Neinstein Plastic Surgery in New York and Atlantic Brain and Spine in North Carolina have announced security incidents that exposed patient information.
Neinstein Plastic Surgery, New York
Neinstein Plastic Surgery in New York City has identified unauthorized access to an email account that contained sensitive patient information. Unauthorized activity was identified in the email account on December 2, 2025. The account was secured, and an investigation was initiated to determine the nature and scope of the activity. The investigation confirmed that the account had been accessed by an unauthorized individual between November 12, 2025, and November 20, 2025, and that this was a financially motivated attack rather than an attempt to obtain patient information; however, patient information may have been obtained in the incident.
The account was reviewed and on February 20, 2026, Neinstein Plastic Surgery confirmed that emails and documents in the account contained information such as names, contact information, dates of birth, driver’s license or passport numbers, Social Security numbers, credit card or financial account information, health insurance information, and clinical information, which may have included healthcare provider names, diagnoses, and treatment information. The types of information involved vary from individual to individual.
The incident was reported to law enforcement, additional technical safeguards have been implemented to improve email security, and further employee training has been provided. While there has been no known misuse of patient information, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The data breach has been reported to the appropriate authorities, although it is currently unclear how many individuals have been affected.
Atlantic Brain and Spine, North Carolina
Wilmington, North Carolina-based Atlantic Brain and Spine has disclosed a January 2026 cybersecurity incident. Suspicious activity was identified within its computer network on January 26, 2026. Third-party specialists were engaged to investigate the incident and confirmed that certain patient data had been accessed by an unauthorized third party.
The exposed data is still being reviewed; however, Atlantic Brain and Spine determined that the impacted data includes names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, financial account information, treatment/diagnosis information, prescription/medication information, dates of service, provider names, medical record numbers, patient account numbers, Medicare/Medicaid ID numbers, health insurance information, and/or medical billing/claims information. The types of data involved vary from individual to individual.
Atlantic Brain & Spine is working with third-party cybersecurity specialists to implement additional measures to prevent similar incidents in the future and is reviewing its policies and procedures related to data privacy and security. Since the review is ongoing, it is unclear how many individuals have been affected at this moment in time.
The post Data Breaches Announced by Neinstein Plastic Surgery; Atlantic Brain and Spine appeared first on The HIPAA Journal.