Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents

Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company in West Virginia, and Open Door Health Center of Illinois.

Boston Healthcare for the Homeless Program, Massachusetts

Boston Healthcare for the Homeless Program, a Boston, MA-based nonprofit organization that provides healthcare services for the homeless population, has notified state attorneys general about a network security incident first identified on November 11, 2025.

The incident was detected when it experienced a network disruption. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party accessed its network and potentially viewed or obtained files containing sensitive patient information.

The review of the affected data was completed on June 8, 2026, when it was learned that names, Social Security numbers, credit/debit card information, government identification numbers, financial account codes, medical information, health records, and health insurance information were involved. The affected individuals have been offered single-bureau credit score, credit report, and credit monitoring services for 12 months. While the total number of affected individuals is unclear, at least 184,914 Massachusetts residents have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Monongalia County General Hospital Company, West Virginia

Monongalia County General Hospital Company, aka Mon General, has recently confirmed a data breach that exposed the personal and medical information of certain patients. Suspicious activity was identified within its email system on May 6, 2026. Assisted by a digital forensics company, Mon General determined that a small number of employee email accounts had been accessed by an unauthorized third party. Employees had responded to phishing emails and disclosed their credentials.

The forensic investigation confirmed that the incident was limited to the email accounts; however, they did contain patient information such as first and last names, birth dates, email addresses, phone numbers, Social Security numbers, health information, and health insurance information. Notifications have been issued, and the affected patients have been offered two years of complimentary credit monitoring and identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

Open Door Health Center of Illinois

Open Door Health Center of Illinois, a primary care and sexual health care clinic in Chicago, Illinois, has fallen victim to a cyberattack that appears to have involved the theft of patient data. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 affected individuals. There is currently no substitute breach notice on the Open Door Health Center of Illinois website, so the types of data involved are not yet known. This appears to have been a ransomware attack by the Inc Ransom ransomware group, which added Open Door Health Center of Illinois to its dark web data leak site on May 21, 2026. Inc Ransom is a ransomware group that engages in data theft and extortion. The group claims to have exfiltrated sensitive data.

The post Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents appeared first on The HIPAA Journal.

Texas Hearing Institute Ransomware Attack Affects 30,000 Patients

Texas Hearing Institute has announced a cybersecurity incident involving the protected health information of almost 30,000 patients. Data breaches have also recently been announced by Family Partnerships of Central Florida and SportsMed Physical Therapy.

Texas Hearing Institute

The Center for Hearing and Speech, doing business as Texas Hearing Institute, a provider of pediatric audiology services, has notified 29,744 current and former patients about a security incident identified on March 20, 2026. Suspicious network activity was identified, and immediate action was taken to lock down and secure its environment. Assisted by third-party cybersecurity specialists, Texas Hearing Institute determined on or around April 22, 2026, that certain parts of its network were accessed by an unauthorized third party, including files containing patient information.

The list of the affected individuals was finalized on June 19, 2026, and notification letters were mailed on June 26, 2026. Information potentially compromised in the incident includes names, personal identifiers, Social Security numbers, diagnosis and treatment information, and financial account information. The affected individuals have been offered complimentary single-bureau credit score, credit record, and credit monitoring services.

While not mentioned in the breach notification letters, this appears to have been a ransomware attack. The Interlock ransomware group claimed responsibility and states on its data leak site that 540 GB of data was copied in the attack. Interlock is a ransomware-as-a-service group that steals data and encrypts files, demanding payment for the decryption keys and to prevent the publication of stolen data. The group proceeded to leak the stolen data, indicating the ransom was not paid. As such, the affected individuals are strongly advised to take advantage of the credit monitoring services being offered.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Family Partnerships of Central Florida

Community Based Care of Brevard, doing business as Family Partnerships of Central Florida, a community-based care lead agency contracted by the Florida Department of Children and Families, has notified 8,151 individuals that some of their protected health information has been leaked online. The MoneyMessage threat group claimed responsibility for the attack.

