Author Archives: Steve Alder

Citrix Patches Third Actively Exploited NetScaler Zero Day

Citrix has released another patch for a zero day vulnerability under active exploitation, just a few days after patches were released for two other actively exploited zero day flaws. Like the previous two zero day flaws, the latest vulnerability affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances. The former is often used to provide cloud applications to employees, while the latter is commonly used as an SSL VPN to provide single sign-on to remote workers.

The previously patched two zero-days can lead to remote code execution; however, the latest vulnerability is believed to only allow an attacker to crash the system, with repeated attacks resulting in denial of service. Citrix explained that it has observed targeted attacks on unmitigated NetScaler systems and has yet to determine the impact on the integrity of customer data. Security researchers have found evidence that threat actors are chaining one of the earlier RCE zero day flaws – CVE-2026-8877 – with the latest vulnerability.

The vulnerability is tracked as CVE-2026-88779 and is rated high severity, with a CVSS v4.0 severity score of 8.7. The flaw is a memory overflow vulnerability in SAML that affects customer-managed deployments configured as a SAML Service Provider (SAML SP / SAML IdP). Citrix also warned that Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have been automatically updated with the fixed version.

Patches to fix the vulnerability were issued on October 4, 2026. Users who have already patched the previous two zero days will also need to apply the latest fix to protect against exploitation. Citrix is urging all customers with vulnerable appliances to upgrade to the fixed version as soon as possible. Further information can be found in the Citrix security bulletin.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Vulnerable versions:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
  • Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282

Patched versions:

  • NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
  • NetScaler ADC / NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases

The post Citrix Patches Third Actively Exploited NetScaler Zero Day appeared first on The HIPAA Journal.

WindRose Health Network Discloses Data Breach Affecting 33K Individuals

Data breaches have been announced by WindRose Health Network and Advantage Home Health Care in Indiana, Camden-on-Gauley Medical Center in West Virginia, and Lakes Region Visiting Nursing Association in New Hampshire.

WindRose Health Network, Indiana

WindRose Health Network, a network of Federally Qualified Health Centers that provide primary care and behavioral health services at several locations in central Indiana, has started notifying 33,158 individuals about a cybersecurity incident that exposed limited patient data. An unauthorized third party gained access to a limited part of its network by exploiting a previously undisclosed vulnerability in a remote access tool used by one of its vendors. The vendor informed WindRose Health Network about the vulnerability on August 4, 2026. Immediate action was taken to secure its environment, and cybersecurity experts were engaged to investigate.

The investigation determined that the vulnerability had been exploited, resulting in unauthorized network access between August 3 and August 4, 2026. The remote access tool could not be used to access patients’ medical records; however, patient data was stored in files on the affected parts of its network. The data review determined that patient names, patient ID numbers, health insurance information, dates of service, and provider names were potentially accessed or copied. The affected patients have been advised to remain vigilant against identity theft and fraud.

Advantage Home Care, Missouri

Advantage Home Health Care (AHHC), one of the largest home healthcare providers in the state of Indiana, has notified 19,851 individuals about a recent cybersecurity incident. The home health care agency learned on June 16, 2026, that an unauthorized third party had gained access to one of its computer servers. The forensic investigation determined that its systems were first accessed on June 9, 2026. On June 26, 2026, AHCC learned that the files containing patient data had been acquired in the incident, including patients’ first and last names, birth dates, addresses, phone numbers, Social Security numbers, and medical information related to the care received.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Employee data was also compromised related to the AHHC employee health plan, including health insurance and plan enrolment information, claims information, healthcare provider information, and health benefits information. Adults and minors affected by the incident have been offered 12 months of complimentary single-bureau credit monitoring, credit report, and credit score services. While not specifically mentioned in the notification letter, the group behind the attack appears to be The Gentlemen, a prolific ransomware group that has claimed many healthcare victims.

