Valley Oaks Health Data Breach Settlement Gets First Nod from Court

Valley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated lawsuit has recently been settled. Hackers accessed the Valley Oaks Health network between June 8, 2023, and June 13, 2023, and potentially obtained files containing names, Social Security numbers, driver’s license numbers, state ID numbers, credit/debit card numbers, access codes/passwords, biometric data, and other sensitive information.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In re: Valley Oaks Data Incident Litigation – as the lawsuits had overlapping claims and classes. The consolidated lawsuit is pending in the Superior Court for Tippecanoe, Indiana. The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, and unjust enrichment, all of which are denied by Valley Oaks Health, which maintains there was no wrongdoing.

Valley Oaks Health sought to have the lawsuit dismissed; however, the motion to dismiss was rejected by the court. A full day of mediation did not result in a settlement; however, after several months of negotiations, a settlement was agreed to avoid the cost, delay, and risks of protracted litigation.  The settlement has recently received preliminary approval from the court.

Valley Oaks Health has agreed to pay attorneys’ fees and expenses, settlement notification and administration costs, and service awards for the seven class representatives (total of $17,500). Attorneys’ fees are capped at $450,000. Claims may be submitted for reimbursement of up to $500 in documented, unreimbursed ordinary losses due to the data breach, including up to four hours of lost time at $20 per hour. A claim may also be submitted for up to $5,000 as reimbursement for documented, unreimbursed extraordinary losses. If claims are not submitted for reimbursement of losses or lost time, a claim may be submitted for an alternative $40 cash payment. All class members are entitled to enroll in two years of medical data monitoring services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The deadline for opting out, objecting to the settlement, and submitting a claim is November 9, 2026. The final fairness hearing has been scheduled for December 10, 2026.

The post Valley Oaks Health Data Breach Settlement Gets First Nod from Court appeared first on The HIPAA Journal.

Bacon County Health Services Investigating Cyber Incident

Data breaches have been announced by Bacon County Health Services in Georgia, Comprehensive Orthopaedics & Musculoskeletal Care in Connecticut, Imagine the Possibilities in Iowa, and Health Plans Inc. in Massachusetts.

Bacon County Health Services

Bacon County Health Services, an Alma, Georgia-based nonprofit healthcare organization, is investigating a data security incident involving unauthorized access to systems containing patient information. Bacon County Health Services provides healthcare services to individuals in and around Alma through Bacon County Hospital, Twin Oaks Convalescent Center, and a rural health clinic.

Suspicious network activity was identified on July 27, 2026, and the forensic investigation determined that an unauthorized third party had access to its computer network between July 10, 2026, and July 27, 2026.  The investigation confirmed that files containing patient information were exfiltrated by the threat actor. The data review is ongoing, and the number of affected individuals and the types of data involved have yet to be determined. Notification letters will be mailed to the affected individuals when the data review is concluded. At the time of announcing the incident, no misuse of the affected data had been identified.

While the incident may not have affected all patients, Bacon County Health Services has warned all patients to remain vigilant against identity theft and fraud. To meet breach reporting requirements, the HHS’ Office for Civil Rights has been informed and provided with an estimate of at least 501 affected individuals. The total will be updated when the data review is concluded.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Comprehensive Orthopaedics & Musculoskeletal Care

Comprehensive Orthopaedics & Musculoskeletal Care, a Connecticut-based orthopedic practice, has recently notified the HHS’ Office for Civil Rights about a breach of the protected health information of 21,897 individuals. According to the practice’s substitute data breach notice, suspicious network activity was identified on February 12, 2026. Immediate action was taken to investigate the activity and secure its network, and it was confirmed that an unauthorized third party potentially accessed sensitive data.

The investigation and data review were completed on June 17, 2026, confirming that the impacted data included names, dates of birth, Social Security numbers, financial account numbers, payment card information, government-issued ID numbers, medical information, and health insurance information. While not described as a ransomware attack, a ransomware group called Crypto24 claimed to have exfiltrated sensitive data, including patients’ protected health information. The group has published the stolen data on its dark web data leak site.

