Solara Medical Supplies Pays $3 Million to Settle HIPAA Security Rule Violations

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $3 million settlement with Solara Medical Supplies, a California-based supplier of insulin pumps and continuous glucose monitors, resolving potential violations of the HIPAA Security Rule and Breach Notification Rule. The case stemmed from a 2019 phishing attack that compromised…

Read More

Children’s Hospital Colorado Pays Over $500,000 for MFA Failures Leading to HIPAA Breach

HHS Office for Civil Rights reached a settlement with Children’s Hospital Colorado following a data breach that exposed the protected health information of thousands of patients. The breach was tied directly to failures in implementing multi-factor authentication (MFA) across critical systems, resulting in a penalty exceeding $500,000. OCR’s investigation determined that the hospital had not…

Read More

Cybersecurity Compliance Deadlines Loom

Earlier this year, the New York State Department of Financial Services laid out new cybersecurity requirements for financial services companies. These rules (codified in 23 NYCRR 500) took effect on March 1 and established an array of “regulatory minimum standards” that companies must now meet. When all is said and done, financial services companies will…

Read More