Compliance News

Compliance News & Updates

Daily AI-analyzed compliance news covering HIPAA breaches, GDPR fines, PCI DSS updates, SOC 2 changes, and regulatory developments across every major framework.

Critical Security Alert: Check Point VPN and Google Chrome Vulnerabilities Under Active Exploitation

Cybersecurity researchers have identified critical vulnerabilities in Check Point VPN solutions and Google Chrome that are currently being actively exploited by threat actors. Healthcare organizations and other HIPAA-covered entities using these technologies face immediate risks of data breaches and compliance violations, requiring urgent patching and remediation efforts.

HIPAA
NIST CSF
Google NewsJun 9, 2026

Sports Bar Server Confronts Customer's HIPAA Misconception in Viral Social Media Exchange

A sports bar server recently defended herself against a customer's incorrect accusation of a HIPAA violation, highlighting widespread public misunderstanding of healthcare privacy laws. The incident demonstrates how HIPAA protections only apply to covered entities like healthcare providers, not general service establishments.

HIPAA
Google NewsJun 8, 2026

Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach

A cybercriminal group has claimed responsibility for a massive data breach at DentaQuest, potentially exposing millions of patient records containing protected health information. The incident represents one of the largest healthcare data breaches of 2026, raising significant HIPAA compliance concerns for the dental insurance provider.

HIPAA
NIST CSF
Google NewsJun 5, 2026

Onsite Women's Health Settles $2.5 Million HIPAA Data Breach Case

Onsite Women's Health has agreed to pay $2.5 million to settle HIPAA violations related to a data breach that compromised patient health information. The settlement highlights critical gaps in healthcare data protection and the importance of proper HIPAA compliance programs for medical providers.

HIPAA
Google NewsJun 4, 2026

Medical Billing Company Data Breach Compromises Patient Information Across Seven Healthcare Groups

A medical billing company has reported a data breach that has affected seven separate medical groups, potentially compromising protected health information (PHI) of numerous patients. The incident highlights critical HIPAA compliance challenges when healthcare organizations rely on third-party business associates for billing services.

HIPAA
Google NewsJun 1, 2026

Healthcare Organizations Express Low Confidence in AI-Powered Identity Breach Defense Capabilities

A new study reveals that healthcare organizations lack confidence in their ability to defend against AI-incited identity breaches, highlighting critical gaps in cybersecurity preparedness. This finding raises significant concerns about HIPAA compliance and patient data protection as AI-powered attack vectors become increasingly sophisticated.

HIPAA
Google NewsMay 28, 2026

Medicover Genetics Cyprus Achieves ISO 27001 Certification, Setting New Standards for Healthcare Information Security

Medicover Genetics Cyprus has successfully obtained ISO 27001 certification, demonstrating its commitment to robust information security management in the sensitive field of genetic testing and healthcare data protection. This achievement positions the company as a leader in healthcare compliance and data security within the Cyprus medical sector.

ISO 27001
GDPR
HIPAA
Google NewsMay 27, 2026

OCR Submits Annual HIPAA Compliance and Data Breach Report to Congress for 2024

The Office for Civil Rights (OCR) has delivered its annual report to Congress detailing HIPAA compliance enforcement activities and healthcare data breach statistics for 2024. The report provides critical insights into enforcement trends, penalty amounts, and the evolving threat landscape affecting covered entities and business associates across the healthcare industry.

HIPAA
Google NewsMay 26, 2026

Best Buy Customer Discovers Patient Medical Records Instead of iPad Mini in Shocking HIPAA Breach

A Los Angeles customer who ordered an iPad Mini from Best Buy instead received a package containing sensitive patient medical records, creating a potential HIPAA violation. This incident highlights critical gaps in retail supply chain security and the risks of improper handling of protected health information in commercial environments.

HIPAA
Google NewsMay 24, 2026

May 2026 HIPAA Data Breach Roundup: Nine Healthcare Organizations Compromised

Nine HIPAA-regulated healthcare entities experienced significant data breaches in May 2026, potentially exposing protected health information of thousands of patients. These incidents highlight ongoing cybersecurity vulnerabilities in the healthcare sector and underscore the critical need for robust data protection measures. Healthcare organizations face potential regulatory penalties and must implement immediate remediation steps to comply with HIPAA breach notification requirements.

