Luminis Health Working to Restore Systems After Cyberattack
Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M.D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey.
Luminis Health, Maryland
Luminis Health, a nonprofit health system that includes Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, announced on September 4, 2026, that it has fallen victim to a cyberattack. The incident has affected both hospitals, which continue to serve patients, although certain appointments have had to be rescheduled. Currently, the phone system and MyChart patient portal remain offline.
Luminis Health said the priority continues to be providing safe, high-quality care to patients; meanwhile, third-party cybersecurity and legal experts have been engaged to investigate and rectify the incident and safely and securely restore access to the affected systems. The health system is currently unable to provide a timeline for how long those processes will take, and it is too soon to tell what extent, if any, that patient data was involved. Should it be determined that patient data was exposed or stolen, patients will be notified in due course. At present, no ransomware or data extortion group appears to have claimed responsibility for the attack.
Jeffrey David Reuben, M.D.
Jeffrey David Reuben, M.D., a Texas-based orthopedic surgeon serving patients at NW Surgery in Houston and medical centers in Bellaire, has recently reported a data security incident that has affected 17,017 current and former patients. The incident was identified on or around April 27, 2026, and assisted by third party cybersecurity professionals, it was confirmed that an unauthorized third party accessed systems containing patient information between April 18 and April 19, 2026.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The investigation and data review were completed on or around July 15, 2026, when it was confirmed that the exposed data included names, Social Security numbers, driver’s license numbers, government-issued ID numbers, and financial information. While no actual or attempted misuse of the affected data has been identified, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months.
Well Child
Well Child, a provider of school-based healthcare services through partnerships with school districts in Tennessee and Mississippi, has announced a cybersecurity incident that was first identified on June 1, 2026. All servers were immediately taken offline when the incident was identified to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. On June 5, 2026, the investigation confirmed that files containing sensitive personal information had been exfiltrated from a temporary storage server.
The investigation and data review are ongoing; however, it has been determined that the exfiltrated data included Vision Screening Reports, Vision Screening Data Files, Available Students Lists, and PEDS (Parents’ Evaluation of Developmental Status) assessment documents. In addition to student names, the files contained protected health information such as birth dates, medical record numbers, provider names, diagnoses, assessment/test results, treatment dates, and billing and/or procedure codes. For a limited number of individuals, Social Security numbers were also involved. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 500 individuals. The total will be updated when the data review is concluded.
Horizon Eye Care Laser & Eye Surgery Center
Horizon Eye Care Laser & Eye Surgery Center, an ophthalmology practice and eye surgery center with six locations in New Jersey, is investigating a network server hacking incident. Suspicious network activity was identified on or around June 8, 2026. Immediate action was taken to isolate the affected systems, and third-party cybersecurity experts were engaged to investigate the incident.
The investigation and data review are ongoing; however, it has now been confirmed that patient data was compromised in the incident, including names, demographic information, treatment information, and health insurance information. The breach has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 501 affected individuals, as the number of affected individuals has yet to be determined.
The post Luminis Health Working to Restore Systems After Cyberattack appeared first on The HIPAA Journal.
June 2026 Healthcare Data Breach Report – The HIPAA Journal
June 2026 Healthcare Data Breach Report
In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.
The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023.
Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals. While June’s victim total is substantial, the victim count is down 36.3% month-over-month, and 58.7% lower than the 12-month average of 10,906,096 individuals per month. It should be noted that the 12-month average is skewed by an unusually high total for October 2025.
The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.7% from a high of 54.4 million individuals in 2024, and down 22.1% from 2025.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The Biggest Healthcare Data Breaches Reported in June 2026
In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS. The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1.4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management. The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.
The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1.25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company. A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.