Camden-on-Gauley Medical Center, West Virginia

Camden Family Health, a network of community health centers serving the Mountain Lake Region in West Virginia, has identified unauthorized access to parts of its computer network. Suspicious activity was identified on July 18, 2026; steps were immediately taken to secure its systems, and an investigation was launched to determine the cause of the activity.

The investigation confirmed that an unauthorized third party accessed its network on July 18, 2026, and potentially viewed or obtained files containing the information of patients of Camden-on-Gauley Medical Center. The review of the affected files confirmed that patients’ medical information and health insurance information were potentially accessed or acquired. The number of affected individuals has not yet been publicly disclosed. The incident has been reported to the HHS’ Office for Civil Rights using an estimate of at least 501 individuals.

Lakes Region Visiting Nursing Association, New Hampshire

Lakes Region Visiting Nursing Association, a non-profit Medicare-certified home health and hospice agency based in Meredith, New Hampshire, has notified 1,274 individuals about a recent security incident. Suspicious activity was identified within its email environment on June 2, 2026. Its incident response protocols were immediately implemented, and third-party cybersecurity specialists were engaged to investigate the activity. They confirmed that an unauthorized third party had gained access to a single employee email account.

The account was reviewed, and on August 13, 2026, it was confirmed that patient data had been exposed. The exact types of data are not detailed in the substitute breach notification letter on its website. The affected individuals have been offered complimentary credit monitoring and identity theft protection services, and steps have been taken to improve security. In addition to a password reset, multifactor authentication has been implemented throughout its email tenant.

The post WindRose Health Network Discloses Data Breach Affecting 33K Individuals appeared first on The HIPAA Journal.

Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act

A bipartisan bill that seeks to improve healthcare cybersecurity and resilience has been unanimously passed by the U.S. Senate. The bill – The Health Care Cybersecurity and Resiliency Act (S.B. 3315) – calls for healthcare providers to implement cybersecurity best practices and key cybersecurity measures, and authorizes grants for rural hospitals and under-resourced healthcare providers to help them make the necessary cybersecurity improvements.

The Health Care Cybersecurity and Resiliency Act was initially proposed in 2025 by Senator Bill Cassidy (R-LA) and is co-sponsored by Senators Mark Warner (D-VA), John Cornyn (R-TX), and Maggie Hassan (D-NH). The bill was introduced following the ransomware attack on Change Healthcare, which caused massive disruption across the U.S. healthcare system, and seeks to strengthen cyber defenses, improve threat-sharing, establish workforce development and employee cybersecurity training programs, and provide better cybersecurity-related resources to help rural and low-resource healthcare providers bolster their defenses.

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has already proposed an update to the HIPAA Security Rule that includes extensive cybersecurity requirements for HIPAA-regulated entities; however, the final rule has been pushed back until at least July 2027, and it may not even progress to a final rule. A final decision has yet to be made by the Trump Administration about whether a final rule will be published.

The Health Care Cybersecurity and Resiliency Act requires certain cybersecurity measures to be adopted, such as encryption of electronic protected health information, implementation of multifactor authentication, ongoing monitoring for cyber events, and penetration tests. The bill also requires the adoption of cybersecurity best practices in line with national cybersecurity frameworks such as the NIST Cybersecurity Framework.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The bill requires the HHS to develop a cybersecurity incident response plan and designates the Administration for Strategic Preparedness and Response as the Sector Risk Management Agency. The bill recognizes the importance of adopting recognized security practices and requires more transparency about data breaches. The public would be able to see, via updated fields on the OCR breach portal, whether the reporting entity had implemented recognized security practices prior to a data breach occurring, and whether any corrective action was taken by OCR against a regulated entity in response to a data breach.

The Senate Health, Education, Labor, and Pensions (HELP) Committee voted 22-1 in favor to advance the bill, and on October 1, 2026, the full U.S. Senate unanimously passed the bill. It will now head to the U.S. House of Representatives for consideration. While the bill proposes a grant program to help low-resource healthcare organizations make the necessary cybersecurity changes, the bill does not stipulate how much will be made available. That will be a matter for the House and Senate Appropriations Committees to decide.

