Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times.

The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time.

This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class action lawsuits filed by patients who had their data stolen and healthcare providers seeking compensation for the financial and operational disruptions they experienced. On June 7, 2024, the Judicial Panel on Multidistrict Litigation consolidated an initial 49 lawsuits, including 19 consumer complaints and 30 healthcare provider complaints, although the number of lawsuits included in the action has grown to more than 150. The consolidated lawsuit – In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation – was centralized in the U.S. District Court for the District of Minnesota.

The stolen data files are designated discovery material, and due to the sensitive nature of the data and the volume of records, heightened security practices are required to protect against unauthorized access and data theft. The rules concerning the stolen dataset were approved by the plaintiffs’ attorneys and were verified by a cybersecurity expert as being sufficient to ensure the security of the data before being sent to the judge for approval. The stipulated protective order has recently been approved by Magistrate Judge Dulce Foster.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UHG will provide a single copy of the data on an encrypted hard drive built to a federal security standard, and must provide the key to decrypt the data separately, to ensure that in the event of loss or theft of the drive, the data cannot be accessed. The plaintiffs’ attorneys are required to encrypt the data again once they have received the hard drive, using industry-standard encryption. No copies may be made of the data, and the data cannot be saved to the shared file library used by all individuals involved in the case. The plaintiffs’ attorneys are prohibited from using the dataset to identify or locate potential class members.

The hard drive must only be used on computers that are air-gapped – disconnected from the Internet and all networks, with no Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated prior to use, and when the computers are used, no cables, phones, or storage devices are permitted nearby.  When data access is required, only small samples may be accessed, and no more than 25 people are permitted access at any one time. All samples must be encrypted with strong encryption and a complex password set of at least 16 characters.

An audit trail must be maintained, including a detailed chain of custody of the drive and data, and the log must be provided to UHG on request. When the case ends, or if the plaintiffs’ claims are thrown out, the data must be securely destroyed within 30 days, using a government-approved data wiping method – NIST SP 800-88 – or the hard drive must be physically destroyed, and a detailed certificate of destruction obtained under penalty of perjury.

In the event of a security incident or unauthorized data access or data sharing, UHG must be notified within 48 hours. Should it turn out to be a genuine security incident, both sides are required to engage an external digital forensic firm, and if the plaintiffs are found to be at fault, they must pay the full investigation costs.

The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal.

Critical Vulnerabilities Identified in Popular Consumer Fertility Device

Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking device, and the Pulsetto Vagus Nerve Stimulator. Vulnerabilities in the former could result in sensitive data exposure and data manipulation. The latter has a vulnerability that poses a safety risk to users.

Mira Hormone Monitor & Mira Android App

Multiple vulnerabilities have been identified in the Mira Hormone Monitor and its associated Android app that could expose sensitive health data, cause a denial-of-service condition, and allow an unauthorized individual to take control of user accounts and manipulate data, potentially resulting in failed fertility treatments, missed fertility windows, or unwanted pregnancies.

The vulnerabilities were identified by a team of researchers at Northeastern University SPQR Lab. The research was partly funded by the Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) through a grant issued under the Universal Patching and Remediation for Autonomous Defense program. The vulnerabilities were reported to the device manufacturer, Quanovate Tech, which has taken steps to address the vulnerabilities.

The researchers conducted a full-chain security assessment of the Mira Ultra 5 fertility hormone analyzer and associated Android app and cloud infrastructure. The researchers identified 20 vulnerabilities in the device, app, and cloud infrastructure, including two critical vulnerabilities. The most serious vulnerabilities could be exploited by an attacker to gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information, and to gain control of cloud accounts and access hormone record information and account settings.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key Vulnerabilities

The vulnerabilities include weak or missing authentication, transmission of user data to third parties through analytics code and SDKs, hard-coded API keys, a lack of rate-limiting/IP-throttling, and publicly accessible firmware. The vulnerabilities affect Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4.

Vulnerability CVSS v3.1 Base Score CVSS v4.0 Base Score Outcome of Successful Exploitation
CVE-2026-68067 9.8 (Critical) 9.8 (Critical) Gain control of cloud accounts and access hormone record information and account settings.
CVE-2026-67568 9.1 (Critical) 9.3 (Critical) Gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information.
CVE-2026-66875 8.8 (High) 8.7 (High) Extract stored hormone measurements; denial-of-service; passively track the user.
CVE-2026-67558 7.4 (High) 8.2 (High) Capture live session token information; inject forged hormone measurements into the victim’s cloud record and clinical trend view.
CVE-2026-66098 6.5 (Medium) 7.1 (High) Denial-of-service; disrupt ovulation tracking and fertility monitoring workflow.
CVE-2026-66832 6.5 (Medium) 6.9 (Medium) Obtain live session token.
CVE-2026-66340 5.3 (Medium) 6.9 (Medium) Brute force access to user account
CVE-2026-64934 4.3 (Medium) 5.3 (Medium) Submission of arbitrary firmware version strings for their own device; evade vendor-side vulnerable-fleet analytics; suppress security update prompts to the user; misrepresent patch-adoption metrics.

