New York renews push to enact Consumer Health Information Privacy Act (NYHIPA) – Nixon Peabody
Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches – The HIPAA Journal
Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches
There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.

Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.

As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million of those notices. A mega data breach at Under Armour involved more than 72.7 million notices, while the SoundCloud data breach saw 29.8 million victim notices issued.
There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare. In H1 2026, only 7 healthcare data breaches required more than 1 million notices.
| HIPAA-Regulated Entity | State | Entity Type | Type of Breach | Individuals Affected |
| TriZetto Provider Solutions | MO | Business Associate | Hacking/IT Incident | 3,433,965 |
| QualDerm Partners, LLC | TN | Healthcare Provider | Hacking/IT Incident | 3,117,874 |
| Nacogdoches Memorial Hospital n | TX | Healthcare Provider | Hacking/IT Incident | 2,507,073 |
| Navia Benefit Solutions, Inc. | WA | Business Associate | Hacking/IT Incident | 2,151,330 |
| Insightin Health, Inc. | MD | Business Associate | Hacking/IT Incident | 1,949,534 |
| New York City Health and Hospitals Corporation | NY | Healthcare Provider | Hacking/IT Incident | 1,800,000 |
| Xsolis, Inc. | TN | Business Associate | Hacking/IT Incident | 1,396,519 |
While very large data breaches may have been reported in lower numbers in the first half of the year, healthcare data breaches continue to be reported in volume. The ITRC tracking data show 281 healthcare data compromises in the first half of the year, which puts the industry in second spot behind financial services with 387 compromises. The data for 2025 show a slight year-over-year fall in financial services data breaches, from 396 in H1, 2025, and a slight increase in healthcare data breaches, rising from 270 in H1, 2025. Across the 281 healthcare data breaches, more than 11.7 million patients have been affected. Current OCR data (from July 23, 2026) show that number has already more than doubled to over 28.8 million victims, although the total is still well below last year’s H1, 2026 count of 42.8 million healthcare victims.

