HIPAA Compliance News

Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data

The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts to track consumer product-related injuries. By the end of the year, CPSC hopes that more than 100 hospitals will provide the requested records to the Kansas-based government contractor Konza Health, which was awarded a $15.9 million contract last year to support the National Electronic Injury Surveillance System (NEISS) Remodel project.

NEISS has been in operation for more than 5 decades, and its primary purpose is to collect data on consumer product-related injuries in the United States. NEISS is an important public health research tool; however, data collection is labor-intensive and involves a manual review and coding of medical records from around 70 of the nation’s 5,000+ hospital emergency departments. Currently, 14 states do not have any participating hospitals, which limits the geographic reach of the system and has reduced CPSC’s ability to identify rare and emerging product hazards.

Under the planned NEISS Remodel (NEISS-R) project, coverage will be expanded to all 50 states to ensure data is collected from currently underrepresented and non-represented states. The plan involves automating data collection by leveraging modem technology and the country’s electronic health record infrastructure. In so doing, CPSC said it will be able to identify rare and emerging hazards much more rapidly than the legacy system allows.

NEISS-R will see data exchanged through a federally designated Qualified Health Information Network (QHIN), which CPSC claims “is supported by contractual privacy requirements and standardized security safeguards.” The data collected will be limited, as will data retention, to the minimum necessary information to support CPSC’s statutory mission, and will support de-identification before the data reaches CPSC. CPSC says the project will result in a more timely, more accurate, and more cost-effective system, which will better protect American families.

Under the current system, emergency department nurses are required to review patient charts, manually identify consumer-related accidents, and enter that information into a national database. Under the new system, data collection would be automated, and it would be the responsibility of Konza Health, a TEFCA QHIN, to strip out identifying information prior to data transfers to CPSC.

According to the letters sent by Konza Health to hospitals, “Using accident-related diagnosis codes, Konza Health will identify patients that may have experienced a consumer product-related accident. For identified accidents, Konza Health will gather additional patient clinical information and provide it to CPSC for follow-up.” The letters request meetings with the selected hospitals to establish connectivity methods to allow secure data exchange for the project.

The NEISS-R project has sparked privacy fears, as under the manual system, nurses were instructed not to provide identifiable information such as patient names, addresses, or birth dates; however, the automated system would involve sending identifiable patient data Konza Health. While it is claimed that the data provided to CPSC will be unchanged from the information it has obtained for the past five decades, far broader access to patient data is sought.

KFF Health News reports that, based on emails shared by hospitals and interviews with people involved or familiar with the discussions between the hospitals and Konza Health, the data requested falls well outside of the CPSC’s consumer product safety mission. “In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt,” explained KFF Health News. “A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information — such as names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis.” According to communications between Konza Health and technology officials at one hospital, ER data is requested for more than 10,000 conditions, including injuries totally unrelated to consumer products.

CPSC and Konza Health have faced resistance from some hospitals over the mandatory provision of the data, and have suggested that refusing to provide the required data could be viewed as information blocking, potentially leading to significant penalties; however, the information being sought raises HIPAA concerns. Under HIPAA, hospitals are permitted, but not required, to submit data to CPSC for public health purposes, but any disclosure should be limited to the minimum necessary information to achieve the purpose for the disclosure. Since CPSC is collecting data to fulfil its consumer product safety mission, any data disclosed should be limited to that purpose. Should CPSC require more data than it has previously collected, further rulemaking would be necessary.

Participating hospitals could find themselves between a rock and a hard place – potential fines for information blocking if they do not agree to provide the requested data and potential HIPAA fines if they do. However, under the current information blocking regulations, there is a privacy exception, the purpose of which is to ensure that health information is not required to be disclosed in a way that is prohibited under state or federal privacy laws, and under the HIPAA minimum necessary standard, disclosures should be restricted to information required for CPSC’s public health activities, which concern consumer product safety.

The post Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.

May 2026 Healthcare Data Breach Report

Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting 500 or more individuals were reported in May 2026. May’s current total represents a 27.1% month-over-month increase in data breaches. Over the past 12 months, an average of 64 large healthcare data breaches were reported each month.

Healthcare data breaches in the past 12 months - May 2026

From January 1, 2026, to May 31, 2026, 319 data breaches affecting 500 or more individuals have been reported to OCR. This time last year, the total stood at 342 large data breaches.

HEalthcare data breaches - January 1 - May 31 - 2022-2026

While data breaches increased from April, the number of affected individuals fell by 34.8% to 879,447 individuals. In May, an average of 14,417 individuals were affected by healthcare data breaches, down from an average of 28,116 individuals in April. Over the past 12 months, an average of 10.6 million individuals have been affected by healthcare data breaches each month.

Individuals affected by healthcare data breaches in the past 12 months - May 2026

Data breaches are down slightly year-over-year, but there has been a massive reduction in the number of affected individuals. Very large data breaches have not been reported to OCR in the numbers seen in previous years. From January 1, 2026, to May 31, 2026, across the 319 data breaches, at least 21,085,405 individuals have been affected. The OCR breach portal shows that from January 2025 to May 2025, 33,116,809 individuals were affected by data breaches.

