Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to write past the end of a heap allocation and crash an Orthanc process in a denial-of-service attack.

Orthanc DICOM Server is a free-to-use, standalone, open-source, lightweight DICOM server that is used in both clinical and research environments. It can complement or act as a gateway to existing PACS systems, and was developed to improve interoperability and workflow efficiency.

An integer overflow in a specified pitch and buffer-size computation results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image file, causing a crash and denial-of-service condition.

The vulnerability is tracked as CVE-2026-87020 and has been assigned a CVSS v3.1 base score of 8.1 and a CVSS v4.0 base score of 7.2. The vulnerability was identified by penetration tester Andrej Tomci, who reported the issue to the Cybersecurity and Infrastructure Security Agency.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The vulnerability affects all Orthanc DICOM Server prior to 1.13.0. Orthanc has fixed the vulnerability in version 1.13.0. and later versions.  Users are advised to verify the installed Orthanc DICOM Server version and download the latest version if a vulnerable version is in use. It is also recommended to restrict network access to Orthanc instances to trusted hosts only.

The post Orthanc DICOM Server Vulnerability Can Lead to Denial of Service appeared first on The HIPAA Journal.

Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits

Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data security incidents that exposed patient information.

Central Maine Medical Center Data Breach Settlement

Central Maine Medical Center, a Lewiston, Maine-based nonprofit healthcare provider, has agreed to pay $1,368,025 to settle a consolidated class action lawsuit stemming from a 2025 cyberattack and data breach.

The attack was identified on June 1, 2026, and caused the shutdown of IT systems, network servers, and its phone system. The forensic investigation determined that hackers had access to its network between March 19, 2025, and June 1, 2025, and potentially obtained personal and protected health information. According to the lawsuit, notification letters were mailed to 218,884 individuals.

Six putative class action lawsuits were filed in response to the data breach, alleging that Central Maine Healthcare was at fault as reasonable and appropriate cybersecurity measures had not been implemented. The lawsuits were consolidated into a single complaint – In re Central Maine Data Security Litigation – naming the defendants Central Maine Healthcare Corporation and Central Maine Medical Center. The defendants deny all claims and contentions in the lawsuit, including claims of fault, wrongdoing, and liability. The lawsuit was settled to avoid the time, cost, and uncertainty of continued litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement fund will be used to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The remainder of the settlement fund will be used to pay benefits to the class members. Class members may claim one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be around $60 per class member.  In addition to one of those payments, class members may claim a one-year membership to a medical record monitoring service. The deadline for objection and opting out is September 13, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 28, 2026.

Susan B. Allen Memorial Hospital Data Breach Settlement

A settlement has been agreed to resolve class action litigation against the Butler, Kansas acute-care medical facility, Susan B. Allen Memorial Hospital, to resolve claims stemming from a July 2025 cyberattack and data breach. Hackers gained access to its network and potentially obtained personal and protected health information. The data breach was initially reported to the HHS’ Office for Civil Rights as affecting up to 12,097 individuals, although the HHS’ Office for Civil Rights breach portal has since been updated to indicate that only 11,866 individuals had protected health information compromised in the incident.

Four putative class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims and classes. The consolidated lawsuit, In Re: Susan B. Allen Data Security Litigation, is pending in the District Court of Butler County, Kansas. The plaintiffs allege that the hospital was at fault for the data breach as it failed to implement appropriate cybersecurity measures, and the defendant maintains there was no wrongdoing. A settlement was agreed to avoid the cost, time, distraction, and uncertainty of continued litigation.

The settlement provides two years of credit monitoring and identity theft protection services for all class members. In addition, a claim may be submitted for reimbursement of out-of-pocket losses due to the data breach up to a maximum of $100 per class member. In addition, a claim may be submitted for reimbursement of up to four hours of lost time at $25 per hour. Claims have been capped at an aggregate of $100 per class member. Claims must be submitted by November 12, 2026. Individuals wishing to object to the settlement or exclude themselves must do so by October 13, 2026. The final fairness hearing has been scheduled for December 7, 2026.

The post Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect

Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration.

CVE-2026-82583 could be exploited by an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in the disclosure of stored credentials for connected systems, allow arbitrary file write, and trigger a denial-of-service condition. The vulnerability has been assigned a CVSS v3.1 severity score of 8.3 (v4:0: 7.2)

CVE-2026-78224 is due to the XSLT Transformer Step building a bare TransformerFactory without the proper security options set, which could allow data exfiltration and denial-of-service attacks via XXE injection. The vulnerability has a CVSS v3.1 severity score of 8.2 (v4.0: 8.8)

CVE-2026-82578 can also allow data exfiltration and denial-of-service attacks via XXE injection. When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions. The vulnerability has a CVSS v3.1 severity score of 7.5 (v4.0: 8.7)

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All three vulnerabilities affect v4.7.1 and earlier versions. NextGen has fixed all three vulnerabilities in Mirth Connect v4.7.2. Customers have been advised to update to the latest fixed version as soon as possible. The latest version can be downloaded from the NextGen Healthcare customer portal.

The post High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect appeared first on The HIPAA Journal.

Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data

The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).

According to the September 8, 2026, filing, Veradigm recently learned that one of its third-party vendors had experienced a cybersecurity incident that impacted a small number of Veradigm’s customers. Veradigm explained that a threat actor obtained credentials from the vendor’s environment for a Veradigm Application Programming Interface (API) used for customer services. The threat actor was able to use the access to copy patient data.

The threat actor only had access to the API, and no other parts of its network were compromised, including servers, databases, or other systems. Veradigm determined that data stolen in the incident included the personal information of patients, which for certain patients may have involved their Social Security numbers; however, the company has determined that clinical and medical information was not involved and remained secure. As a precaution against data misuse, Veradigm is offering the affected individuals complimentary credit monitoring services.

The investigation is ongoing, and Veradigm has yet to publicly disclose how many individuals have been affected. The company said the incident did not impact its operations, and while the extent of any potential liabilities associated with the incident has not yet been determined, the company does not believe the incident is reasonably likely to have a material impact on the company’s business, operations, financial condition, or results of operations.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Veradigm did not disclose the name of the threat actor behind the attack, which appears to be a prolific threat group called The Gentlemen. The Gentlemen added Veradigm to its dark web data leak site on September 5, 2026. The posting alleges that data exfiltrated in the attack includes names, addresses, phone numbers, email addresses, and other personally identifiable information, and that 3.5 million patient records have been obtained. A threat has been issued to publish the stolen data if the ransom is not paid.

The post Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data appeared first on The HIPAA Journal.