Court Rules

Healthcare Enforcement Actions

Privacy and consumer protection enforcement actions against healthcare companies.

792

Total Actions

$23.1B

Total Fines

TX

Purdue Pharma, Inc. and the Sackler Family

Texas Attorney General Ken Paxton announced the effective date of a $7.4 billion settlement with Purdue Pharma, Inc. and the Sackler family over their role in fueling the opioid crisis. Texas will receive $286.5 million from the settlement, bringing the state’s total opioid recovery funds to over $3 billion. The settlement includes permanent bans on Sackler opioid sales in the U.S., public release of 30 million company documents, and distribution of funds for addiction treatment and prevention over 15 years.

$7.4B

CT

Purdue Pharma

Connecticut Attorney General William Tong announced that Purdue Pharma will dissolve as the company’s bankruptcy concludes and a $7.4 billion settlement with Purdue and the Sackler family takes effect. The settlement permanently bars the Sacklers from selling opioids in the U.S., directs funds to addiction treatment and prevention, and requires the release of over 30 million documents related to Purdue’s opioid business. Connecticut is expected to receive $64 million from the settlement, with first payments anticipated in fall 2026.

$7.4B

NY

Purdue Pharma

New York Attorney General Letitia James announced the shutdown of opioid manufacturer Purdue Pharma as part of a $7.4 billion settlement with a bipartisan coalition of 54 other state attorneys general. The Sackler family, former owners of Purdue, are permanently barred from selling opioids in the U.S. and have no involvement in Knoa Pharma, the new public benefit corporation replacing Purdue. Purdue was sentenced on criminal charges related to its role in the opioid crisis on April 28, 2026, with the new entity operating under strict oversight and excess revenue funding opioid abatement efforts.

$7.4B

VA

Virginia Attorney General Jay Jones joined a bipartisan coalition of 44 state attorneys general in submitting a comment letter supporting a proposed U.S. Department of Labor rule to increase transparency requirements for pharmacy benefit managers (PBMs) servicing employer-funded ERISA health plans. The coalition urged the DOL to clarify that the proposed rule does not preempt existing state PBM transparency laws and to coordinate enforcement with state attorneys general. This action is a policy advocacy comment letter and does not constitute an enforcement action against any specific entity.

FTC

Vanilla Chip LLC

The FTC alleged that Vanilla Chip LLC (d/b/a TruHeight) deceptively advertised height-enhancing supplements for children and teens without competent scientific evidence, and used fake employee-written and incentivized 5-star reviews. The proposed settlement requires TruHeight and its principals to pay $750,000, bars false health claims, and prohibits misleading review practices. A $4 million total judgment is partially suspended due to the respondents' inability to pay the full amount.

$750K

HHS

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Manhattan Retirement Foundation d/b/a Meadowlark Hills

Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

Data BreachHealth DataSecurity Failure
HHS

Weill Cornell Medicine

Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

Data BreachHealth DataUnauthorized Data Sharing
HHS

QualDerm Partners, LLC

QualDerm Partners, LLC (Healthcare Provider, TN) reported a HIPAA breach affecting 3,117,874 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

The Center for Advanced Eye Care

The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

Data BreachHealth DataSecurity Failure
HHS

Option Care Health, Inc.

Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
CT

23andMe

Connecticut Attorney General William Tong submitted testimony in support of genetic privacy legislation that would grant residents exclusive control over their DNA and genetic data. The legislation is inspired by his office's investigation into 23andMe's data breach affecting over six million customers and the company's subsequent bankruptcy. The bill requires express consent for DNA use, imposes security measures, and prohibits marketing use of DNA.

Data BreachBiometric Data
HHS

VNS Behavioral Health Inc. (“VNS Health”)

VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

Emanuel Medical Center

Emanuel Medical Center (Healthcare Provider, GA) reported a HIPAA breach affecting 28,963 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

44North

44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

Data BreachHealth DataSecurity Failure
HHS

Easterseals Northeast Indiana

Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Wee Care Pediatrics, LLC

Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

National Association on Drug Abuse Problems

National Association on Drug Abuse Problems (Healthcare Provider, NY) reported a HIPAA breach affecting 90,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Cedar Valley Services

Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Academic Urology & Urogynecology of Arizona

Academic Urology & Urogynecology of Arizona (Healthcare Provider, AZ) reported a HIPAA breach affecting 73,281 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Resource Corporation of America

Resource Corporation of America (Business Associate, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Communications Workers of America Local 1180 Security Benefits Fund

Communications Workers of America Local 1180 Security Benefits Fund (Health Plan, NY) reported a HIPAA breach affecting 18,550 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Other.

