HIPAA authorization requires more than a cookie banner – Yahoo
HIPAA authorization requires more than a cookie banner – Tahlequah Daily Press
Security Standards Required for Custom EHR Development – FINE Homes and Living
Clym Adds HIPAA Authorization to Its Consent Management Platform – markets.businessinsider.com
March 1, 2026: Small Healthcare Data Breach HIPAA Reporting Deadline – The HIPAA Journal
March 1, 2026: Small Healthcare Data Breach HIPAA Reporting Deadline
Healthcare data breaches discovered in calendar year 2025 that affected fewer than 500 individuals must be reported to the HHS’ Office for Civil Rights by March 1, 2026.
The HIPAA Breach Notification Rule requires data breaches affecting 500 or more individuals to be reported to OCR within 60 days of the discovery of a data breach. Individuals must also be notified within 60 days, and a notice must be submitted to prominent media outlets where the affected individuals are located if 500 or more individuals are affected in a state or jurisdiction.
The breach notification requirements for small breaches are different. The affected individuals must still be notified within 60 days of the discovery of a data breach; however, a media notice is not required. OCR must still be notified about small healthcare data breaches, but HIPAA-regulated entities can delay submitting notifications to OCR. All small healthcare data breaches must be reported to OCR within 60 days of the end of the calendar year when the breach was discovered.
Each small data breach must be reported separately via the OCR data breach portal. HIPAA-regulated entities should not leave uploading data breach reports until the last minute, in case of any technical issues with the data breach portal. Late reporting of breaches puts HIPAA-regulated entities at risk of a financial penalty, and OCR could opt to conduct a compliance investigation to determine if there is broader noncompliance with the HIPAA Rules.
Financial penalties for breach notification failures have been relatively rare since the HIPAA Enforcement Rule was enacted; however, in 2025, noncompliance with the HIPAA Breach Notification Rule was the second most common reason for financial penalty after risk analysis failures. Last year, OCR closed 21 HIPAA cases with settlements or civil monetary penalties, 5 of which included penalties for breach notification failures.
The post March 1, 2026: Small Healthcare Data Breach HIPAA Reporting Deadline appeared first on The HIPAA Journal.
Academic Urology & Urogynecology of Arizona Data Breach Affects 73K Patients – The HIPAA Journal
Academic Urology & Urogynecology of Arizona Data Breach Affects 73K Patients
Academic Urology & Urogynecology of Arizona, a division of Palo Verde Hematology and Oncology that serves patients throughout Arizona, has announced a significant data breach, potentially affecting 73,281 current and former patients.
Unauthorized access to its computer network was detected on or around May 22, 2025. Steps were taken to secure its network to prevent further unauthorized access, and third-party cybersecurity experts were engaged to conduct a forensic investigation. On January 30, 2026, it was confirmed that there had been unauthorized access to its network between May 18, 2025, and May 22, 2025, during which time, files containing patient data may have been viewed or acquired.
The data involved varies from individual to individual and may include some or all of the following: full names, dates of birth, Social Security numbers, account numbers, account types, routing numbers, medical record numbers, mental or physical conditions, diagnoses/diagnosis codes, treatment locations, procedure types, provider names, dates of service, other medical benefits/entitlements, prescription information, health insurance group numbers, health insurance claim numbers, subscriber member numbers, patient account numbers and patient identification numbers.
Notification letters were mailed to the affected individuals on or around February 12, 2026. At the time of issuing notifications, no evidence had been found to indicate misuse of patient data. As a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.
Livingston HealthCare, Montana
Livingston HealthCare in Livingston, Montana, has warned patients about a recent cybersecurity incident that may have resulted in unauthorized access to patient data. Livingston HealthCare, which operates a critical access hospital serving the greater Park County area, announced on February 13, 2026, that it was experiencing disruption to its phone systems and network due to a suspected cybersecurity incident.
Certain systems were taken offline while the incident was assessed, and it is working to restore the affected systems and will bring them back online when it is safe to do so. The phone system has been restored, and while network services are still limited, care continues to be provided to patients uninterrupted. At this stage of the investigation, it is not possible to determine the extent to which patient data has been compromised. Livingston HealthCare said it will continue to provide updates on the incident, recovery, and any data breach via its website.
Livingston HealthCare said it has learned of advertisements and communications suggesting patients could be entitled to compensation as a result of the incident. Patients have been warned not to disclose any sensitive information, such as Social Security numbers, banking information, or other confidential details, unless they are certain of the recipient’s identity and legitimacy.
The post Academic Urology & Urogynecology of Arizona Data Breach Affects 73K Patients appeared first on The HIPAA Journal.