Individuals affected by healthcare data breaches - jan 1 - May 31, 2022-2026

Biggest Healthcare Data Breaches of May 2026

In May 2026, 17 data breaches affecting 10,000 or more individuals were reported to OCR, all of which were hacking incidents. The biggest data breach of the month was reported by Radiology Associates of Richmond, affecting more than 266,000 individuals, followed by a hacking incident at Western Orthopaedics which affected more than 113,000 individuals.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking incident
Western Orthopaedics, P.C. CO Healthcare Provider 113,330 Hacking incident
ERMI LLC GA Healthcare Provider 74,074 Hacking incident
Singing River Health System MS Healthcare Provider 53,888 Hacking incident
Southern Illinois Ob-Gyn Associates, S.C. IL Healthcare Provider 38,700 Hacking incident
Gastro Health FL Healthcare Provider 35,632 Unauthorized access to email accounts
Eyemart Express, LLC TX Healthcare Provider 25,000 Hacking incident
Connecticut Department of Social Services CT Health Plan 22,500 Unauthorized access to provider portal website
Bridle Trails Family Dentistry WA Healthcare Provider 20,976 Unauthorized access to email account
Community Connections DC Healthcare Provider 18,943 Ransomware attack (INCRansom)
Virta Medical PC CO Healthcare Provider 14,636 Hacking incident (Lapsus$)
Saurabh N. Patel, M.D – Florida Retina Center LA Healthcare Provider 13,652 Hacking incident
Greenbaum Rowe Smith & Davis LLP NJ Business Associate 12,801 Hacking incident
Wellpoint Washington, Inc. IN Health Plan 12,020 Unauthorized access to email account
Defense Health Agency (TriWest) VA Health Plan 11,848 Hacking incident
IKRON Corporation OH Healthcare Provider 11,845 Hacking incident
Elara Caring TX Healthcare Provider 10,490 Hacking incident at third-party vendor

May’s total number of affected individuals may increase considerably over the coming weeks and months, as healthcare organizations complete their data breach investigations. HIPAA-regulated entities have 60 days from the date of discovery of a data breach to issue notifications to the HHS’ Office for Civil Rights and the affected individuals. HIPAA requires OCR to be notified even if the total number of individuals has yet to be determined by the 60-day deadline. In such cases, an estimate should be provided. Many regulated entities use a placeholder estimate of 500 or 501 individuals in such cases, and in May, 7 regulated entities appear to have used these placeholder figures.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
United Medical Doctors CA Healthcare Provider 501 Hacking/IT Incident
NJ Pain Care Specialists, LLC NJ Healthcare Provider 501 Hacking/IT Incident
Palomar Health Medical Group CA Healthcare Provider 501 Hacking/IT Incident
Aroostook Mental Health Center ME Healthcare Provider 501 Hacking/IT Incident
Campbell University NC Healthcare Provider 500 Hacking/IT Incident
BAYADA Home Health Care, Inc. NJ Healthcare Provider 500 Hacking/IT Incident
Integrated Pain Associates TX Healthcare Provider 500 Hacking/IT Incident

Causes of May 2026 Healthcare Data Breaches

Hacking and other IT incidents dominated the breach reports in May, as has been the case each month for several years. Out of the month’s 61 large healthcare data breaches, 54 were classed as hacking/IT incidents – 88.5% of the month’s data breaches. Across those incidents, the protected health information of 853,532 individuals was compromised- 88.5% of the month’s total affected individuals. On average, hacking/IT incidents affected 15,806 individuals in May, with a median breach size of 3,619 individuals.

Causes of May 2026 healthcare data breaches

There were 7 data breaches classed as unauthorized access/disclosure incidents, representing 11.5% of the month’s breaches. Across those incidents, the protected health information of 25,915 individuals was unlawfully accessed or disclosed. On average, 3,702 individuals were affected by each incident in May. The median breach size was 3,086 individuals. There were no reported theft, loss, or improper disposal incidents in May.

Given the large number of hacking incidents, it is no surprise that the most common location of breached protected health information was network servers. Email incidents were also reported in high numbers.

Location of breached PHI in May 2026 healthcare data breaches

States Affected by May 2026 Healthcare Data Breaches

Large healthcare data breaches were reported by HIPAA-regulated entities in 26 U.S. states and the District of Columbia. California was the worst affected state with 6 breaches.

State Breaches
California 6
Florida, New Jersey, New York, North Carolina, Ohio, Texas & Virginia 4
Colorado 3
Indiana, Maine, Michigan, Pennsylvania, South Carolina & the District of Columbia 2
Arizona, Connecticut, Georgia, Illinois, Iowa, Louisiana, Massachusetts, Mississippi, Oregon, Tennessee, Washington & Wisconsin 1

In terms of affected individuals, Virginia topped the list with almost 300,000 state residents affected.

State Individuals Affected State Individuals Affected
Virginia 290,254 Louisiana 13,652
Colorado 128,661 Pennsylvania 7,095
Georgia 74,074 South Carolina 6,946
Mississippi 53,888 Iowa 6,666
Florida 44,649 Michigan 6,456
Texas 40,045 California 5,303
Illinois 38,700 North Carolina 4,949
Ohio 28,540 Massachusetts 3,086
Connecticut 22,500 Maine 3,024
Washington 20,976 Oregon 2,856
District of Columbia 20,014 Arizona 2,316
New York 19,674 Tennessee 1,807
Indiana 17,325 Wisconsin 1,080
New Jersey 14,911

Data Breaches at HIPAA -Regulated Entities

In May 2026, 42 data breaches were reported by healthcare providers, 9 breaches were reported by health plans, and 10 data breaches were reported by business associates. When a breach occurs at a business associate, the affected covered entities must be informed. Each covered entity may delegate the breach notification responsibilities to the business associate, but it is ultimately the responsibility of each covered entity to ensure that breach notifications are issued. In many cases, a breach at a business associate is reported by the covered entity.