“My bipartisan bill, the Health Care Cybersecurity and Resiliency Act, would ensure health institutions can safeguard Americans’ health data against increasing attacks,” said Sen. Cassidy. “At a time when cyberattacks not only put patients’ sensitive health data at risk but can delay lifesaving care, we need to do more to provide support.”

The post Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act appeared first on The HIPAA Journal.

CISA Sends CIRCIA Final Rule for White House Review

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has penned a final rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, which has been sent to the White House for review. CIRCIA requires CISA to develop and implement regulations for critical infrastructure entities concerning the reporting of cybersecurity incidents and ransomware payments to CISA. CISA worked with the Sector Risk Management Agencies for each of the 16 critical infrastructure sectors, the Department of Justice, other appropriate federal agencies, and the DHS-chaired Cyber Incident Reporting Council when developing the rule.

CIRCIA covers 16 critical infrastructure sectors, including healthcare and public health (HPH), and will apply to businesses, government entities, contractors, and other entities. The key requirements are for critical infrastructure entities to report cyber incidents to CISA within 72 hours of a determination that a substantial incident has occurred. In the event of a ransomware attack where a ransom is paid, CISA must be notified within 24 hours of the payment being made.

There are thresholds for reporting, which are generally based on company size and annual revenue, although they vary from sector to sector. An estimated 316,000 entities will need to comply with the reporting requirements. For the healthcare sector, they include hospitals with 100 or more beds, any critical access hospital regardless of size, any HPH sector entity that exceeds the Small Business Administration size standards, as well as manufacturers of regulated drugs and medical devices. The reporting requirements will be in addition to the reporting requirements under HIPAA.

CISA currently encourages all critical infrastructure entities to voluntarily report cyber incidents and ransom payments; however, mandatory reporting is necessary to allow CISA to effectively track cyber trends across critical infrastructure sectors, deploy resources to assist victims, and warn other entities about attacks and techniques in time for them to take action to prevent attacks or mitigate harm from a successful attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

CISA’s Notice of Proposed Rulemaking (NPRM) was published on April 4, 2024, followed by a 30-day comment period that was extended in response to comments from industry groups due to the length and complexity of the rule. CISA received a significant volume of comments from stakeholders and the public on the proposed rule, including substantial criticism due to its broad scope and overlap with existing reporting requirements.

While the initial target was an October 2025 release of a final rule, the release date was extended to May 2026, and again to September 2026. CISA has held town hall meetings, and the final rule has now been sent to the Office of Management and Budget for review. A final rule is expected to be published before the end of the year.

The post CISA Sends CIRCIA Final Rule for White House Review appeared first on The HIPAA Journal.

Fairchild Medical Center & Boone Health Settle Pixel Lawsuits

Fairchild Medical Center and Boone Health have agreed to settlements to resolve complaints alleging they impermissibly disclosed patient data to third parties via the use of pixels and other website tracking tools.

Fairchild Medical Center Pixel Settlement

Fairchild Medical Center in Yreka, California, has agreed to settle a class action lawsuit over its use of third-party tracking tools such as Meta Pixel on its website, which allegedly resulted in disclosures of patient data to third parties without patients’ knowledge or consent.

The lawsuit – Delgado v. Siskiyou Hospital, Inc. d/b/a Fairchild Medical Center – was filed in the Superior Court for Siskiyou County, California, and asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, violations of the California Constitution, California Invasion of Privacy Act, California Confidentiality of Medical Information Act, the Comprehensive Computer Data Access and Fraud Act, and Cal. Bus. & Prof. Code. The defendant disagrees with the claims and contentions in the lawsuit and maintains there was no wrongdoing, and the plaintiffs believe their claims have merit. To avoid the cost, delay, and risks of continued litigation, all parties agreed to settle the lawsuit.

Fairchild Medical Center has agreed to pay attorneys’ fees and expenses, settlement administration costs, a service award to the class representative, and benefits to the class members. The class consists of all California citizens whose information was disclosed to third parties – approximately 1,000 individuals. Those individuals are eligible to enroll in a one-year membership to the CyEx Privacy Shield Pro product and may claim a one-time cash payment of $25.00. The deadline for exclusion and opting out has passed. Claims must be submitted by November 2, 2026, and the final approval hearing has been scheduled for October 15, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Boone Health and CH Allied Services Pixel Settlement

Boone Health, a healthcare network that includes Boone Hospital Center in Columbia, Missouri, and its parent company, CH Allied Services, have agreed to settle class action litigation stemming from the use of the Meta Pixel tracking tool, Google Analytics code, and related tools which are alleged to have collected and disclosed sensitive patient data to third parties without patients’ knowledge or consent.

The first lawsuit was filed on December 5, 2022, and was refiled – Doe, et al. v. Boone Health, Inc., et al. – in the Circuit Court of Cole County, 19th Judicial Circuit, State of Missouri, adding further plaintiffs to the action. The lawsuit alleged that the plaintiffs and class members were harmed as a result of the disclosure of their personal and health information, and that their data was collected without their knowledge or consent. The defendants deny wrongdoing and disagree with all claims and contentions in the lawsuit and filed a motion to dismiss the action; however, that attempt was unsuccessful.

Following the court’s decision to deny the motion to dismiss, the parties agreed to settle the lawsuit to avoid the cost, distraction, and risks associated with a trial and related appeals. The defendants have agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and benefits for the class members.

The class consists of Boone Health patients who reside in Missouri and logged into the patient portal between April 1, 2021, and December 5, 2022. A claim may be submitted for a cash payment of $20.00, and class members will be automatically enrolled in a 12-month membership to the CyEx Privacy Shield Pro product. The deadline for exclusion is October 9, 2026, and the deadline for objection is November 9, 2026. Claims must be submitted by November 9, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

The post Fairchild Medical Center & Boone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.

Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents

AngMar Management Services, a Mansfield, Texas-based home health and hospice management company, has identified unauthorized access to its information technology systems. The incident was identified on July 20, 2026, and the forensic investigation determined that an unauthorized individual potentially accessed and/or acquired files containing patient information on or around July 18, 2026.

The review of the affected data was completed on September 8, 2026, when it was confirmed that the data compromised in the incident included names, addresses, dates of birth, Social Security numbers, patient IDs, medical record numbers, health insurance information, dates of service, diagnosis/condition information, provider names, prescription information, and/or medical history information. AngMar Management Services said it has implemented additional security measures to reduce the risk of similar incidents in the future. The affected individuals have been offered complimentary credit monitoring services.

The incident appears to have been a ransomware attack by the Interlock ransomware group, which added AngMar Management Services to its dark web data leak site in August 2026. The group claims to have exfiltrated 710 GB of data in the incident. The total number of affected individuals has yet to be publicly disclosed; however, the Texas Attorney General was informed that the personal and protected health information of 35,916 Texas residents was potentially compromised in the incident.

Eskenazi Health

Eskenazi Health, an Indianapolis, Indiana-based safety net health system, has announced a cybersecurity incident involving unauthorized access to certain patient data. A threat actor had gained access to the email account of a trusted business contact and used that account to send thousands of emails to contacts in the address book, including to an Eskenazi Health employee. The email appeared to have been sent by a trusted contact and contained a document notification. The employee clicked the link in the email and entered their contact details as part of the authentication process. The threat actor captured the credentials and used them to access the employee’s cloud-based work account.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The employee responded to the email on June 3, 2026, and the compromised account was identified by Eskenazi Health on July 27, 2026. During that time, emails and attachments in the account may have been accessed or acquired. The review of the account determined that it contained patients’ demographic and contact information, health insurance and billing information, internal identifiers such as medical record numbers, medical and treatment information, Social Security numbers, and sensitive health information such as substance use disorder diagnosis and treatment information.

