TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries – The HIPAA Journal
TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries
Data breaches have been announced by TriWest Healthcare Alliance, Texas Medicaid and Healthcare Partnership, the Minnesota Health Insurance Network, and Secure Health Plans of Georgia.
TriWest Healthcare Alliance
TriWest Healthcare Alliance, a contractor that manages care for active duty, retired, and National Guard and Reserve military personnel and their family members under the United States Department of Veterans Affairs VAPCCC program, has shared information on a data breach reported to the HHS’ Office for Civil Rights on May 21, 2026. According to the OCR breach report, the protected health information of 11,848 individuals was potentially compromised in the incident.
The security incident was first identified on April 16, 2026. The forensic investigation confirmed that an unauthorized third party gained limited access to parts of its network and downloaded files containing protected health information. Data compromised in the incident includes names, Department of Defense Benefits Numbers, beneficiaries’ ZIP codes, and health-related information. Only 5 individuals had their addresses, dates of birth, and Social Security numbers stolen.
At the time of issuing notification letters, some of which were sent on July 2, 2026, no misuse of the impacted information had been identified; however, as a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring services for 24 months. Security controls have been enhanced, system monitoring tools have been strengthened, and additional security awareness training has been provided to its workforce.
Texas Medicaid and Healthcare Partnership
Texas Medicaid and Healthcare Partnership (TMHP), a state Medicaid contractor, has recently reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 2,045 individuals. According to the TMHP substitute data breach notice, this was a fraud-related incident that involved unauthorized access to certain internal systems between February 5, 2026, and March 26, 2026.
When the unauthorized access was detected, immediate action was taken to contain the incident and secure its network, and additional security measures have been implemented to harden security. The forensic investigation determined on April 20, 2026, that personal and protected health information of 1,828 Medicaid clients and 217 healthcare providers had been exposed.
For Medicaid clients, the data compromised in the incident included full names, addresses, dates of birth, Social Security numbers, Medicaid numbers, Medicaid benefits information, Medicaid card information, and health information. Healthcare provider information included full names, addresses, emails, medical license information, financial information, driver’s license numbers, Social Security numbers, tax identification numbers, and other provider enrollment management system information.
Notification letters were mailed to the affected individuals on June 18, 2026, who have been offered complimentary identity theft protection and identity recovery services. TMHP said that at the time of issuing notifications, no information had been found to indicate any actual or attempted misuse of the impacted information.
Minnesota Health Insurance Network
Minnesota Health Insurance Network, a Burnsville, MN-based health insurance brokerage, has started notifying individuals about a recent security incident that exposed personal and protected health information. The security incident was identified on March 17, 2026, and its forensic investigation determined that there had been unauthorized access to parts of its network between March 16 and March 17, 2026, during which time files were exfiltrated from its network.
The affected data has been reviewed and found to include names, dates of birth, Social Security numbers, driver’s license/state ID numbers, other government-issued ID numbers, financial account numbers, credit/debit card information, diagnosis and treatment information, and health insurance information. Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While regulators have been notified, the incident is not currently listed on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.
Secure Health Plans of Georgia
Secure Health Plans of Georgia (Secure Health), a provider of administrative services, care management, and healthy lifestyle programs to employers with self-funded health benefit plans, is reviewing files that were exposed in a recent cybersecurity incident. The incident was identified on February 12, 2026, and the forensic investigation confirmed unauthorized access to its systems on or before February 3, 2026, until February 12, 2026. During that time, files containing individuals’ protected health information may have been viewed or copied. Secure Health has not yet confirmed the exact types of information exposed in the incident, although protected health information was exposed.
The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 individuals. The total will be updated when the data review is concluded, and notification letters will be mailed stating the types of data involved. Secure Health has taken steps to strengthen security to prevent similar incidents in the future.
The post TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries appeared first on The HIPAA Journal.
Clover Health Assessing Impact of Social Engineering Incident
Clover Health Investments has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident first identified on July 4, 2026. Clover Health Investments is a publicly traded health insurer that provides Medicare Advantage plans, directly contracts with the U.S. government, and manages care for Medicare beneficiaries in 11 states. The company also provides technology and software tools to physicians.
Unusual login activity was identified, and its forensic investigation confirmed that a hacker had accessed three employee email accounts after the employees had been tricked by social engineering into disclosing their credentials. Clover Health activated its incident response plan to contain the incident and believes that unauthorized access has been terminated.
Clover Health said the compromised accounts belonged to non-managerial health plan employees who were responsible for handling member visit scheduling and broker-facing sales work. The accounts did not have permissions to access corporate financial or claims systems, but they could access some personal and protected health information.
The volume of exposed data has yet to be determined, and Clover Health has not publicly confirmed whether sensitive data was exfiltrated from its systems. Clover Health has reported the incident to law enforcement and is working with third-party cybersecurity experts to investigate the incident and review the information that was exposed, viewed, or exfiltrated.
Clover Health said it does not believe that the incident has had a material impact on business operations, its financial condition, or results of operations. Notifications will be mailed to the affected individuals if it is determined that HIPAA-protected data has been exposed or stolen, and Clover Health has confirmed that steps are being taken to strengthen security to prevent similar incidents in the future.
The post Clover Health Assessing Impact of Social Engineering Incident appeared first on The HIPAA Journal.
Supervisors consider AI use policy for its HIPAA program – Kalona News
$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation – The HIPAA Journal
$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation
Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved unauthorized access to systems containing the personal and protected health information of 624,496 individuals.
Healthcare Services Group is a Bensalem, PA-based provider of environmental, dining, and nutritional support services, and works with more than 3,000 healthcare facilities in 48 U.S. states. Suspicious network activity was identified on or around October 7, 2024, and the forensic investigation determined that its network was first breached by an unauthorized third party on September 27, 2024.
Prompt action was taken to prevent further unauthorized access, but files containing protected health information had already been exfiltrated from its network. Those files contained information such as names, Social Security numbers, driver’s license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information.
Notification letters started to be mailed to the affected individuals on August 25, 2025, and on August 27, 2025, the first class action lawsuit was filed. Further lawsuits were filed that made similar claims, and the actions were consolidated into a single complaint – Williamson, et al. v. Healthcare Services Group, Inc. – in the United States District Court for the Eastern District of Pennsylvania.
The consolidated lawsuit asserted claims for negligence, breach of implied contract, breach of contracts to which the plaintiffs and class members were intended third-party beneficiaries, breach of fiduciary duty, unjust enrichment, violations of the New Jersey Consumer Fraud Act and Washington Consumer Protection Act, and declaratory and injunctive relief.
Healthcare Services Group denies any wrongdoing and disagrees with all claims and contentions in the lawsuit. All parties agreed to a settlement as they concluded that further litigation would likely be expensive and protracted, and by settling, all parties avoid the uncertainty and risks of a trial.
Healthcare Services Group has agreed to establish a $3,000,000 settlement from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class members will be deducted. The remaining funds will be used to pay benefits to the class members. Class members are entitled to claim three years of single-bureau credit monitoring services, which include identity theft insurance and identity theft recovery services.
A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member, and a claim may also be submitted for a one-time pro rata cash payment. The cash payments will exhaust the settlement fund, and their value depends on the number of valid claims received. Requests for exclusion and objections must be submitted by September 4, 2026. The deadline for submitting a claim is October 1, 2026, and the final fairness hearing is scheduled for September 24, 2026.
The post $3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation appeared first on The HIPAA Journal.