Family Partnerships of Central Florida launched an investigation when it learned about the data leak to determine the nature and scope of the incident. The investigation confirmed that a threat actor had access to its network between December 4, 2025, and January 2, 2026, and exfiltrated files containing names, birth dates, Social Security numbers, driver’s license numbers, state IDs, financial account information, and personal health information.

Since data has been leaked online, the affected individuals have been advised to remain vigilant against identity theft and fraud. The notification letters include information on how they can protect against data misuse. The substitute breach notice does not mention complimentary credit monitoring or identity theft protection services. Family Partnerships of Central Florida said it is reviewing its policies, procedures, and processes related to the storage and access of sensitive information to reduce the risk of similar incidents in the future.

SportsMed PT, New Jersey

SportsMed Physical Therapy in Glen Rock, New Jersey, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on May 8, 2026. The investigation confirmed that the breach was limited to a single email account, which has now been secured. The account was reviewed, and while the investigation into the incident is ongoing, SportsMed Physical Therapy said the exposed data included names in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information.

No actual or attempted misuse of the exposed data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. The breach was recently reported to the HHS’ Office for Civil Rights as affecting 3,400 individuals.

The post Texas Hearing Institute Ransomware Attack Affects 30,000 Patients appeared first on The HIPAA Journal.

Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients

A data breach at Aesto Health, a Birmingham, Alabama-based healthcare technology company, has affected several of its healthcare provider clients. Aesto Health provides secure data migration, legacy data archiving, and electronic health record (EHR) exchanges for medical practices and healthcare enterprises. According to its announcement, a security incident was identified on or around December 18, 2025, involving part of its Amazon Web Services (AWS) infrastructure. Third-party cybersecurity experts were engaged to investigate the incident and confirmed that its AWS environment was accessed by an unauthorized third party between December 2 and December 18, 2025.

The affected parts of its infrastructure were reviewed and confirmed to contain personally identifiable information and protected health information, including full names, Social Security numbers, partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. Aesto Health said it had taken many precautions to safeguard the sensitive data in its possession and continually evaluates and modifies its security practices. Credit monitoring and identity theft protection services have been made available.

The incident is known to have affected more than two dozen of its healthcare provider clients. They started to be notified on June 26, 2026. Whenever there is a data breach at a business associate of a HIPAA-covered entity, the affected covered entity is ultimately responsible for ensuring that the requirements of the HIPAA Breach Notification Rule are met. The covered entity may delegate the responsibility for issuing notification letters to the breached business associate, or it may choose to issue notification letters itself. As a result, it is often difficult to determine how many individuals have been affected by a business associate data breach, although in this case the breach has certainly affected hundreds of thousands of patients.

Based on state Attorney General breach listings, at least 80,622 South Carolina residents, 37,253 Washington residents, 731 Oregon residents, and 91 Vermont residents have been affected; however, many of the affected clients have chosen to report the breach themselves. In some cases, clients report that tens of thousands of their patients have been affected. For instance, Village Practice Management has confirmed that more than 25,000 of its patients have been affected, and Everside Health informed the Washington Attorney General that approximately 22,000 individuals have been affected in Washington alone.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The healthcare providers known to have been affected are detailed in the table below, although others may also have been affected.

  • Edwards County Medical Center
  • Effingham Obstetrics & Gynecology Associates, PLLC
  • Ellenville Regional Hospital
  • Everside Health
  • Gila Health Resources, LLC
  • Graham County Hospital
  • Greenwood County Hospital
  • Henry County Hospital
  • Little River Memorial Hospital
  • Main Street Medical Services, PLLC
  • Marana Health
  • Mid-South OB-GYN, PLLC
  • Midtown Community Health Center
  • Missoula Community Health Services Inc., dba Mineral Community Hospital
  • Monroe Health Center
  • My Doctor, LLC
  • Nebraska Orthopedic Center, P.C
  • Park West Health Systems, Inc.
  • Quincy Valley Medical Center
  • Rural Health Resources of Jackson County Inc. d/b/a Holton Community Hospital
  • Shenandoah Valley Medical System Inc.
  • Sterling Health Solutions
  • Texas Spine Consultants, LLP
  • Together Women’s Health Medical Group of Alabama, PC
  • Together Women’s Health Medical Group, PC
  • Village Practice Management (VillageMD; Village Medical)
  • Women’s Health Associates, Inc.