The account has been secured, additional protective measures have been implemented, and employee education about cyber threats is being enhanced to prevent similar incidents in the future. The affected individuals have been notified and offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

Suffolk County House of Correction | Nashua Street Jail

Inmates at Suffolk County House of Correction and Nashua Street Jail in Boston, Massachusetts, have been affected by a cybersecurity incident at Computer Systems Integrated Inc. Computer Systems Integrated is a technology company affiliated with Correctional Psychiatric Services, a healthcare provider serving inmates at several correctional facilities in the state. Computer Systems Integrated runs the electronic health record system used by the correctional facilities.

The cybersecurity incident is under investigation, and it is currently unclear how many inmates have been affected or what types of information were involved. The incident appears to be limited to Suffolk County House of Correction and Nashua Street Jail.

The post Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents appeared first on The HIPAA Journal.

OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance for state Medicaid Agencies clarifying when the Part 2 regulations permit Medicaid applicants’ or beneficiaries’ SUD records to be used to verify an exclusion from the community engagement requirement for Medicaid eligibility.

The Confidentiality of Substance Use Disorder (SUD) Patient Records regulation, 42 CFR part 2 (Part 2), generally applies to federally assisted programs that provide SUD diagnosis, treatment, or referral for treatment, as well as organizations that receive Part 2-covered records such as health plans that pay for SUD treatment and government benefit programs such as Medicaid.

Under the Medicaid program, adult beneficiaries (aged 19-64) are generally required to engage in work, community service, or other activities for 80 hours per month, or be in at least half-time in education, as a condition of eligibility. There are certain exceptions to these requirements, such as individuals with special medical needs, which may include certain individuals with SUD or those participating in SUD treatment programs.

Under federal law, state Medicaid agencies are required to use reliable and available information to verify an applicant’s or beneficiary’s compliance or exclusion, where possible, without requiring the individual to submit additional information. The Centers for Medicaid and Medicare Services (CMS) has been working with OCR, which is responsible for administering and enforcing the Part 2 regulations, to produce technical assistance for state Medicaid agencies on the use of Part 2 records for verification of exclusion from the community engagement requirement.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“This OCR guidance will help state Medicaid agencies use information they already have to identify individuals who are excluded from the community engagement requirement, while continuing to protect the confidentiality of SUD patient records as required by Part 2,” said OCR Director Paula M. Stannard. “This new guidance helps ensure that state Medicaid agencies comply with Part 2 while also meeting their obligations to verify Medicaid eligibility — and without imposing unnecessary documentation burdens on eligible applicants and beneficiaries.”

The post OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions appeared first on The HIPAA Journal.

Data Breaches Announced by Saber Healthcare & Buchalter

Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to Arrowhead Regional Medical Center.  Bright Smile Dental Care in Indiana has fallen victim to a ransomware attack, although unauthorized access to patient data is considered unlikely.

Saber Healthcare

Saber Healthcare, a Beachwood, Ohio-based skilled nursing, long-term, and senior rehabilitation care provider, has started notifying individuals about unauthorized access to one of its computer servers. The incident was identified on July 27, 2026, and immediate action was taken to secure its systems and prevent further unauthorized access. Third-party cybersecurity experts were engaged to assist with the investigation, which indicated that data stored on the server may have been accessed or acquired.

On August 19, 2026, the review of the server was completed, and up-to-date address information was obtained to allow notification letters to be mailed. Data compromised in the incident varies from individual to individual and may include names in combination with one or more of the following: date of birth, driver’s license/state issued identification number, health insurance information, medical information, financial account information, passport number, and/or Social Security number.

