HIPAA Compliance News

H1 2026 Healthcare Data Breach Report

There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023. While the year-over-year reduction in healthcare data breaches is a step in the right direction, healthcare data breaches continue to be reported in high numbers. In the first six months of the year, large healthcare data breaches were reported at a rate of more than 2.2 per day.

H1, 2026 Healthcare data breaches

Across the 397 reported data breaches, the protected health information of 33.77 million individuals was exposed or impermissibly disclosed. That represents a 22.6% reduction in affected individuals compared to H1 2025, and it is the lowest number of affected individuals in H1 since 2023.

H1 2026 healthcare data breaches: individuals affected

If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025. The current total also suggests that this year could see a major reduction in affected individuals, as more than 140 million individuals were affected in 2025. That said, several very large data breaches have yet to be added to the OCR breach portal for this year.

The Biggest Healthcare Data Breaches in H1 2026

In the first half of the year, nine healthcare data breaches were reported that affected more than 1 million individuals, the largest breach of which affected more than 5.8 million individuals. All but two of the top twenty data breaches were due to hacking incidents or ransomware attacks. The two non-hacking breaches were unauthorized access/disclosure incidents, and both occurred at state departments of human services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Rank Regulated Entity State Covered Entity Type Individuals Affected Type of Breach
1 Lumexa Imaging NC Healthcare Provider 5,830,949 Hacking Incident
2 TriZetto Provider Solutions MO Business Associate 3,433,965 Hacking Incident
3 QualDerm Partners, LLC TN Healthcare Provider 2,951,318 Hacking Incident
4 Nacogdoches Memorial Hospital TX Healthcare Provider 2,507,073 Hacking Incident
5 Navia Benefit Solutions, Inc. WA Business Associate 2,151,330 Hacking Incident
6 Insightin Health, Inc. MD Business Associate 1,949,534 Hacking Incident
7 New York City Health and Hospitals Corporation NY Healthcare Provider 1,800,000 Hacking Incident
8 Xsolis, Inc. TN Business Associate 1,396,519 Hacking Incident
9 MCBS, LLC GA Business Associate 1,261,464 Hacking Incident
10 OpenLoop Health, Inc. IA Business Associate 716,000 Hacking Incident
11 Illinois Department of Human Services IL Health Plan 705,017 Unauthorized Disclosure Incident
12 ApolloMD Business Services, LLC GA Business Associate 626,540 Hacking Incident (Ransomware)
13 Erie Family Health Centers IL Healthcare Provider 570,000 Hacking Incident
14 Centers Lab NJ LLC NJ Healthcare Provider 542,377 Hacking Incident
15 Networking Technology, Inc. (RXNT) NC Business Associate 353,844 Hacking Incident
16 Minnesota Department of Human Services MN Health Plan 303,965 Unauthorized Access Incident
17 North Texas Behavioral Health Authority TX Healthcare Provider 285,086 Hacking Incident
18 Florida Physician Specialists FL Healthcare Provider 276,498 Hacking Incident
19 Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking Incident
20 Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Hacking Incident

The majority of the data breaches reported in H1 2026 were relatively small, affecting fewer than 10,000 individuals. Currently, 37 healthcare data breaches are listed as affecting 500 or 501 individuals. These are commonly used placeholder figures when data reviews are incomplete by the breach reporting deadline. The majority of those 37 data breaches are likely to see the totals increased, potentially significantly. The Change Healthcare data breach in 2024 was initially reported to OCR as affecting at least 500 individuals but was subsequently increased to 192.7 million individuals!

Scale of Breach – Affected Individuals Data Breaches
Over 1,000,000 9
100,000 – 999,999 21
10,000 – 99,999 102
1000 – 9,999 175
Under 1000 90

Causes of H1 2026 Healthcare Data Breaches

While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft incidents, rather than hacking/IT incidents, which increased for the third consecutive year.

H1 Healthcare data breach causes 2022-2026

H1 2026 Hacking/IT Incidents

Hacking/IT incidents remain the leading cause of healthcare data breaches and increased again in 2026. Ransomware groups continue to attack the healthcare sector, and there has been an increasing trend of data theft and extortion incidents, where data is stolen and threats are issued to publish the stolen data, but files are not encrypted.

As also observed by the Identity Theft Resource Center, there has been a growing trend of breached entities failing to disclose the nature of data breaches, including the cause, whether ransomware was involved, and, concerningly, if data was stolen in the incident. The lack of a breach cause makes it difficult to assess trends, while the failure to disclose whether data has been stolen makes it difficult for individuals to gauge the level of risk they face.

In H1, 343 hacking/IT incidents were reported, affecting an average of 94,167 individuals (median breach size: 4,800 individuals). Hacking/IT incidents have increased by 2.1% year-over-year increase in hacking/IT incidents, although the number of affected individuals has reduced by 14.7% year-over-year.

H1 2026 individuals affected by healthcare hacking/IT incidents

H1 2026 Unauthorized Access/Disclosure Incidents

Unauthorized access and disclosure incidents were the second leading cause of healthcare data breaches in H1 2026. These incidents include any unauthorized access to and disclosure of patient records that are not hacking- or IT-related. They include snooping incidents by insiders, misdirected emails and mailings, and unauthorized data sharing between HIPAA-regulated entities and third parties.

These incidents tend to affect far fewer individuals than hacking and IT incidents, although not always. Incidents involving website tracking tools such as pixels, for example, can affect millions of individuals. The two largest unauthorized access/disclosure incidents made it into the top 20 largest breaches of the first half of the year and occurred at the Illinois Department of Human Services and Minnesota Department of Human Services. The former involved data uploaded to a website for internal use that was accessible via the public internet, and the latter involved a user associated with an authorized healthcare provider accessing data without authorization.

