Law Firm Data Breaches Surge: While few of these are specifically HIPAA related (law firms can be business associates of covered entities, but that's not a relevant issue here), it is interesting to see how law firms are a hot new target for hackers. Like healthcare entities, law firms have access to confidential and highly sensitive information; some attacks target business and deal information, where the hackers are trying to get a jump ahead of stock price changes involving the firm's clients (or to otherwise get actionable data on the clients), while others seek to gain information that the hackers can use to extort a ransom payment from the firm.
Also like healthcare entities, some small law firms think they are safe because of their small size, whereas the opposite is usually true: small firms are less likely to have robust defenses, which make them easier to victimize.