAA Security Rule. The risk management standard requires specific risk management measures to be implemented to address the risks and vulnerabilities identified by the risk analysis.

OCR has confirmed that the risk analysis enforcement initiative has been expanded to cover risk management. In addition to requiring evidence showing that an accurate and comprehensive risk analysis has been conducted, OCR requires evidence that identified risks have been subjected to a HIPAA-compliant risk management process. OCR wants to ensure that regulated entities are acting on the results of their risk analyses and are taking appropriate actions to reduce risks and vulnerabilities to ePHI.

The post HHS Updates Security Risk Assessment Tool appeared first on The HIPAA Journal.

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.

Large Healthcare data breaches in the past 12 months - June 2026

The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023.

Year to date figures for large healthcare data breaches - June 2026

Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals. While June’s victim total is substantial, the victim count is down 36.3% month-over-month, and 58.7% lower than the 12-month average of 10,906,096 individuals per month. It should be noted that the 12-month average is skewed by an unusually high total for October 2025.

Individuals affected by large healthcare data breaches in the past 12 months - June 2026

The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.7% from a high of 54.4 million individuals in 2024, and down 22.1% from 2025.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Year to date figures for individuals affected by healthcare data breaches - June 2026

The Biggest Healthcare Data Breaches Reported in June 2026

In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS. The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1.4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management. The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.

The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1.25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company. A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.

A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025. Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information.

HIPAA-Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Xsolis, Inc. TN Business Associate 1,396,519 Network server hacking incident
MCBS, LLC GA Business Associate 1,261,464 Data theft and extortion incident (PEAR)
Centers Lab NJ LLC NJ Healthcare Provider 542,377 Data theft and extortion incident (Worldleaks)
Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Network server hacking incident
Operation PAR, Inc. FL Business Associate 145,714 Data theft and extortion incident (Worldleaks)
Chicago Family Health Center IL Healthcare Provider 90,000 Network server hacking incident
Aitkin County Health and Human Services MN Business Associate 83,114 Phishing incident
Minnesota Epilepsy Group, P.A. MN Healthcare Provider 80,061 Network server hacking incident
Gay & Lesbian Community Services Center of Orange County, Inc. CA Healthcare Provider 75,532 Network server hacking incident
Colorado Health Network Inc. CO Healthcare Provider 68,212 Network server hacking incident – data theft confirmed
Women’s Center for Radiology FL Healthcare Provider 66,422 Network server hacking incident
Blue Fish Pediatrics TX Healthcare Provider 62,150 Network server hacking incident
NYC Health + Hospitals NY Healthcare Provider 58,778 Hacking incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 37,384 Phishing incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 34,574 Network server hacking incident
Kentucky Mountain Health Alliance KY Healthcare Provider 30,830 Network server hacking incident – data theft confirmed
Center for Hearing and Speech dba Texas Hearing Institute TX Healthcare Provider 29,774 Ransomware attack (Interlock) – data theft confirmed
Waveny LifeCare Network, Inc. CT Healthcare Provider 27,113 Network server hacking incident
Elara Caring TX Healthcare Provider 22,172 Hacking incident at third party vendor – data theft confirmed
Minidoka Memorial Hospital ID Healthcare Provider 22,000 Data theft and extortion incident (Blackwater)
Meridian Health Plan of Illinois IL Health Plan 21,027 Employee errors – Impermissible granting certain providers access to its network
City of Middletown OH Healthcare Provider 20,608 Ransomware attack – data theft confirmed
McLeod Physician Associates II SC Healthcare Provider 19,553 Malware identified on network server awaiting decommissioning
Optalis Management Solutions MI Healthcare Provider 13,723 Network server hacking incident
All About Women’s Care CO Healthcare Provider 12,000 Hacking incident via an employee VPN account – data theft confirmed

In June, nine healthcare data breaches were reported to HHS with totals of 500 or 501 affected individuals. These totals are often used as placeholder figures when data reviews are ongoing and the 60-day reporting deadline under the HIPAA Breach Notification Rule is reached. HIPAA requires an estimate to be provided if the total number of affected individuals has yet to be determined. The data breaches in the table below may prove to be far larger than the initial breach report indicates. It may be several weeks or even months before the total number of affected individuals is confirmed.