In H1, 51 unauthorized access/disclosure incidents were reported, affecting an average of 28,710 individuals (median breach size: 2,315 individuals).  That represents a 3.8% year-over-year decline in unauthorized access/disclosure incidents, and a 74.2% decline in affected individuals.

H1 2026 individuals affected by healthcare unauthorized access/disclosure

H1 2026 Loss/Theft Incidents

Loss and theft of electronic devices containing protected health information and paper records used to be a leading cause of data breaches; however, the adoption of digital records, data encryption, and cloud storage of protected health information has helped reduce these incidents. In H1 2026, only two such incidents were reported – one loss and one theft incident, both involving a relatively small number of paper records. That equates to a 75% year-over-year reduction in data breaches, and a 96.7% reduction in affected individuals.

H1 2026 individuals affected by healthcare unauthorized loss/theft incidents

H1, 2026 Improper Disposal Incidents

Improper disposal incidents are rarely reported, and when they are, they almost always involve paper records inadvertently disposed of with regular trash. Only one such incident was reported by a HIPAA-regulated entity in H1 2026 – a relatively small data breach affecting an estimated 1,000 individuals. A single improper disposal incident was also reported in H1 2025, althopugh the number of affected individuals has fallen by 97% year-over-year.

H1 2026 individuals affected by healthcare unauthorized improper disposal incidents

Data Breaches at HIPAA Regulated Entities

Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches). Healthcare clearinghouses survived the first 6 months of the year without any data breaches. The same order applies in terms of individuals affected by those breaches, with healthcare providers topping the list (19,701,297 individuals), followed by business associates (12,505,090 individuals), and health plans (1,559,474 individuals).

Those figures do not tell the full story, as when a data breach occurs at a business associate, it is not always the business associate that reports the data breach. When a data breach occurs at a business associate, the business associate must notify each affected covered entity, and the covered entity may delegate the reporting and notification requirements to the business associate or may choose to report the data breach and/or send notification letters themselves. If a breach occurs at a business associate, some affected covered entities may delegate the reporting and notification responsibilities to the business associates while others may not. As such, business associate data breaches are often underrepresented in the raw breach data.

The charts below are based on where the data breach occurred, rather than the reporting entity. While the same order applies to both data breaches and affected individuals, almost 100 more breaches occurred at business associates than the raw data suggests.

H1 2026 healthcare data breaches at HIPAA-regulated entities

H1 2026 healthcare data breaches at HIPAA-regulated entities - individuals affected

Based on the adjusted data, the average size of a data breach at a healthcare provider (87,629 individuals) and a business associate (87,643 individuals) was virtually identical, although the median size of a data breach at a healthcare provider (6,323 individuals) is twice that of a business associate (3,086 individuals). In H1 2026, health plan breaches were less severe. The average breach size was less than half the size at other entities at 41,042 individuals, and the median breach size was 2,871 individuals.

Location of Breached Protected Health Information

Given the high number of hacking incidents, it is unsurprising that the most common location of breached protected health information is network servers, as has been the case for several years. Email remains a common location of breached healthcare data due to a relatively high prevalence of phishing and social engineering incidents. While not infallible, multifactor authentication would have prevented many of these data breaches.

A small but significant number of healthcare data breaches involved paper records, although the number of incidents involving physical records is falling. Breaches of protected health information in “other” locations – including the cloud – are on the rise.  Widespread adoption of encryption and use of the cloud have helped to drastically reduce the number of loss and theft incidents.

H1 2026 healthcare data breaches: location of breached protected health information

Geographic Distribution of Healthcare Data Breaches

In H1 2026, large healthcare data breaches were reported by HIPAA-regulated entities in 44 U.S. states, the District of Columbia, and Puerto Rico. The only states to escape the first half of the year unscathed were Hawaii, Montana, New Mexico, North Dakota, South Dakota, and Wyoming.

As a general rule, the states with the biggest populations experience the most data breaches, and vice versa for the states with the fewest number of breaches. California, Texas, Florida, and New York are the most heavily populated states in that order, and the same order applies in H1 2026 in terms of data breaches.

Rank State Data Breaches State Individuals Affected
1 California 38 North Carolina 6,358,110
2 Texas 36 Tennessee 4,635,531
3 Florida 24 Missouri 3,468,743
4 New York 20 Texas 3,188,111
5 Illinois 16 Washington 2,270,117
6 Michigan 15 New York 2,113,172
7 North Carolina 14 Georgia 2,005,142
8 Pennsylvania 13 Maryland 1,968,198
9 Washington 13 Illinois 1,756,341
10 Massachusetts 12 Florida 846,997
11 Colorado 11 Iowa 767,730
12 Tennessee 11 New Jersey 702,065
13 Virginia 11 Minnesota 486,202
14 Minnesota 10 Virginia 458,060
15 Ohio 10 California 430,336
16 Georgia 9 Colorado 324,483
17 Indiana 9 South Carolina 318,963
18 Kentucky 9 Pennsylvania 213,188
19 Maryland 9 Michigan 207,522
20 New Jersey 9 Ohio 139,151
21 Oklahoma 9 Connecticut 133,735
22 South Carolina 8 Puerto Rico 116,236
23 Alabama 7 Alabama 103,406
24 Connecticut 7 Kentucky 89,363
25 Missouri 7 Utah 82,335
26 Iowa 6 Arizona 76,546
27 Oregon 6 Idaho 66,625
28 Utah 6 Massachusetts 66,382
29 Idaho 5 Mississippi 60,133
30 Kansas 5 Indiana 49,271
31 Maine 5 Maine 45,932
32 Louisiana 4 Kansas 40,760
33 Arizona 3 Louisiana 37,963
34 District of Columbia 3 Nevada 37,796
35 Arkansas 2 Nebraska 26,937
36 Mississippi 2 District of Columbia 21,481
37 Puerto Rico 2 Oklahoma 18,392
38 West Virginia 2 Oregon 10,278
39 Wisconsin 2 Vermont 5,892
40 Alaska 1 Arkansas 5,800
41 Delaware 1 Rhode Island 5,630
42 Nebraska 1 Wisconsin 2,654
43 Nevada 1 West Virginia 1,500
44 New Hampshire 1 New Hampshire 1,221
45 Rhode Island 1 Delaware 908
46 Vermont 1 Alaska 523

HIPAA Enforcement Activity in H1 2026

OCR has increased the number of penalties imposed for HIPAA violations in recent years, although financial penalties are still relatively rare. OCR investigates all data breaches affecting 500 or more individuals, and when potential HIPAA violations are identified, they are typically resolved through voluntary compliance or by providing technical assistance.

