HIPAA Laws and Regulations
Advice about HIPAA laws and regulations for healthcare industry professionals
Public Health Emergency in Texas Prompts Limited Waiver of HIPAA Sanctions & Penalties
On July 8, 2025, HHS Secretary Robert F. Kennedy Jr. mentioned the declaration of a Public Health Emergency in Texas due to severe storms, flooding, and straight-line winds starting July 2, 2025. The HHS Secretary also reported a limited waiver of HIPAA sanctions and penalties for HIPAA-covered hospitals in some Texas locations under the PHE for a period. The PHE…
Court Rejects Google’s Motion to Dismiss Healthcare Tracking Technology Lawsuit
Google LLC in California is facing a lawsuit with allegations that the tech company illegally obtained personal health information (PHI) through tracking codes installed on healthcare organizations’ websites. Google filed a motion to dismiss, but the court rejected the request, and so most of the claims were permitted to move forward. Google’s tracking technology consists of Google Analytics code, tracking…
City of Oakland Settles its Class Action Data Breach Lawsuits
The City of Oakland, located in California, has decided to resolve a lawsuit due to a ransomware attack and data security breach that impacted over 13,000 present and past employees. The City discovered the attack in February 2023, and sent breach notification letters to the impacted employees at the beginning of March 2023. The Play ransomware group professed to be…
High Severity Vulnerability Identified in INFINITT PACS
INFINITT Healthcare discovered three vulnerabilities in its INFINITT PACS. There was a high-severity vulnerability with publicly accessible exploits. CISA’s alert states that a threat actor can exploit the vulnerabilities even in a low-level attack. Vulnerability CVE-2025-27721 is a high-severity vulnerability. An unauthorized user who successfully exploits the vulnerability would be able to access the system with no need for authorization…
Columbus Regional Healthcare to Pay $1,175,000 to Resolve Data Breach
Columbus Regional Healthcare has decided to pay $1,175,000 to settle litigation associated with a data breach in May 2023. The breach was discovered on May 21, 2023, and based on forensic investigation, hackers got access to areas of its system from May 19, 2023 to May 21, 2024, which included systems containing the personal data and protected health information (PHI)…
Judge Okays $7 Million Settlement with Brightline Data Breach
Virtual mental health service provider Brightline is to pay $7 million to settle a lawsuit associated with a hacking incident involving the Clop threat group in 2023 that led to the stealing of the protected health information (PHI) of about 1 million people. The Clop threat group stole data from 130 companies in January 2023 and Brightline was one of…