The pie charts below show where the data breach occurred, rather than the reporting entity, which shows that 22 of the 61 breaches (rather than 10) occurred at business associates in May.

May 2026 data breaches at HIPAA-regulated entities

Individuasl affected by data breaches at HIPAA-regulated entities in May 2026

HIPAA Enforcement Activity in May 2026

No enforcement actions were announced by OCR or state attorneys general in May.

The post May 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes

There has been some good news for the HIPAA-regulated entities that feel unprepared for the proposed changes to the HIPAA Security Rule. The Department of Health and Human Services (HHS) had proposed a May 2026 release date for a final rule implementing the proposed changes to the HIPAA Security Rule; however, the U.S. Office of Management and Budget (OMB) website has been updated, showing the final rule has been pushed back a year, with the final action due in July 2027.

Why HIPAA Security Rule Changes Have Been Proposed

The HHS’ Office for Civil Rights (OCR), under the Biden administration, issued a Notice of Proposed Rulemaking (NPRM) to strengthen the HIPAA Security Rule in December 2024, and published the proposed rule in the Federal Register on January 6, 2025.  The original HIPAA Security Rule was enacted more than two decades ago in 2003 and was updated by the HIPAA Omnibus Final Rule in 2013, but there have been no substantial changes to the Security Rule in the past 13 years.

Today, almost all aspects of healthcare rely on computer and network technologies, and cybersecurity is far more of a concern than when the Security Rule was first published. Over the past 10 years, cyberattacks on healthcare organizations and breaches of electronic protected health information (ePHI) – that the Security Rule was introduced to protect – have been steadily increasing, especially in 2018, when there was a rampant escalation in hacking incidents and healthcare ransomware attacks. Not only have these incidents increased substantially, but there has also been an alarming upward trend in the number of individuals affected and the harm these incidents cause.

Take the ALPHV/BlackCat ransomware attack on Change Healthcare in February 2024. The attack on this key healthcare technology company and clearinghouse had massive implications for the healthcare industry. The company’s systems touch one in every three patient records and are relied on by hospitals, physicians, pharmacies, and laboratories across the country for billing and payment processing. The attack caused severe cash flow problems for the company’s clients, care delivery was affected, and some providers were forced to temporarily close. The outage caused by the attack lasted for weeks, while the disruption for providers continued for much longer. The ePHI of an estimated 192.7 million Americans was stolen in the attack. The attackers breached the Change Healthcare network via a Citrix remote access portal using stolen credentials, and crucially, multifactor authentication was not enabled. Multifactor authentication is one of the requirements of the Security Rule update, as is network segmentation to limit the impact of cyberattacks.   

New Security Rule Requirements

The proposed HIPAA Security Rule update is intended to address changes in the healthcare environment and technology, force HIPAA-regulated entities to make cybersecurity updates to combat cyberattacks and prevent data breaches, and correct deficiencies in the HIPAA Security Rule that OCR has identified from its investigations of data breaches, complaints, and its HIPAA audit program. The updates are based on current cybersecurity best practices and methodologies, and are common sense updates given the extent to which the healthcare industry is being targeted by cyber actors and how frequently they breach healthcare networks.

The proposed changes are substantial, and include the elimination of the addressable implementation classification; strict mandatory cybersecurity requirements such as encryption, multifactor authentication, network segmentation, and anti-malware protection; annual penetration tests, vulnerability scans every 6 months, and annual audits of Security Rule compliance; more prescriptive requirements for risk analyses, which must be conducted at least annually and be based on a comprehensive and accurate technology asset inventory and network map showing how ePHI flows; dedicated backup and recovery controls for ePHI; shorter timelines for business associates and verification of their technical safeguards; and extensive documentation requirements.

Proposed Regulatory Update Attracts Considerable Criticism

The 390-page proposed update was not particularly well received and attracted considerable criticism from hospitals, health systems, and industry groups. OCR received almost 5,000 comments in response to the proposed rule. While industry stakeholders accepted the need for improvements to security to combat the cybersecurity crisis in healthcare, they viewed the proposed rule as an impossible mandate, as it would place substantial financial burdens on healthcare organizations, cause massive operational disruptions, create a huge administrative burden, and has an unworkable timeframe for implementation.

The proposed rule lacks much of the flexibility of the original rule, attracting criticism for the one-size-fits-all approach to cybersecurity. Since the new requirements are extensive, forcing HIPAA-regulated entities to commit substantial funds to compliance will require many to divert funds away from patient care. The pain would be particularly acute for small and rural healthcare providers who are already working on razor-thin margins. The HHS accepts that compliance will not be cheap, calculating that the proposed changes will have a one-year industry cost of $9 billion, with annual industry costs of $6 billion a year for years two through five.

More Time to Prepare for Inevitable New Security Requirements

The timeframes released by government entities for implementing new rules are not legally binding. The final rule may have been delayed by a year and could be delayed further; however, OCR could press ahead and release a final rule ahead of the proposed July 2027 date.

Changes to the HIPAA Security Rule are inevitable to ensure it remains effective. One of the criticisms of the proposed rule was the short implementation timeframe, which was viewed by industry groups as unworkable. While there may be a huge collective sigh of relief at the delay, it is important to use the extra time wisely. Waiting for the final rule to be issued before implementing the required changes runs the risk of missing the implementation deadline and facing the regulatory risks associated with late compliance.