Additional network security measures have been implemented, and data security policies and procedures are being reviewed. No evidence has been found to indicate any misuse of the exposed data; however, the affected individuals have been advised to remain vigilant against identity theft and fraud. The number of affected individuals has yet to be publicly disclosed, although based on disclosures to state attorneys general, the incident has affected more than 3,000 individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Buchalter, LLP (Arrowhead Regional Medical Center)

Patients of Arrowhead Regional Medical Center (ARMC) in Colton, California, have been affected by a cybersecurity incident at the law firm Buchalter, LLP. Buchalter provides legal services to the hospital and was provided with limited patient data in connection with those services. On August 28, 2026, Buchalter discovered that limited data was accessed by an unauthorized third party. An internal investigation was launched, with assistance provided by third-party cybersecurity experts to determine the nature and scope of the unauthorized activity.

On September 4, 2026, it was confirmed that certain ARMC patients had data compromised in the incident, and on September 21, 2026, contact information was obtained to allow notification letters to be mailed. At the time of issuing the notification letters, no misuse of the affected data had been identified.  The data types involved are detailed in the individual notification letters. Buchalter said it has taken steps to improve data security to prevent similar incidents in the future. The number of affected individuals has not yet been publicly disclosed.

Bright Smile Dental Care

Bright Smile Dental Care, a Fishers, Indiana-based dental practice, has experienced a ransomware attack involving a server containing its practice management, dental imaging, and electronic health record software. The incident was identified on August 3, 2026, and third-party cybersecurity experts were engaged to investigate the incident and mitigate its impact.

Bright Smile Dental Care said patient data on the server was protected with encryption, and the keys to decrypt the data are not believed to have been obtained by the ransomware group. While there is a low likelihood of unauthorized data access, patients have been warned that the server contained their names, dates of birth, addresses, email addresses, phone numbers, insurance information, information about dependents, health information, and in some cases, Social Security numbers.

Notification letters have been mailed to the affected individuals, and complimentary credit monitoring services have been offered to individuals whose Social Security numbers were present on the server. The number of affected individuals has yet to be publicly disclosed.

The post Data Breaches Announced by Saber Healthcare & Buchalter appeared first on The HIPAA Journal.

CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit

CPAP Medical Supplies and Services, a Jacksonville, Florida-based provider of durable medical equipment for treating sleep apnea, has agreed to pay up to $500,000 in benefits to individuals affected by a December 2024 cyberattack and data breach.

The cybersecurity incident was identified in late December 2024, and the forensic investigation determined that an unauthorized third party accessed its network between December 13, 2024, and December 21, 2024, and potentially obtained the personal and protected health information of current and former patients and employees. The HHS’ Office for Civil Rights was notified that the electronic protected health information of 90,133 individuals was compromised in the incident. The affected individuals were notified around August 15, 2025.

Four class action complaints were filed in response to the data breach in the District Court for the Middle District of Florida. Since the lawsuits asserted similar claims and had overlapping classes, they were consolidated into the first complaint filed. The defendant denies wrongdoing, fault, and liability, disagrees with all claims and contentions in the lawsuit, and sought to have the lawsuit dismissed. The motion to dismiss was granted in part and denied in part, and the lawsuit was allowed to proceed. The plaintiffs maintain that the defendant was at fault for failing to implement sufficient cybersecurity measures and should have prevented the cyberattack and data breach.

All parties engaged in negotiations, and on September 4, 2026, the terms of a settlement were agreed upon by all parties.  The federal complaint was dropped, and the consolidated lawsuit – Brett Conner v. CPAP Medical Supplies and Services, Inc. – was refiled and is pending in the Circuit Court for Broward County, Florida. The defendant has agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and up to $500,000 in benefits for the class members.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The benefits are two years of medical data monitoring services, and claims may also be submitted for up to $5,000 as reimbursement for documented, unreimbursed losses due to the data breach. If that total is exceeded, claims will be paid pro rata. There is no alternative cash payment. The deadline for opting out and objecting to the settlement is October 30, 2026. Claims must be submitted by November 26, 2026, and the final fairness hearing was scheduled for December 1, 2026.

The post CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit appeared first on The HIPAA Journal.