Tennessee Pathology Group Announces 170K-record Data Breach

Anatomic and Clinical Laboratory Associates is notifying almost 170,000 patients about a recent cybersecurity incident. Data breaches have also been announced by ZenPatient, Saint Pete MRI, Carlyle Senior Care, SportsMed Physical Therapy, and Lifeways Inc.

Anatomic and Clinical Laboratory Associates

Anatomic and Clinical Laboratory Associates, P.C., a Nashville, TN-based physician-owned pathology group, has announced a significant data breach involving the protected health information of 169,626 current and former patients.

An investigation was launched on December 1, 2025, when anomalous activity was identified within its computer network. Third-party cybersecurity experts were engaged to assist with the investigation and ensure the security of its computer systems. During the course of the investigation, unauthorized network access was confirmed. It is unclear from the breach notice when the unauthorized access occurred or for how long its network was compromised.

The review of the exposed data was completed on April 27, 2026, when it was confirmed that personal and protected health information had been exposed. The affected individuals had their names exposed, along with one or more of the following data elements: date of birth, Social Security number, taxpayer identification number, date(s) of service, medical provider name(s), mental/physical condition, medical treatment/procedure information, diagnosis or clinical information, medical history, patient account number, and/or medical record number.

Notification letters were mailed to the affected individuals on June 23, 2026, and complimentary credit monitoring and identity theft protection services have been offered to certain individuals, dictated by the types of information involved. Anatomic and Clinical Laboratory Associates have implemented additional security measures to prevent similar incidents in the future.

ZenPatient

ZenPatient, Inc., a Santa Monica, CA-based provider of telehealth and messaging software platform, has announced a cybersecurity incident that involved unauthorized access to its network between December 2025 and February 2026. Suspicious activity was identified within its computer network on February 27, 2026. Assisted by third-party cybersecurity professionals, the incident was investigated, and it was confirmed that an unauthorized third party had access to its network between December 5, 2025, and February 12, 2026, during which time certain files were exfiltrated from its network.

The compromised files were reviewed and found to contain names, addresses, birth dates, and medical information. Notification letters were sent to the affected individuals on July 17, 2026. ZenPatient said it is unaware of any misuse of patient data as a result of the incident; however, as a precaution against data misuse, complimentary credit monitoring services have been made available to the affected individuals for 12 months. Additional cybersecurity measures have been implemented to reduce the risk of similar incidents in the future. The data breach has been reported to regulators, but the number of affected individuals has yet to be publicly disclosed.

Saint Pete MRI

Saint Pete MRI, a St. Petersburg, FL-based full-service diagnostic imaging and sleep lab, is notifying certain patients about a cybersecurity incident it identified on or around February 23, 2025. Immediate action was taken to investigate the incident and secure its computer systems, and a third-party cybersecurity firm was engaged to assist with those processes.

The investigation confirmed that electronic patient care and imaging systems were not subject to unauthorized access; however, the unauthorized party behind the incident may have acquired certain scanned data. The affected files were reviewed, and on April 7, 2026, Saint Pete MRI confirmed that they contained names, dates of birth, Social Security numbers, driver’s license numbers or state identification numbers, medical information, and/or health insurance information.

Notification letters were mailed to the affected individuals on July 22, 2026, around 17 months after the incident was first identified. The incident is not currently shown on the HHS’ Office for Civil Rights data breach portal, so it is unclear how many individuals have been affected.

Carlyle Senior Care Management Company

Carlyle Senior Care Management Company, a South Carolina-based management company for Carlyle Senior Care independent living, senior living, and skilled nursing care facilities in the state, has reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 4,060 individuals.

There is currently no substitute data breach notice on the Carlyle Senior Care website, and no press release appears to have been issued, so it is unclear what data types were involved. This appears to have been a ransomware attack conducted by the Insomnia ransomware group, which claimed on its data leak site to have stolen data from Carlyle Senior Care of Florence. Insomnia claimed to have notified Carlyle Senior Care about the breach on October 31, 2025, then proceeded to leak the stolen data. Insomnia claimed to have stolen patient records, internal documents, and sensitive information.

SportsMed Physical Therapy

SportsMed Physical Therapy, a physical therapy clinic with locations in New Jersey and Connecticut, has identified unauthorized access to a single email account. The breach was identified on May 8, 2026, and the account was secured. An investigation was launched to determine the individuals affected and the types of data involved.

