Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack

Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US).

Midwest Spine and Brain Institute (3C Care Systems)

Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems. According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation.

The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C Care Systems. The investigation concluded on June 18, 2026, revealing that personally identifiable information and protected health information was potentially involved, including first and last names in combination with one or more of the following: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service, and health insurance claim and/or policy information.

MSBI is mailing notification letters to the affected individuals and has offered complimentary identity monitoring and protection services to individuals whose Social Security numbers were involved. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many MSBI patients have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

No information was provided as to the nature of the data breach, but this appears to have been a ransomware attack by the now-disbanded RansomHub ransomware operation on or around November 21, 2024. RansomHub claimed it had exfiltrated 100 GB of data from 3C Care Systems, although no separate breach announcement appears to have been made by the IT company, and those claims remain unverified. It is unclear if clients other than MSBI had data compromised in the incident.

Brookhaven ENT Allergy and Facial Surgery

Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, has notified 30,403 individuals that some of their personal and protected health information was compromised in a recent cybersecurity incident. The incident involved a third-party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. The CareCloud breach listing on the OCR data breach portal indicates that 3.75 million individuals were affected.

The incident occurred between March 10, 2026, and March 16, 2026, and the file review determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information had potentially been compromised. You can read more about the CareCloud data breach in this post. At the time of issuing notifications, no actual or attempted misuse of the impacted data had been identified.

Silver Summit Medical Corporation (Digestive Disease Center and Heart Vascular & Leg Center), California

Silver Summit Medical Corporation, doing business as the Digestive Disease Center and Heart Vascular & Leg Center, has notified certain patients about a cybersecurity incident at a third-party vendor that exposed some of their protected health information. The Bakersfield, California-based ambulatory surgical center learned about the incident on or around July 20, 2026. The investigation determined that an unauthorized third party accessed the unnamed vendor’s systems from November 27, 2025, to November 30, 2025, and exfiltrated files containing personal and protected health information.

The data review determined that the exfiltrated files contained names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, taxpayer identification numbers, passport numbers, and/or other government identifiers. Protected health information included diagnoses, treatment information, prescription information, and health insurance information. The affected individuals were notified on August 19, 2026, and complimentary credit monitoring and identity theft protection services have been made available. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so the number of affected individuals is not yet known.

Premier Medical Group of the Hudson Valley, New York

Premier Medical Group of the Hudson Valley, a Poughkeepsie, New York-based multispecialty practice, has started notifying patients impacted by a cybersecurity incident this summer. The incident disrupted certain IT systems, and the forensic investigation determined that there was unauthorized access to files containing patient information on June 14, 2026. The substitute data breach notice on the practice’s website does not state when the incident was detected.

The review of the affected data determined on July 14, 2026, that the exposed files included patient names, contact information, dates of birth, health insurance information, provider names, patient identification numbers, dates of service, medications, and diagnostic and treatment information. Premier Medical Group said it will continue to evaluate and implement enhanced safeguards and security measures to protect its systems from unauthorized access and continue to provide security training to its workforce. The number of affected individuals has yet to be publicly disclosed.

Risk Program Administrators

Risk Program Administrators LLC (RPA), a California-based insurance program administration and management firm, has notified 8,309 individuals about the exposure of some of their personal and protected health information earlier this year. On or around June 16, 2026, RPA identified suspicious activity within an employee’s email account. The account was secured, and an investigation was launched, which confirmed that the account, and certain emails within that account, had been accessed by an unauthorized third party between May 27, 2025, and June 16, 2025.

The account was reviewed and found to contain information such as names, dates of birth, Social Security numbers, financial account information, health insurance information, and medical information, including treatment types, locations, costs, physician information, mental or physical condition, subscriber member numbers, and admission dates.

TELUS Health (US)

TELUS Health (US) LTD., a Canton, Massachusetts-based digital health and wellness provider part of the Canadian telecommunications company TELUS, has disclosed a data breach that involved unauthorized access to systems containing protected health information. Telus Health’s announcement on its website states that the investigation is ongoing, and it has yet to publicly disclose the types of information compromised in the incident. It is unclear exactly when the attack occurred; however, it appears to have occurred in January 2026. The ShinyHunters threat group claimed responsibility for the attack and the exfiltration of 1 petabyte (1,000 TB) of data.

The threat group communicated with Bleeping Computer, which reported in March 2026 that systems were breached using compromised Google Cloud credentials obtained in the Salesloft Drift breach. While the breach had the potential to be massive, it was recently reported to the HHS’ Office for Civil Rights as involving the protected health information of just 2,641 individuals. TELUS Health said it has implemented additional security safeguards to better safeguard the data within its environment.

