PrivacySignal
Healthcare

Minnesota Epilepsy Group; Campbell University; City of Middletown Announce Data Breaches

HIPAA Journal · · US Federal · Healthcare Privacy

Three separate organizations — Minnesota Epilepsy Group, Campbell University, and the City of Middletown, Ohio — have each disclosed data breaches. The incidents span healthcare, higher education, and local government, suggesting no single attack but a broad pattern of exposure across different sectors.

Why this matters: A medical group specializing in epilepsy holds some of the most sensitive health information a person can have. A seizure disorder touches employment, driving, insurance, and stigma. When that data leaks, the harm is not abstract. Campbell University and a municipal government round out this cluster, which means students, patients, and residents are all affected at once. None of these organizations chose to hold this data — people had no real option but to hand it over. That is exactly when the duty to protect it is highest.

Who should care: Healthcare professionals · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Healthcare
K KevinMD.com · · International

Health data privacy with AI starts before you press send

A piece published via KevinMD argues that protecting health data in AI interactions requires decisions made before information is ever entered into a system, not after.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai#privacy Read original →
Healthcare
The Guardian — Privacy · · International

NHS England chief says staff suspected of snooping on patients’ records should be suspended immediately

Jim Mackey says access to NHS systems should be cut off while allegations are investigated, as he urges trusts to take a ‘zero tolerance’ approach NHS staff suspected of snooping on patients’ medical records should be suspended immediately and barred from using health service computers, the head of NHS England has said. Jim Mackey urged NHS England’s 205 health trusts to pursue a “zero tolerance” approach to staff who are suspected of inappropriately accessing records. Continue reading...

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems

Notification letters are being mailed to individuals affected by data breaches at the pharmacy benefit management service provider MedImpact Healthcare […] The post Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation

CVS Health, Criteo, and American Wellness Corp have agreed to pay $20.5 million to settle class action lawsuits tied to website tracking practices. The settlements resolve litigation that appears to center on how user data was collected and shared through tracking tools on health-related websites.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

#healthcare#surveillance Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Gastroenterology Practice and Hospice Companies

Data breaches have been announced by Gastroenterology & Hepatology of Central New York, Three Oaks Hospice, and Doctor’s Choice Home […] The post Data Breaches Announced by Gastroenterology Practice and Hospice Companies appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

California Seeks to Implement AI Guardrails for Mental Health Treatment

The California Senate has unanimously passed a bill to establish guardrails on the use of artificial intelligence in mental health treatment. The legislation moves forward amid broader national debate over how AI tools should be regulated in clinical and therapeutic settings.

Who should care: Healthcare professionals · Privacy officers · Compliance · AI governance · Lawyers · Administrators · General readers · Policy

#healthcare#ai-governance#ai Read original →