Data BreachHealth DataUnauthorized Data Sharing
HHS

VPS Medical PLLC

VPS Medical PLLC (Healthcare Provider, PA) reported a HIPAA breach affecting 4,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Cedar Point Health, LLC

Cedar Point Health, LLC (Healthcare Provider, CO) reported a HIPAA breach affecting 23,114 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

University Spine Center

University Spine Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 582 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

Data BreachHealth DataSecurity Failure
HHS

Alexes Hazen MD, PLLC

Alexes Hazen MD, PLLC (Healthcare Provider, NY) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email, Network Server.

Data BreachHealth DataSecurity Failure
HHS

First Choice Community Home Care, Inc.

First Choice Community Home Care, Inc. (Healthcare Provider, TX) reported a HIPAA breach affecting 725 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

BlueCross BlueShield of Tennessee, Inc.

BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 1,670 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

ApolloMD Business Services, LLC

ApolloMD Business Services, LLC (Business Associate, GA) reported a HIPAA breach affecting 626,540 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Five Star Home Health, Inc.

Five Star Home Health, Inc. (Healthcare Provider, OK) reported a HIPAA breach affecting 1,575 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Houston Health Department

Houston Health Department (Healthcare Provider, TX) reported a HIPAA breach affecting 7,445 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Carolina Foot & Ankle Associates

Carolina Foot & Ankle Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Wendy Foster OD

Wendy Foster OD (Healthcare Provider, KS) reported a HIPAA breach affecting 20,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Counseling Center of Wayne & Holmes Counties

Counseling Center of Wayne & Holmes Counties (Healthcare Provider, OH) reported a HIPAA breach affecting 83,354 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Adapt Integrated Health Care

Adapt Integrated Health Care (Healthcare Provider, OR) reported a HIPAA breach affecting 2,908 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Marin Cancer Care

Marin Cancer Care (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

EDGAR A MARTORELL MD LLC

EDGAR A MARTORELL MD LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 1,107 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Cottage Hospital

Cottage Hospital (Healthcare Provider, NH) reported a HIPAA breach affecting 1,005 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

TriZetto Provider Solutions

TriZetto Provider Solutions (Business Associate, MO) reported a HIPAA breach affecting 3,433,965 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Apex Spine & Neurosurgery, LLC

Apex Spine & Neurosurgery, LLC (Healthcare Provider, GA) reported a HIPAA breach affecting 2,500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Triad Radiology Associates

Triad Radiology Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 11,011 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

WIRX Pharmacy

WIRX Pharmacy (Healthcare Provider, PA) reported a HIPAA breach affecting 20,047 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Issaqueena Pediatric Dentistry PA

Issaqueena Pediatric Dentistry PA (Healthcare Provider, SC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Personalis, Inc.

Personalis, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 650 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
FTC

Express Scripts, Inc.

Antitrust enforcement action where the FTC settled with Express Scripts, a major pharmacy benefit manager, for using anticompetitive rebating practices that artificially inflated insulin prices. The settlement requires ESI to change its business practices to increase transparency and lower patient out-of-pocket costs, potentially saving $7 billion over 10 years.

HHS

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates.

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates. (Healthcare Provider, MO) reported a HIPAA breach affecting 17,110 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
NJ

Novartis AG, Sandoz AG, Sandoz Group AG

New Jersey Acting Attorney General Jennifer Davenport, alongside 42 states and territories, filed a multistate complaint against Novartis AG and its subsidiaries Sandoz AG and Sandoz Group AG alleging a conspiracy to fix prices, allocate markets, and rig bids for 31 generic drugs, inflating costs for consumers and public healthcare programs. The complaint also alleges Novartis fraudulently spun off Sandoz to shield itself from liability for prior antitrust violations. This action builds on evidence from three previous multistate generic drug price-fixing complaints.

HHS

Pafford Medical Services

Pafford Medical Services (Healthcare Provider, AR) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Mindoula Health, Inc.

Mindoula Health, Inc. (Business Associate, MD) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
CT

Lannett Company, Inc., Bausch Health US, LLC, Bausch Health Americas, Inc.

Connecticut Attorney General William Tong led a coalition of 48 states and territories in announcing settlements with Lannett Company, Inc. and Bausch Health entities totaling $17.85 million. The settlements resolve allegations that the companies engaged in conspiracies to inflate prices and limit competition for generic prescription drugs. The companies agreed to cooperate in ongoing litigation and implement internal reforms, while a new complaint was filed against Novartis and subsidiaries.

