PrivacySignal
Healthcare

Vermont Enacts Privacy Legislation to Regulate Health-Related Information

Inside Privacy (Covington) · · International · Healthcare Privacy

Vermont has passed two health-focused privacy laws: H.639, which regulates direct-to-consumer genetic testing companies, and S.71, a broader privacy act that adds extra protections for consumer health data. Both measures expand the state's oversight of how sensitive personal health information is collected and used.

Why this matters: Genetic data is not like a password. You cannot change it, and it does not just describe you — it describes your relatives too. Direct-to-consumer DNA companies have had a rough few years on privacy, including a major breach and a bankruptcy that put customer data at risk. Vermont is now telling those companies that they have real obligations. The broader health data law matters because most people assume their health information is already protected. Often it is not, especially when it flows through apps and wellness platforms that fall outside federal health privacy rules.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
M Modern Healthcare · · International

Senate eyes a health privacy upgrade for your Apple Watch

The U.S. Senate is considering legislation that would strengthen privacy protections for health data collected by consumer wearables such as the Apple Watch. The move would extend health privacy rules beyond traditional medical providers to cover the growing market of personal health tracking devices.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Healthcare
Nextgov/FCW · · US Federal

Social Security expands electronic health record sharing to speed up disability claims adjudication

The Social Security Administration has expanded a system that pulls structured electronic health records directly from providers, giving the agency near-instant access to medical data for people applying for disability benefits. The goal is to cut the notoriously long wait times for disability claim decisions.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

American Addiction Centers & Oculus Pathology Disclose Hacking Incidents

American Addiction Centers in Tennessee and Oculus Pathology in Texas have each disclosed separate hacking incidents. Both organizations operate in healthcare, meaning the breached data likely includes sensitive medical and personal information covered under HIPAA.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight

A large-scale audit of over 80,000 online review responses from nearly 4,000 medical and dental practices found an estimated 21,000 public replies that likely disclosed patient information in violation of HIPAA. The violations were not hidden in back-end systems — they were sitting in publicly visible responses to patient reviews.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon

A Beverly Hills plastic surgeon has confirmed a data theft and extortion incident, joining a string of recent healthcare data breaches that also include SunCloud Health, Minnesota ENT, and several other medical providers.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Vishing Attack Provides Threat Act with Access to Quantum Health Network

Quantum Health, a healthcare navigation and care coordination company, disclosed a data breach after a vishing attack — a voice-based social engineering scheme — gave threat actors unauthorized access to its network. Heart of America Medical Center was also named in connection with recent breach announcements.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →