Breach feed · live
Sierra Nevada Health Plan · NV · 250,000 affected · hackingInnovative Scientific Solutions, LLC · SC · 143,842 affected · hacking/it incidentLennox International Inc. · TX · 3,709 affected · hacking/it incidentL.A. Care Health Plan · CA · 2,885 affected · unauthorized access/disclosureWashington VA Medical Center · DC · 1,467 affected · unauthorized access/disclosureProvidence · CA · -1 affected · breachIowa Department of Health and Human Services · IA · 6,717 affected · unauthorized access/disclosurePacific Northwest Health System · OR · 15,000 affected · insiderMazzola Mardon, P.C. · NY · 2,123 affected · hacking/it incidentDefense Health Agency · VA · 1,300 affected · unauthorized access/disclosure
Sun, May 3, 2026
Vol. 1 · No. 18Sunday, May 3, 2026Edition: National

HIPAA Pulse.

Breach intelligence · HIPAA news · Prevention
From Patient Protect
Breach of the week

NYSDFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental

There is an update regarding the 2023 Delta Dental breach involving MOVEit software. Delta Dental was one of many customers whose patient data was exposed after Clop exploited a zero-day vulnerability to attack MOVEit and acquire its clients' data. More than 7 million patients were reportedly affected by the breach, although the number specific to New... Source

Litigation

Michigan residents sue Thomson Reuters over public display of Social Security numbers

Caitlyn Rosen reports: A class of Michiganders asserted in a federal lawsuit filed Thursday that a Thomson Reuters search engine wrongfully published their Social Security numbers. In an 11-page lawsuit filed in the U.S. District Court for the Eastern District of Michigan, the class claims Reuters search engines publicly displayed plaintiffs’ social security numbers in... Source

Technology

Maine health system lays off 38 IT staff after EHR upgrades

Lewiston, Maine-based Central Maine Healthcare is laying off 38 IT employees as part of a series of new technology updates. The health system said on its website that it is transitioning to a new electronic medical record, which includes Epic's MyChart portal, expected to go live for patient scheduling on Friday.

Technology

One Mississippi health system's journey to a system-wide Epic EHR

South Central Regional Medical Center is a Mississippi health system that offers a wide range of medical services and specialties and strives to deliver compassionate care with superior patient outcomes.THE CHALLENGEThe health system faced the challenge of coordinating a large-scale EHR implementation across five diverse geographical and operational areas while maintaining patient care continuity.

Breach tracker · Last 30 days

HHS OCR · State AG · OCR Enforcement · FTC · CISA · Updated nightly
Incidents reported
175
Last 30 days, all sources
Individuals affected
3641.22M
Cumulative across the archive
Confirmed breaches
62%
2,050 of 3,312 incidents
Total in archive
3,312
All-time tracked
Open the full tracker →
Security Rule 2026 · Coverage hub

OCR’s final Security Rule is expected in May. We’re tracking every provision change, comment letter, and enforcement signal.

Comprehensive draft-vs-final redline analysis, sector-specific readiness assessments, and a comment-letter database covering every public submission. Free for any practice that needs it.

~26
Days to expected finalization

Pattern analysis

All patterns →
Stay informed

The same team behind HIPAA Pulse runs an every-other-Wednesday briefing on the breaches, regulatory moves, and analysis worth your time.

HIPAA Pulse is published by Patient Protect. The newsletter comes from the same place — which means you’ll see the occasional update about the Patient Protect platform. We try to keep that light. If you want only the editorial content, the RSS feed has no product material.

Every other Wednesday · Free · Unsubscribe anytime

About HIPAA Pulse

HIPAA Pulse is a publication from Patient Protect, the HIPAA compliance platform built for independent healthcare practices. We cover breaches, OCR enforcement, regulatory developments, and tactical guidance for the people who actually have to comply with the rule. The breach data, regulatory tracking, and pattern analysis are useful regardless of what software you use.