If regulated entities use the time to plan and they start implementing some of the proposed requirements over the coming 12 months, the pain will be eased when the final rule drops. In the meantime, cybersecurity will be improved, helping to prevent cyberattacks, costly downtime, and many data breaches.

Steve Alder, Editor-in-Chief, The HIPAA Journal.

The post HIPAA Security Rule Update Postponed: More Time Given to Implement Major HIPAA Security Rule Changes appeared first on The HIPAA Journal.

April 2026 Healthcare Data Breach Report

In April 2026, 47 healthcare data breaches affecting 500 or more individuals were reported to the HHS’ Office for Civil Rights (OCR). That represents a 33.8% reduction in large healthcare data breaches from the 71 large data breaches reported in March 2026, and well below the 12-month average of 62.4 data breaches per month.

healthcare data breaches in the past 12 months - April 2026

The year-to-date figures also show a reduction in large healthcare data breaches. From January 1 to April 30, 252 large healthcare data breaches have been reported by HIPAA-regulated entities, compared to 276 (-8.7%) for the corresponding period in 2025 and 299 (-15.7%) for the corresponding period in 2024.

Healthcare data breaches - January 1 to April 30 (2022-2026)

Across the 47 data breaches, the protected health information of 1,336,264 individuals was exposed or impermissibly disclosed – the second lowest monthly total in the past 12 months, and currently an 84.9% reduction from March 2026. The number of affected individuals is likely to increase, as some regulated entities have reported breaches with placeholder estimates of 500 or 501 affected individuals.

Individuals affected by healthcare data breaches in the past 12 months (April 2026)

The year-to-date figures for affected individuals are encouraging. From January 1 to April 30, the protected health information of 20.1 million individuals has been breached, and while that is a sizeable figure, it is a reduction of 25.5% from the corresponding period in 2025 and a reduction of 48.8% from the corresponding period in 2024.

Individuals affected by healthcare data breaches - january 1 to April 30 (2022-2026)

The Biggest Healthcare Data Breaches Reported in April 2026

In April, 15 data breaches affecting 10,000 or more individuals were reported to the HHS’ Office for Civil Rights, all but one of which were hacking incidents. The biggest data breach of the month was reported by the medical group Florida Physician Specialists, involving unauthorized access to the protected health information of 276,498 individuals.  Two of the 15 data breaches were confirmed ransomware attacks, and one incident involved unauthorized access by “a business counterparty” after access was thought to have been terminated.

Regulated Entity State Covered Entity Type Individuals Affected Type of Breach Location of Breached Information Cause of Breach
Florida Physician Specialists FL Healthcare Provider 276,498 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
Southern Illinois Dermatology IL Healthcare Provider 160,312 Hacking/IT Incident Network Server Hacking incident
Laurel Eye Clinic PA Healthcare Provider 145,221 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
Innovative Scientific Solutions, LLC SC Healthcare Provider 143,842 Hacking/IT Incident Network Server Hacking incident
Hospital Caribbean Medical Center PR Healthcare Provider 92,000 Hacking/IT Incident Network Server Ransomware attack (The Gentlemen) – Data theft confirmed
Tri-Cities Gastroenterology TN Healthcare Provider 67,115 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
City Health, a medical corporation CA Healthcare Provider 65,000 Unauthorized Access/Disclosure Electronic Medical Record Access to its electronic medical record system by a former business counterparty after termination
Hematology Oncology Consultants MI Healthcare Provider 62,972 Hacking/IT Incident Network Server Hacking incident – Data theft likely
GrayRobinson, P.A. FL Business Associate 54,131 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
Rocky Mountain Associated Physicians, P.C. UT Healthcare Provider 50,640 Hacking/IT Incident Network Server Hacking incident
Heart South Cardiovascular Group AL Healthcare Provider 46,666 Hacking/IT Incident Network Server Hacking incident
Mt. Spokane Pediatrics WA Healthcare Provider 32,021 Hacking/IT Incident Network Server Hacking incident – Data theft confirmed
University of Nebraska Medical Center NE Healthcare Provider 26,937 Hacking/IT Incident Network Server Hacking of a third-party software application
Liberty Bankers Life Ins. Co. TX Health Plan 20,202 Hacking/IT Incident Network Server Hacking incident at a business associate
Bayside Dental WA Healthcare Provider 10,216 Hacking/IT Incident Network Server Ransomware attack (Sinobi) – Data theft claimed

Three data breaches were reported in April before data reviews had been completed. Placeholder figures of 500 or 501 affected individuals were used and will be updated when the file reviews are concluded.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Spokane Digestive Disease Center, P.S. WA Healthcare Provider 501 Unauthorized access to its email environment
FMRS Health Systems, Inc. WV Healthcare Provider 500 Hacking incident – data theft confirmed
CARE Clinic MN Healthcare Provider 500 Unauthorized access to its email environment

Causes of April 2026 Healthcare Data Breaches

Hacking and other types of IT incidents dominated the breach reports in April, accounting for 36 (76.6%) of the 47 reported large data breaches. Across those incidents, the protected health information of 1,240,571 individuals was exposed or impermissibly disclosed. Hacking/IT incidents accounted for 92.8% of the affected individuals in April. The average breach size was 32,883 individuals, and the median breach size was 4,547 individuals.