A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025. Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information.
| HIPAA-Regulated Entity | State | Covered Entity Type | Individuals Affected | Cause of Breach |
| Xsolis, Inc. | TN | Business Associate | 1,396,519 | Network server hacking incident |
| MCBS, LLC | GA | Business Associate | 1,261,464 | Data theft and extortion incident (PEAR) |
| Centers Lab NJ LLC | NJ | Healthcare Provider | 542,377 | Data theft and extortion incident (Worldleaks) |
| Anatomic and Clinical Laboratory Associates, P.C. | TN | Healthcare Provider | 169,626 | Network server hacking incident |
| Operation PAR, Inc. | FL | Business Associate | 145,714 | Data theft and extortion incident (Worldleaks) |
| Chicago Family Health Center | IL | Healthcare Provider | 90,000 | Network server hacking incident |
| Aitkin County Health and Human Services | MN | Business Associate | 83,114 | Phishing incident |
| Minnesota Epilepsy Group, P.A. | MN | Healthcare Provider | 80,061 | Network server hacking incident |
| Gay & Lesbian Community Services Center of Orange County, Inc. | CA | Healthcare Provider | 75,532 | Network server hacking incident |
| Colorado Health Network Inc. | CO | Healthcare Provider | 68,212 | Network server hacking incident – data theft confirmed |
| Women’s Center for Radiology | FL | Healthcare Provider | 66,422 | Network server hacking incident |
| Blue Fish Pediatrics | TX | Healthcare Provider | 62,150 | Network server hacking incident |
| NYC Health + Hospitals | NY | Healthcare Provider | 58,778 | Hacking incident at business associate |
| UnitedHealth Care Services, Inc. Single Affiliated Covered Entity | CT | Health Plan | 37,384 | Phishing incident at business associate |
| UnitedHealth Care Services, Inc. Single Affiliated Covered Entity | CT | Health Plan | 34,574 | Network server hacking incident |
| Kentucky Mountain Health Alliance | KY | Healthcare Provider | 30,830 | Network server hacking incident – data theft confirmed |
| Center for Hearing and Speech dba Texas Hearing Institute | TX | Healthcare Provider | 29,774 | Ransomware attack (Interlock) – data theft confirmed |
| Waveny LifeCare Network, Inc. | CT | Healthcare Provider | 27,113 | Network server hacking incident |
| Elara Caring | TX | Healthcare Provider | 22,172 | Hacking incident at third party vendor – data theft confirmed |
| Minidoka Memorial Hospital | ID | Healthcare Provider | 22,000 | Data theft and extortion incident (Blackwater) |
| Meridian Health Plan of Illinois | IL | Health Plan | 21,027 | Employee errors – Impermissible granting certain providers access to its network |
| City of Middletown | OH | Healthcare Provider | 20,608 | Ransomware attack – data theft confirmed |
| McLeod Physician Associates II | SC | Healthcare Provider | 19,553 | Malware identified on network server awaiting decommissioning |
| Optalis Management Solutions | MI | Healthcare Provider | 13,723 | Network server hacking incident |
| All About Women’s Care | CO | Healthcare Provider | 12,000 | Hacking incident via an employee VPN account – data theft confirmed |
In June, nine healthcare data breaches were reported to HHS with totals of 500 or 501 affected individuals. These totals are often used as placeholder figures when data reviews are ongoing and the 60-day reporting deadline under the HIPAA Breach Notification Rule is reached. HIPAA requires an estimate to be provided if the total number of affected individuals has yet to be determined. The data breaches in the table below may prove to be far larger than the initial breach report indicates. It may be several weeks or even months before the total number of affected individuals is confirmed.
| HIPAA Regulated Entity | State | Covered Entity Type | Individuals Affected | Cause of Breach |
| Gail J May Ltd d/b/a/ Insight Optical | IL | Healthcare Provider | 501 | Network server hacking incident at business associate |
| Community Health Center of Buffalo Inc. | NY | Healthcare Provider | 501 | Network server hacking incident |
| Cherry Street Services, Inc. | MI | Healthcare Provider | 501 | Network server hacking incident |
| Northeast Professional Caregivers | OH | Healthcare Provider | 500 | Email compromise |
| Columbia Orthopaedic Group | MO | Healthcare Provider | 500 | Network server hacking incident |
| Decatur Diagnostic Laboratory Inc. | AL | Healthcare Provider | 500 | Network server hacking incident |
| Ohio Living | OH | Healthcare Provider | 500 | Network server hacking incident |
| Signature Healthcare Corporation | MA | Healthcare Provider | 500 | Network server hacking incident |
| MVP VIP Holdco dba Heart of America Eye Care | MO | Healthcare Provider | 500 | Network server hacking incident |
Causes of June 2026 Healthcare Data Breaches
Out of the 25 data breaches affecting 10,000 or more individuals, all but one was due to hacking. Across all of June’s reported data breaches, 81.8% of the breaches were hacking/IT incidents, and 1,481,468 individuals were affected by those incidents – 89.7% of all individuals affected by data breaches in June. The average breach size was 81,091 individuals, and the median breach size was 6,504 individuals.