HIPAA
Google NewsMay 22, 2026

HHS Announces Major Restructuring of Office for Civil Rights: What Healthcare Organizations Need to Know

The U.S. Department of Health and Human Services (HHS) has announced a significant restructuring of its Office for Civil Rights (OCR), the primary enforcement body for HIPAA regulations. This organizational change will impact how healthcare entities interact with federal privacy and security oversight, potentially affecting enforcement priorities and compliance procedures for covered entities and business associates nationwide.

HIPAA
Google NewsMay 20, 2026

Esse Health Pays $2.53 Million to Settle Major HIPAA Data Breach Lawsuit

Esse Health has agreed to pay $2.53 million to settle a class-action lawsuit stemming from a significant data breach that compromised protected health information. The settlement highlights the ongoing financial and legal risks healthcare organizations face when HIPAA compliance failures lead to patient data exposure.

HIPAA
Google NewsMay 15, 2026

Atrium Health and Interim HealthCare Hit by Business Associate Data Breaches

Two prominent healthcare organizations, Atrium Health and Interim HealthCare, have been affected by data breaches involving their business associates. These incidents highlight critical vulnerabilities in third-party vendor relationships and underscore the importance of robust business associate agreements under HIPAA compliance frameworks.

HIPAA
Google NewsMay 14, 2026

Tech Exactly Launches HIPAA Compliance Service to Support Healthcare Startups

Tech Exactly has launched a specialized service designed to help healthcare startups achieve HIPAA compliance from the ground up. The new offering addresses the growing need for streamlined compliance solutions as digital health companies face increasing regulatory scrutiny and data protection requirements.

HIPAA
Google NewsMay 13, 2026

Gandara Mental Health Center Settles Class Action Data Breach Lawsuit

Gandara Mental Health Center has reached a settlement in a class action lawsuit stemming from a data breach that exposed protected health information of patients. The settlement highlights ongoing challenges healthcare organizations face in maintaining HIPAA compliance and protecting sensitive mental health records from cybersecurity threats.

HIPAA
Google NewsMay 13, 2026

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2023

The Office for Civil Rights (OCR) has submitted its annual report to Congress detailing HIPAA compliance activities and healthcare data breach statistics for 2023. The report provides comprehensive insights into breach trends, enforcement actions, and compliance challenges facing covered entities and business associates.

HIPAA
Google NewsMay 12, 2026

March 2026 Healthcare Data Breach Report Shows Alarming HIPAA Compliance Failures

The HIPAA Journal's March 2026 healthcare data breach report documents multiple significant security incidents affecting healthcare organizations nationwide. These breaches exposed thousands of patient records and highlight ongoing challenges in healthcare cybersecurity and HIPAA compliance.

HIPAA
Google NewsMay 11, 2026

Tenovi Achieves SOC 2 Type 2 Compliance for Remote Patient Monitoring Platform

Tenovi, a remote patient monitoring company, has successfully achieved SOC 2 Type 2 compliance, demonstrating the effectiveness of their security controls over time. This certification validates Tenovi's commitment to protecting patient health data and maintaining robust cybersecurity practices in their healthcare technology platform.

SOC 2
HIPAA
Google NewsMay 7, 2026

RXNT Healthcare Technology Breach: Critical HIPAA Compliance Analysis

RXNT, a healthcare technology company providing EHR and practice management solutions, has notified customers about a cybersecurity incident resulting in a data breach. The incident potentially affects protected health information (PHI) of patients across multiple healthcare practices that use RXNT's cloud-based platform.

HIPAA
Google NewsMay 6, 2026

South Texas Oncology and Hematology Settles Data Breach Lawsuit for $1.1 Million

South Texas Oncology and Hematology has agreed to pay $1.1 million to settle a data breach lawsuit involving patient health information. The settlement highlights ongoing HIPAA compliance challenges for healthcare organizations and the significant financial consequences of inadequate data protection measures.