Causes of APril 2026 healthcare data breaches

There were 9 unauthorized access/disclosure incidents in April, which accounted for 19.1% of the month’s data breaches. Across those incidents, the protected health information of 86,717 individuals was accessed without authorization or was impermissibly disclosed – 6.5% of the month’s affected individuals. The average breach size was 9,635 individuals, and the median breach size was 1,467 individuals. There were no loss, theft, or improper disposal incidents in April.

Location of breached PHI in April 2026

States Affected by April 2026 Healthcare Data Breaches

Data breaches were reported by HIPAA-regulated entities in 25 states, the District of Columbia, and Puerto Rico in April. California was the worst-affected state in terms of data breaches, while Florida was the worst-affected state in terms of the number of individuals affected.

April 2026 Healthcare Data Breaches

State Breaches
California 6
Texas & Washington 4
Florida & Virginia 3
Illinois, Minnesota, Oklahoma, Pennsylvania & West Virginia 2
Alabama, Delaware, Iowa, Indiana, Kentucky, Maryland, Michigan, Missouri, Nebraska, New Jersey, New York, South Carolina, Tennessee, Utah, Vermont, the District of Columbia & Puerto Rico 1

Individuals Affected by April 2026 Healthcare Data Breaches

State Individuals Affected State Individuals Affected
Florida 331,316 Oklahoma 8,233
Illinois 162,203 Maryland 7,213
Pennsylvania 145,976 Iowa 6,717
South Carolina 143,842 Indiana 5,900
Pouerto Rico 92,000 Vermont 5,892
California 78,846 Minnesota 5,885
Tennessee 67,115 Kentucky 3,677
Michigan 62,972 Virginia 2,552
Utah 50,640 New York 2,123
Alabama 46,666 Missouri 2,027
Washington 46,202 West Virginia 1,500
Nebraska 26,937 District of Columbia 1,467
Texas 26,648

April 2026 Data Breaches at HIPAA Regulated Entities

In April 2026, 36 data breaches were reported by healthcare providers, 8 breaches were reported by health plans, and 3 data breaches were reported by business associates. When a breach occurs at a business associate, the affected covered entities must be informed. Each covered entity may delegate the breach notification responsibilities to the business associate, but it is ultimately the responsibility of each covered entity to ensure that breach notifications are issued. In many cases, a breach at a business associate is reported by the covered entity.

The pie charts below show where the data breach occurred, rather than the reporting entity, which shows that 11 of the 47 breaches (rather than 3) occurred at business associates in April.

Data breaches at HIPAA-regulated entities in April 2026

Individuals affected by healthcare data breaches at HIPAA-regulated entities in April 2026

HIPAA Enforcement Activity in April 2026

The HHS’ Office for Civil Rights, the main enforcer of HIPAA compliance, announced 4 settlements with HIPAA-regulated entities in April to resolve alleged violations of the HIPAA Rules. When alleged HIPAA violations are settled, the settlement agreement includes a corrective action plan to address the areas of noncompliance identified by OCR. When a civil monetary penalty is imposed, OCR cannot compel the regulated entity to adopt a corrective action plan.

All four of the settlements related to ransomware attacks, and in all cases, OCR identified a risk analysis failure. The HIPAA Security Rule requires regulated entities to conduct a comprehensive and accurate risk analysis to identify risks and vulnerabilities to electronic protected health information. It is the most commonly identified HIPAA Security Rule violation.  You can read more about each enforcement action in this post. No state attorneys general announced any HIPAA penalties in April.

HIPAA -Regulated Entity Entity Type Reason for Investigation Alleged HIPAA violation(s) Settlement Amount
Regional Women’s Health Group (Axia Women’s Health) Healthcare Provider Reported ransomware attack involving the protected health information of 37,989 individuals Risk analysis failure; impermissible disclosure of ePHI $320,000
Assured Imaging Affiliated Covered Entities Healthcare Provider Reported ransomware attack involving the protected health information of 244,813 individuals Risk analysis failure (never conducted); breach notification failure $375,000
Consociate, Inc. (Consociate Health) Business Associate Reported ransomware attack involving the protected health information of 136,539 individuals Risk analysis failure $225,000
Star Group, L.P. Health Benefits Plan Health Plan Reported ransomware attack involving the protected health information of 9,316 individuals Risk analysis failure $245,000

 

The post April 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures

The national retail company Spencer Gifts LLC has agreed to a $450,000 settlement to resolve alleged violations of the HIPAA Rules that OCR identified while investigating a data breach affecting 10,023 members of its employer-sponsored group health plan (Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans).

In November 2021, staff were prevented from connecting to the company’s virtual private network. The IT issue was investigated, and the access issues were determined to be due to a ransomware attack. A threat actor had accessed the company’s network between November 24, 2021, and November 26, 2021, and used ransomware to encrypt files, including files on servers that stored plan members’ electronic protected health information (ePHI). Data exposed and potentially stolen in the incident included names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers. OCR was notified about the data breach on January 24, 2022.

OCR investigates all reported breaches affecting 500 or more individuals to determine whether they were the result of HIPAA noncompliance. Under its current enforcement initiative, OCR is laser-focused on the risk analysis provision of the HIPAA Security Rule. OCR requires evidence to demonstrate that a regulated entity has conducted a thorough and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

OCR determined that Spencer Gifts had failed to conduct a HIPAA-compliant risk analysis, in violation of 45 C.F.R. § 164.308(a)(1)(ii)(A) of the HIPAA Security Rule.  Spencer Gifts was also found to have failed to implement policies and procedures to comply with the HIPAA Privacy, Security, and Breach Notification Rules, in violation of 45 C.F.R. § 164.316(a) and 45 C.F.R. § 164.530(i)(1).

OCR determined that the HIPAA violations warranted a financial penalty. Spencer Gifts was informed of OCR’s determination and intention to impose a financial penalty, and the health plan was given the opportunity to settle the alleged violations informally. Spencer Gifts agreed to pay a $450,000 financial penalty and adopt a corrective action plan to address the alleged areas of noncompliance.

The corrective action plan requires Spencer Gifts to conduct a comprehensive and accurate risk analysis, review and update its HIPAA policies and procedures, distribute those policies and procedures to the workforce, and provide HIPAA training to its workforce.

This is the 20th OCR investigation of a ransomware attack resulting in a financial penalty for noncompliance with the HIPAA Rules, the 14th enforcement action under OCR’s risk analysis enforcement initiative, and the 7th HIPAA penalty to be announced this year. So far this year, OCR has collected $1,728,000 in penalties to resolve alleged violations of the HIPAA Rules from three healthcare providers, two health plans, and two business associates.

The post Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures appeared first on The HIPAA Journal.

Compliancy Group Acquires Healthicity

Compliancy Group has acquired Healthicity in a deal that combines two healthcare compliance software companies and expands Compliancy Group’s platform to include healthcare compliance, workforce compliance, risk assessment, third-party risk management, incident management, provider auditing, coding auditing, and documentation auditing.

The acquisition was announced on June 17, 2026. Financial terms of the transaction were not disclosed. Compliancy Group said the combined organization will serve more than 3,000 healthcare organizations across the United States and selected global markets.

Healthicity provides healthcare compliance and medical auditing software and advisory services. Its products include Compliance Manager, Audit Manager+, and Compliance Advisory Services, which are used by health systems, hospitals, physician groups, and other healthcare organizations to manage compliance programs and auditing activities.

Compliancy Group said the acquisition will allow healthcare organizations to manage more elements of their compliance programs through a single platform ecosystem. The expanded offering will combine Healthicity’s provider, coding, and documentation auditing capabilities with Compliancy Group’s existing compliance management tools, including workforce compliance, risk assessment, third-party risk, and incident management.

Darin Johnson, Chief Executive Officer of Healthicity, said Compliancy Group was selected as the right strategic partner for Healthicity’s software and customers because of its service reputation, regulatory expertise, and product innovation. Johnson said the two companies share a customer-focused approach and are positioned to deliver greater value together than either company could independently.

Crispin Vary, Chief Executive Officer of Compliancy Group, said the transaction will allow healthcare organizations to run broader compliance programs from a single partner. “For the first time, a healthcare organization can run its entire compliance program, from workforce training and risk assessment to vendor oversight, incident management, and now provider, coding, and documentation auditing, from a single trusted partner with one conformance score,” said Vary. Compliancy Group provides healthcare compliance software and advisory support for organizations that need to build, manage, and maintain compliance programs. Healthicity provides software and expert guidance for healthcare compliance management and medical auditing.

The acquisition brings the two businesses together at a time when healthcare organizations face increasing pressure to document the effectiveness of their compliance programs and demonstrate that required risk management, auditing, training, vendor oversight, and incident response activities are being performed.

The post Compliancy Group Acquires Healthicity appeared first on The HIPAA Journal.

Parents Sue Minnesota Hospital to Enforce HIPAA Right of Access for Minor Child’s Medical Records

The parents of a 15-year-old child have filed a lawsuit against a Minnesota hospital for failing to provide them with full access to their minor child’s medical records. Under federal law – The HIPAA Privacy Rule – parents have the right to obtain a copy of the medical records of their minor children in the form and format requested. While there are exceptions to the HIPAA Right of Access concerning parental access to the medical records of minor children, none apply in this case.

The daughter of Shaun and Katherine Johnson was diagnosed with a rare chromosomal condition called mosaic Turner syndrome when she was aged 11. The condition requires lifelong heart monitoring due to elevated cardiovascular risks, and the parents require real-time access to their child’s medical records to help them effectively manage her care.

The parents lost access to their daughter’s medical records when she turned 12, when Fairview Health Services applied its policy of shutting off parental access to children’s MyChart medical records. Under the hospital’s policy, which is based on an interpretation of state law, access can only be continued if hospital staff conduct a private interview with the child, and the child and staff agree to restore full MyChart access to the child’s parents.  The parents declined to sign the consent form and have therefore been refused access to their child’s medical records through MyChart.

The parents submitted a request for access to their minor child’s records via an Authorization for Release of Protected Health Information, and were provided with a copy of some of their daughter’s records; however, the request took three weeks to process, and the copy lacked important details required for the management of the child’s care. For instance, medical images can only be provided in electronic form via the MyChart portal.

“When your child is diagnosed with a serious condition, every appointment, test result, and next step matters,” said father Shaun Johnson. “Instead of allowing us to manage her care through the normal MyChart system, Fairview forced us into a delayed, inadequate, and burdensome workaround.”

The Center for Individual Rights (CIR), a Washington D.C.-based non-profit, public interest law firm dedicated to defending individual liberties, filed a complaint with the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), alleging the refusal to provide parents with access to the MyChart portal for their minor children over 12 years of age was a violation of the HIPAA Privacy Rule.

