Author Archives: Steve Alder

ShinyHunters Leaks 7.1 Million Baxter International Records

The ShinyHunters data theft and extortion group recently claimed responsibility for an intrusion at the medical device manufacturer Baxter International (Baxter). Baxter was added to its dark web data leak site a day after Baxter issued a statement about a cybersecurity incident. ShinyHunters proceeded to leak around 7.1 million records allegedly stolen in the incident. The data leak suggests that Baxter refused to negotiate payment or that negotiations broke down.

Baxter is a Deerfield, Illinois-based manufacturer of medical devices for renal care, IV solutions & infusion pumps, surgical products, inhaled anesthetics, and a range of patient monitoring devices and digital health tools. According to an August 13, 2026, statement from Baxter, unauthorized activity was detected within certain third-party applications. The company immediately activated its cybersecurity response procedures and launched an investigation, with assistance provided by third-party cybersecurity and digital forensics experts. The investigation is ongoing to determine the types and amount of information that may have been accessed or acquired.

Baxter said the incident did not have any impact on patient services or business continuity, and the company continues to operate normally. The incident has not had any impact on its products, connected solutions, or technologies used by customers to deliver patient care. Baxter said it does not anticipate the incident having a material impact on financials or the results of operations. The name of the threat group behind the incident was not publicly disclosed.

On August 14, 2026, ShinyHunters added an entry to its dark web data leak site claiming responsibility for the attack. ShinyHunters gave Baxter an August 17, 2026, deadline to negotiate payment, and threatened to leak the stolen data if payment was not made. On August 19, 2026, ShinyHunters released the stolen data for download.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Baxter has not confirmed the nature of the stolen data, only stating that the attack involved certain third-party applications. ShinyHunters claims that 7.1 million Salesforce records were exfiltrated in the attack, some of which contained personally identifiable information. While the group claims to have obtained 7.1 million records, that does not necessarily mean that 7.1 million patients have been affected. Baxter said it will provide updates as appropriate as additional information is confirmed.

ShinyHunters is one of the most active data theft and extortion groups. The group targets large organizations and has claimed several healthcare victims. In June 2026, ShinyHunters claimed to have exfiltrated 8.8 terabytes of data from Amazon-owned OneMedical, including the protected health information of 153,000 patients. Also in June, the group claimed to have exfiltrated 234 GB of data from DentaQuest, including the protected health information of approximately 2.6 million individuals. ShinyHunters was also behind an incident at another medical device manufacturer earlier this year. In July, Medtronic confirmed that the protected health information of 3.8 million patients was stolen in the attack. Other healthcare victims include iRhythm, AdaptHealth, and Him & Hers.

ShinyHunters has targeted companies across a range of different sectors, and while the group’s attacks appear to be opportunistic, the list of victims includes many healthcare organizations. The increasing number of attacks on healthcare organizations prompted Health-ISAC to issue an alert to the healthcare and public health sector in July about the ShinyHunters group.

The post ShinyHunters Leaks 7.1 Million Baxter International Records appeared first on The HIPAA Journal.

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

More than a dozen U.S. health care systems have issued warnings to patients about an ongoing phishing campaign involving emails purporting to be legitimate communications sent via their MyChart patient portal. Many of the emails claim that the recipient is a winner of a MyChart Medicare Kit, although other healthcare benefits, Medicare packages, free gifts, or rewards may be offered. Texas Health Resources has warned patients that some email communications offered a “Senior Health Package.”

Healthcare providers that use Epic Systems’ electronic health records and MyChart portals, including Methodist Health System, Premier Health, Sentara Health, Metro Health, and Texas Health Resources, have added scam warnings to their websites about the campaign. The scammer most likely seeks MyChart credentials, Medicare information, financial account information, or other sensitive data.

The emails are not sent from legitimate healthcare provider email addresses or domains, and while they include a MyChart logo, they have not been sent by Epic Systems. The logo is used to make the messages appear legitimate. An example of one of the phishing emails is detailed below, although other messages may also be used in this campaign.