HIPAA
Google NewsApr 27, 2026

Federal Court Dismisses HIPAA-Related Wrongful Termination Claim Against UC Health

A federal court has rejected a wrongful termination lawsuit filed against UC Health by an employee who reported HIPAA violations. The dismissal establishes important precedent for healthcare organizations facing retaliation claims from employees who report privacy violations.

HIPAA
Google NewsApr 27, 2026

Multiple Healthcare Data Breaches Expose Patient Information: HIPAA Compliance Under Scrutiny

Mindpath Health, Springfield Hospital, and Lone Peak Psychiatry have announced separate data breaches compromising patient protected health information (PHI). These incidents highlight ongoing cybersecurity challenges in healthcare and trigger mandatory HIPAA breach notification requirements for affected organizations.

HIPAA
Google NewsApr 21, 2026

Chattanooga Heart Institute Pays $3.75 Million to Settle Major HIPAA Data Breach Lawsuit

Chattanooga Heart Institute has agreed to pay $3.75 million to resolve a class-action lawsuit stemming from a significant data breach that exposed protected health information. The settlement highlights the substantial financial consequences healthcare organizations face when HIPAA compliance failures lead to patient data exposure.

HIPAA
Google NewsApr 17, 2026

HIPAA Violations in Plastic Surgery: When Patient Photos Are Posted Without Consent

Plastic surgeons who post patient photos without proper authorization face serious HIPAA violations and potential legal consequences. Patients have specific rights regarding their medical images, and healthcare providers must obtain explicit written consent before using photos for marketing or educational purposes.

HIPAA
Google NewsApr 15, 2026

PCI Pal Secures Triple Compliance Win with HIPAA, HITRUST, and SOC 2 Type II Certifications

PCI Pal has achieved HIPAA, HITRUST, and SOC 2 Type II compliance certifications as part of its strategic expansion into the US enterprise market. These certifications position the company to serve healthcare organizations and other regulated industries requiring stringent data protection standards.

HIPAA
SOC 2
Google NewsApr 14, 2026

2025 Cybercrime Losses Exceed $20 Billion: Critical HIPAA Compliance Implications

Cybercrime losses in 2025 exceeded $20 billion according to The HIPAA Journal, with healthcare organizations among the most targeted sectors. Healthcare entities face heightened risks of HIPAA violations and must strengthen cybersecurity measures to protect protected health information (PHI) from increasingly sophisticated attacks.

HIPAA
NIST CSF
Google NewsApr 8, 2026

Cyberattack Forces Ambulance Diversions from Brockton Hospital as Signature Healthcare Battles Security Incident

Signature Healthcare is experiencing a cyberattack that has forced ambulance diversions from Brockton Hospital, disrupting critical emergency services. The incident highlights vulnerabilities in healthcare IT systems and potential HIPAA compliance implications as the organization works to restore normal operations.

HIPAA
NIST CSF
Google NewsApr 8, 2026

Healthcare Software Company Reports Major EHR Data Breach: HIPAA Compliance Analysis

A healthcare software company has announced a significant security breach of its electronic health record (EHR) environment, potentially exposing protected health information (PHI) of numerous patients. The incident highlights critical vulnerabilities in healthcare IT infrastructure and triggers mandatory HIPAA breach notification requirements for affected covered entities and business associates.

HIPAA
Google NewsMar 30, 2026

Lawsuit Challenges CDPAP Outsourcing Plan Over HIPAA Compliance Violations

A lawsuit has been filed to block the outsourcing of Consumer Directed Personal Assistance Program (CDPAP) services, citing potential HIPAA violations and patient privacy concerns. The legal challenge raises critical questions about healthcare data protection when outsourcing sensitive patient care services to third-party vendors.

HIPAA
Google NewsMar 27, 2026

Six Healthcare Organizations Report Data Breaches Affecting Patient Information

Six healthcare organizations have recently reported data breaches involving protected health information to federal authorities, highlighting ongoing cybersecurity challenges in the healthcare sector. These incidents underscore the critical importance of robust data protection measures and HIPAA compliance in healthcare organizations.

