HIPAA Pulse by Patient Protect logo

HIPAA Pulse by Patient Protect

Archives
Log in
July 22, 2026

HIPAA Pulse | July 22

HIPAA Pulse — July 22, 2026
A lab's federal filing beat the extortion group's own number. A hospital system's third incident this year traces back to a vendor again. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Patient Protect
HIPAA Pulse

HIPAA PULSE

July 22, 2026  ·  Bi-Weekly Briefing

A Lab's Portal Count, a Hospital's Third Incident & the Rule Pushed to 2027

An extortion group claimed 540,000 records from a New Jersey lab. HHS OCR's portal lists 542,377 — a rare case where the portal count is higher than the criminals' own claim.

Centers Lab NJ is this window's largest disclosure by far, and the number worth remembering isn't the one that broke first. Meanwhile NYC Health + Hospitals is now three incidents into 2026, twice traced back to a vendor. Same lesson, different building.

We also caught three historical mega-breaches surfacing this week with fresh 2026 dates. HHS quietly pushed the Security Rule's finalization target a full year.

61.5%

of everything this window is Centers Lab NJ alone. WorldLeaks claimed roughly 540,000 records. HHS OCR's portal lists 542,377. Extortion claims are pressure tactics, not source-of-record numbers.

Since the last issue, July 8

27

new OCR + State AG entries, historical re-filings stripped out

70%

hacking or IT incident, 19 of the 27

83K

Aitkin County HHS, MN — largest after Centers Lab

Centers Lab NJ alone is 542,377 of the window's 881,416 affected individuals. The other 26 entries add up to roughly 339,000 combined.

Open the live dashboard Free · No account · Updated nightly

Breach of Note: Centers Lab NJ LLC

HHS OCR June 18  ·  542,377 affected  ·  Hacking/IT Incident  ·  New Jersey

Centers Laboratory, a healthcare testing provider, discovered suspicious activity in its systems on August 25, 2025. The investigation traced unauthorized access back to August 9–14, 2025. WorldLeaks listed the company on its dark web leak site that October, claiming roughly 720 GB stolen and putting a rounded figure of about 540,000 into circulation. The claim resurfaced widely in mid-July 2026, once HHS's own portal listing caught up.

The portal figure came in at 542,377 — higher than the extortion group's own claim, not lower. Regulatory filings and company notices carry a legal notification obligation behind them; extortion-group claims carry an incentive to sound impressive. Only one of the two comes with a paper trail, and this time the paper trail said more.

The real question for your practice is which number you'd repeat if a headline broke tomorrow. Treat an extortion group's claim as a floor to watch, not a figure to cite, and check the OCR portal once a listing lands.

Worth asking: Do you send specimens to Centers Laboratory, or a lab with a similar arrangement? Does your BAA with any lab vendor set a notification deadline shorter than the federal 60-day maximum? When you cite a breach's scope, is it the OCR portal figure, or the number that broke first? Run the free assessment.

NYC Health + Hospitals, again through a vendor

Solventum Health Information Systems, a business associate, exposed 58,778 patients' names, addresses, dates of birth, medical record numbers, and diagnoses. Access happened around March 29. Solventum notified NYC Health + Hospitals on April 21. The health system's public notice came roughly seven weeks later, on June 11. This is its third disclosed incident of 2026, after a 1.8-million-record network breach in March and a smaller one at a separate care-management partner. Three incidents in a year, at least two vendor-caused, at one covered entity. The pattern this newsletter tracked all quarter at a radiology practice is showing up again at a hospital system: a vendor's notification timeline becomes your operational timeline, unless the BAA forces it faster.