Epic Systems MyChart phishing scam

Example of a phishing email impersonating MyChart

“We’ve seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official,” explained Trevor Berceau, Director R&D, Epic Systems. “Some might try to steal your login information or promise free gifts if you enter payment details. The increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal. If something doesn’t feel right, however, stop and check.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The threat actor behind the campaign has yet to be identified, and it is unclear how the cybercriminal or group behind the scam obtained patients’ contact information. It is likely that email addresses were obtained in a previous data breach, although that data breach may not necessarily have occurred at their healthcare provider.

The advice to patients is to delete any such messages immediately and not click on any links, including the “unsubscribe” link. It is important not to reply to the email, and to never disclose personal or financial information in response to one of these communications or attempt to log in to the patient portal using the link in the message. If any action has been taken, such as logging in via the link, patients should immediately reset their MyChart portal password and contact their healthcare provider’s MyChart support team.

Patients should remain vigilant against any unsolicited emails, text messages, or phone calls claiming to offer free gifts or rewards. Recipients of emails or text messages should carefully check the sender’s information to ensure that it has come from a legitimate email address or domain. These messages often include spelling and grammatical errors, unusual requests, free gifts or rewards, and often advise the recipient to take immediate action. If in any doubt about the legitimacy of any request, patients should contact the relevant healthcare provider using verified contact information. Never use any contact information included in the suspicious communication.

The post Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam appeared first on The HIPAA Journal.

Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit

Tift Regional Health System Inc, a non-profit health system serving patients in south central Georgia, has agreed to pay $1.2 million to settle a class action lawsuit stemming from a 2022 cyberattack that exposed patient data.

Tift Regional Health, which operates as Southwell, Inc., which is also a defendant, identified suspicious activity within its computer network on or around August 16, 2022. The forensic investigation confirmed that its network was accessed by an unauthorized third party between August 11, 2022, and August 17, 2022. The compromised parts of the network contained documents that included patient names, birth dates, Social Security numbers, and a range of sensitive medical information. Tift Regional Health said those documents may have been accessed or copied in the attack. A ransomware group  – Hive – claimed responsibility for the attack. Hive claimed to have stolen 1 terabyte of data and proceeded to leak some of that data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 180,142 individuals.

Multiple class action lawsuits were filed against the defendants in response to the data breach. The lawsuits were consolidated into a single action – In Tift Regional Health System, Inc. Data Breach Litigation – in the Superior Court of Tift County, State of Georgia, as the lawsuits had overlapping claims. The consolidated lawsuit alleged that the cyberattack and data breach were due to the defendants’ failures to properly secure, safeguard, and encrypt patient data, and destroy patient data in a timely manner when it was no longer required.  The lawsuit also took issue with the length of time it took to notify the affected individuals. They were not notified about the data breach until August 11, 2023, almost a year after the incident occurred.

The lawsuit asserted claims for negligence, negligence per se, breach of fiduciary duty, breach of implied contract, breach of contract, breach of the covenant of good faith and fair dealing, unjust enrichment, invasion of privacy, violation of the Georgia Uniform Deceptive Trade Practices Act, and for equitable and injunctive relief. The defendants deny the claims and contentions in the lawsuit and maintain there was no wrongdoing and no liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Both sides agreed to a settlement to avoid the costs and risks of a trial. The defendants have agreed to establish a $1,200,000 settlement fund to pay benefits to the class members after attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives have been deducted. The defendants have also implemented a range of additional measures to better secure sensitive data in their possession, and those measures will be maintained for at least two years at an estimated cost of $4.5 million.

All class members are entitled to enroll in a two-year credit/medical data monitoring and identity theft protection service, and claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to a maximum of $5,000 per class member, or a claim may be submitted for an alternative cash payment.

The cash payments will be paid pro rata after all other claims and costs have been deducted, and they will exhaust the settlement fund. The cash payments are expected to be approximately $75 per class member but may be higher or lower. The settlement has received preliminary approval from the court, and the final fairness hearing is scheduled for September 14, 2026. The deadline for opting out and objecting to the settlement is September 15, 2026. Claims must be submitted by October 15, 2026.

The post Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.

DAP Health Settles Data Breach Lawsuit for $1,300,000

DAP Health, a nonprofit community healthcare network based in Southern California, has agreed to settle a class action lawsuit that was filed in response to a cyberattack on its computer systems that exposed sensitive patient data.