The researchers coordinated with the device manufacturer and CISA and previewed the findings after Quanovate had completed two rounds of remediation. Quanovate has released updates to fix these vulnerabilities, and users should upgrade to the latest firmware/app versions: iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No evidence has been found of any actual or attempted exploitation of the vulnerabilities.

Pulsetto Vagus Nerve Stimulator

A high-severity vulnerability has been identified in the firmware of the Pulsetto Vagus Nerve Stimulator. Successful exploitation could allow an attacker to disable electrical safety mechanisms or modify other stimulation output settings.

The issue is due to the firmware accepting hidden commands over its Bluetooth Low Energy (BLE) interface. The commands are sent without authorization or encryption and are never issued by the companion mobile application; however, they are fully processed when the device is powered on.

The vulnerability is tracked as CVE-2026-18844 and affects all current versions. The vulnerability has been assigned a CVSS v3.1 base score of 8.1, and a v4.0 base score of 7.2.  The vulnerability was identified by researcher and security author A.C. Buglione, who reported the vulnerability to CISA.  CISA reached out to Pulsetto regarding the vulnerability but did not receive a response. CISA has therefore advised users to contact Pulsetto directly for information on how the issue can be remediated.

The post Critical Vulnerabilities Identified in Popular Consumer Fertility Device appeared first on The HIPAA Journal.

Data Breaches Announced by Five Small Healthcare Organizations

Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of Raleigh; Arkansas Oral & Maxillofacial Surgeons; Alpine Agency of the Midlands; Princeton Family Eye Care; and James C. Standring, DDS.

Family Medical Associates of Raleigh, North Carolina

Family Medical Associates of Raleigh, a multi-provider family medical practice in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, and activated its incident response protocol. Steps were immediately taken to investigate, contain, and remediate the incident; law enforcement was notified, and third-party cybersecurity professionals were engaged. The investigation and data review are ongoing; however, it has been confirmed that certain systems were intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026, who potentially downloaded internal data, including files containing patients’ protected health information.

The data review has not yet been completed, but the types of data exposed in the incident include names, demographic information, contact information, medical and treatment information, health insurance information, financial/payment-related information, government-issued ID numbers, and other data related to the medical services provided. Family Medical Associates of Raleigh said it is unaware of any actual or attempted misuse of patient data as a result of the incident; however, patients have been advised to remain vigilant against identity theft and fraud by monitoring their accounts, free credit reports, and explanation of benefits statements.

Since the investigation has yet to conclude, the number of affected individuals is currently unknown. While the name of the threat actor behind the attack was not disclosed, the Genesis ransomware group claimed responsibility for the attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Arkansas Oral & Maxillofacial Surgeons, Arkansas

Arkansas Oral & Maxillofacial Surgeons, a Hot Springs, Arkansas-based provider of oral surgery, dental implants, and other dental and cosmetic dentistry services, has announced a data security incident that was first identified on April 7, 2026.

An investigation was initiated, and on June 2, 2026, it was confirmed that an unauthorized third party had accessed its network and exfiltrated files containing patient information. The files have been reviewed and were found to contain information such as names, contact information, birth dates, medical record numbers, government identification numbers (including Social Security numbers), diagnoses, treatment records, health insurance information, prescription histories, and payment information.

The affected individuals have been notified by mail and provided with recommendations on how to protect themselves against data misuse. Based on the substitute breach notice on the Arkansas Oral & Maxillofacial Surgeons website, credit monitoring and identity theft protection services do not appear to have been offered. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many patients have been affected.

This appears to have been a data theft and extortion attempt. The PEAR threat group claimed responsibility. PEAR does not encrypt files, as the group engages in data theft and extortion, threatening to publish stolen data if the ransom is not paid.

Alpine Agency of the Midlands, South Carolina

Alpine Agency of the Midlands, LLC, a small, independent health and benefits insurance company based in Columbia, South Carolina, has recently disclosed a security incident involving unauthorized access to its email system. Alpine provides services to insurance carriers, employers, and health plans, and is provided with certain health data by its clients in connection with the services it provides.