The largest unauthorized access/disclosure incident of the month – Meridian Health Plan of Illinois – affected 21,027 individuals and was due to employees granting healthcare providers access to a portal for managing patient information and processing claims that should not have been given access. There were 11 unauthorized access/disclosure incidents in June, accounting for 16.7% of the month’s data breaches, and 10,914 individuals were affected – 2.7% of the month’s affected individuals. The average breach size was 10,914 individuals, and the median breach size was 6,721 individuals. One improper disposal incident was reported affecting an estimated 1,000 patients. Paper records were disposed of along with regular trash, rather than being sent for shredding. No loss or theft incidents were reported in June.
Location of Breached Protected Health Information
The bar chart below shows the locations of breached protected health information in June 2026 healthcare data breaches. Network servers were the most common location of breached protected health information, followed by email accounts and electronic health records.
Data Breaches at HIPAA Regulated Entities
When a data breach occurs at a HIPAA-covered entity – healthcare provider, health plan, or healthcare clearinghouse – the HIPAA Breach Notification Rule requires them to report the breach within 60 days of discovery. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within the same time frame.
The affected covered entities are ultimately responsible for ensuring that notifications are issued to the HHS, individuals, and in some cases the media, within 60 days of being notified. A HIPAA-covered entity may delegate the notification responsibilities to the business associate. Some choose to issue notifications themselves. The raw breach data on the OCR breach portal shows data breaches based on the reporting entity, not where the data breach occurred. In June, healthcare providers reported 45 breaches, business associates reported 14 breaches, and 7 breaches were reported by health plans. The pie charts below show where the breach actually occurred rather than the reporting entity to better reflect breaches at business associates.
Geographical Distribution of Healthcare Data Breaches
In June, HIPAA-regulated entities based in 24 U.S. states reported large healthcare data breaches. Florida and Texas were the worst affected states with seven reported breaches per state.
| State | Breaches |
| Florida & Texas | 7 |
| Illinois | 5 |
| Colorado, Michigan & New York | 4 |
| California, Connecticut, Minnesota, Missouri, Ohio & Tennessee | 3 |
| Idaho, Kentucky, Massachusetts, South Carolina & Washington | 2 |
| Alabama, Georgia, Indiana, Kansas, New Jersey, Oklahoma & Pennsylvania | 1 |
While Florida and Texas ranked top for breaches, they ranked 4th and 6th in terms of the number of affected individuals. Tennessee, Georgia, and New Jersey topped the list for affected individuals, with each state only registering one large data breach.
| State | Individuals Affected | State | Individuals Affected |
| Tennessee | 1,567,038 | Michigan | 24,396 |
| Georgia | 1,261,464 | Idaho | 22,750 |
| New Jersey | 542,377 | Ohio | 21,608 |
| Florida | 233,367 | South Carolina | 20,690 |
| Minnesota | 164,893 | Washington | 9,825 |
| Texas | 124,459 | Missouri | 3,311 |
| Illinois | 120,089 | Indiana | 3,070 |
| Connecticut | 99,071 | Pennsylvania | 2,720 |
| Colorado | 87,814 | Oklahoma | 1,607 |
| California | 80,783 | Massachusetts | 1,506 |
| New York | 74,733 | Kansas | 534 |
| Kentucky | 31,367 | Alabama | 500 |
HIPAA Enforcement Activity in June 2026
In June, OCR announced a single enforcement action to resolve potential violations of the HIPAA Rules by the American mall-based retailer, Spencer Gifts. Retailers are not typically HIPAA-covered entities, but Spencer Gifts is a health plan under HIPAA as it sponsors employee benefits and welfare benefit plans. Spencer Gifts was investigated after OCR received a report about a breach of the protected health information of 10,023 members of its flexible benefits and welfare benefit plans. The OCR investigation determined that Spencer Gifts failed to conduct a HIPAA-compliant risk analysis and failed to implement HIPAA Privacy, Security, and Breach Notification Rule policies and procedures. The alleged HIPAA violations were resolved with a settlement that includes a $450,000 financial penalty and a corrective action plan.
