Please turn JavaScript on
The HIPAA Guide icon

The HIPAA Guide

Following The HIPAA Guide's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with The HIPAA Guide!

The HIPAA Guide: HIPAA Training and HIPAA News

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.17 / day

Message History

Aesto LLC, doing business as Aesto Health, a business associate that provides healthcare data management services and software to HIPAA-covered entities, has experienced a massive data breach affecting more than 9.5 million individuals. The data breach was reported to the HHS’ Office for Civil Rights in mid-August; however, it has only just been listed on the OCR breach porta...


Read full story

The HHS’ Office for Civil Rights (OCR) has announced that a settlement has been agreed with a California-based healthcare provider to resolve an alleged violation of the HIPAA right of access. Azul Vision, an optometry and ophthalmology services provider, has agreed to pay a $50,000 financial penalty to resolve the alleged Privacy Rule violation.

OCR launched a HIPAA r...


Read full story

An unknown cybercriminal actor has been targeting patients across the country with phishing attempts mimicking the electronic health record (EHR) vendor Epic Systems. Epic is the largest EHR vendor by market share, and its EHR software is used by many of the largest health systems in the United States, including for their patient portals.

The phishing campaign imperson...


Read full story

Personally identifiable health information that is created, stored, maintained, or transmitted by a HIPAA-regulated entity is subject to the HIPAA Rules. Limits are placed on uses and disclosures of that information, and safeguards must be implemented to ensure the privacy and security of that information. The same rules do not apply to health information collected by a weara...


Read full story

Cybersecurity agencies in the United States and South Korea have issued a warning about Gunra, a ransomware-as-a-service (RaaS) operation that has started targeting government and critical infrastructure entities, including healthcare organizations.

The financially motivated threat group was first identified in 2025, and in 2026, the group started running a RaaS operat...


Read full story