Imagine the Possibilities

Imagine the Possibilities, an Iowa-based nonprofit organization that provides community-based support services for individuals with intellectual difficulties, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 1,693 individuals. The security incident occurred at one of its business associates, the Waterloo, IA-based insurance agency PDCM Insurance. Suspicious activity was identified within the PDCM Insurance network on April 28, 2025, and the forensic investigation confirmed unauthorized access to files and folders between April 27, 2025, and April 28, 2025. The review of the affected data was recently completed.

Data potentially compromised in the incident included names in combination with one or more of the following: date of birth, Social Security number, driver’s license number, state identification number, taxpayer identification number, financial account information, treatment information, diagnosis, treating/referring physician, prescription/medication information, group health insurance/subscriber number, medical policy number, individual health insurance/subscriber number, and/or medical record number. It is currently unclear how many of the company’s clients have been affected. PDCM Insurance said it has reviewed its security policies and procedures and has implemented additional safeguards to prevent similar incidents in the future.

Health Plans Inc.

Health Plans Inc., a Westborough, Massachusetts-based third-party administrator of self-funded employer health and benefit plans, has disclosed a cybersecurity incident involving one of its SaaS vendors. The number of affected individuals has yet to be publicly disclosed.

The incident involved Alegeus, a Waltham, Massachusetts-based provider of a SaaS platform for administering healthcare accounts. The data breach details have yet to be publicly disclosed, other than Social Security numbers being exposed. Alegeus has confirmed that it has taken steps to reduce the risk of similar incidents in the future and is offering the affected individuals two years of complimentary credit monitoring services.

The post Bacon County Health Services Investigating Cyber Incident appeared first on The HIPAA Journal.

