Colorado Behavioral Healthcare Provider Discovers Insider Data Breach
Data breaches have been announced by NAS Recovery Solutions, Entyre Care Massachusetts, Carle Health, and Brown Health Medical Group-MA.
NAS Recovery Solutions
NAS Recovery Solutions, a Lakewood, Colorado-based substance use disorder treatment and behavioral health services provider, has announced a data breach affecting up to 7,000 current and former clients. According to the company’s breach notice, this was an insider breach rather than a hacking incident. The company learned on May 13, 2026, that certain workforce members had downloaded client data without authorization.
The investigation revealed only limited information had been copied, such as first and last names, dates of birth, and telephone numbers; however, since NAS Recovery Solutions is a substance use disorder (SUD) treatment provider, it could be inferred that the individuals were receiving SUD treatment. There are no indications that any other information was obtained by the workforce members. The breach notice does not provide any clue as to why that information was obtained.
NAS Recovery Solutions said it has reviewed workforce access and security controls and is implementing additional safeguards to prevent similar incidents in the future. Additional training has been provided to the workforce on HIPAA and patient privacy, and appropriate corrective action has been taken against the workforce members involved. The sanctions imposed were not disclosed in the notice.
Entyre Care Massachusetts
Entyre Care Massachusetts Inc., a Boston, MA-based home healthcare company, has discovered that an employee accidentally published files containing personal information in a publicly accessible online repository on March 2, 2026. The exposed files were identified on March 12, 2026, and were immediately secured.
The investigation uncovered no evidence to suggest that the files had been accessed or downloaded; however, it was not possible to rule out unauthorized access during the period of exposure. The files only contained limited information, such as names, ages, and Medicaid IDs; however, out of an abundance of caution, the affected individuals have been offered 24 months of complementary credit monitoring and identity theft protection services.
Carle Health
Carle Health, an Illinois nonprofit health system, has confirmed that 1,444 of its patients were affected by a data breach at its vendor Xsolis in January 2026. Xsolis is a vendor that provides an AI-powered software platform to healthcare providers to improve case and utilization management. We have covered the data breach, which affected more than 1.4 million individuals, in this post. Carle Health said the compromised information included names, birth dates, diagnoses, treatment dates and locations, medical record numbers, doctors’ names, Social Security numbers, and health insurance information.
Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts)
Lifespan Physicians Group of Massachusetts Inc., which does business as Brown Health Medical Group-MA, has recently announced that the sensitive data of certain patients has been exposed. According to the notification to the Vermont Attorney General, the impacted data includes names, Social Security numbers, government identification numbers, financial account codes, and health records. The incident affected 86 Vermont residents, but it is currently unclear how many individuals have been affected in total.
The post Colorado Behavioral Healthcare Provider Discovers Insider Data Breach appeared first on The HIPAA Journal.
Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data – The HIPAA Journal
What Counts as Health Privacy for Remote Workers – quasa.io
Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data
The cardiovascular medical practice, Heart Care Centers of Illinois (HCCI), announced on July 18, 2026, that certain patients had some of their personal and protected health information exposed in a phishing attack.
HCCI said it launched an investigation into an unsuccessful phishing attempt and discovered a historical suspicious activity within an employee’s email account on January 15, 2026. Third-party digital forensics experts were engaged to investigate the activity and confirmed that an unauthorized third party gained access to the account between August 22, 2024, and November 6, 2024.
A data analytics firm was engaged to review the account. On June 11, 2026, the review was completed, confirming that the following types of information were present in the account: names, addresses, telephone/fax numbers, Social Security numbers, dates of birth, driver’s license numbers/state identification numbers, payment card information, financial account numbers, passport numbers, diagnosis/condition information, prescription information, treatment information, health insurance information, and provider information.
The affected individuals were notified on July 10, 2026, and complimentary credit monitoring and identity restoration services have been offered. HCCI has reviewed its existing policies and procedures and has taken steps to reduce the risk of similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.
Madera Community Hospital
Madera Community Hospital in California has notified the California Attorney General about a security incident involving unauthorized access to its network between May 28 and May 29, 2025. The unauthorized access was identified on May 29, 2025, and action was immediately taken to secure its network and prevent further unauthorized access.
Third-party cybersecurity experts were engaged to investigate the incident. No evidence was found to indicate any removal of data; however, the hospital said, “based on subsequent developments, we have reason to believe that a third party acquired files from a portion of its network.” No further information was provided on what that evidence was. The hospital did state that it has not found definitive proof that any data was removed, and none of the impacted data appears to have been published or otherwise shared.
The data review was completed in April 2026, contact information was verified, and notification letters have now been mailed to the affected individuals. Data exposed in the incident includes names, birthdates, contact information, login credentials, government identification numbers (such as Social Security numbers), financial account information, and limited medical information and limited biometric information. The affected individuals have been offered complementary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have potentially been affected.
The post Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data appeared first on The HIPAA Journal.
Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company – The HIPAA Journal
Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company
Security incidents have resulted in the exposure of patient data at United Technology Systems, Meridian Health Plan of Illinois, and Little Flower Children and Family Services.
Unlimited Technology Systems
Unlimited Technology Systems LLC (UTS), a Montgomery, Ohio-based revenue cycle management company and practice management software provider, has identified unauthorized activity within a commercial data center that contained the personal and protected health information of patients of its healthcare provider clients.
According to its data breach notification letter, unauthorized activity was identified on October 19, 2025. Assisted by a third-party cybersecurity and digital forensics company, UTS determined that an unauthorized third party may have obtained a copy of files from that environment between October 5 and October 10, 2025.
The data review has recently been completed, and UTS has confirmed that the following types of information may have been involved: name, address, email address, phone number, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned documents such as driver’s license or other government ID documents. UTS said full medical records, medical images, and financial information were not involved.
As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring services for 24 months, and UTS has implemented enhanced security measures to prevent similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.
Meridian Health Plan of Illinois
Meridian Health Plan of Illinois, a government-sponsored managed care service provider, has announced a data breach affecting 21,027 individuals. The incident was detected on April 28, 2026, when unauthorized access to the Meridian provider portal was identified. The provider portal is used by healthcare providers to manage patient information and process claims.
The unauthorized access was blocked, and an investigation was launched to determine the nature and scope of the breach. Meridian Health Plan has confirmed that personally identifiable information such as member names, contact information, and dates of birth had been exposed, along with protected health information such as Member ID numbers, health plan names, eligibility and claims information, and provider information. At the time of issuing notification letters, no misuse of the exposed information had been identified. Credit monitoring and identity theft protection services do not appear to have been made available.
Little Flower Children and Family Services
Little Flower Children and Family Services, a New York-based provider of support services to individuals with developmental disabilities and their families, has recently issued notification letters to individuals informing them that some of their information was exposed in a recent security incident.
Unusual network activity was identified on March 20, 2026, and the forensic investigation confirmed unauthorized access to its network between March 12, 2026, and March 20, 2026. While the review of the affected data is ongoing to determine the specific information exposed, Little Flower Children and Family Services said the types of data likely compromised in the incident include the following:
Name, address, phone number, email address, date of birth, Social Security number, driver’s license number, state ID number, taxpayer ID number, passport number, financial account information, payment card information, digital signature, biometric data, diagnosis and treatment information, prescription information, Medicare/Medicaid number, health insurance information, and treatment cost information. The affected individuals are being offered complementary credit monitoring and identity theft protection services, and steps have been taken to improve security to prevent similar incidents in the future.
The post Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company appeared first on The HIPAA Journal.