Healthcare compliance and security intelligence for independent practices.
Patient Protect monitors authoritative healthcare, regulatory and security sources and publishes a Response only when the evidence supports a meaningful operational takeaway.
HHS OCR · Federal Register · eCFR · CISA · CISA KEV · FBI / IC3
Not every healthcare incident earns a Response. These are the developments where the source record supports something an independent practice should understand or review.
CareCloud filed a breach report with HHS OCR. The filing discloses no individual count, and reported figures moved substantially as the incident developed — which is the reason to track the filing rather than the coverage.
Madera Community Hospital filed a breach report with HHS OCR covering 150,000 individuals. A risk analysis scoped only to availability will not address confidentiality threats such as data removal.
Brown Health Medical Group filed a breach report with HHS OCR covering 311,760 individuals. Server-level ePHI access puts the Security Rule's technical safeguards — access control and audit logging — directly in scope.
Unlimited Technology Systems filed a breach report with HHS OCR covering 3.8 million individuals. A vendor incident of this size reaches every covered entity in its client base.
Amgen filed a breach report with HHS OCR involving a cloud environment. The filing discloses no individual count. The question it raises for a practice is which cloud-hosted vendors hold PHI under a signed BAA.
Medical Computer Business Services filed a breach report with HHS OCR covering 1.2 million individuals. Billing vendors hold dense concentrations of PHI, which is what makes the BAA scope worth checking.
DentaQuest filed a breach report with HHS OCR covering 15 million individuals. Practices that route claims through a benefits administrator have their own notification questions to work through.
Centers Laboratory filed a breach report with HHS OCR covering 542,377 individuals. A practice that sent orders or specimens to a breached laboratory may have notification duties of its own, depending on the arrangement.
Medtronic filed a breach report with HHS OCR. The filing discloses no individual count. Where a device manufacturer holds patient data, the BAA language determines what the practice is entitled to know.
Xsolis filed a breach report with HHS OCR. The filing discloses no individual count and does not establish how access was obtained.
iRhythm Holdings filed a breach report with HHS OCR. The filing discloses no individual count. Where a practice relies on hosted cardiac monitoring, the BAA determines what it can expect after an incident.
A consumer genetics platform is generally not a HIPAA covered entity, so the obligations here run to the practice rather than the platform. What matters is credential hygiene and what a practice recommends to patients.
Radiology Associates of Richmond filed a breach report with HHS OCR. The filing discloses no individual count. Role-based access and PHI monitoring are the controls most directly implicated by this kind of record.
OpenLoop Health filed a breach report with HHS OCR covering 716,000 individuals. Telehealth vendors aggregate ePHI across many practices, so a single vendor incident reaches a wide client base.
01
Patient Protect monitors authoritative regulatory, enforcement and healthcare-security sources.
02
Material facts are checked against the source of record. Unknown facts remain unknown; allegations remain attributed.
03
A Response publishes only when the verified event supports a meaningful compliance or security takeaway for an independent practice.
HIPAA Pulse
The regulatory, enforcement and healthcare-security developments that actually matter to an independent practice — sourced, verified and translated into what to review.
No spam. Unsubscribe anytime.
Want more from Patient Protect? See all email options
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.
Part of the HIPAA Foundation · 15+ free tools
See the full collectionPulse reports what happened elsewhere. The platform runs the response controls on your own stack — BAA scope, workforce access, incident-response documentation.
Next in the sequence
Healthcare Breach DatasetThe Breach Dashboard, HIPAA Response, Signal, and the open dataset provide different views of the same healthcare compliance and security landscape.