OCR responded, confirming in a letter to the Privacy Officer of Fairview Health Services and CIR that parents are permitted access to their minor child’s medical records under HIPAA. OCR recommended filing a second complaint if the matter was not resolved, which CIR did six weeks later when the parents’ access had not been restored. The second complaint is still pending with OCR. OCR subsequently issued a “Dear Colleague” letter to the medical community confirming that, under HIPAA, and absent special circumstances, healthcare providers may not place additional limitations on parental access to their minor children’s medical records. In this case, the special circumstances do not apply.

Under Minnesota law, children have the right to decide who has access to their medical records related to pregnancy, sexually transmitted diseases, physical and sexual abuse, and substance abuse diagnosis and treatment. Fairview Health Services allows parents or legal guardians to have partial proxy access, excluding those areas, for minor children aged 12-17 years of age. Full proxy access is only granted with the child’s consent. Since the parents object to an intrusive, unsupervised interview with their daughter, they are prevented from having timely and complete access to their daughter’s medical records to the extent required to engage effectively in her care.

The lawsuit alleges federal law preempts state law and that Fairview Health’s policy is inconsistent with Minnesota law. The lawsuit seeks a declaratory judgment and permanent injunction ordering that the Minnesota Health Records Act requires providing the parents with unrestricted access to their daughter’s medical records. “A hospital cannot apply state law to lock parents out of their own child’s medical records,” said CIR Litigation Director Caleb Kruckenberg. “Federal law is supreme. Our federalist system is built to better protect individual rights—in this case, the parental right to supervise and participate in a minor child’s medical care.”

The post Parents Sue Minnesota Hospital to Enforce HIPAA Right of Access for Minor Child’s Medical Records appeared first on The HIPAA Journal.

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has submitted its annual reports to Congress on compliance with the Health Insurance Portability and Accountability Act (HIPAA) and breaches of unsecured protected health information for calendar year 2024.

The reports are a requirement of the Health Information Technology for Economic and Clinical Health (HITECH) Act and provide a snapshot of the state of compliance in healthcare, the actions taken by OCR in response to potential noncompliance, and the extent to which sensitive health information is being exposed or stolen. The reports to Congress are based on the number of data breaches that occurred in each calendar year, not the year in which the data breach was reported. In calendar year 2024, OCR received 742 reports of data breaches affecting 500 or more individuals; however, only 663 reports related to breaches that occurred in 2024.

2023 was a particularly bad year for large healthcare data breaches. In its previous reports to Congress, OCR reported that 732 large data breaches occurred in 2023, a 17% increase from the previous year, with more than 113 million individuals affected. While there was an improvement in 2024 with 9% fewer large data breaches reported, an unprecedented number of individuals were affected by large data breaches, smashing the previous record. Across the 663 reported data breaches, the protected health information of 242,908,056 individuals was exposed or impermissibly disclosed. The massive total was largely due to a single data breach at Change Healthcare, which affected an estimated 192 million individuals. In 2024, OCR received 74,299 reports of data breaches affecting fewer than 500 individuals, although across those incidents, only 340,618 individuals were affected.

OCR investigates all large data breaches and opened investigations into all 663 breaches, plus two smaller data breaches. The vast majority of data breach investigations are resolved through voluntary corrective actions taken by the affected regulated entity or the provision of technical assistance. OCR resolved 785 data breach investigations in 2024, including 12 with resolution agreements, corrective action plans, and monetary settlements or civil monetary penalties. In 2024, OCR collected $7,813,831 in penalties to resolve alleged HIPAA violations uncovered through its investigations of data breaches, plus a further $950,000 penalty stemming from an investigation in response to media reports of a data breach.

Year Data Breaches (Under 500 individuals) Percentage Change

(Under 500 individuals)

Data Breaches (500+ individuals) Percentage Change (500+ individuals)
2024 74,299 +9% 663 -9%
2023 68,315 +7% 732 +17%
2022 63,966 +15% 626 +3%
2021 63,571 -4% 609 -7%
2020 66,509 +6% 656 +61%
2020 to 2024 12% increase 1% increase

Source: OCR reports to Congress (breaches each calendar year, irrespective of reporting date)

In the 2024 breaches of unsecured protected health information report, OCR explained that there is a continued need for HIPAA-regulated entities to improve compliance. Noncompliance with the HIPAA Rules is often identified. Many data breaches could have been prevented through proactive compliance, rather than addressing security issues after exploitation. Some of the most common areas of noncompliance were the risk analysis, risk management, information system activity review, audit controls, and person or entity authentication standards and implementation specifications of the HIPAA Security Rule.

If a risk analysis is incomplete or not conducted, risks are likely to persist unaddressed and can be exploited by threat actors. Risks also need to be reduced to a reasonable level to make it harder for threat actors to succeed. Access controls can prevent breaches as well as limit the harm caused if a network is breached. OCR’s investigations of data breaches found many instances of scant internal controls limiting lateral movement and excessive privileges for many user accounts, which allowed threat actors to gain access to multiple systems containing ePHI. OCR also commonly found weak authentication practices, such as default passwords and single-factor remote access, rather than multifactor authentication. Improving compliance across these areas would drastically reduce the number of large healthcare data breaches reported each year.

The most common cause of breaches, as has been the case for several years, was hacking/IT incidents, which accounted for 81% of all data breaches and 241,582,022 of the affected individuals (99.45%). The most common location of breached protected health information was network servers. For smaller breaches, the main cause was unauthorized access/disclosure incidents, most commonly involving paper/films.