Financial penalties are typically reserved for egregious or particularly impactful HIPAA violations, when there has been a history of noncompliance, and when OCR has an enforcement initiative targeting a specific aspect of the HIPAA regulations. Currently, OCR has two main enforcement initiatives, one targeting noncompliance with the HIPAA Right of Access of the HIPAA Privacy Rule, and another targeting noncompliance with the risk analysis implementation specification of the HIPAA Security Rule.

The HIPAA Right of Access enforcement initiative has been active since late 2019 and has resulted in more than 55 financial penalties. The risk analysis enforcement initiative is more recent and was formally launched in October 2024 in response to widespread noncompliance with this specific security rule provision and its importance for cybersecurity. To date, OCR has imposed 14 financial penalties under this initiative. The risk analysis enforcement initiative has been expanded this year to include risk management. In addition to demonstrating that a HIPAA-compliant risk analysis has been conducted, OCR requires evidence that the identified risks have been properly managed and reduced to a low and acceptable level in a reasonable time frame.

Between January 1 and June 30, 2026, OCR announced seven settlements to resolve alleged violations of the HIPAA Rules, all seven of which included a financial penalty for a risk analysis violation. While OCR has not announced a specific initiative targeting noncompliance with the HIPAA Breach Notification Rule, two of the seven penalties this year included a fine for breach notification failures. Five of the fourteen penalties imposed in 2025 also included penalties for breach notification failures, which suggests OCR is paying close attention to the time taken to issue breach notifications to OCR, the affected individuals, and the media.

H1 2026 HIPAA Settlements and Civil Monetary Penalties

Covered Entity Type of Entity Amount Settlement / Civil Monetary Penalty Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans Health Plan $450,000 Settlement Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
Regional Women’s Health Group (Axia Women’s Health) Healthcare Provider $320,000 Settlement Risk analysis failure; impermissible disclosure of the ePHI of 10,023 individuals.
Assured Imaging Affiliated Covered Entities Healthcare Provider $375,000 Settlement Risk analysis failure (never conducted); breach notification failure.
Consociate, Inc. (Consociate Health) Business Associate $225,000 Settlement Risk analysis failure.
Star Group, L.P. Health Benefits Plan Health Plan $245,000 Settlement Risk analysis failure.
MMG Fusion Business Associate $10,000 Settlement Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
Top of the World Ranch Treatment Center Healthcare Provider $103,000 Settlement Risk analysis failure

OCR is the main enforcer of the HIPAA Rules, although state attorneys general are also authorized to enforce HIPAA compliance and can impose financial penalties in their respective states. In H1 2026, only one penalty was announced at the state level. Massachusetts and Connecticut participated in a joint investigation of Comstar LLC over a data breach affecting 585,621 individuals (326,426 Massachusetts residents & 22,829 Connecticut residents). The investigation identified violations of the HIPAA Security Rule and the Massachusetts Data Security Regulations. The case was settled with a $515,000 financial penalty.

HIPAA Regulatory Updates

There were no new updates to the HIPAA Rules in the first half of 2026, although there are two pending final rules. During President Trump’s first term in December 2020, OCR proposed an update to the HIPAA Privacy Rule to support coordinated care and improve individual engagement in healthcare. The proposed rule was formally introduced in the Federal Register in January 2021, but a final rule stalled, as OCR had other priorities under the Biden Administration. The return of President Trump for a second term has seen the proposed rule rekindled. OCR set a target of August 2026 for the release of a final rule, although it has yet to be issued.

The other pending final rule is for proposed changes to the HIPAA Security Rule. A notice of proposed rulemaking was announced by OCR in the final days of the Biden administration in late December 2024 and was published in the Federal Register on January 6, 2025. OCR received several thousand comments from industry stakeholders about the proposed changes, including a significant amount of criticism. OCR set a target release date of May 2026 for a final rule; however, it has now been pushed back until July 2027, although a final decision about whether to issue a final rule has yet to be made by the Trump administration.

While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy. The Notice of Privacy Practices compliance deadline aligned with the compliance deadline for changes to the 42 CFR Part 2 regulations concerning substance use disorder (SUD) patient records to align those regulations more closely with HIPAA.

About this Report

This report is based on healthcare data breaches affecting 500 or more individuals that were reported to the HHS’ Office for Civil Rights in H1 2026. The data for this report was obtained from OCR on September 10, 2026, and includes supplemental information from data breach reporting from the HIPAA Journal.

You can view more comprehensive healthcare data breach facts and statistics from 2009 to the present on our data breach statistics page, and more comprehensive and up-to-date information on HIPAA enforcement actions on our HIPAA violation cases page, both of which are regularly updated. Information on the latest regulatory changes can be found on our HIPAA Updates/HIPAA Changes page.

The post H1 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Labcorp Settles Multistate Data Breach Investigation for $2.3 Million

A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp) regarding a 2019 data breach at its debt collection company, American Medical Collection Agency (AMCA). Labcorp has agreed to pay $2,287,455, which will be divided among the 44 states participating in the action.