HIPAA
Google NewsMar 27, 2026

Excelsior Orthopaedics and Buffalo Surgery Center Pay $2.4 Million to Settle Major Data Breach Lawsuit

Excelsior Orthopaedics and Buffalo Surgery Center have agreed to pay $2.4 million to settle a class-action lawsuit stemming from a significant data breach. The settlement addresses claims related to HIPAA violations and inadequate protection of patient health information.

HIPAA
Google NewsMar 27, 2026

Split NLRB Decision Favors Hospital in High-Profile Union Leader Termination Case

The National Labor Relations Board issued a split decision supporting a hospital's termination of a union leader, marking a significant ruling in healthcare labor relations. The case establishes important precedent for how hospitals can address union leadership conduct while maintaining compliance with federal labor laws and healthcare regulations.

HIPAA
Google NewsMar 27, 2026

Deaconess Health System Reports Patient Data Compromise in Vendor Security Breach

Deaconess Health System has disclosed that patient health information was compromised through a third-party vendor data breach. The incident highlights critical HIPAA compliance challenges when healthcare organizations rely on external service providers for data processing and storage.

HIPAA
Google NewsMar 25, 2026

OpenLoop Health Discloses HIPAA Data Breach Affecting Telehealth Platform

OpenLoop Health, a telehealth platform provider, has disclosed a data breach potentially exposing protected health information (PHI) of patients. The incident represents another significant HIPAA security breach in the healthcare technology sector, highlighting ongoing cybersecurity challenges facing telehealth providers.

HIPAA
Google NewsMar 24, 2026

CMS Issues Final Rule on HIPAA Standards for Health Care Claims Attachments

The Centers for Medicare & Medicaid Services (CMS) has released a final rule establishing HIPAA standards for health care claims attachments, affecting healthcare providers, payers, and clearinghouses. This rule standardizes the electronic submission of supporting documentation for medical claims, requiring covered entities to implement new technical and administrative safeguards for protected health information in claims processing.

HIPAA
Google NewsMar 24, 2026

The HIPAA Journal Announces Free Email Security Webinar on PHI Protection and Encryption Requirements

The HIPAA Journal is hosting a free webinar titled 'HIPAA Email Security 101' focusing on Protected Health Information (PHI) handling, encryption requirements, and compliance obligations for healthcare organizations. The educational session addresses critical email security practices required under HIPAA regulations.

HIPAA
Google NewsMar 18, 2026

Iran-Linked Hackers Wipe Data from U.S. Medical Device Manufacturer in Major HIPAA Security Incident

An Iran-linked hacking group successfully infiltrated and wiped data from a U.S. medical device manufacturer, raising serious HIPAA compliance concerns for the healthcare industry. The cyberattack demonstrates the growing threat posed by nation-state actors targeting healthcare infrastructure and protected health information (PHI).

HIPAA
NIST CSF
Google NewsMar 12, 2026

Senate Advances Bipartisan Health Care Cybersecurity Reform Legislation

The U.S. Senate has advanced bipartisan legislation aimed at strengthening cybersecurity requirements for healthcare organizations. The reform bill addresses vulnerabilities in medical data protection and aims to enhance HIPAA compliance standards across the healthcare sector.

HIPAA
NIST CSF
Google NewsMar 11, 2026

Trump Administration's Aggressive Cyber Strategy: Major Implications for HIPAA Compliance

The Trump administration has announced a comprehensive cybersecurity strategy that will significantly impact healthcare organizations' HIPAA compliance requirements. The new initiative focuses on strengthening critical infrastructure protection, including healthcare systems that handle sensitive patient data. Healthcare entities will need to reassess their cybersecurity frameworks to align with enhanced federal requirements.

HIPAA
NIST CSF
Google NewsMar 10, 2026

Mindbowser Inc. Achieves SOC 2 Certification, Bolstering Healthcare Data Security Standards

Mindbowser Inc., a technology consulting firm, has successfully obtained SOC 2 Type II certification, demonstrating enhanced security controls for healthcare data protection. This certification strengthens the company's ability to serve enterprise healthcare clients with compliant data handling practices and robust security frameworks.