Introducing Our New Cybersecurity Partner: Blue Team Alpha

Introducing Our New Cybersecurity Partner: Blue Team Alpha
Cyberattacks on healthcare organizations can do far more than expose data. They can disrupt patient care, take essential systems offline, interrupt revenue, and leave organizations facing costly recovery work, regulatory scrutiny, and lasting reputational damage.
That is why The HIPAA Journal has conducted an extensive search for a cybersecurity partner capable of helping healthcare organizations protect their operations and the electronic protected health information entrusted to them. We wanted a partner with deep technical expertise, first-hand experience responding to serious cyber incidents, a strong understanding of regulated industries, and the ability to support organizations before, during, and after an attack.
We chose Blue Team Alpha.
A Veteran-Owned Cybersecurity Firm with a Mission to Protect
Blue Team Alpha is a veteran-owned cybersecurity firm with a mission to help secure and defend America’s critical infrastructure. More than 65% of its experts have backgrounds with the U.S. Department of Defense, Department of Homeland Security, and other government organizations.
That experience is reflected in the company’s disciplined, mission-focused approach. Blue Team Alpha brings together specialists in incident response, digital forensics, penetration testing, security operations, risk management, and cybersecurity leadership. Its teams have worked across all 16 critical infrastructure sectors, including healthcare.
For healthcare organizations, that combination is particularly important. Protecting health information requires more than satisfying a compliance checklist. Organizations must understand where their real vulnerabilities are, take practical steps to reduce risk, detect threats quickly, and be ready to contain and recover from an incident when defenses are breached.
Blue Team Alpha has hands-on experience helping healthcare organizations address these challenges, including conducting penetration testing for a hospital, responding to cyber incidents affecting healthcare providers, supporting recovery for a dental provider, and delivering managed security operations services for healthcare organizations.
Why The HIPAA Journal Chose Blue Team Alpha
The HIPAA Journal’s goal was to find a partner that could offer healthcare organizations credible, practical support across the full cybersecurity lifecycle. Blue Team Alpha stood out for several reasons:
Proven incident-response capabilities: Its specialists are available around the clock to investigate attacks, contain threats, support recovery, and help organizations restore business-critical operations.
A highly experienced team: Blue Team Alpha combines military, government, and private-sector cybersecurity experience with a wide range of professional security certifications.
Support before, during, and after an incident: The firm can identify weaknesses, strengthen defenses, respond to active attacks, and help organizations improve their security following an incident.
Experience in healthcare and other critical sectors: Its team understands that downtime and data loss in healthcare can affect both business operations and patient care.
A practical approach to risk: Assessments are designed to identify and prioritize risk and provide an actionable path for improvement, rather than simply generating another report that sits unused.
Cybersecurity Services Available to Healthcare Organizations
Through our partnership, HIPAA Journal readers can access Blue Team Alpha’s broad range of cybersecurity services, including:
Emergency Incident Response and Recovery
Blue Team Alpha provides 24/7 support for organizations experiencing ransomware, malware, data breaches, business email compromise, insider threats, and other security incidents. Services include rapid breach assessment, containment, threat eradication, digital forensics, system restoration, and assistance with re-establishing business continuity.
Digital Forensics and Incident Investigation
Digital forensics and incident response services help determine what happened, how attackers gained access, which systems and data may have been affected, and whether the threat has been fully removed. Blue Team Alpha also offers memory forensics, compromise assessments, and anomaly investigation and analysis.
Penetration Testing
Penetration testing goes beyond an automated vulnerability scan by emulating the techniques a real attacker may use to gain access to systems and data. Blue Team Alpha combines testing technology with manual analysis by experienced specialists to uncover weaknesses and provide prioritized recommendations for remediation.
Vulnerability Assessments and Vulnerability Management
Blue Team Alpha can identify technical vulnerabilities, prioritize them according to risk, track security improvements over time, and assist with remediation. This gives healthcare organizations a clearer understanding of which weaknesses require the most urgent attention.
Ransomware Readiness Assessments and Tabletop Exercises
Ransomware readiness assessments help organizations identify gaps in their ability to prevent, respond to, and recover from an attack. Tabletop exercises allow leadership, IT, security, compliance, legal, and communications teams to test their response plans in a controlled environment before they face a real emergency.
Managed Security Operations and Threat Detection
Blue Team Alpha’s managed security services include security monitoring, managed detection and response, ransomware protection, security information and event management, log ingestion, and managed security awareness and phishing training.
Virtual CISO Services
Organizations that do not need or cannot justify a full-time Chief Information Security Officer can access strategic cybersecurity leadership through Blue Team Alpha’s virtual CISO service. This can include risk assessment, security planning, policy development, incident-response planning, oversight, and support for regulatory and contractual requirements.
Cybersecurity Risk Assessments and Compliance Assistance
Blue Team Alpha conducts risk assessments to help organizations identify threats, vulnerabilities, control weaknesses, and compliance gaps. The resulting recommendations can help leadership prioritize investments and develop a practical risk-treatment plan. The company also provides compliance assistance for frameworks and standards that include HIPAA, HITRUST, and the NIST Cybersecurity Framework.
Incident Response Retainers and Cyber Insurance Preparation
Incident response retainers give organizations access to a team that is prepared to act when an incident occurs, reducing delays at a time when every hour matters. Blue Team Alpha can also help organizations review their preparedness for cyber insurance applications and requirements.
A Free Cybersecurity Risk Analysis Consultation for HIPAA Journal Readers
To celebrate the new partnership, Blue Team Alpha is offering HIPAA Journal readers a free 30-minute cybersecurity risk analysis consultation, normally valued at $250.
The session will be tailored to your organization’s needs. You can use the time to obtain specific advice about a cybersecurity concern, discuss a known or suspected weakness, review an area of your security program, or identify the most important next steps for reducing risk.
The consultation can also serve as the starting point for your organization’s annual HIPAA security risk assessment. In 30 minutes, a Blue Team Alpha specialist can help clarify the scope of the assessment, identify the people and information that will be needed, discuss likely areas of exposure, and help you determine what to prioritize. The consultation is not, by itself, a complete HIPAA Security Rule risk analysis, but it can help you begin the process with clearer direction and expert support.
Whether you have an immediate question or want to take a more proactive look at your organization’s security posture, this is an opportunity to speak directly with an experienced cybersecurity professional and receive practical guidance tailored to your organization.
Book Your Free 30-Minute Cybersecurity Risk Analysis Consultation

The post Introducing Our New Cybersecurity Partner: Blue Team Alpha appeared first on The HIPAA Journal.