Suspicious activity was identified within certain computer systems on or around July 22, 2024. An investigation was launched, which confirmed that an unauthorized third party gained access to an email server and exfiltrated emails and files containing personally identifiable information and protected health information. Data stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, birth certificate numbers, vehicle license plate and VIN numbers, financial account numbers, Medicare/Medicaid numbers, health insurance information, and a range of medical information.

Notification letters started to be sent to the affected individuals in December 2024, and the breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 129,048 individuals. The first class action lawsuit in response to the data breach was filed in January 2025, and a second lawsuit was filed in early February 2025. The plaintiffs agreed to work together, and an amended complaint – Donald Crosslin and Matthew Paone v. DAP Health, Inc. was filed in the Superior Court for the State of California for the County of Riverside in June 2025.

The lawsuit alleged that the data breach could have been prevented and was a result of a failure to implement reasonable and appropriate cybersecurity measures. The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, and violations of the California Confidentiality of Medical Information Act, California’s Unfair Competition Law, and the California Consumer Privacy Act. DAP Health denies all material allegations, including claims of wrongdoing, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Following extensive arm’s-length negotiations, all parties agreed to settle the litigation, with no admission of wrongdoing or liability by the defendant. Under the terms of the settlement, DAP Health has agreed to establish a $1.3 million settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the two class representatives. The remainder of the fund will be used to pay for class member benefits.

Class members may submit a claim for reimbursement of documented losses due to the data breach up to a maximum of $5,000 per class member. Regardless of whether a reimbursement claim is submitted, class members may claim a pro rata cash payment. The cash payments are estimated to be $25 per class member. Class members who were California residents on July 22, 2024, can also claim a statutory cash payment of $75. In addition, all class members can submit a claim for two years of complimentary credit monitoring and identity theft protection services.

The deadline for exclusion and objection is September 1, 2026. The deadline for submitting a claim is October 21, 2026. The settlement has received preliminary approval from the court, and the final fairness hearing has been scheduled for October 1, 2026.

The post DAP Health Settles Data Breach Lawsuit for $1,300,000 appeared first on The HIPAA Journal.

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 500 critical infrastructure victims.

When the cybersecurity advisory was first issued in March 2025, the authorizing agencies determined that Medusa had conducted more than 300 attacks on critical infrastructure entities between 2021 and February 2025. The Medusa ransomware operation emerged in June 2021 and initially operated as a closed ransomware group, with the developers conducting all aspects of the operation, including development, ransomware campaigns, and ransom negotiations.

In early 2023, Medusa morphed into a RaaS operation, using affiliates to conduct attacks for a percentage of the ransom payments. The group also launched a data leak site in 2023 and adopted double extortion tactics, issuing threats to publish stolen data to pressure victims into paying to prevent data leaks as well as to obtain the keys to decrypt data. Since the transformation into a RaaS group, attacks have increased substantially, with the developers and the group’s affiliates conducting attacks. In a little over a year, the group has claimed more than 200 victims in critical infrastructure sectors, compared to 300 in the previous four years.

Affiliates are given various levels of control based on their experience and profitability, with newer and less experienced affiliates having lower levels of trust. For instance, the developers retain control of important aspects of campaigns such as ransom negotiations for newer and less experienced affiliates. The developers recruit initial access brokers (IABs) on cybercriminal forums to provide access to victims’ networks, typically paying between $100 and $1 million to the IAB for access.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While some RaaS groups have a policy of not attacking healthcare organizations, that is certainly not true of Medusa, which has frequently attacked the healthcare and public health (HPH) sector. While the group is largely believed to operate opportunistically, conducting attacks by focusing on organizations with unpatched, remotely exploitable software vulnerabilities, the high percentage of victims in the HPH sector could indicate targeting of the sector.

Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.  No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.

Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.

The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.

March 13, 2025: Critical Infrastructure Entities Warned About Medusa Ransomware as Victim Count Hits 300

A warning has been issued about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 300 victims in critical infrastructure sectors including healthcare, education, and manufacturing. The group has been active since June 2021 when it started as a closed group, before adopting the RaaS model, where affiliates are recruited to conduct attacks for a percentage of any ransom payments they generate.

Around two years after the group formed, Medusa launched a data leak site where victims are named and stolen data is published if the ransom is not paid. This double extortion method, where the ransom must be paid to obtain the decryption keys and prevent the publication of stolen data, is common among RaaS groups, although in the case of Medusa, its core members have retained control of ransom negotiations.