SOC 2
HIPAA
Google NewsMar 9, 2026

Pharmacy Customer Reports HIPAA Violation After Witnessing Tech's Inappropriate Actions

A pharmacy customer reported witnessing a technician's behavior that appeared to violate HIPAA privacy requirements, raising concerns about patient information protection in retail pharmacy settings. The incident highlights ongoing challenges healthcare providers face in maintaining staff compliance with federal privacy regulations.

HIPAA
Google NewsMar 7, 2026

Business Associate Settles Major HIPAA Violations for Unreported Breach Affecting 15 Million Individuals

A business associate has reached a settlement with federal regulators over HIPAA violations related to an unreported data breach that affected 15 million individuals. The case highlights critical compliance failures in breach notification requirements and the severe consequences of delayed reporting to covered entities and regulators.

HIPAA
Google NewsMar 5, 2026

Excel Healthcare Data Breach Triggers Class Action Lawsuit Investigation

Excel Healthcare is facing a class action lawsuit investigation following a data breach that potentially exposed patient protected health information. The incident highlights ongoing HIPAA compliance challenges in healthcare organizations and may result in significant financial penalties for affected patients.

HIPAA
Google NewsMar 2, 2026

Pinnacle Holdings Data Breach Sparks Lawsuit Investigation and HIPAA Compliance Concerns

Pinnacle Holdings is under investigation for a significant data breach that has triggered a lawsuit probe by Claim Depot. The breach potentially affects sensitive personal and healthcare information, raising serious HIPAA compliance questions for the organization and its data handling practices.

HIPAA
NIST CSF
Google NewsMar 1, 2026

IU Health Files Lawsuit Against Healthcare Tech Company Following Major 2024 Data Breach

Indiana University Health has filed a lawsuit against a healthcare technology company in connection with a significant data breach that occurred in 2024. The legal action highlights ongoing concerns about third-party vendor security and HIPAA compliance in healthcare organizations, potentially affecting thousands of patients' protected health information.

HIPAA
Google NewsMar 1, 2026

The College of Health Care Professions Data Breach Triggers Legal Investigation

The College of Health Care Professions is under investigation for a potential data breach that may have exposed protected health information of students and patients. The incident has prompted a class-action lawsuit investigation, highlighting critical HIPAA compliance concerns for educational healthcare institutions.

HIPAA
NIST CSF
Google NewsFeb 27, 2026

January 2026 Healthcare Data Breach Report: Critical HIPAA Compliance Insights

The January 2026 Healthcare Data Breach Report from The HIPAA Journal documents significant protected health information (PHI) breaches affecting healthcare organizations nationwide. Multiple incidents involved unauthorized access to patient records, highlighting ongoing challenges in healthcare cybersecurity and HIPAA compliance implementation.

HIPAA
Google NewsFeb 27, 2026

Rebound Orthopedics & Neurosurgery Settles Data Breach Lawsuit for $2.5 Million

Rebound Orthopedics & Neurosurgery agreed to pay $2.5 million to settle a class-action lawsuit following a significant data breach that compromised patient health information. The settlement highlights the ongoing financial and legal risks healthcare organizations face when HIPAA-protected data is compromised, emphasizing the critical importance of robust cybersecurity measures in medical practices.

HIPAA
Google NewsFeb 26, 2026

Carolina Foot & Ankle Associates Reports December 2025 Cyberattack Affecting Patient Data

Carolina Foot & Ankle Associates has notified patients about a cyberattack that occurred in December 2025, potentially compromising protected health information. The healthcare provider is working with cybersecurity experts and law enforcement to investigate the incident and implement additional security measures.

HIPAA
Google NewsFeb 26, 2026

Healthcare Data Breach Statistics Reveal Evolving Threats to Patient Privacy

New healthcare data breach statistics show concerning trends in patient data security vulnerabilities across the industry. The analysis reveals key patterns in breach types, affected entities, and compliance failures that healthcare organizations must address to maintain HIPAA compliance.

HIPAA
Google NewsFeb 26, 2026

Stay compliant with confidence

PoliWriter generates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.

Get Started Free