HIPAA Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Gail J May Ltd d/b/a/ Insight Optical IL Healthcare Provider 501 Network server hacking incident at business associate
Community Health Center of Buffalo Inc. NY Healthcare Provider 501 Network server hacking incident
Cherry Street Services, Inc. MI Healthcare Provider 501 Network server hacking incident
Northeast Professional Caregivers OH Healthcare Provider 500 Email compromise
Columbia Orthopaedic Group MO Healthcare Provider 500 Network server hacking incident
Decatur Diagnostic Laboratory Inc. AL Healthcare Provider 500 Network server hacking incident
Ohio Living OH Healthcare Provider 500 Network server hacking incident
Signature Healthcare Corporation MA Healthcare Provider 500 Network server hacking incident
MVP VIP Holdco dba Heart of America Eye Care MO Healthcare Provider 500 Network server hacking incident

Causes of June 2026 Healthcare Data Breaches

Out of the 25 data breaches affecting 10,000 or more individuals, all but one was due to hacking. Across all of June’s reported data breaches, 81.8% of the breaches were hacking/IT incidents, and 1,481,468 individuals were affected by those incidents – 89.7% of all individuals affected by data breaches in June. The average breach size was 81,091 individuals, and the median breach size was 6,504 individuals.

Causes of June 2026 healthcare data breaches

The largest unauthorized access/disclosure incident of the month – Meridian Health Plan of Illinois – affected 21,027 individuals and was due to employees granting healthcare providers access to a portal for managing patient information and processing claims that should not have been given access. There were 11 unauthorized access/disclosure incidents in June, accounting for 16.7% of the month’s data breaches, and 10,914 individuals were affected – 2.7% of the month’s affected individuals. The average breach size was 10,914 individuals, and the median breach size was 6,721 individuals. One improper disposal incident was reported affecting an estimated 1,000 patients. Paper records were disposed of along with regular trash, rather than being sent for shredding. No loss or theft incidents were reported in June.

Location of Breached Protected Health Information

The bar chart below shows the locations of breached protected health information in June 2026 healthcare data breaches. Network servers were the most common location of breached protected health information, followed by email accounts and electronic health records.

Location of breached protected health information - June 2026

Data Breaches at HIPAA Regulated Entities

When a data breach occurs at a HIPAA-covered entity – healthcare provider, health plan, or healthcare clearinghouse – the HIPAA Breach Notification Rule requires them to report the breach within 60 days of discovery. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within the same time frame.

The affected covered entities are ultimately responsible for ensuring that notifications are issued to the HHS, individuals, and in some cases the media, within 60 days of being notified. A HIPAA-covered entity may delegate the notification responsibilities to the business associate. Some choose to issue notifications themselves. The raw breach data on the OCR breach portal shows data breaches based on the reporting entity, not where the data breach occurred. In June, healthcare providers reported 45 breaches, business associates reported 14 breaches, and 7 breaches were reported by health plans. The pie charts below show where the breach actually occurred rather than the reporting entity to better reflect breaches at business associates.

June 2026 data breaches at HIPAA-regulated entities

Individuals affected by June 2026 data breaches at HIPAA-regulated entities

Geographical Distribution of Healthcare Data Breaches

In June, HIPAA-regulated entities based in 24 U.S. states reported large healthcare data breaches. Florida and Texas were the worst affected states with seven reported breaches per state.

State Breaches
Florida & Texas 7
Illinois 5
Colorado, Michigan & New York 4
California, Connecticut, Minnesota, Missouri, Ohio & Tennessee 3
Idaho, Kentucky, Massachusetts, South Carolina & Washington 2
Alabama, Georgia, Indiana, Kansas, New Jersey, Oklahoma & Pennsylvania 1

While Florida and Texas ranked top for breaches, they ranked 4th and 6th in terms of the number of affected individuals. Tennessee, Georgia, and New Jersey topped the list for affected individuals, with each state only registering one large data breach.