$17.9M

HHS

Lincoln National Corporation d/b/a/ Lincoln Financial

Lincoln National Corporation d/b/a/ Lincoln Financial (Health Plan, IN) reported a HIPAA breach affecting 998 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Health and Hospital Corporation of Marion County

Health and Hospital Corporation of Marion County (Healthcare Provider, IN) reported a HIPAA breach affecting 792 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email, Laptop.

Data BreachHealth DataUnauthorized Data Sharing
HHS

BAYADA Home Health Care, Inc.

BAYADA Home Health Care, Inc. (Healthcare Provider, NJ) reported a HIPAA breach affecting 9,526 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Wakefield & Associates, LLC

Wakefield & Associates, LLC (Business Associate, TN) reported a HIPAA breach affecting 31,751 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
CT

Comstar, LLC

Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.

Data BreachSecurity FailureHealth Data

$515K

HHS

Clinic Service Corporation

Clinic Service Corporation (Business Associate, CO) reported a HIPAA breach affecting 82,331 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
MA

Comstar, LLC

Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.

Data BreachHealth DataSecurity Failure

$515K

HHS

WindRose Health Network

WindRose Health Network (Healthcare Provider, IN) reported a HIPAA breach affecting 691 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Pecan Tree Dental, PLLC

Pecan Tree Dental, PLLC (Healthcare Provider, TX) reported a HIPAA breach affecting 13,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
FTC

Top Healthcare Options Insurance Agency Inc

Telemarketing enforcement case where the FTC obtained a temporary restraining order against defendants who deceptively marketed limited benefit health plans as comprehensive health insurance. The scheme caused tens of millions of dollars in harm to consumers seeking health coverage. The court halted operations at the FTC's request.

HHS

Precipio, Inc.

Precipio, Inc. (Healthcare Provider, CT) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Jefferson-Blount-St. Clair Mental Health Authority

Jefferson-Blount-St. Clair Mental Health Authority (Healthcare Provider, AL) reported a HIPAA breach affecting 30,434 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

True RCM, a Rapid Care Transcription, Inc., Company

True RCM, a Rapid Care Transcription, Inc., Company (Business Associate, MD) reported a HIPAA breach affecting 1,247 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

Data BreachHealth DataSecurity Failure
HHS

AdventHealth Daytona Beach

AdventHealth Daytona Beach (Healthcare Provider, FL) reported a HIPAA breach affecting 821 individuals. Breach type: Loss. Location of breached information: Paper/Films.

Data BreachHealth Data
HHS

Middlesex Sheriff's Office

Middlesex Sheriff's Office (Healthcare Provider, MA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Benton County Health

Benton County Health (Healthcare Provider, OR) reported a HIPAA breach affecting 1,476 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Minnesota Department of Human Services

Minnesota Department of Human Services (Health Plan, MN) reported a HIPAA breach affecting 303,965 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Central Texas MHMR Center dba Center for Life Resource

Central Texas MHMR Center dba Center for Life Resource (Healthcare Provider, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Superior Care Plus LLC d/b/a Supportive Home Health LLC

Superior Care Plus LLC d/b/a Supportive Home Health LLC (Healthcare Provider, OH) reported a HIPAA breach affecting 1,415 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

360 Dental PC

360 Dental PC (Healthcare Provider, PA) reported a HIPAA breach affecting 11,273 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Administrators of the Tulane Educational Fund d/b/a Tulane University Medical Group

Administrators of the Tulane Educational Fund d/b/a Tulane University Medical Group (Healthcare Provider, LA) reported a HIPAA breach affecting 6,556 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

Southern Immediate Care, LLC

Southern Immediate Care, LLC (Healthcare Provider, AL) reported a HIPAA breach affecting 7,447 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

Florence County Commission on Alcohol & Drug Abuse – dba Circle Park Behavioral Health Services (“Circle Park”)

Florence County Commission on Alcohol & Drug Abuse – dba Circle Park Behavioral Health Services (“Circle Park”) (Healthcare Provider, SC) reported a HIPAA breach affecting 7,020 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

TMG Health, Inc.