AMCA is a subsidiary of the debt collection company Retrieval-Masters Creditors Bureau (RMCB) and provides small debt collection services to healthcare organizations, including laboratories and medical testing facilities. The hacking incident was identified by RMCB on March 19, 2029, and the forensic investigation determined that a hacker breached the AMCA network around 8 months before the intrusion was detected. The hacker had access to the network from August 1, 2018, until March 30, 2019, and exfiltrated sensitive data including names, personal information, Social Security numbers, financial information, medical test information, and diagnostic codes.

The AMCA data breach was the largest data breach reported in 2019 by a HIPAA-regulated entity, affecting more than 27.5 million individuals, including more than 10.2 million Labcorp patients. The high cost of remediation forced AMCA to file for bankruptcy protection. AMCA was also investigated by the coalition, led by the Indiana, Texas, Connecticut, and New York attorneys general, and received permission from the bankruptcy court to settle the multistate action, filing for dismissal of the bankruptcy on December 9, 2020.

The settlement required AMCA to develop, implement, and maintain an information security program and implement a range of data security measures, including developing an incident response plan and appointing a qualified Chief Information Security Officer (CISO). A financial penalty of $21 million was suspended due to the financial position of the company.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The investigation of Burlington, NC-based Labcorp was led by the attorneys general of Connecticut, Florida, Indiana, Illinois, Michigan, and Texas and identified potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state consumer protection and breach notification laws. The Labcorp settlement includes a financial penalty and injunctive relief. Labcorp must ensure that it does not misrepresent the extent to which it maintains and protects the privacy, security, and confidentiality of personal information (PI) and protected health information (PHI) and must implement a range of security measures, including but not limited to the following:

  • Review, revise, and update its information security program.
  • Employ an executive or officer as a CISO to oversee the implementation and maintenance of its information security program.
  • Provide security awareness training to all personnel who have access to or responsibility for PI and/or PHI.
  • Implement an incident response plan, which must include a plan for vendor security incidents.
  • Ensure procedures are implemented for reporting vendor security incidents internally to senior management.
  • Develop policies and procedures governing the collection, use, disclosure, and retention of PI and PHI, including specific policies and procedures for PI and PHI shared with debt collectors.
  • Minimize the PI and PHI shared with debt collectors.
  • Develop, implement, and maintain a vendor risk management program; maintain a vendor risk management team; and use security assessment and management tools for vendor assessment and monitoring, with specific requirements for debt collectors.
  • Require all debt collectors to conduct risk assessments, and contractually require debt collectors to conduct penetration tests of systems containing PI and PHI, and annual SOC 2 Type 2 audits.
  • Labcorp must also engage a third-party assessor to perform an information security assessment, with a focus on vendor risk management.

Labcorp was also named as a defendant in class action litigation against AMCA and other AMCA clients, and agreed to a $35,000,000 settlement earlier this year. The class action lawsuit is ongoing against other AMCA clients.

The post Labcorp Settles Multistate Data Breach Investigation for $2.3 Million appeared first on The HIPAA Journal.

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U.S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures.

The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR), following its initial introduction in the 118th Congress 2D Session on September 25, 2024. When the bill was first introduced, 394 large hacking-related healthcare data breaches had been reported to the Department of Health and Human Services Office for Civil Rights (OCR), involving the protected health information of 43 million Americans.

At the time, the senators explained that cyberattacks are delaying and disrupting patient care, harming patient health and national security, and putting Americans at risk of identity theft and fraud. “These hacks are entirely preventable and are the direct result of lax cybersecurity practices by health care providers and their business partners,” explained the Senators.

The situation has only worsened in the two years since the bill was first introduced. The OCR breach portal lists year-to-date figures (Jan 1 – Aug 31) of 426 hacking-related breaches, involving the protected health information of 73 million Americans. That’s an 8% increase in hacking-related data breaches and a 70% increase in affected individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

On January 24, 2024, OCR published two sets of voluntary cybersecurity performance goals (CPGs) for the healthcare and public health (HPH) sector – Essential and Enhanced – that consist of high-impact measures that should be adopted by healthcare organizations to strengthen and mature their cybersecurity programs. As predicted by OCR at the time, voluntary goals alone would not be enough to drive the behavioral changes needed across the sector to improve cybersecurity.

The CPGs were followed by a proposed update to the HIPAA Security Rule, which mandates significant additional cybersecurity requirements. The proposed update has proven hugely unpopular, with industry groups and health systems calling for the proposed rule to be scrapped. A final rule has been delayed until July 2027, although a final decision about whether a final rule will actually be released has yet to be made by the Trump administration. Part of the problem, especially for rural and other low-resource healthcare providers, is a lack of funding to make the necessary cybersecurity improvements, which is something that the Health Infrastructure Security and Accountability Act seeks to address.

“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy,” explained Sen. Warner. “This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”

As the Senators explained, the U.S. health care system is particularly at risk for cyberattacks due to its size, technological dependence, collection of sensitive personal information, and unique vulnerability to disruptions. Healthcare organizations are viewed as low-hanging fruit, and attacks can be highly profitable for cybercriminals. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow,” said Sen. Wyden. “Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every American’s medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.”

