Data breaches have recently been announced by the Women’s Center for Radiology in Florida, Optalis Management Solutions in Michigan, the Association for Neurologically Impaired Brain Injured in New York, the Cardiovascular Institute of New England in Rhode Island, and the Kubota Tractor Corporation in Texas.
Women’s Center for Radiology, Florida
Women’s Center for Radiology, a Florida-based women’s radiology practice with two centers in Orlando, has notified 66,422 patients about a data security incident identified on April 29, 2026. Assisted by third-party cybersecurity specialists, the Women’s Center for Radiology determined that an unauthorized third party had access to its network between April 26, 2026, and April 28, 2026, and accessed or downloaded files containing patient information.
After securing its network, the files were reviewed and found to contain patient information such as names, addresses, dates of birth, contact information, diagnosis/condition information, lab test results, treating/referring physician names, medical record numbers, driver’s license numbers, and health insurance information. Data privacy and security policies, procedures, and processes are being reviewed to reduce the likelihood of similar incidents in the future. While data misuse has not been identified, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.
Optalis Management Solutions, Michigan
Optalis Management Solutions, a Michigan-based management company that operates Optalis Health & Rehabilitation’s skilled nursing, rehabilitation, assisted living, and independent living facilities, has notified 13,723 individuals about a breach of some of their protected health information. Suspicious activity was identified within its computer network, and the investigation confirmed unauthorized access occurred between April 14, 2025, and April 19, 2025. After a breach was confirmed by third-party cybersecurity specialists, a document review was initiated to determine the individuals and data types involved. That process concluded on June 10, 2026.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Data potentially viewed or obtained in the incident included full names in combination with one or more of the following: Social Security number, driver’s license number/state ID number, credit/debit card information, financial account information, diagnosis and treatment information, and/or health insurance policy number. Notifications were mailed to the affected individuals on June 29, 2026, and individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services.
Kubota Tractor Corporation, Texas
Kubota Tractor Corporation, a Japanese company that makes agricultural and construction equipment, has recently confirmed that hackers gained access to certain parts of its network earlier this year. The forensic investigation determined that its network was first compromised on March 16, 2026, and the hackers maintained access for more than a month. The unauthorized access was detected and blocked on April 20, 2026. The company, which has its U.S. HQ in Grapevine, Texas, determined that this was a reportable breach under HIPAA, as the incident involved unauthorized access to the protected health information of beneficiaries of its Employee Welfare Benefit Plan.
Employee data potentially compromised in the incident includes names in combination with one or more of the following: Social Security number, date of birth, taxpayer identification number, driver’s license or other government-issued identification number, financial account information for direct deposit, payment card information for corporate cards, benefit enrollment information, and limited claims information. For dependents of employees, the exposed data may have included names in combination with one or more of the following: Social Security number, date of birth, benefit enrollment information, and limited claims information. Notification letters were mailed to the 5,891 affected individuals on June 30, 2026, and complimentary identity monitoring services have been offered.
Cardiovascular Institute of New England, Rhode Island
The Cardiovascular Institute of New England, a heart care practice with seven locations in Rhode Island, started mailing notification letters to patients on July 28, 2026, about a data security incident identified on or around February 12, 2026. Suspicious activity was identified within its email environment, and the investigation confirmed unauthorized email access, which may have resulted in patient data being viewed or acquired.
The review of the affected email accounts was completed on or around July 14, 2026, when the practice learned that names, phone numbers, dates of birth, financial account numbers, medical information, medical diagnoses, treatment information, treatment locations, clinical information, prescription information, and medical insurance provider information had been exposed. No evidence has been found to suggest that any patient data has been misused.
Email security policies, procedures, and security measures are being reviewed, and steps are being taken to reduce the risk of similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.
The Association for Neurologically Impaired Brain Injured, New York
The Association for Neurologically Impaired Brain Injured (ANIBIC), a New York-based not-for-profit agency that provides services to individuals with developmental and neurological disabilities, has recently informed the HHS’ Office for Civil Rights about a breach of the protected health information of 1,918 individuals. According to its substitute breach notice, suspicious activity was identified within its computer network on or around March 8, 2026. The investigation determined that an unauthorized third party accessed files containing program member information between March 7, 2026, and March 8, 2026.
The compromised information included names, contact information, Social Security numbers, dates of birth, health insurance information, and service details such as diagnoses, treatment information, and prescriptions. Notification letters were mailed to the affected individuals on July 17, 2026, and complimentary identity monitoring services have been offered to individuals whose Social Security numbers were involved.
The post Data Breaches Announced by Five HIPAA-Regulated Entities appeared first on The HIPAA Journal.