The post Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack appeared first on The HIPAA Journal.

Five Healthcare Providers Report Ransomware-Related Data Breaches

Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.

Alta Orthopaedics Medical Group, California

Alta Orthopaedics, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, has recently confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen in a cybersecurity incident earlier this year. Unusual network activity was identified on March 10, 2026, and the investigation determined that an unauthorized third party had accessed information on its network between February 3, 2026, and February 6, 2026.

The review of the affected data was completed on June 24, 2026. Personally identifiable information potentially compromised in the incident included names, contact information, Social Security numbers, driver’s licence numbers/state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth, and login information. Protected health information compromised in the incident included diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information, and biometric data.

Notification letters have been mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been made available for 24 months. While not mentioned in the notification letters, this appears to have been a ransomware attack. The INC Ransom ransomware group claimed responsibility for the attack and said 26 GB of data was exfiltrated. The data was subsequently leaked.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Cornerstone Behavioral Healthcare, Maine

Cornerstone Behavioral Healthcare, a Worcester, Maine-based mental health and substance use disorder treatment provider, has notified patients that some of their protected health information may have been compromised in a May 2026 ransomware attack. Cornerstone identified the attack on May 26, 2026, the same day that the attackers gained access to its network. The attacker’s access to its network was blocked within an hour of discovery, and computers on the affected parts of the network were powered down rapidly, limiting the extent of file encryption. Cornerstone said it believes that less than 10% of the data on the affected computers and servers was encrypted.

The initial findings of the investigation indicated that the protected health information of approximately 2,830 patients was compromised as a result of the attack, including names, addresses, other contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare information, and Social Security numbers. Further investigation determined on July 22, 2026, that a log of appointment reminders was also compromised, which included the protected health information of approximately 12,000 patients. The log data included names, birth dates, appointment times, and reminders of documentation due.

The investigation has now been completed, and the HHS’ Office for Civil Rights has been informed that, in total, the protected health information of 14,830 patients was potentially compromised in the incident. Cornerstone explained in its refreshingly detailed breach notification letter that it received a ransom demand but did not pay. All affected computers were wiped, new computers were purchased, and all systems, policies, and procedures have been reviewed. Additional security measures have been implemented on its servers, and special training has been provided to the workforce on ransomware.

Cameron Regional Medical Center, Missouri

Cameron Regional Medical Center, a 60-bed acute care hospital in Cameron, Missouri, announced in August 2026 that it recently discovered that it was the victim of a sophisticated ransomware attack. The attack was detected on June 18, 2026, when files on its network were encrypted. In an announcement on August 18, 2026, the hospital explained that the investigation into the attack is ongoing; however, the initial findings indicate that patients’ protected health information was subject to unauthorized access and may have been exfiltrated from its network.

While the specific types of data involved for each patient have yet to be determined, Cameron Regional Medical Center said the information likely compromised includes names plus some or all of the following:  home addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient ID numbers, agency-assigned identification numbers, treatment cost information, health insurance information, electronic/digital signatures, and/or employer-assigned identification numbers.

Third-party cybersecurity experts have been engaged to investigate the attack and assist with evaluating and reinforcing its security measures to ensure optimal data security. At the time of issuing the notification, no actual or attempted misuse of patient data had been identified. Individual notification letters will be mailed to the affected individuals when the data review is concluded. While the name of the ransomware group was not disclosed, the Anubis ransomware group claimed responsibility and leaked some of the stolen data as proof of the attack, including patient information. The group claimed to have exfiltrated around 500 GB of data.

Suntree Internal Medicine, Florida

Suntree Internal Medicine, an internal medicine practice in Melbourne, Florida, has notified 9,810 individuals about a cybersecurity incident first identified on September 28, 2025. Unusual activity was identified in certain systems, and immediate action was taken to contain the incident. An investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts.

The investigation confirmed unauthorized network access and the exposure of files containing patient information. Those files may have been copied from its network, although at the time of issuing the breach notice, no misuse of patient information had been identified. The data review confirmed that the following information was exposed: names, addresses, treatment information, and health insurance information. Suntree Internal Medicine has implemented additional security measures to reduce the risk of similar incidents in the future. While the incident was not described as a ransomware attack, a ransomware group called INC Ransom claimed responsibility for the attack on its dark web data leak site. The listing states that data was exfiltrated.