According to the joint cybersecurity alert from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), the Medusa developers recruit initial access brokers (IABs) on cybercriminal forums and marketplaces and incentivize them to work solely with Medusa. The authoring agencies have observed affiliates using phishing to obtain credentials to access victims’ networks, as well as exploiting unpatched software vulnerabilities, including last year’s ScreenConnect vulnerability CVE-2024-1709 and the Fortinet EMS SQL injection vulnerability CVE-2023-48788.

Once access to a victim’s network has been gained, Medusa actors use living off the land techniques for user, system, network, and file system enumeration, including legitimate tools such as Advanced IP Scanner, SoftPerfect Network Scanner, PowerShell, Windows Command Prompt, and Ingress Tool Transfer capabilities, as well as Windows Management Instrumentation (WMI) for querying system information.

The authoring agencies have observed Medusa actors using several different PowerShell detection evasion techniques, and they are known to hide their activities by deleting the PowerShell command line history. Endpoint detection and response tools are disabled by using vulnerable or signed drivers to kill processes, and legitimate remote access software is often used to evade detection and assist with lateral movement, along with Remote Desktop Protocol (RDP) and PsExec. Rclone is used to facilitate data exfiltration, and the encryptor is deployed across the network using tools such as Sysinternals PsExec, PDQ Deploy, and BigFix. Windows Defender and other security tools are also disabled on specific targets, backup processes are terminated, and shadow copies are deleted to prevent restoration of encrypted files without paying the ransom. Victims are given 48 hours to make contact to negotiate the ransom payment, with Medusa actors also known to reach out to victims via phone or email. There has been at least one instance where a further ransom demand was issued after the initial payment was made, where the affiliate behind the attack claimed not to have been paid.

The cybersecurity alert shares indicators of Compromise (IOCs), known MITRE ATT&CK tactics and techniques, and recommended mitigations, the most important of which are mitigating known vulnerabilities promptly, segmenting networks to restrict lateral movement, filtering network traffic to prevent unknown or untrusted origins from accessing remote services on internal systems, implementing multifactor authentication for webmail, VPNs, and all accounts that access critical systems, and educating the workforce about phishing identification and avoidance.

The post Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs appeared first on The HIPAA Journal.

Free Webinar Recording: Inside 250 HIPAA Investigations – What You Need to Know

Free Webinar Inside a HIPAA InvestigationLearn exactly what happens during a HIPAA investigation. Understand where organizations fail so you can avoid government fines and drawn-out investigations.

Based on real experience from over 250 actual OCR investigations.

When it comes to HIPAA investigations, many organizations lean on the hope that they will never be implicated. But, with the rise of ransomware breaches and patient complaints, your organization is much more likely to end up in the crosshairs of the Office for Civil Rights (OCR) than you might expect. 

While you can’t always prevent breaches from occurring, you can control your preparedness for everything that follows when it comes to your HIPAA compliance posture. 

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Join Jake Dewberry, Chief Legal Officer, and Ryan Boudreau, Senior Vice President of Operations from Abyde, as they walk through the details of what an investigation actually looks like and where organizations fail based on their experience in over 250 OCR investigations. They will be sharing real (redacted) examples from past investigations, detailing what the OCR asks for, how to respond safely, and how others failed so you can avoid government fines and drawn-out investigations. 


On Demand Webinar Recording

August 19th Event Ended – Available on Demand 

 

 A recording will be made available to anyone who registers but is unable to attend the live event.


Attendees discover:

  • What triggers an investigation
  • What to do immediately after receiving an investigation letter
  • A breakdown of what the OCR is really asking for, including the most commonly missed requirement
  • Best practices for building your response
  • The possible results of an investigation
  • Real examples of investigation letters

Speakers: 

Jake Dewberry Jake Dewberry – Chief Legal Officer

Jake Dewberry serves as the Chief Legal Officer at Abyde. With over 14 years of experience in the healthcare industry, Jake has worked closely with hospitals and small to mid-sized practices across the country, helping them navigate the evolving world of healthcare technology and regulatory requirements. Jake is also a licensed attorney based in Florida. At Abyde, he wears multiple legal hats — from advising clients during breach responses and audits, to managing the company’s day-to-day legal operations, and staying on top of federal and state regulatory changes impacting HIPAA and OSHA compliance.