State Individuals Affected State Individuals Affected
Tennessee 1,567,038 Michigan 24,396
Georgia 1,261,464 Idaho 22,750
New Jersey 542,377 Ohio 21,608
Florida 233,367 South Carolina 20,690
Minnesota 164,893 Washington 9,825
Texas 124,459 Missouri 3,311
Illinois 120,089 Indiana 3,070
Connecticut 99,071 Pennsylvania 2,720
Colorado 87,814 Oklahoma 1,607
California 80,783 Massachusetts 1,506
New York 74,733 Kansas 534
Kentucky 31,367 Alabama 500

HIPAA Enforcement Activity in June 2026

In June, OCR announced a single enforcement action to resolve potential violations of the HIPAA Rules by the American mall-based retailer, Spencer Gifts. Retailers are not typically HIPAA-covered entities, but Spencer Gifts is a health plan under HIPAA as it sponsors employee benefits and welfare benefit plans. Spencer Gifts was investigated after OCR received a report about a breach of the protected health information of 10,023 members of its flexible benefits and welfare benefit plans. The OCR investigation determined that Spencer Gifts failed to conduct a HIPAA-compliant risk analysis and failed to implement HIPAA Privacy, Security, and Breach Notification Rule policies and procedures. The alleged HIPAA violations were resolved with a settlement that includes a $450,000 financial penalty and a corrective action plan.

In the year to June 30, 2026, OCR resolved seven HIPAA investigations with financial penalties with penalties totaling $1,728,000. All seven of the investigations found risk analysis failures, and two involved breach notification failures. State attorneys general may also investigate data breaches and impose financial penalties for HIPAA violations, although no cases were announced in June 2026.

About this Report

The HIPAA Journal monthly data breach reports are based on data obtained from the HHS Office for Civil Rights and have been combined with breach report data from other sources. The data breaches included in this report were reported in June 2026 but occurred weeks or months previously. The figures in this report may increase or decrease as HIPAA-regulated entities complete their breach investigations, and will be reflected in our healthcare data breach statistics page and our annual HIPAA data breach reports. Further information about HIPAA enforcement actions can be found in our HIPAA violations cases page.

The post June 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Azul Vision Settles HIPAA Right of Access Case for $50,000

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve an alleged violation of the HIPAA Rules, and its 55th penalty under its HIPAA Right of Access enforcement initiative.

Azul Vision Inc. is a California-based provider of optometry and ophthalmology services. OCR launched an investigation in response to a complaint from a patient who alleged that she had not been provided with timely access to her medical records. The complaint was filed with OCR in April 2023, three months after the patient submitted a request to Azul Vision for a copy of her health information. She did not receive the requested records until January 2025 – two years after her request was submitted.

The HIPAA Privacy Rule gives patients the right to timely access to their medical records for a reasonable, cost-based fee. When a healthcare provider receives a request from a patient wishing to exercise that right, the healthcare provider has 30 days from receipt of the request to provide the requested records, although under certain circumstances, a 30-day extension is possible. OCR’s investigation determined that Azul Vision failed to take timely action in response to the request, in violation of the right of access standard of the HIPAA Privacy Rule.

Under OCR’s enforcement initiative, the HIPAA violation warranted a financial penalty. Azul Vision was given the opportunity to settle the alleged violation informally, and a $50,000 financial penalty was agreed to resolve the investigation. In addition to the financial penalty, Azul Vision has agreed to adopt a corrective action plan to address the alleged violation and ensure future compliance with the HIPAA Rules.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The corrective action plan requires Azul Vision to review and revise its policies and procedures to comply with the HIPAA Privacy Rule and ensure its workforce receives training on the HIPAA right of access and Azul Vision’s policies and procedures.  Azul Vision will be monitored for compliance with the corrective action plan and must submit reports to OCR of all right of access requests, including the date the requests were received and the completion dates.

“OCR’s 55th enforcement action in the Right of Access Initiative demonstrates the Trump Administration’s commitment to enforcing timely access to requested protected health information,” said OCR Director Paula M. Stannard. “The right of access is key to empowering individuals to take control of their own health. It should not be necessary for OCR to initiate a right of access investigation before a covered entity will provide an individual with access to their requested records.”

The post Azul Vision Settles HIPAA Right of Access Case for $50,000 appeared first on The HIPAA Journal.

Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data

The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts to track consumer product-related injuries. By the end of the year, CPSC hopes that more than 100 hospitals will provide the requested records to the Kansas-based government contractor Konza Health, which was awarded a $15.9 million contract last year to support the National Electronic Injury Surveillance System (NEISS) Remodel project.

NEISS has been in operation for more than 5 decades, and its primary purpose is to collect data on consumer product-related injuries in the United States. NEISS is an important public health research tool; however, data collection is labor-intensive and involves a manual review and coding of medical records from around 70 of the nation’s 5,000+ hospital emergency departments. Currently, 14 states do not have any participating hospitals, which limits the geographic reach of the system and has reduced CPSC’s ability to identify rare and emerging product hazards.

Under the planned NEISS Remodel (NEISS-R) project, coverage will be expanded to all 50 states to ensure data is collected from currently underrepresented and non-represented states. The plan involves automating data collection by leveraging modem technology and the country’s electronic health record infrastructure. In so doing, CPSC said it will be able to identify rare and emerging hazards much more rapidly than the legacy system allows.

NEISS-R will see data exchanged through a federally designated Qualified Health Information Network (QHIN), which CPSC claims “is supported by contractual privacy requirements and standardized security safeguards.” The data collected will be limited, as will data retention, to the minimum necessary information to support CPSC’s statutory mission, and will support de-identification before the data reaches CPSC. CPSC says the project will result in a more timely, more accurate, and more cost-effective system, which will better protect American families.

Under the current system, emergency department nurses are required to review patient charts, manually identify consumer-related accidents, and enter that information into a national database. Under the new system, data collection would be automated, and it would be the responsibility of Konza Health, a TEFCA QHIN, to strip out identifying information prior to data transfers to CPSC.

According to the letters sent by Konza Health to hospitals, “Using accident-related diagnosis codes, Konza Health will identify patients that may have experienced a consumer product-related accident. For identified accidents, Konza Health will gather additional patient clinical information and provide it to CPSC for follow-up.” The letters request meetings with the selected hospitals to establish connectivity methods to allow secure data exchange for the project.

The NEISS-R project has sparked privacy fears, as under the manual system, nurses were instructed not to provide identifiable information such as patient names, addresses, or birth dates; however, the automated system would involve sending identifiable patient data Konza Health. While it is claimed that the data provided to CPSC will be unchanged from the information it has obtained for the past five decades, far broader access to patient data is sought.

KFF Health News reports that, based on emails shared by hospitals and interviews with people involved or familiar with the discussions between the hospitals and Konza Health, the data requested falls well outside of the CPSC’s consumer product safety mission. “In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt,” explained KFF Health News. “A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information — such as names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis.” According to communications between Konza Health and technology officials at one hospital, ER data is requested for more than 10,000 conditions, including injuries totally unrelated to consumer products.

CPSC and Konza Health have faced resistance from some hospitals over the mandatory provision of the data, and have suggested that refusing to provide the required data could be viewed as information blocking, potentially leading to significant penalties; however, the information being sought raises HIPAA concerns. Under HIPAA, hospitals are permitted, but not required, to submit data to CPSC for public health purposes, but any disclosure should be limited to the minimum necessary information to achieve the purpose for the disclosure. Since CPSC is collecting data to fulfil its consumer product safety mission, any data disclosed should be limited to that purpose. Should CPSC require more data than it has previously collected, further rulemaking would be necessary.

Participating hospitals could find themselves between a rock and a hard place – potential fines for information blocking if they do not agree to provide the requested data and potential HIPAA fines if they do. However, under the current information blocking regulations, there is a privacy exception, the purpose of which is to ensure that health information is not required to be disclosed in a way that is prohibited under state or federal privacy laws, and under the HIPAA minimum necessary standard, disclosures should be restricted to information required for CPSC’s public health activities, which concern consumer product safety.

The post Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.

May 2026 Healthcare Data Breach Report

Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting 500 or more individuals were reported in May 2026. May’s current total represents a 27.1% month-over-month increase in data breaches. Over the past 12 months, an average of 64 large healthcare data breaches were reported each month.

Healthcare data breaches in the past 12 months - May 2026

From January 1, 2026, to May 31, 2026, 319 data breaches affecting 500 or more individuals have been reported to OCR. This time last year, the total stood at 342 large data breaches.