The 2026 Health Infrastructure Security and Accountability Act remains largely unchanged from the 2024 version, other than shifting the timeline forward by two years. The key requirements of the bill are:

  • Mandatory minimum cybersecurity standards for covered entities and business associates, established, enforced, and updated by the HHS. Updates are required at least every two years.
  • Heightened cybersecurity standards for systemically important entities and entities critical to national security.
  • Continuity/recovery plans for all covered entities for technical failures, disruptive cyber events, and natural disasters, and stress tests to evaluate whether the entity has the capabilities to recover essential functions.
  • Written annual statements signed by the chief executive officer and chief information security officer attesting that the company is compliant with applicable security standards.
  • Mandatory annual security risk analyses, including specific assessments of the extent to which the entity is exposed to risk through its business associates.
  • Independent audits of covered entities’ security measures to assess compliance with the HHS’s CPGs.
  • Annual HHS audits of at least 20 HIPAA-regulated entities to assess data security practices, focused on those of systemic importance.
  • Increased financial penalties under HIPAA for failing to meet security requirements – A minimum $500 penalty for no knowledge; $5,000 for reasonable cause; $50,000 for willful neglect (corrected); and $250,000 for willful neglect (uncorrected).
  • A government investment of $1.3 billion to help hospitals strengthen cybersecurity: $800 million in up-front investment for hospitals in rural and underserved urban communities to adopt the essential cybersecurity goals, and $500 million in incentives available to all hospitals to adopt the enhanced CPGs.
  • Medicare accelerated and advanced payments in response to cybersecurity incidents.

The post Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act appeared first on The HIPAA Journal.

Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company Ambry Genetics Corporation have agreed to a settlement to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Ambry Genetics has agreed to pay a $700,000 financial penalty and adopt a corrective action plan to address the areas of noncompliance identified by OCR during its investigation of a breach of the electronic protected health information (ePHI) of 225,370 individuals.

The data breach was reported to OCR on March 22, 2020, initially as involving the protected health information of 232,772 individuals, although the total was later updated to 225,370 individuals. Ambry Genetics identified suspicious activity within its email environment on January 22, 2020, and its forensic investigation determined that an unauthorized third party gained access to an employee’s email account as a result of a response to a phishing email. The account was accessed by a criminal actor between January 22 and January 24, 2020, exposing names, addresses, dates of birth, driver’s license numbers, diagnosis/condition information, medications, treatment information, and some Social Security numbers.

OCR investigates all data breaches affecting 500 or more individuals and launched an investigation after being informed about the phishing-related data breach. OCR determined that Ambry Genetics failed to conduct an accurate and thorough risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

In addition, there was a failure to implement policies and procedures for terminating access to ePHI when the employment of members of the workforce was terminated, or access to ePHI was otherwise no longer required. Unique usernames had not been assigned to all members of the workforce who required access to ePHI to allow them to be identified and their interactions with ePHI to be tracked.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

OCR notified Ambry Genetics of the findings of the investigation and the intention to impose a financial penalty, along with an offer to settle the alleged HIPAA violations informally. Ambry Genetics accepted and agreed to settle the alleged HIPAA violations with a $700,000 financial penalty and a corrective action plan to ensure full compliance with the HIPAA Rules. Ambry Genetics will be monitored for compliance with the corrective action plan for a period of two years.

The corrective action plan requires Ambry Genetics to conduct a comprehensive and accurate risk analysis and develop and implement a risk management program to reduce and mitigate the risks identified by the risk analysis. Policies and procedures must be developed to ensure compliance with the HIPAA Security Rule and other HIPAA policies and procedures, and all members of the workforce must be assigned unique identification to allow their activity to be tracked in information systems containing ePHI. All workforce members must receive HIPAA training on the policies and procedures.  The phishing attack has proven costly for Ambry Genetics. Ambry Genetics faced class action litigation over the data breach and settled the lawsuit for $12.25 million.

“Email phishing is a common cyberattack that can lead to a breach of PHI and reveal HIPAA Security Rule deficiencies,” said OCR Director Paula M. Stannard. “Conducting a compliant risk analysis, engaging in risk management, and full implementation of the Security Rule provisions continue to be the foundation for effective cybersecurity and the best cyber defense.” This is the 10th financial penalty to be imposed by OCR this year to resolve alleged violations of the HIPAA Rules, and its 188th penalty to date. All but one of this year’s penalties have resolved risk analysis failures. So far this year, OCR has collected $3,030,250 in HIPAA fines.

The post Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations appeared first on The HIPAA Journal.

HHS Updates Security Risk Assessment Tool

The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.

The SRA Tool was developed by the Department of Health and Human Services Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the Office for Civil Rights (OCR). The downloadable tool was first released in March 2014 to help small- and medium-sized HIPAA-regulated entities navigate the risk analysis requirement of the HIPAA Security Rule.

The tool guides regulated entities through the process of conducting and documenting risk analyses, the aim of which is to identify potential weaknesses and gaps in security policies and all risks and vulnerabilities to ePHI. Only by conducting a comprehensive and accurate risk analysis will HIPAA- regulated entities be able to identify all risks and vulnerabilities to ePHI. If risks and vulnerabilities remain unknown, regulated entities will not be able to take the necessary steps to reduce them to a low and acceptable level and comply with the Risk Management standard of the HIPAA Security Rule.

The SRA Tool has received many upgrades over the years to improve usability and add compliance features. The latest release –September 2026 –includes content improvements in questions, responses, and education, expanding the tool to make it more comprehensive and ensure it remains relevant in an evolving cybersecurity environment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key updates include the addition of new technologies that have been adopted by regulated entities; a new assessment-scope question to ensure that risk assessments account for every location that creates, receives, maintains, or transmits ePHI; new remote access and telework questions; modernization of the asset inventory to cover technologies that practices are now using; and an update to the system-activity logging question to reflect the varied systems used by regulated entities.  The new version also includes updated software libraries, bug fixes, and tweaks in response to feedback to make the application and Excel workbook easier to use.

OCR Actively Enforcing Risk Analysis and Risk Management Compliance

HIPAA-regulated entities have long struggled with conducting risk analyses, and 12 years after the tool was first released, OCR still frequently identifies noncompliance in this area. OCR often finds that risk analyses have never been completed, that they are incomplete or inaccurate, or that there is a lack of documentation of risk analysis processes and procedures.