 

Ryan BoudreauRyan Boudreau – Senior Vice President of Operations 

Ryan Boudreau is the Senior Vice President of Operations at Abyde, where he leads a team of HIPAA and OSHA compliance experts. A cybersecurity and risk management veteran with nearly 15 years of experience, his team has successfully navigated hundreds of OCR investigations on behalf of their clients.

Abyde is a leader in the compliance software industry, streamlining HIPAA & OSHA requirements for thousands of practices across the United States.


On Demand Webinar Recording

August 19th Event Ended – Available on Demand

 A recording will be made available to anyone who registers but is unable to attend the live event.

The post Free Webinar Recording: Inside 250 HIPAA Investigations – What You Need to Know appeared first on The HIPAA Journal.

Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident

Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.

Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston.  The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity.  The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.

Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.

Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Baylor Genetics said the incident did not impact its laboratory operations, which continued without interruption throughout the investigation, and there was no impact on the company’s ability to provide genetic testing services. Baylor Genetics has enhanced its security and monitoring controls, strengthened identity and access management, and has implemented additional security controls to prevent similar incidents in the future.  Complimentary credit monitoring and identity theft protection services have been offered to at least some patients.

The data breach has been reported to regulators; however, it is currently unclear how many patients and employees had data compromised in the incident. The breach has affected patients in California, as the California Attorney General was notified about the data breach, as was the Vermont Attorney General. At least 2,630 Vermont residents have been affected.

The post Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident appeared first on The HIPAA Journal.

American Addiction Centers & Oculus Pathology Disclose Hacking Incidents

Hacking incidents have been announced by American Addiction Centers in Tennessee and Oculus Pathology in Texas. Regional Center of Orange County in California has discovered the improper disposal of paper records.

American Addiction Centers, Tennessee

American Addiction Centers, a Brentwood, Tennessee-based provider of addiction treatment services at more than 30 facilities across the United States, has notified the California Attorney General about a recent security incident involving a third-party vendor. According to the notice, suspicious activity was identified within its Salesforce environment on June 5, 2026.

The forensic investigation determined on June 12, 2026, that there had been unauthorized access to its Salesforce instance on May 12, 2026, and data was exfiltrated from that system. The forensic investigation confirmed that the incident did not affect any other systems. The data review confirmed that names, contact information, Social Security numbers, and health insurance information were acquired, along with brief descriptions that patients provided related to their health. The affected data related to initial outreach to American Addiction Centers.

American Addiction Centers said that security measures had been implemented prior to the breach and that it will continue to review its security measures to further protect and monitor its Salesforce environment, and complimentary credit monitoring and identity theft protection services have been made available. At present, it is unclear how many individuals have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Oculus Pathology, Texas

Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology group that provides services in several U.S. states, has announced an email security incident that has exposed patient information. Suspicious activity was identified within an employee’s email account on April 1, 2026. An investigation was launched to determine the nature and scope of the activity, and it was determined that a small number of employee email accounts had been accessed by an unauthorized third party between March 31, 2026, and April 2, 2026.

Data review specialists were engaged to investigate the incident. Data exposed in the incident includes personally identifiable information such as names, birth dates, Social Security numbers, driver’s license numbers/state ID numbers, and individual tax identification numbers. Some financial account numbers and payment card numbers were exposed, in some cases with access information.

In addition, protected health information was exposed, including clinical information, health insurance information, diagnoses, treatment and procedure information, treatment locations, medical record numbers, Medicare numbers, prescription information, and patient IDs. The data review is ongoing. Oculus Pathology has yet to announce how many individuals have been affected in total.

Regional Center of Orange County, California

Regional Center of Orange County, a Santa Ana, California-based nonprofit organization that provides services to approximately 29,000 Orange County residents with autism, epilepsy, cerebral palsy, and intellectual and cognitive disabilities, has announced a data security incident that has exposed sensitive data. The incident involved paper records that were mistakenly disposed of by a Janitorial service contracted to clean its Cypress office. The incident occurred on May 27, 2026, and was discovered on May 28, 2026. Documents had been disposed of in regular trash bins rather than being sent for secure destruction. Attempts were made to retrieve the documents; however, the trash had already been collected.