Penalties to Resolve Alleged HIPAA Violations in Calendar Year 2024

HIPAA-Regulated Entity Penalty Type Penalty Amount Individuals Affected Areas of Alleged HIPAA Noncompliance
Plastic Surgery Associates of South Dakota Settlement $500,000 10,226 Risk analysis; security measures to reduce risks and vulnerabilities; reviews of records of information systems activity; policies and procedures to address security incidents
Providence Medical Institute Civil Monetary Penalty $240,000 85,000 across three ransomware attacks Business associate agreement; policies and procedures to only allow authorized persons or software to access ePHI
Bryan County Ambulance Authority Settlement $90,000 14,273 Risk analysis
Children’s Hospital Colorado Civil Monetary Penalty $548,265 14,210 across two email-related incidents Risk analysis; workforce HIPAA Privacy Rule training.
Gulf Coast Pain Management Consultants Civil Monetary Penalty $1,190,000 34,310 Risk analysis; review of records of activity in information systems; termination of access rights of terminated employees; procedures for establishing/modifying access rights to information systems.
Elgon Information Systems Settlement $80,000 31,248 Risk analysis
Virtual Private Network Solutions Settlement $90,000 At least 6,400 Risk analysis
Northeast Surgical Group Settlement $10,000 15,298 Risk analysis
Solara Medical Supplies Settlement $3,000,000 115,538 across two incidents Risk analysis; breach notification letters to individuals, HHS, and media.
USR Holding Settlement $337,750 2,903 Risk analysis; review of activity in information systems; procedures for creating and maintaining exact retrievable copies of ePHI; prevention of unauthorized access and deletion of ePHI.
Warby Parker Civil Monetary Penalty $1,500,000 More than 197,986 individuals Risk analysis; security measures to reduce risks and vulnerabilities; review of records of activity in information systems.
Health Fitness Settlement $227,816 4,304 Risk analysis
Heritage Valley Health System Settlement $950,000 Undisclosed Risk analysis; contingency plan for emergencies; policies and procedures restricting access to ePHI

In calendar year 2024, OCR received 30,256 new complaints about potential violations of the HIPAA Rules and carried over 2,955 complaints from previous years. Out of those, OCR resolved 28,228 complaints, 17,466 without opening an investigation, and 9,392 were resolved through the provision of technical assistance.

Out of the 1,370 complaint investigations completed by OCR in 2024, around half (48%) required the regulated entity to take corrective action, and in 51% of the investigations, insufficient evidence was found to indicate violations of the HIPAA Rules. Nine complaint investigations were resolved with financial penalties totaling $1,180,781. The most common issues prompting complaints were impermissible uses and disclosures (660 complaints), Right of Access violations (541 complaints), missing general safeguards (481 complaints), lacking HIPAA Security Rule administrative safeguards (147 complaints), and missing or late individual breach notifications (122 complaints).

OCR initiated 730 compliance reviews and completed 797 compliance reviews in 2024 that did not arise from complaints. While OCR is required by the HITECH Act to conduct audits of HIPAA-regulated entities, no audits were initiated in 2024. OCR is also responsible for outreach activities to improve the education of the public with respect to their HIPAA Rights, and HIPAA-regulated entities about large data breach trends. OCR conducted 89 such outreach activities in calendar year 2024.

The report on compliance with the HIPAA Privacy, Security, and Breach Notification Rules shows there was a slight year-over-year decrease in complaints and a small increase in initiated compliance reviews.

Year Complaints received YoY Percentage Change in Complaints Initiated Compliance Reviews (including complaints and breaches) YoY Percentage Change in Initiated Compliance Reviews
2024 30,256 – 2% 797 -3%
2023 30,968 + 2% 773 +14%
2022 30,435 -11% 676 + <1%
2021 34,077 +25% 674 -10%
2020 27,182 -4% 746 +22%
2020 to 2024 +11% +7%

Penalties Arising from Substantiated HIPAA Compliance Complaints in 2024

In total, OCR imposed 22 financial penalties to resolve HIPAA violations in calendar year 2024, 13 in response to reports of data breaches and 9 in response to complaints. In total, OCR collected $9,944,612 in settlements and penalties. Complaints resolved with financial penalties are detailed in the table below. Further information on each fine can be found on our HIPAA Violation Cases page.

HIPAA-Regulated Entity Penalty Type Penalty Amount Individuals Affected Areas of Alleged HIPAA Noncompliance
Essex Residential Care dba Hackensack Meridian Health, West Caldwell Care Center Civil Monetary Penalty $100,000 1 HIPAA Right of Access
American Medical Response Civil Monetary Penalty $115,200 1 HIPAA Right of Access
Cascade Eye and Skin Centers Settlement $250,000

 

291,000 Risk analysis; monitoring of information systems
Rio Hondo Community Mental Health Center Civil Monetary Penalty $100,000 1 HIPAA Right of Access
Inmediata Health Group Settlement $250,000 1,565,338 Risk analysis; monitoring of information systems
Holy Redeemer Hospital Settlement $35,581 1 HIPAA Right of Access
Gums Dental Care Civil Monetary Penalty $70,000 1 HIPAA Right of Access
South Broward Memorial Hospital District dba Memorial Healthcare System Settlement $60,000 1 HIPAA Right of Access
Oregon Health and Science University Civil Monetary Penalty $200,000 1 HIPAA Right of Access

 

The post OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024 appeared first on The HIPAA Journal.