Search Articles

Search through our archive of curated compliance and cybersecurity news.

Found 4 results for "HIPAA"

Clear search

HHS OCR settled a HIPAA Security Rule investigation with Top of the World Ranch Treatment Center for failing to conduct adequate risk analysis following a phishing attack that compromised ePHI for 1,980 patients. The settlement marks OCR's 11th en...

My Take: Risk analysis isn't a nice-to-have document you dust off for audits—it's the thing that tells you phishing is coming and encryption matters. OCR keeps hammering this same nail because most covered entities still don't get it: if you haven't done a real risk analysis, you're just hoping nothing bad happens.

From digest: 2026-08

A cyberattack on an Ohio counseling center has exposed personal and health information of approximately 83,000 clients. As a healthcare provider, the organization is subject to HIPAA breach notification requirements and must notify affected indivi...

My Take: Mental health records are the crown jewels for attackers—far more damaging than credit cards—yet counseling centers often run on shoestring budgets with IT security to match. If you're a small healthcare provider handling sensitive data, you can't afford to treat cybersecurity as optional anymore; HHS is running out of patience with the "we're too small to be a target" excuse.

From digest: 2026-06

Hacking Wheelchairs over Bluetooth

Jan 14, 2026 Schneier on Security security incident

Researchers discovered a critical Bluetooth authentication vulnerability in WHILL wheelchairs that allows remote attackers to control device movements and override safety restrictions without credentials. CISA issued an advisory regarding this vul...

My Take: Medical device security is where compliance theater meets actual life-or-death consequences—no amount of HIPAA documentation matters if someone can remotely drive a wheelchair off a curb. If you're auditing medical IoT, stop asking for policies and start asking: "Show me how you're segmenting this thing from the network and what happens when Bluetooth auth fails."

From digest: 2026-02

Covenant Health Data Breach Impacts 478,000 Individuals

Jan 02, 2026 SecurityWeek data breach

Covenant Health, a Massachusetts-based healthcare provider, disclosed a significant data breach affecting 478,188 individuals after a ransomware attack on May 18, 2025. The breach exposed sensitive personal and health information including names, ...

My Take: Props to Covenant for not paying—refusing to fund criminal operations is the right call even when it hurts. But here's the hard truth: if Qilin got in and exfiltrated 478k records, your HIPAA "compliance" program failed at the only job that actually matters.

From digest: 2026-01