HIPAA Digest | Catapult Business Innovations – November 27, 2025

Alleva Achieves ONC Certification, SOC 2, and HIPAA Compliance for Its Behavioral Health Platform

This news shows Alleva achieved ONC Certification, SOC 2, and HIPAA compliance for its Behavioral Health Platform, signaling strong data security and regulatory readiness that buyers of AI-driven marketing and health tech demand from vendors.

Read full article

Trinity Health; Precision Imaging Centers Settle Class Action Data Breach Lawsuits

Class-action data breach settlements underscore the financial and reputational risk of PHI exposure, highlighting why healthcare partners and their vendors must invest in strong security controls and incident response to protect customer data.

Read full article

VITAS Hospice Services Discovers Month-Long Network Intrusion

The month-long intrusion shows how long a breach can go undetected, stressing the need for continuous monitoring, quick detection, and solid vendor risk management when deploying AI-driven marketing or patient-facing tools.

Read full article

Rockhill Women’s Care & Harbor Regional Center Announced Data Breaches

The breaches at care providers illustrate how PHI can be exposed through various channels, underscoring the importance of breach preparedness and third-party risk management for any business relying on PHI-rich data and marketing tech.

Read full article

Sen. Cassidy introduces legislation that would change the way consumer apps and wearables handle health data

Proposed health-data legislation could introduce new privacy and consent requirements for consumer health apps and wearables, affecting how healthcare marketing tech and AI tools collect, store, and use PHI.

Read full article