Unusual activity was identified within an employee email account in November 2025. The account was secured, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that the incident affected a single email account, which was first accessed by an unauthorized third party on October 28, 2026. Emails and associated attachments may have been copied by the attacker.

The account was reviewed and found to contain first and last names, addresses, dates of birth, health insurance information, and limited Social Security numbers. Notifications will be mailed to the affected individuals when the review is completed. In the meantime, the breach has been reported to the HHS’ Office for Civil Rights as affecting at least 500 individuals. The total will be updated when the file review is concluded.

Princeton Family Eye Care, Texas

Princeton Family Eye Care, a small optometry practice in Princeton, Texas, has notified certain patients about a recent data breach. On May 4, 2026, suspicious activity was identified within its email environment. Assisted by third-party cybersecurity experts, the practice secured its email systems, investigated the activity, and confirmed that a company email account had been accessed by an unauthorized third party.

A data review firm was engaged to determine the types of data involved and the individuals affected, and that process has recently been completed. The data exposed in the incident varied from individual to individual and may have included names in combination with one or more of the following: date of birth, contact information, government identification numbers (such as a driver’s license, passport, or Social Security number), and limited medical information (such as treatment details, health insurance records, or a medical record number).

No misuse of the affected information has been identified; however, the affected patients have been advised to remain vigilant against misuse of their information. The breach was reported to the Texas Attorney General as involving the data of 933 Texas residents.

James C. Standring, DDS, California

James C. Standring, DDS, a dental practice in Crescent City, California, has notified 6,658 patients about a data security incident involving unauthorized access to its computer systems. While the data breach was reported to the HHS’ Office for Civil Rights on July 17, 2026, this appears to have been a historical data breach.

According to the breach explanation on the dental practice website, unauthorized access to certain computer systems was first identified on September 2, 2024. Assisted by third-party cybersecurity specialists, the practice determined that the incident resulted in the exposure of the data of current and former patients, including names, addresses, email addresses, Social Security numbers, driver’s license/state ID numbers, medical information, health insurance information, financial account/payment card information, and other personal information maintained by the practice.

No misuse of the affected data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. No explanation was provided about why it took 22 months from the date of discovery to issue notification letters.

The post Data Breaches Announced by Five Small Healthcare Organizations appeared first on The HIPAA Journal.

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is targeting government and critical infrastructure entities, including healthcare organizations, and organizations in other sectors. The group has conducted attacks in the Americas, Europe, Middle East, Africa, and Asia-Pacific, with attacks accelerating in 2026.

Gunra ransomware was first identified as a financially motivated threat group in April 2025; however, in 2026, it transitioned into a RaaS group. The group is attempting to recruit experienced affiliates from other groups by offering an 80% cut of any generated ransoms, as well as initial access brokers who can deliver enterprise-scale footholds.

The group primarily targets Windows systems and uses advanced encryption methods. In late 2025, the group also developed a Linux variant of its encryptor to allow cross-platform targeting. The encryptor is based on leaked Conti ransomware source code. The group engages in double extortion attacks, stealing sensitive data before encrypting files. After file encryption, victims receive a ransom note in each affected directory and are required to initiate negotiations via a Tor-based negotiation panel. Victims are provided with unique login credentials to access the negotiation panel and are given between 5 and 10 days to commence negotiations.

The group has been observed gaining access to victims’ networks by exploiting known vulnerabilities in Internet-facing devices, including firewalls and VPN appliances, such as the CVE-2024-55591 and CVE-2025-24472 authentication bypass vulnerabilities in FortiOS/FortiProxy. The group has also been observed exploiting Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.

Multiple stealth and defense impairment techniques are used to hinder detection and analysis. Data collected and exfiltrated includes business-critical documents, databases, personally identifiable information (PII), and internal email communications, including from Microsoft OneDrive and SharePoint. The stolen data is used as leverage to pressure victims into paying the ransom. Threats are issued to publish or sell the stolen data on a dedicated dark web data leak site if the ransom is not paid. The group’s data leak site currently lists more than 30 worldwide victims.

The #StopRansomware cybersecurity advisory recommends taking immediate action to reduce the risk of an attack, including prioritizing patching for known exploited vulnerabilities, especially vulnerabilities in VPNs and RDP-exposed infrastructure. Networks should be segmented to hamper lateral movement from initially compromised devices to other organizational systems, and immutable backups should be created and stored in physically separate, segmented locations to ensure data can be recovered without paying the ransom.

Full details of the group’s tactics, techniques, and procedures (TTPs), Indicators of Compromise (IoC), and recommended mitigations are detailed in the cybersecurity advisory.

The post Healthcare Orgs Warned About Gunra Ransomware Attacks appeared first on The HIPAA Journal.