The post Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients appeared first on The HIPAA Journal.

ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit

A $3,500,000 settlement has received preliminary approval from the court to resolve class action data breach litigation against ZOLL Medical Corporation. The litigation relates to a January 2023 data breach that affected more than 1 million individuals.

Zoll Medical is a Chelmsford, Massachusetts-based global medical device and software company that makes products for resuscitation, cardiac monitoring, and critical cardiopulmonary conditions. Unauthorized network access was identified on January 28, 2023, and the investigation confirmed that personally identifiable information (PII) and protected health information (PHI) were exposed in the incident, mainly relating to individuals who received or were considered for use of the ZOLL LifeVest wearable cardioverter defibrillator. According to the breach notice submitted to the HHS’ Office for Civil Rights, the electronic protected health information (ePHI) of 997,097 individuals was involved, including names, addresses, dates of birth, and Social Security numbers. Those individuals started to be notified about the data breach in March 2023.

The data breach sparked 15 class action lawsuits, which were consolidated on April 24, 2023. The consolidated class action complaint was filed on February 26, 2024 – Smith et al. v. ZOLL Medical Corporation – in the U.S. District Court of Massachusetts on behalf of a nationwide class. The plaintiffs claimed that ZOLL Medical had failed to comply with its responsibilities under HIPAA, including a failure to implement appropriate technical, physical, and administrative safeguards to secure the privacy of ePHI, and violated the HIPAA Breach Notification Rule by not issuing timely breach notices. The lawsuit claimed that the breach notices did not include sufficient information about the nature of the breach to allow the victims to take action to protect themselves against data misuse.

The consolidated complaint brough claims for negligence, negligence per se, breach of fiduciary duty, breach of implied contract, unjust enrichment, and declaratory judgment and injunctive relief, and included allegations of violations of the Florida Deceptive and Unfair Trade Practices Act, Kansas Consumer Protection Act, New York General Business Law, Pennsylvania Unfair Trade Practices and Consumer Protection Law, and Illinois Consumer Fraud and Deceptive Business Practices Act.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

ZOLL Medical disagreed with all claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability. ZOLL Medical sought to have the complaint dismissed, asserting that the plaintiffs failed to state a claim entitling them to relief. The judge issued an order granting the motion to dismiss in part; however, the negligence claims under Massachusetts, Pennsylvania, Illinois, Florida, Texas, and New York law were permitted, along with the claims for breach of fiduciary duty, unjust enrichment, and breach of implied-in-law contract. While mediation was unsuccessful, subsequent negotiations resulted in a settlement that was agreeable to all parties.

The settlement class includes all living individuals who received a notice that their information was impacted by the data incident, with limited exceptions. From the $3,500,000 settlement fund, attorneys’ fees and expenses, settlement administration costs, taxes and tax-related expenses, and service awards for the class representatives will be deducted. The remaining funds will be used to pay for class member benefits.

Class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses incurred due to the data breach up to a maximum of $5,000 per class member. All class members may submit a claim for a cash payment, which will be paid pro rata from the remainder of the settlement fund. Individuals who had their Social Security numbers exposed will receive two shares per valid claim. The SSN share is estimated to be $100, and the non-SSN share is estimated to be $50. The deadline for objection and opting out has passed. Claims must be submitted by September 2, 2026, and the final fairness hearing has been scheduled for September 10, 2026.

The post ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.