Associated Endocrinologists, Michigan

Associated Endocrinologists, a consultative endocrinology practice with locations in Farmington Hills and Clarkston, Michigan, has started notifying 4,979 patients about a cybersecurity incident earlier this year. There is currently no substitute breach notice on the practice website, and the HIPAA Journal has been unable to find a press release about the incident, which was reported to the HHS’ Office for Civil Rights on July 29, 2026. It is currently unclear exactly what types of information were exposed or stolen in the incident. The RansomHouse ransomware group claimed responsibility for the attack on its data leak site in early February and claimed to have exfiltrated data and encrypted files on January 31, 2025

The post Five Healthcare Providers Report Ransomware-Related Data Breaches appeared first on The HIPAA Journal.

Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation

Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident that affected around 8.9 million individuals. MCNA is a provider of dental insurance in Florida, and a third-party administrator of dental benefits in other states and Puerto Rico. MCNA’s subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex.

The cybersecurity incident was identified on March 6, 2023, and the forensic investigation determined that an unauthorized third party accessed its network between February 22, 2023, and March 7, 2023, and potentially viewed or obtained private information. The investigation confirmed that sensitive data was exfiltrated from its network.

The compromised data included names, addresses, telephone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan names and numbers, and information related to the dental and orthodontic care provided. Notification letters started to be sent to the affected individuals on May 26, 2023.

The defendant was named in 25 putative class action complaints, the first of which was filed on June 5, 2023. The lawsuits were materially and substantively identical and were consolidated into a single complaint. The consolidated lawsuit alleged that MCNA was responsible for the data breach due to the failure to implement appropriate cybersecurity measures. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, violations of state consumer protection act statutes, and declaratory and injunctive relief.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

MCNA denies any wrongdoing and sought to have the complaint dismissed. The motion was granted in part and denied in part, and an amended complaint – Crowe, et al., v. Managed Care of North America, Inc., et al. – was filed in the United States District Court for the Southern District of Florida. The defendant’s motion to deny the amended complaint was denied by the court. The parties attended mediation, and a settlement was negotiated that was acceptable to all parties.

Under the terms of the settlement, MCNA will cover costs associated with the litigation, including attorneys’ fees up to $6,400,000 and litigation costs up to $1,313,000. All class members are entitled to enroll in two years of medical data monitoring services, valued at $179.40 per year per settlement class member. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $2,500 per class member. There is no alternative cash payment. Claims for reimbursement of losses have been capped at $2,500 per class member and will be paid pro rata if that cap is exceeded. MCNA has also agreed to make changes to its business practices and has implemented additional security measures to better protect sensitive data. The deadline for objection, opting out, and submitting a claim is October 19, 2026. The final fairness hearing has been scheduled for November 16, 2026.

The post Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation appeared first on The HIPAA Journal.

Nutex Health Confirms Sensitive Data Stolen in August Cyberattack

Nutex Health, a Houston, Texas-based healthcare management and operations company that delivers care through 27 micro-hospitals, specialty hospitals, and outpatient departments in 12 U.S. states, has disclosed a cyberattack involving the exfiltration of data from some of its servers. Nutex is currently investigating the incident to determine the extent of data theft, including whether provider, employee, or patient data were exposed or stolen.

The incident was disclosed in an August 24, 2026, Item 8.01 Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). Nutex explained that it recently learned of unauthorized activity related to data stored on its computer network. The company activated its incident response plan, implemented containment measures, and engaged an independent third-party cybersecurity response team and forensics experts to assist with the investigation and determine the extent to which data was exposed or stolen.

Per that filing, Nutex said the incident is still being assessed, and it has yet to determine whether private and confidential data was compromised in the incident. At the time, Nutex said it did not believe that the unauthorized access has, had, or is reasonably likely to have a material impact on the company’s business strategy, operations, financial condition or results of operations. Nutex did not disclose the name of the threat group behind the attack or whether it received a ransom demand, but it was aware that private and/or confidential information may be disclosed by the threat actor. At the time, no cybercriminal group had claimed responsibility for the attack.

Then, on August 31, 2026, Nutex filed an Item 1.05 Form 8-K filing with the SEC confirming that this is a material cybersecurity incident. The August 31, 2026, filing states that, “Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business, and financial information that is private and/or confidential.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Nutex also confirmed that the threat actor has threatened to publish the stolen data; however, the company has not yet identified any material impact on its business operations or financial reporting systems. Nutex is continuing to assess the impacted data and the extent to which patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated.

The threat group behind the attack on Nutex appears to be The Gentlemen, a ransomware-as-a-service (RaaS) operation that first appeared in mid-2025 and significantly ramped up attacks in 2026. While the group’s attacks appear to be opportunistic, the healthcare sector accounts for around 9% of its attacks. The Gentlemen engages in double extortion tactics, exfiltrating sensitive data and demanding a ransom to decrypt files and prevent the release of stolen data.

The post Nutex Health Confirms Sensitive Data Stolen in August Cyberattack appeared first on The HIPAA Journal.