As ITRC has reported for several years, the trend of withholding important information from breach notices has continued. ITRC reports that 76% of all notices failed to include information about the attack vector (1,378 notices). Only 24% of notices contained information about the attack vector – the lowest ever rate since ITRC has been producing its data breach reports. “This opacity prevents consumers, businesses and policymakers from understanding their true risk exposure or taking meaningful preventive action,” explained ITRC. To put that total into perspective, 93% of victim notices included information about the attack vector in 2021.
The ITRC data show a significant increase in insider wrongdoing incidents, with 21 such incidents identified in H1, 2026, compared to just 3 in all of 2025 – a sevenfold increase. ITRC tracked 14 zero-day attacks in H1 2026, which is close to the total of 17 for all of 2025. While there were only 38 tracked supply chain incidents in H1 2026, they required more than 280.6 million victim notices. “Supply chain cyberattacks alone accounted for 199 of 206 affected entities and 280.6 million of 280.6 million combined victim notices,” explained ITRC in the report.
Cyberattacks accounted for 69.7% of data breaches in H1, 2026, and 92.3% of all victim notices. System and human error accounted for 6.9% of breaches and 0.9% of victim notices. By far the main cause of cyberattacks was phishing/smishing/BEC, with 157 incidents, followed by system & human error (125 incidents), and ransomware attacks (76 incidents), although 402 events remain unclassified due to the lack of transparency about breach causes. Total cyberattacks are down 7.8% compared to H1, 2025, with ransomware attacks up by 4.1%.
The post Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches appeared first on The HIPAA Journal.
Colorado Behavioral Healthcare Provider Discovers Insider Data Breach – The HIPAA Journal
Colorado Behavioral Healthcare Provider Discovers Insider Data Breach
Data breaches have been announced by NAS Recovery Solutions, Entyre Care Massachusetts, Carle Health, and Brown Health Medical Group-MA.
NAS Recovery Solutions
NAS Recovery Solutions, a Lakewood, Colorado-based substance use disorder treatment and behavioral health services provider, has announced a data breach affecting up to 7,000 current and former clients. According to the company’s breach notice, this was an insider breach rather than a hacking incident. The company learned on May 13, 2026, that certain workforce members had downloaded client data without authorization.
The investigation revealed only limited information had been copied, such as first and last names, dates of birth, and telephone numbers; however, since NAS Recovery Solutions is a substance use disorder (SUD) treatment provider, it could be inferred that the individuals were receiving SUD treatment. There are no indications that any other information was obtained by the workforce members. The breach notice does not provide any clue as to why that information was obtained.
NAS Recovery Solutions said it has reviewed workforce access and security controls and is implementing additional safeguards to prevent similar incidents in the future. Additional training has been provided to the workforce on HIPAA and patient privacy, and appropriate corrective action has been taken against the workforce members involved. The sanctions imposed were not disclosed in the notice.
Entyre Care Massachusetts
Entyre Care Massachusetts Inc., a Boston, MA-based home healthcare company, has discovered that an employee accidentally published files containing personal information in a publicly accessible online repository on March 2, 2026. The exposed files were identified on March 12, 2026, and were immediately secured.
The investigation uncovered no evidence to suggest that the files had been accessed or downloaded; however, it was not possible to rule out unauthorized access during the period of exposure. The files only contained limited information, such as names, ages, and Medicaid IDs; however, out of an abundance of caution, the affected individuals have been offered 24 months of complementary credit monitoring and identity theft protection services.
Carle Health
Carle Health, an Illinois nonprofit health system, has confirmed that 1,444 of its patients were affected by a data breach at its vendor Xsolis in January 2026. Xsolis is a vendor that provides an AI-powered software platform to healthcare providers to improve case and utilization management. We have covered the data breach, which affected more than 1.4 million individuals, in this post. Carle Health said the compromised information included names, birth dates, diagnoses, treatment dates and locations, medical record numbers, doctors’ names, Social Security numbers, and health insurance information.
Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts)
Lifespan Physicians Group of Massachusetts Inc., which does business as Brown Health Medical Group-MA, has recently announced that the sensitive data of certain patients has been exposed. According to the notification to the Vermont Attorney General, the impacted data includes names, Social Security numbers, government identification numbers, financial account codes, and health records. The incident affected 86 Vermont residents, but it is currently unclear how many individuals have been affected in total.
The post Colorado Behavioral Healthcare Provider Discovers Insider Data Breach appeared first on The HIPAA Journal.
Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data – The HIPAA Journal
What Counts as Health Privacy for Remote Workers – quasa.io
Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data
The cardiovascular medical practice, Heart Care Centers of Illinois (HCCI), announced on July 18, 2026, that certain patients had some of their personal and protected health information exposed in a phishing attack.
HCCI said it launched an investigation into an unsuccessful phishing attempt and discovered a historical suspicious activity within an employee’s email account on January 15, 2026. Third-party digital forensics experts were engaged to investigate the activity and confirmed that an unauthorized third party gained access to the account between August 22, 2024, and November 6, 2024.
A data analytics firm was engaged to review the account. On June 11, 2026, the review was completed, confirming that the following types of information were present in the account: names, addresses, telephone/fax numbers, Social Security numbers, dates of birth, driver’s license numbers/state identification numbers, payment card information, financial account numbers, passport numbers, diagnosis/condition information, prescription information, treatment information, health insurance information, and provider information.
The affected individuals were notified on July 10, 2026, and complimentary credit monitoring and identity restoration services have been offered. HCCI has reviewed its existing policies and procedures and has taken steps to reduce the risk of similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.
Madera Community Hospital
Madera Community Hospital in California has notified the California Attorney General about a security incident involving unauthorized access to its network between May 28 and May 29, 2025. The unauthorized access was identified on May 29, 2025, and action was immediately taken to secure its network and prevent further unauthorized access.
Third-party cybersecurity experts were engaged to investigate the incident. No evidence was found to indicate any removal of data; however, the hospital said, “based on subsequent developments, we have reason to believe that a third party acquired files from a portion of its network.” No further information was provided on what that evidence was. The hospital did state that it has not found definitive proof that any data was removed, and none of the impacted data appears to have been published or otherwise shared.
The data review was completed in April 2026, contact information was verified, and notification letters have now been mailed to the affected individuals. Data exposed in the incident includes names, birthdates, contact information, login credentials, government identification numbers (such as Social Security numbers), financial account information, and limited medical information and limited biometric information. The affected individuals have been offered complementary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have potentially been affected.
The post Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data appeared first on The HIPAA Journal.