HEalthcare data breaches - January 1 - May 31 - 2022-2026

While data breaches increased from April, the number of affected individuals fell by 34.8% to 879,447 individuals. In May, an average of 14,417 individuals were affected by healthcare data breaches, down from an average of 28,116 individuals in April. Over the past 12 months, an average of 10.6 million individuals have been affected by healthcare data breaches each month.

Individuals affected by healthcare data breaches in the past 12 months - May 2026

Data breaches are down slightly year-over-year, but there has been a massive reduction in the number of affected individuals. Very large data breaches have not been reported to OCR in the numbers seen in previous years. From January 1, 2026, to May 31, 2026, across the 319 data breaches, at least 21,085,405 individuals have been affected. The OCR breach portal shows that from January 2025 to May 2025, 33,116,809 individuals were affected by data breaches.

Individuals affected by healthcare data breaches - jan 1 - May 31, 2022-2026

Biggest Healthcare Data Breaches of May 2026

In May 2026, 17 data breaches affecting 10,000 or more individuals were reported to OCR, all of which were hacking incidents. The biggest data breach of the month was reported by Radiology Associates of Richmond, affecting more than 266,000 individuals, followed by a hacking incident at Western Orthopaedics which affected more than 113,000 individuals.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking incident
Western Orthopaedics, P.C. CO Healthcare Provider 113,330 Hacking incident
ERMI LLC GA Healthcare Provider 74,074 Hacking incident
Singing River Health System MS Healthcare Provider 53,888 Hacking incident
Southern Illinois Ob-Gyn Associates, S.C. IL Healthcare Provider 38,700 Hacking incident
Gastro Health FL Healthcare Provider 35,632 Unauthorized access to email accounts
Eyemart Express, LLC TX Healthcare Provider 25,000 Hacking incident
Connecticut Department of Social Services CT Health Plan 22,500 Unauthorized access to provider portal website
Bridle Trails Family Dentistry WA Healthcare Provider 20,976 Unauthorized access to email account
Community Connections DC Healthcare Provider 18,943 Ransomware attack (INCRansom)
Virta Medical PC CO Healthcare Provider 14,636 Hacking incident (Lapsus$)
Saurabh N. Patel, M.D – Florida Retina Center LA Healthcare Provider 13,652 Hacking incident
Greenbaum Rowe Smith & Davis LLP NJ Business Associate 12,801 Hacking incident
Wellpoint Washington, Inc. IN Health Plan 12,020 Unauthorized access to email account
Defense Health Agency (TriWest) VA Health Plan 11,848 Hacking incident
IKRON Corporation OH Healthcare Provider 11,845 Hacking incident
Elara Caring TX Healthcare Provider 10,490 Hacking incident at third-party vendor

May’s total number of affected individuals may increase considerably over the coming weeks and months, as healthcare organizations complete their data breach investigations. HIPAA-regulated entities have 60 days from the date of discovery of a data breach to issue notifications to the HHS’ Office for Civil Rights and the affected individuals. HIPAA requires OCR to be notified even if the total number of individuals has yet to be determined by the 60-day deadline. In such cases, an estimate should be provided. Many regulated entities use a placeholder estimate of 500 or 501 individuals in such cases, and in May, 7 regulated entities appear to have used these placeholder figures.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
United Medical Doctors CA Healthcare Provider 501 Hacking/IT Incident
NJ Pain Care Specialists, LLC NJ Healthcare Provider 501 Hacking/IT Incident
Palomar Health Medical Group CA Healthcare Provider 501 Hacking/IT Incident
Aroostook Mental Health Center ME Healthcare Provider 501 Hacking/IT Incident
Campbell University NC Healthcare Provider 500 Hacking/IT Incident
BAYADA Home Health Care, Inc. NJ Healthcare Provider 500 Hacking/IT Incident
Integrated Pain Associates TX Healthcare Provider 500 Hacking/IT Incident

Causes of May 2026 Healthcare Data Breaches

Hacking and other IT incidents dominated the breach reports in May, as has been the case each month for several years. Out of the month’s 61 large healthcare data breaches, 54 were classed as hacking/IT incidents – 88.5% of the month’s data breaches. Across those incidents, the protected health information of 853,532 individuals was compromised- 88.5% of the month’s total affected individuals. On average, hacking/IT incidents affected 15,806 individuals in May, with a median breach size of 3,619 individuals.