Widespread noncompliance with this vital Security Rule implementation specification prompted OCR to launch a new risk analysis enforcement initiative in 2024 to encourage and improve compliance. To date, OCR has imposed 14 financial penalties under this initiative, which remains a key enforcement priority for OCR. Further, the planned update to the HIPAA Security Rule, which now has a July 2027 proposed release date, will increase the risk analysis requirements further.

The risk analysis is only the first step in the risk management process. HIPAA-regulated entities must ensure that the identified risks and vulnerabilities are managed effectively and reduced to a low and acceptable level. At the 2026 NIST/OCR conference, Safeguarding Health Information: Building Assurance through HIPAA Security 2026, OCR Director Paula Stannard explained that many regulated entities appear to be confusing risk management with the cybersecurity performance goals (CPGs) issued by OCR in January 2024.

While the CPGs can be adopted by regulated entities to improve their security posture and prevent cyberattacks and data breaches, simply implementing those measures does not satisfy the risk management requirements of the HIPAA Security Rule. The risk management standard requires specific risk management measures to be implemented to address the risks and vulnerabilities identified by the risk analysis.

OCR has confirmed that the risk analysis enforcement initiative has been expanded to cover risk management. In addition to requiring evidence showing that an accurate and comprehensive risk analysis has been conducted, OCR requires evidence that identified risks have been subjected to a HIPAA-compliant risk management process. OCR wants to ensure that regulated entities are acting on the results of their risk analyses and are taking appropriate actions to reduce risks and vulnerabilities to ePHI.

The post HHS Updates Security Risk Assessment Tool appeared first on The HIPAA Journal.

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.

Large Healthcare data breaches in the past 12 months - June 2026

The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023.

Year to date figures for large healthcare data breaches - June 2026

Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals. While June’s victim total is substantial, the victim count is down 36.3% month-over-month, and 58.7% lower than the 12-month average of 10,906,096 individuals per month. It should be noted that the 12-month average is skewed by an unusually high total for October 2025.

Individuals affected by large healthcare data breaches in the past 12 months - June 2026

The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.7% from a high of 54.4 million individuals in 2024, and down 22.1% from 2025.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Year to date figures for individuals affected by healthcare data breaches - June 2026

The Biggest Healthcare Data Breaches Reported in June 2026

In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS. The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1.4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management. The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.

The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1.25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company. A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.

A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025. Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information.

HIPAA-Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Xsolis, Inc. TN Business Associate 1,396,519 Network server hacking incident
MCBS, LLC GA Business Associate 1,261,464 Data theft and extortion incident (PEAR)
Centers Lab NJ LLC NJ Healthcare Provider 542,377 Data theft and extortion incident (Worldleaks)
Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Network server hacking incident
Operation PAR, Inc. FL Business Associate 145,714 Data theft and extortion incident (Worldleaks)
Chicago Family Health Center IL Healthcare Provider 90,000 Network server hacking incident
Aitkin County Health and Human Services MN Business Associate 83,114 Phishing incident
Minnesota Epilepsy Group, P.A. MN Healthcare Provider 80,061 Network server hacking incident
Gay & Lesbian Community Services Center of Orange County, Inc. CA Healthcare Provider 75,532 Network server hacking incident
Colorado Health Network Inc. CO Healthcare Provider 68,212 Network server hacking incident – data theft confirmed
Women’s Center for Radiology FL Healthcare Provider 66,422 Network server hacking incident
Blue Fish Pediatrics TX Healthcare Provider 62,150 Network server hacking incident
NYC Health + Hospitals NY Healthcare Provider 58,778 Hacking incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 37,384 Phishing incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 34,574 Network server hacking incident
Kentucky Mountain Health Alliance KY Healthcare Provider 30,830 Network server hacking incident – data theft confirmed
Center for Hearing and Speech dba Texas Hearing Institute TX Healthcare Provider 29,774 Ransomware attack (Interlock) – data theft confirmed
Waveny LifeCare Network, Inc. CT Healthcare Provider 27,113 Network server hacking incident
Elara Caring TX Healthcare Provider 22,172 Hacking incident at third party vendor – data theft confirmed
Minidoka Memorial Hospital ID Healthcare Provider 22,000 Data theft and extortion incident (Blackwater)
Meridian Health Plan of Illinois IL Health Plan 21,027 Employee errors – Impermissible granting certain providers access to its network
City of Middletown OH Healthcare Provider 20,608 Ransomware attack – data theft confirmed
McLeod Physician Associates II SC Healthcare Provider 19,553 Malware identified on network server awaiting decommissioning
Optalis Management Solutions MI Healthcare Provider 13,723 Network server hacking incident
All About Women’s Care CO Healthcare Provider 12,000 Hacking incident via an employee VPN account – data theft confirmed

In June, nine healthcare data breaches were reported to HHS with totals of 500 or 501 affected individuals. These totals are often used as placeholder figures when data reviews are ongoing and the 60-day reporting deadline under the HIPAA Breach Notification Rule is reached. HIPAA requires an estimate to be provided if the total number of affected individuals has yet to be determined. The data breaches in the table below may prove to be far larger than the initial breach report indicates. It may be several weeks or even months before the total number of affected individuals is confirmed.