TMG Health, Inc. (Business Associate, TX) reported a HIPAA breach affecting 2,076 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

Data BreachHealth DataUnauthorized Data Sharing
HHS

FullBeauty Brands, Inc. Associate Benefits Plan

FullBeauty Brands, Inc. Associate Benefits Plan (Health Plan, NY) reported a HIPAA breach affecting 4,725 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Avosina Healthcare Solutions

Avosina Healthcare Solutions (Business Associate, VA) reported a HIPAA breach affecting 44,425 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Central Ozarks Medical Center

Central Ozarks Medical Center (Healthcare Provider, MO) reported a HIPAA breach affecting 11,818 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

The Center for Neuropsychology and Learning, PC

The Center for Neuropsychology and Learning, PC (Healthcare Provider, MI) reported a HIPAA breach affecting 3,722 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Illinois Department of Human Services

Illinois Department of Human Services (Health Plan, IL) reported a HIPAA breach affecting 705,017 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

Data BreachHealth DataUnauthorized Data Sharing
HHS

ABKSW PREFERRED HEALTH PARTNERS, PLLC d/b/a NORTH TEXAS PREFERRED HEALTH PARTNERS

ABKSW PREFERRED HEALTH PARTNERS, PLLC d/b/a NORTH TEXAS PREFERRED HEALTH PARTNERS (Healthcare Provider, TX) reported a HIPAA breach affecting 2,074 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Devereux Foundation

Devereux Foundation (Healthcare Provider, PA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
OR

Novo Nordisk, Sanofi, Eli Lilly, Express Scripts, CVS Caremark, Optum

Consumer protection case: Oregon Attorney General filed a lawsuit against six major drug companies and pharmacy benefit managers for allegedly coordinating to inflate insulin prices, seeking $900 million in damages under the Unlawful Trade Practices Act.

Security Failure

$900.0M

HHS

Pit River Health Service Inc.

Pit River Health Service Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 1,800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Methodist Homes of Alabama and Northwest Florida

Methodist Homes of Alabama and Northwest Florida (Healthcare Provider, AL) reported a HIPAA breach affecting 1,406 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

Mid Michigan Medical Billing Service, Inc.

Mid Michigan Medical Billing Service, Inc. (Business Associate, MI) reported a HIPAA breach affecting 28,185 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Andover Eye Associates

Andover Eye Associates (Healthcare Provider, MA) reported a HIPAA breach affecting 1,638 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

Steel Encounters, Inc.

Steel Encounters, Inc. (Healthcare Provider, UT) reported a HIPAA breach affecting 959 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Advanced Healthcare Professionals

Advanced Healthcare Professionals (Healthcare Provider, TX) reported a HIPAA breach affecting 800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
CT

Hartford Healthcare

The Connecticut Attorney General reached an agreement with Hartford Healthcare to address antitrust concerns in the acquisition of Manchester Memorial and Rockville General hospitals from Prospect Medical. The agreement includes conditions to limit cost increases, waive physician non-compete clauses, and maintain medical staff privileges to protect competition and physician mobility. This resolves the antitrust review under the state's notice of material change statute.

HHS

Associated Radiologists of the Finger Lakes, P.C.

Associated Radiologists of the Finger Lakes, P.C. (Business Associate, NY) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Exact Sciences Laboratories LLC

Exact Sciences Laboratories LLC (Healthcare Provider, WI) reported a HIPAA breach affecting 2,658 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Docs Medical Group, Inc. dba Pulse Urgent Care

Docs Medical Group, Inc. dba Pulse Urgent Care (Healthcare Provider, CA) reported a HIPAA breach affecting 4,035 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

CareOregon

CareOregon (Health Plan, OR) reported a HIPAA breach affecting 5,473 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

Data BreachHealth DataUnauthorized Data Sharing
NY

OrthopedicsNY, LLP

New York Attorney General Letitia James secured a $500,000 settlement with orthopedics practice OrthopedicsNY, LLP for failing to implement adequate data security measures, leading to a 2023 cyberattack that exposed personal and health information of approximately 656,000 patients and employees. The settlement requires OrthopedicsNY to pay the penalty, fund one year of free credit monitoring for affected individuals, and adopt enhanced data security practices including multifactor authentication, encryption, and annual risk assessments.

Data BreachSecurity FailureHealth Data

$500K

HHS

BlueCross BlueShield of Tennessee, Inc.

BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 780 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Glendale Obstetrics & Gynecology PCA

Glendale Obstetrics & Gynecology PCA (Healthcare Provider, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
OR

U.S. Department of Health and Human Services (HHS)

Health and civil rights enforcement action. Oregon Attorney General Dan Rayfield led a coalition of 19 states and the District of Columbia in filing a lawsuit against the U.S. Department of Health and Human Services (HHS). The suit challenges a December 18, 2025 HHS 'declaration' that claims certain gender-affirming care is 'unsafe and ineffective' and threatens to exclude providers from Medicare/Medicaid for offering such care. The attorneys general argue HHS violated federal administrative law by implementing a major policy change without required notice-and-comment rulemaking, creating fear for patients and providers and threatening state Medicaid programs.