Causes of May 2026 healthcare data breaches

There were 7 data breaches classed as unauthorized access/disclosure incidents, representing 11.5% of the month’s breaches. Across those incidents, the protected health information of 25,915 individuals was unlawfully accessed or disclosed. On average, 3,702 individuals were affected by each incident in May. The median breach size was 3,086 individuals. There were no reported theft, loss, or improper disposal incidents in May.

Given the large number of hacking incidents, it is no surprise that the most common location of breached protected health information was network servers. Email incidents were also reported in high numbers.

Location of breached PHI in May 2026 healthcare data breaches

States Affected by May 2026 Healthcare Data Breaches

Large healthcare data breaches were reported by HIPAA-regulated entities in 26 U.S. states and the District of Columbia. California was the worst affected state with 6 breaches.

State Breaches
California 6
Florida, New Jersey, New York, North Carolina, Ohio, Texas & Virginia 4
Colorado 3
Indiana, Maine, Michigan, Pennsylvania, South Carolina & the District of Columbia 2
Arizona, Connecticut, Georgia, Illinois, Iowa, Louisiana, Massachusetts, Mississippi, Oregon, Tennessee, Washington & Wisconsin 1

In terms of affected individuals, Virginia topped the list with almost 300,000 state residents affected.

State Individuals Affected State Individuals Affected
Virginia 290,254 Louisiana 13,652
Colorado 128,661 Pennsylvania 7,095
Georgia 74,074 South Carolina 6,946
Mississippi 53,888 Iowa 6,666
Florida 44,649 Michigan 6,456
Texas 40,045 California 5,303
Illinois 38,700 North Carolina 4,949
Ohio 28,540 Massachusetts 3,086
Connecticut 22,500 Maine 3,024
Washington 20,976 Oregon 2,856
District of Columbia 20,014 Arizona 2,316
New York 19,674 Tennessee 1,807
Indiana 17,325 Wisconsin 1,080
New Jersey 14,911

Data Breaches at HIPAA -Regulated Entities

In May 2026, 42 data breaches were reported by healthcare providers, 9 breaches were reported by health plans, and 10 data breaches were reported by business associates. When a breach occurs at a business associate, the affected covered entities must be informed. Each covered entity may delegate the breach notification responsibilities to the business associate, but it is ultimately the responsibility of each covered entity to ensure that breach notifications are issued. In many cases, a breach at a business associate is reported by the covered entity.

The pie charts below show where the data breach occurred, rather than the reporting entity, which shows that 22 of the 61 breaches (rather than 10) occurred at business associates in May.

May 2026 data breaches at HIPAA-regulated entities

Individuasl affected by data breaches at HIPAA-regulated entities in May 2026

HIPAA Enforcement Activity in May 2026

No enforcement actions were announced by OCR or state attorneys general in May.

The post May 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes

There has been some good news for the HIPAA-regulated entities that feel unprepared for the proposed changes to the HIPAA Security Rule. The Department of Health and Human Services (HHS) had proposed a May 2026 release date for a final rule implementing the proposed changes to the HIPAA Security Rule; however, the U.S. Office of Management and Budget (OMB) website has been updated, showing the final rule has been pushed back a year, with the final action due in July 2027.

Why HIPAA Security Rule Changes Have Been Proposed

The HHS’ Office for Civil Rights (OCR), under the Biden administration, issued a Notice of Proposed Rulemaking (NPRM) to strengthen the HIPAA Security Rule in December 2024, and published the proposed rule in the Federal Register on January 6, 2025.  The original HIPAA Security Rule was enacted more than two decades ago in 2003 and was updated by the HIPAA Omnibus Final Rule in 2013, but there have been no substantial changes to the Security Rule in the past 13 years.