The review has recently been completed and confirmed that names had been compromised in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information. SportsMed Physical Therapy said it is unaware of any misuse of patient information as a result of the incident. The incident is not currently shown on the HHS’ Office for Civil Rights website, so it is currently unclear how many individuals have been affected.

Lifeways

Lifeways Inc., a nonprofit provider of mental health counseling and addiction services to patients in Idaho and Oregon, identified unauthorized access to an employee’s email account. The email account breach was identified on January 21, 2026, and after securing the account, an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation revealed several employee email accounts had been compromised.

The incident was limited to its email environment. On May 8, 2026, Lifeways confirmed that the exposed information included names, birth dates, Social Security numbers, driver’s license/state identification numbers, financial account numbers, patient account numbers, medical record numbers, diagnoses, treatment and procedure information, prescription information, treatment locations, provider names, Medicare and Medicaid numbers, clinical information, and health insurance information. At the time of issuing notification letters, Lifeways was unaware of any misuse of the exposed information. The Oregon Attorney General was informed that 343 individuals have been affected.

The post Tennessee Pathology Group Announces 170K-record Data Breach appeared first on The HIPAA Journal.

Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches

There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.

Annual data compromises. Source: ITRC

Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.

Victim Count from data compromises. Source: ITRC

As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million of those notices. A mega data breach at Under Armour involved more than 72.7 million notices, while the SoundCloud data breach saw 29.8 million victim notices issued.

There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare. In H1 2026, only 7 healthcare data breaches required more than 1 million notices.

HIPAA-Regulated Entity State Entity Type Type of Breach Individuals Affected
TriZetto Provider Solutions MO Business Associate Hacking/IT Incident 3,433,965
QualDerm Partners, LLC TN Healthcare Provider Hacking/IT Incident 3,117,874
Nacogdoches Memorial Hospital n TX Healthcare Provider Hacking/IT Incident 2,507,073
Navia Benefit Solutions, Inc. WA Business Associate Hacking/IT Incident 2,151,330
Insightin Health, Inc. MD Business Associate Hacking/IT Incident 1,949,534
New York City Health and Hospitals Corporation NY Healthcare Provider Hacking/IT Incident 1,800,000
Xsolis, Inc. TN Business Associate Hacking/IT Incident 1,396,519

While very large data breaches may have been reported in lower numbers in the first half of the year, healthcare data breaches continue to be reported in volume. The ITRC tracking data show 281 healthcare data compromises in the first half of the year, which puts the industry in second spot behind financial services with 387 compromises. The data for 2025 show a slight year-over-year fall in financial services data breaches, from 396 in H1, 2025, and a slight increase in healthcare data breaches, rising from 270 in H1, 2025. Across the 281 healthcare data breaches, more than 11.7 million patients have been affected. Current OCR data (from July 23, 2026) show that number has already more than doubled to over 28.8 million victims, although the total is still well below last year’s H1, 2026 count of 42.8 million healthcare victims.

Data compromises by Industry. Source ITRC

As ITRC has reported for several years, the trend of withholding important information from breach notices has continued. ITRC reports that 76% of all notices failed to include information about the attack vector (1,378 notices). Only 24% of notices contained information about the attack vector – the lowest ever rate since ITRC has been producing its data breach reports. “This opacity prevents consumers, businesses and policymakers from understanding their true risk exposure or taking meaningful preventive action,” explained ITRC. To put that total into perspective, 93% of victim notices included information about the attack vector in 2021.

The ITRC data show a significant increase in insider wrongdoing incidents, with 21 such incidents identified in H1, 2026, compared to just 3 in all of 2025 – a sevenfold increase.  ITRC tracked 14 zero-day attacks in H1 2026, which is close to the total of 17 for all of 2025. While there were only 38 tracked supply chain incidents in H1 2026, they required more than 280.6 million victim notices. “Supply chain cyberattacks alone accounted for 199 of 206 affected entities and 280.6 million of 280.6 million combined victim notices,” explained ITRC in the report.

Cyberattacks accounted for 69.7% of data breaches in H1, 2026, and 92.3% of all victim notices. System and human error accounted for 6.9% of breaches and 0.9% of victim notices. By far the main cause of cyberattacks was phishing/smishing/BEC, with 157 incidents, followed by system & human error (125 incidents), and ransomware attacks (76 incidents), although 402 events remain unclassified due to the lack of transparency about breach causes.  Total cyberattacks are down 7.8% compared to H1, 2025, with ransomware attacks up by 4.1%.

The post Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches appeared first on The HIPAA Journal.