HIPAA Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Gail J May Ltd d/b/a/ Insight Optical IL Healthcare Provider 501 Network server hacking incident at business associate
Community Health Center of Buffalo Inc. NY Healthcare Provider 501 Network server hacking incident
Cherry Street Services, Inc. MI Healthcare Provider 501 Network server hacking incident
Northeast Professional Caregivers OH Healthcare Provider 500 Email compromise
Columbia Orthopaedic Group MO Healthcare Provider 500 Network server hacking incident
Decatur Diagnostic Laboratory Inc. AL Healthcare Provider 500 Network server hacking incident
Ohio Living OH Healthcare Provider 500 Network server hacking incident
Signature Healthcare Corporation MA Healthcare Provider 500 Network server hacking incident
MVP VIP Holdco dba Heart of America Eye Care MO Healthcare Provider 500 Network server hacking incident

Causes of June 2026 Healthcare Data Breaches

Out of the 25 data breaches affecting 10,000 or more individuals, all but one was due to hacking. Across all of June’s reported data breaches, 81.8% of the breaches were hacking/IT incidents, and 1,481,468 individuals were affected by those incidents – 89.7% of all individuals affected by data breaches in June. The average breach size was 81,091 individuals, and the median breach size was 6,504 individuals.

Causes of June 2026 healthcare data breaches

The largest unauthorized access/disclosure incident of the month – Meridian Health Plan of Illinois – affected 21,027 individuals and was due to employees granting healthcare providers access to a portal for managing patient information and processing claims that should not have been given access. There were 11 unauthorized access/disclosure incidents in June, accounting for 16.7% of the month’s data breaches, and 10,914 individuals were affected – 2.7% of the month’s affected individuals. The average breach size was 10,914 individuals, and the median breach size was 6,721 individuals. One improper disposal incident was reported affecting an estimated 1,000 patients. Paper records were disposed of along with regular trash, rather than being sent for shredding. No loss or theft incidents were reported in June.

Location of Breached Protected Health Information

The bar chart below shows the locations of breached protected health information in June 2026 healthcare data breaches. Network servers were the most common location of breached protected health information, followed by email accounts and electronic health records.

Location of breached protected health information - June 2026

Data Breaches at HIPAA Regulated Entities

When a data breach occurs at a HIPAA-covered entity – healthcare provider, health plan, or healthcare clearinghouse – the HIPAA Breach Notification Rule requires them to report the breach within 60 days of discovery. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within the same time frame.

The affected covered entities are ultimately responsible for ensuring that notifications are issued to the HHS, individuals, and in some cases the media, within 60 days of being notified. A HIPAA-covered entity may delegate the notification responsibilities to the business associate. Some choose to issue notifications themselves. The raw breach data on the OCR breach portal shows data breaches based on the reporting entity, not where the data breach occurred. In June, healthcare providers reported 45 breaches, business associates reported 14 breaches, and 7 breaches were reported by health plans. The pie charts below show where the breach actually occurred rather than the reporting entity to better reflect breaches at business associates.

June 2026 data breaches at HIPAA-regulated entities

Individuals affected by June 2026 data breaches at HIPAA-regulated entities

Geographical Distribution of Healthcare Data Breaches

In June, HIPAA-regulated entities based in 24 U.S. states reported large healthcare data breaches. Florida and Texas were the worst affected states with seven reported breaches per state.

State Breaches
Florida & Texas 7
Illinois 5
Colorado, Michigan & New York 4
California, Connecticut, Minnesota, Missouri, Ohio & Tennessee 3
Idaho, Kentucky, Massachusetts, South Carolina & Washington 2
Alabama, Georgia, Indiana, Kansas, New Jersey, Oklahoma & Pennsylvania 1

While Florida and Texas ranked top for breaches, they ranked 4th and 6th in terms of the number of affected individuals. Tennessee, Georgia, and New Jersey topped the list for affected individuals, with each state only registering one large data breach.

State Individuals Affected State Individuals Affected
Tennessee 1,567,038 Michigan 24,396
Georgia 1,261,464 Idaho 22,750
New Jersey 542,377 Ohio 21,608
Florida 233,367 South Carolina 20,690
Minnesota 164,893 Washington 9,825
Texas 124,459 Missouri 3,311
Illinois 120,089 Indiana 3,070
Connecticut 99,071 Pennsylvania 2,720
Colorado 87,814 Oklahoma 1,607
California 80,783 Massachusetts 1,506
New York 74,733 Kansas 534
Kentucky 31,367 Alabama 500

HIPAA Enforcement Activity in June 2026

In June, OCR announced a single enforcement action to resolve potential violations of the HIPAA Rules by the American mall-based retailer, Spencer Gifts. Retailers are not typically HIPAA-covered entities, but Spencer Gifts is a health plan under HIPAA as it sponsors employee benefits and welfare benefit plans. Spencer Gifts was investigated after OCR received a report about a breach of the protected health information of 10,023 members of its flexible benefits and welfare benefit plans. The OCR investigation determined that Spencer Gifts failed to conduct a HIPAA-compliant risk analysis and failed to implement HIPAA Privacy, Security, and Breach Notification Rule policies and procedures. The alleged HIPAA violations were resolved with a settlement that includes a $450,000 financial penalty and a corrective action plan.

In the year to June 30, 2026, OCR resolved seven HIPAA investigations with financial penalties with penalties totaling $1,728,000. All seven of the investigations found risk analysis failures, and two involved breach notification failures. State attorneys general may also investigate data breaches and impose financial penalties for HIPAA violations, although no cases were announced in June 2026.

About this Report

The HIPAA Journal monthly data breach reports are based on data obtained from the HHS Office for Civil Rights and have been combined with breach report data from other sources. The data breaches included in this report were reported in June 2026 but occurred weeks or months previously. The figures in this report may increase or decrease as HIPAA-regulated entities complete their breach investigations, and will be reflected in our healthcare data breach statistics page and our annual HIPAA data breach reports. Further information about HIPAA enforcement actions can be found in our HIPAA violations cases page.

The post June 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Azul Vision Settles HIPAA Right of Access Case for $50,000

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve an alleged violation of the HIPAA Rules, and its 55th penalty under its HIPAA Right of Access enforcement initiative.