Today, almost all aspects of healthcare rely on computer and network technologies, and cybersecurity is far more of a concern than when the Security Rule was first published. Over the past 10 years, cyberattacks on healthcare organizations and breaches of electronic protected health information (ePHI) – that the Security Rule was introduced to protect – have been steadily increasing, especially in 2018, when there was a rampant escalation in hacking incidents and healthcare ransomware attacks. Not only have these incidents increased substantially, but there has also been an alarming upward trend in the number of individuals affected and the harm these incidents cause.

Take the ALPHV/BlackCat ransomware attack on Change Healthcare in February 2024. The attack on this key healthcare technology company and clearinghouse had massive implications for the healthcare industry. The company’s systems touch one in every three patient records and are relied on by hospitals, physicians, pharmacies, and laboratories across the country for billing and payment processing. The attack caused severe cash flow problems for the company’s clients, care delivery was affected, and some providers were forced to temporarily close. The outage caused by the attack lasted for weeks, while the disruption for providers continued for much longer. The ePHI of an estimated 192.7 million Americans was stolen in the attack. The attackers breached the Change Healthcare network via a Citrix remote access portal using stolen credentials, and crucially, multifactor authentication was not enabled. Multifactor authentication is one of the requirements of the Security Rule update, as is network segmentation to limit the impact of cyberattacks.   

New Security Rule Requirements

The proposed HIPAA Security Rule update is intended to address changes in the healthcare environment and technology, force HIPAA-regulated entities to make cybersecurity updates to combat cyberattacks and prevent data breaches, and correct deficiencies in the HIPAA Security Rule that OCR has identified from its investigations of data breaches, complaints, and its HIPAA audit program. The updates are based on current cybersecurity best practices and methodologies, and are common sense updates given the extent to which the healthcare industry is being targeted by cyber actors and how frequently they breach healthcare networks.

The proposed changes are substantial, and include the elimination of the addressable implementation classification; strict mandatory cybersecurity requirements such as encryption, multifactor authentication, network segmentation, and anti-malware protection; annual penetration tests, vulnerability scans every 6 months, and annual audits of Security Rule compliance; more prescriptive requirements for risk analyses, which must be conducted at least annually and be based on a comprehensive and accurate technology asset inventory and network map showing how ePHI flows; dedicated backup and recovery controls for ePHI; shorter timelines for business associates and verification of their technical safeguards; and extensive documentation requirements.

Proposed Regulatory Update Attracts Considerable Criticism

The 390-page proposed update was not particularly well received and attracted considerable criticism from hospitals, health systems, and industry groups. OCR received almost 5,000 comments in response to the proposed rule. While industry stakeholders accepted the need for improvements to security to combat the cybersecurity crisis in healthcare, they viewed the proposed rule as an impossible mandate, as it would place substantial financial burdens on healthcare organizations, cause massive operational disruptions, create a huge administrative burden, and has an unworkable timeframe for implementation.

The proposed rule lacks much of the flexibility of the original rule, attracting criticism for the one-size-fits-all approach to cybersecurity. Since the new requirements are extensive, forcing HIPAA-regulated entities to commit substantial funds to compliance will require many to divert funds away from patient care. The pain would be particularly acute for small and rural healthcare providers who are already working on razor-thin margins. The HHS accepts that compliance will not be cheap, calculating that the proposed changes will have a one-year industry cost of $9 billion, with annual industry costs of $6 billion a year for years two through five.

More Time to Prepare for Inevitable New Security Requirements

The timeframes released by government entities for implementing new rules are not legally binding. The final rule may have been delayed by a year and could be delayed further; however, OCR could press ahead and release a final rule ahead of the proposed July 2027 date.

Changes to the HIPAA Security Rule are inevitable to ensure it remains effective. One of the criticisms of the proposed rule was the short implementation timeframe, which was viewed by industry groups as unworkable. While there may be a huge collective sigh of relief at the delay, it is important to use the extra time wisely. Waiting for the final rule to be issued before implementing the required changes runs the risk of missing the implementation deadline and facing the regulatory risks associated with late compliance.

If regulated entities use the time to plan and they start implementing some of the proposed requirements over the coming 12 months, the pain will be eased when the final rule drops. In the meantime, cybersecurity will be improved, helping to prevent cyberattacks, costly downtime, and many data breaches.

Steve Alder, Editor-in-Chief, The HIPAA Journal.

The post HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes appeared first on The HIPAA Journal.