Three decade-old breaches, right on schedule

Excellus BlueCross BlueShield (10 million, 2015) and Premera Blue Cross (11 million, 2014) both showed up in this week's state filings with brand-new July 2026 dates, alongside the federal government's own 2015 OPM breach (21.5 million). None of these are new. Premera and Excellus are both still generating multistate settlement activity a decade later — California recovered over a million dollars from Premera in a 2019 settlement, and Minnesota has separately settled its own claims — and each settlement produces a filing that looks current. It's the report-date problem our Q2 Verified Breach Brief spent a whole section on. We caught these three. The pattern isn't going anywhere on its own.

The Security Rule just lost a year

HHS moved the proposed Security Rule update to the Long-Term Actions section of its current Unified Agenda. July 2027 is now the anticipated target for final action, a year past the May 2026 date every practice had circled. Placement on the long-term list usually means HHS doesn't expect to finalize within twelve months, and the date is a planning estimate, not a deadline. None of this touches current enforcement: risk analysis remains OCR's most-cited finding regardless of what happens to the proposal.

30-minute system check

Five items, each tied to something above.

1.

Put a notification deadline in every lab and vendor BAA. Shorter than the federal 60-day maximum. NYC Health + Hospitals' gap between vendor notice and public notice was seven weeks — a contract term is what closes that gap next time.

2.

List every reference lab you use. Confirm a current BAA and a named contact for breach notification at each one. Labs are an under-inventoried category.

3.

Check the source before you repeat a number. Centers Lab's portal figure beat the extortion group's claim, not the reverse. Cite the regulatory filing, not the first headline.

4.

Refresh your risk analysis if it's over a year old. Still OCR's most-cited gap. Still true whichever way the Security Rule update eventually lands.

5.

Keep building toward the current NPRM anyway. Encryption at rest and in transit, MFA, a documented scanning cadence. July 2027 has already slipped once; the controls are sound regardless of the date.

The free HIPAA Risk Assessment inventories your vendors, BAAs, and data flows in about 30 minutes. No account needed.

Run the free assessment Free · No account · 30 minutes
 

A word from Patient Protect, who pays for this newsletter to exist

Your vendors are your attack surface. Track them like it.

Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle alerts, including notification-deadline terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.

Start free trial See pricing

Worth reading elsewhere

  Abbott Investigates Two Unrelated Cyber Incidents

ShinyHunters and ShadowByt3$ both claimed separate Abbott business units within days of each other. Still under investigation. Source: DataBreaches.net.

  NY Attorney General Secures $18 Million From 23andMe

Not a HIPAA action — 23andMe isn't a covered entity — but a marker for how aggressively state AGs are pricing genetic data failures.

  Cybercriminals Flock to Healthcare Businesses as Attacks Surge

Dark Reading's first-half read: hospital and clinic attacks grew modestly, service-provider attacks more than doubled.

Five issues in, the shape hasn't changed. Whatever holds the most data in a given window ends up at the top of it, whether that's an AI vendor, a radiology practice, or a diagnostics lab. The entities filing the most disclosures are the ordinary ones, working through vendors they trusted to notify them on time.

Next Pulse drops August 5.

Editorial coverage at hipaapulse.com. Operational response at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.

Patient Protect

Chicago, IL  ·  patient-protect.com  ·  HIPAA Pulse

Instagram LinkedIn X

Breach data reflects publicly reported incidents from federal, regulatory, and community sources. Centers Lab NJ figure reflects the HHS OCR breach portal listing, not the earlier extortion-group claim; discovery and access dates reflect the company's own notice. NYC Health + Hospitals figures reflect its own public notice and Becker's Hospital Review reporting. Excellus, Premera, and OPM figures reflect their original historical disclosures, re-verified independently; none are fresh 2026 incidents despite current filing dates.

You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Unsubscribe  ·  Privacy Policy

© 2026 Patient Protect LLC. All rights reserved.

Don't miss what's next. Subscribe to HIPAA Pulse by Patient Protect:
← Newer HIPAA Pulse | August 5th Older → HIPAA Pulse | July 08 | Q2 Recap
Instagram
Twitter
LinkedIn
YouTube