Azul Vision Inc. is a California-based provider of optometry and ophthalmology services. OCR launched an investigation in response to a complaint from a patient who alleged that she had not been provided with timely access to her medical records. The complaint was filed with OCR in April 2023, three months after the patient submitted a request to Azul Vision for a copy of her health information. She did not receive the requested records until January 2025 – two years after her request was submitted.

The HIPAA Privacy Rule gives patients the right to timely access to their medical records for a reasonable, cost-based fee. When a healthcare provider receives a request from a patient wishing to exercise that right, the healthcare provider has 30 days from receipt of the request to provide the requested records, although under certain circumstances, a 30-day extension is possible. OCR’s investigation determined that Azul Vision failed to take timely action in response to the request, in violation of the right of access standard of the HIPAA Privacy Rule.

Under OCR’s enforcement initiative, the HIPAA violation warranted a financial penalty. Azul Vision was given the opportunity to settle the alleged violation informally, and a $50,000 financial penalty was agreed to resolve the investigation. In addition to the financial penalty, Azul Vision has agreed to adopt a corrective action plan to address the alleged violation and ensure future compliance with the HIPAA Rules.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The corrective action plan requires Azul Vision to review and revise its policies and procedures to comply with the HIPAA Privacy Rule and ensure its workforce receives training on the HIPAA right of access and Azul Vision’s policies and procedures.  Azul Vision will be monitored for compliance with the corrective action plan and must submit reports to OCR of all right of access requests, including the date the requests were received and the completion dates.

“OCR’s 55th enforcement action in the Right of Access Initiative demonstrates the Trump Administration’s commitment to enforcing timely access to requested protected health information,” said OCR Director Paula M. Stannard. “The right of access is key to empowering individuals to take control of their own health. It should not be necessary for OCR to initiate a right of access investigation before a covered entity will provide an individual with access to their requested records.”

The post Azul Vision Settles HIPAA Right of Access Case for $50,000 appeared first on The HIPAA Journal.

Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data

The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts to track consumer product-related injuries. By the end of the year, CPSC hopes that more than 100 hospitals will provide the requested records to the Kansas-based government contractor Konza Health, which was awarded a $15.9 million contract last year to support the National Electronic Injury Surveillance System (NEISS) Remodel project.

NEISS has been in operation for more than 5 decades, and its primary purpose is to collect data on consumer product-related injuries in the United States. NEISS is an important public health research tool; however, data collection is labor-intensive and involves a manual review and coding of medical records from around 70 of the nation’s 5,000+ hospital emergency departments. Currently, 14 states do not have any participating hospitals, which limits the geographic reach of the system and has reduced CPSC’s ability to identify rare and emerging product hazards.

Under the planned NEISS Remodel (NEISS-R) project, coverage will be expanded to all 50 states to ensure data is collected from currently underrepresented and non-represented states. The plan involves automating data collection by leveraging modem technology and the country’s electronic health record infrastructure. In so doing, CPSC said it will be able to identify rare and emerging hazards much more rapidly than the legacy system allows.

NEISS-R will see data exchanged through a federally designated Qualified Health Information Network (QHIN), which CPSC claims “is supported by contractual privacy requirements and standardized security safeguards.” The data collected will be limited, as will data retention, to the minimum necessary information to support CPSC’s statutory mission, and will support de-identification before the data reaches CPSC. CPSC says the project will result in a more timely, more accurate, and more cost-effective system, which will better protect American families.

Under the current system, emergency department nurses are required to review patient charts, manually identify consumer-related accidents, and enter that information into a national database. Under the new system, data collection would be automated, and it would be the responsibility of Konza Health, a TEFCA QHIN, to strip out identifying information prior to data transfers to CPSC.

According to the letters sent by Konza Health to hospitals, “Using accident-related diagnosis codes, Konza Health will identify patients that may have experienced a consumer product-related accident. For identified accidents, Konza Health will gather additional patient clinical information and provide it to CPSC for follow-up.” The letters request meetings with the selected hospitals to establish connectivity methods to allow secure data exchange for the project.

The NEISS-R project has sparked privacy fears, as under the manual system, nurses were instructed not to provide identifiable information such as patient names, addresses, or birth dates; however, the automated system would involve sending identifiable patient data Konza Health. While it is claimed that the data provided to CPSC will be unchanged from the information it has obtained for the past five decades, far broader access to patient data is sought.

KFF Health News reports that, based on emails shared by hospitals and interviews with people involved or familiar with the discussions between the hospitals and Konza Health, the data requested falls well outside of the CPSC’s consumer product safety mission. “In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt,” explained KFF Health News. “A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information — such as names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis.” According to communications between Konza Health and technology officials at one hospital, ER data is requested for more than 10,000 conditions, including injuries totally unrelated to consumer products.

CPSC and Konza Health have faced resistance from some hospitals over the mandatory provision of the data, and have suggested that refusing to provide the required data could be viewed as information blocking, potentially leading to significant penalties; however, the information being sought raises HIPAA concerns. Under HIPAA, hospitals are permitted, but not required, to submit data to CPSC for public health purposes, but any disclosure should be limited to the minimum necessary information to achieve the purpose for the disclosure. Since CPSC is collecting data to fulfil its consumer product safety mission, any data disclosed should be limited to that purpose. Should CPSC require more data than it has previously collected, further rulemaking would be necessary.

Participating hospitals could find themselves between a rock and a hard place – potential fines for information blocking if they do not agree to provide the requested data and potential HIPAA fines if they do. However, under the current information blocking regulations, there is a privacy exception, the purpose of which is to ensure that health information is not required to be disclosed in a way that is prohibited under state or federal privacy laws, and under the HIPAA minimum necessary standard, disclosures should be restricted to information required for CPSC’s public health activities, which concern consumer product safety.

The post Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.