In the year to June 30, 2026, OCR resolved seven HIPAA investigations with financial penalties with penalties totaling $1,728,000. All seven of the investigations found risk analysis failures, and two involved breach notification failures. State attorneys general may also investigate data breaches and impose financial penalties for HIPAA violations, although no cases were announced in June 2026.
About this Report
The HIPAA Journal monthly data breach reports are based on data obtained from the HHS Office for Civil Rights and have been combined with breach report data from other sources. The data breaches included in this report were reported in June 2026 but occurred weeks or months previously. The figures in this report may increase or decrease as HIPAA-regulated entities complete their breach investigations, and will be reflected in our healthcare data breach statistics page and our annual HIPAA data breach reports. Further information about HIPAA enforcement actions can be found in our HIPAA violations cases page.
The post June 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.
A New Bill Would Extend Health Privacy Law to Your Phone. The Hard Part Comes Next. – Petrie-Flom Center
HHS Awards More Than $11 Million to Expand Medical Residencies in Rural and Tribal Communities – hhs.gov
Survey Reveals Patients Want to Know When and How AI is Used in Healthcare – The HIPAA Journal
Survey Reveals Patients Want to Know When and How AI is Used in Healthcare
A recent survey has revealed that patients are concerned about the use of AI tools by doctors’ offices and other healthcare providers, and the vast majority of patients believe that they should be informed if their healthcare provider is using AI tools in connection with their healthcare. The survey also indicates that more than half of patients are unaware whether AI is currently being used in relation to their healthcare.
The survey was conducted on almost 5,000 U.S. adults in late June 2026 by the Pew Research Center. The survey revealed that 72% of patients believe it is extremely important or very important for their healthcare providers to disclose whether they are using AI tools in connection with healthcare, with 16% of respondents believing that it is somewhat important. Only 7% of respondents said they are not too bothered or not at all bothered about being informed about the use of AI.
Concern varied across different uses of AI, with the greatest concern expressed about AI being used to make diagnostic decisions (81%), analyze medical scans (81%), explain medical test results (80%), and take notes during a medical appointment (72%). More than half of patients believe that they should be informed about behind-the-scenes administrative services such as getting prescription refills (64%) and scheduling medical appointments (56%), although the latter had the largest percentage of patients who do not feel that disclosure is needed (33%). Across all areas of questioning, 9% or 10% of patients were not sure if they should be informed, potentially indicating they are unaware of any risks involved.
While most patients believe that they should be informed about the use of AI in healthcare, almost half of all surveyed patients (46%) said they were unaware whether their doctor’s office and other healthcare providers were using AI solutions, with only 16% of patients saying a doctor has actually told them that AI was used in their care. Adoption of AI in healthcare has grown considerably, with ONC’s figures showing that 71% of hospitals were using AI tools in 2024, up from 66% in 2023. Despite the high level of AI adoption, 33% of respondents believe their healthcare providers are not using AI tools, which suggests a lack of transparency.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
While patients want to be informed and have a say in how AI is used in healthcare, many Americans do not believe they have control over how AI is used. The survey revealed that more than half of respondents (53%) believe they either have no say or not much say in the use of AI in healthcare, with 16% believing they have some say. 63% of respondents to the survey would like more say in how AI is used, and only 21% of respondents said they are comfortable with how much say they currently have.
As AI adoption grows, it is important for healthcare providers to explain to patients how the tools are used and to obtain patient consent in order to maintain trust. It is also important for the tools, including transcription tools and chatbots, to be continuously evaluated to ensure they are fit for purpose and are generating accurate results.
The post Survey Reveals Patients Want to Know When and How AI is Used in Healthcare appeared first on The HIPAA Journal.