It was not possible to determine the exact patients involved or the specific types of information, so notification letters have been sent to all individuals who received services at the Cypress office.  Data likely exposed included names, addresses, birth dates, phone numbers, email addresses, unique client identifiers, and personal health information. Regional Center of Orange County said it is reviewing and strengthening internal procedures, staff training, and vendor oversight to prevent similar incidents in the future, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

The post American Addiction Centers & Oculus Pathology Disclose Hacking Incidents appeared first on The HIPAA Journal.

Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon

Data breaches have recently been announced by Terry J. Dubrow, MD, SunCloud Health, Integer Precision Technologies, Minnesota ENT, and Nipro Medical Corp.

Terry J. Dubrow, MD, California

Terry J. Dubrow, MD, a Beverly Hills, CA-based plastic surgeon, has notified the California Attorney General about a recent security incident involving patient information. The practice was contacted by an individual who claimed to have breached its computer systems and copied sensitive patient information. An investigation was launched to establish whether the claim was legitimate, and it was confirmed that there had been unauthorized access to parts of its network starting on January 16, 2026, and that files had been copied.

The affected data was reviewed, and on July 27, 2026, the practice confirmed that patients’ personal information had been obtained, including names, information collected on patient charts, and referring physician information. That information may have included contact information, Social Security numbers, driver’s license numbers or state ID numbers, birth dates, prescription information, treatment information, procedure images, and X-rays. The practice has implemented additional security measures to reduce the risk of similar incidents in the future, and the affected individuals have been offered complimentary identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

SunCloud Health, Illinois

SunCloud Health, a Northbrook, Illinois-based behavioral health treatment network, has recently disclosed a data security incident involving the protected health information of 2,594 individuals. Unusual activity was identified in certain employee email accounts. Steps were taken to secure its email system, and an investigation was initiated to determine the cause of the activity. The investigation confirmed unauthorized access to certain employee email accounts between April 22, 2026, and May 4, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The affected accounts were reviewed, and on June 16, 2026, SunCloud Health determined that the accounts contained patient names and medical information related to the services provided, including diagnoses, medications, and treatment information. The affected individuals were notified by mail on July 23, 2026; existing security protocols have been enhanced, and IT systems are being monitored, with additional safeguards being evaluated.

Integer Precision Technologies, Massachusetts

Integer Precision Technologies, a Hudson, Massachusetts-based company that makes coatings for medical devices, has recently disclosed a data security incident involving a cloud-based SaaS file sharing application. While it is unclear exactly when the incident was detected or for how long access was possible, the investigation determined that an unauthorized third party accessed the application and copied files.

Assisted by a third-party data review firm, the company determined that the files contained personal information including names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account numbers, and some health-related information. The affected individuals have been offered 24 months of complimentary credit monitoring and identity theft protection services, and steps have been taken to enhance security. The number of affected individuals has yet to be publicly disclosed.

Minnesota ENT

Oakdale Ear, Nose, & Throat PA, doing business as Minnesota ENT, has started notifying individuals affected by a recent email security incident. It is unclear from the substitute breach notice when the security incident was detected, or for how long it lasted. The notice states that six employee email accounts were accessed by an unauthorized third party and, assisted by third-party cybersecurity experts, Minnesota ENT determined on July 15, 2026, that the accounts contained HIPAA-protected data.

Data compromised in the incident included first and last names, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information.  Notification letters started to be mailed to the affected individuals on August 12, 2026. The letters include information on the steps that can be taken to protect against data misuse. The number of affected individuals has yet to be publicly disclosed.

Nipro Medical Corp., New Jersey

Nipro Medical Corp., the U.S. subsidiary of the Japanese company Nipro Corp, has identified a security incident that exposed sensitive information. The New Jersey-based company provides medical supplies to hospitals, including renal care products, vascular and interventional devices, and disposable hospital supplies. Nipro said it identified suspicious activity within its IT systems and determined that an unauthorized third party may have viewed or acquired sensitive information such as credit and debit card information, Social Security numbers, and other government identifiers.  The affected individuals have been offered 24 months of complimentary credit monitoring services. The number of affected individuals has yet to be publicly disclosed.

The post Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon appeared first on The HIPAA Journal.