Author Archives: Steve Alder

Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic

Settlements have been agreed to resolve class action data breach lawsuits against Omni Healthcare Financial Holdings and its subsidiaries, and Western Montana Clinic.

Omni Healthcare Financial Holdings Data Breach Settlement

Omni Healthcare Financial Holdings, along with defendants Omni Healthcare Financial, LLC, and Injury Finance, LLC (Omni Healthcare), have settled class action litigation over a January 2024 cybersecurity incident involving the protected health information of 16,852 individuals.

Omni Healthcare, a provider of financial solutions to healthcare organizations and patients, experienced a cybersecurity incident involving unauthorized network access between January 18 and January 19, 2024. Information exposed in the incident included names, contact information, dates of birth, Social Security numbers, diagnosis & treatment information, medical record numbers, treatment costs, provider names, and other information. The affected individuals were notified in April 2025, 15 months after the breach was first detected. In total, Omni Healthcare mailed around 42,000 notifications.

The first class action lawsuit was filed by plaintiff Latasha Hammond on April 16, 2025, followed by a second lawsuit by plaintiff Dawn Hairston. Both lawsuits were filed in the District Court for the Western District of North Carolina, and were consolidated, adding a further two plaintiffs – Hammond et al. v. Omni Healthcare Financial Holdings et al. The litigation was subsequently moved to the Superior Court of Mecklenburg County, North Carolina, where it is pending.

The consolidated lawsuit alleged that the data breach could have been prevented and occurred as a result of the defendants’ failure to implement appropriate industry-standard cybersecurity measures, and its failure to comply with the standards of the HIPAA Privacy and Security Rules. The lawsuit asserted claims for negligence/negligence per se, breach of implied contract, and unjust enrichment. The defendants deny all claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability.

The parties determined that a settlement was the best outcome, as it avoids further legal costs and the uncertainties of a trial and related appeals. The defendants will cover the cost of attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and benefits for the class members.

Class members are entitled to enroll in three years of medical data monitoring and medical identity theft services and may submit a claim for one of two cash payments:

  • Cash Payment A – Reimbursement of documented, unreimbursed losses due to the data breach up to $5,000 per class member, or
  • Cash Payment B – A one-time cash payment of $40 per class member

The final approval hearing has been scheduled for August 13, 2026, and the claims deadline is September 3, 2026.

Western Montana Clinic Data Breach Settlement

Western Montana Clinic, a medical group practice in Missoula, MT, has settled a class action lawsuit stemming from a breach of its email environment in Spring 2025. Suspicious email activity was detected on April 15, 2025, and the forensic investigation confirmed unauthorized access to certain employee email accounts between March 11, 2025, and April 15, 2025.

The data review determined that the protected health information of 8,255 individuals was compromised, and 9,506 individuals were affected in total. Data exposed in the incident included contact information, Social Security numbers, dates of birth, treating physician names, internal identification numbers, dates of service, medication information, diagnostic information, and treatment information. The affected individuals were notified on August 8, 2025.

Western Montana Clinic was sued over the data breach, and the lawsuit – Murphy v. Western Montana Clinic – is pending in the Fourth Judicial District of Montana. The lawsuit claimed the data breach occurred as a result of the failure of the clinic to implement reasonable and appropriate cybersecurity measures, and asserted claims for negligence, negligence per se, breach of implied contract, and unjust enrichment. Western Montana Clinic denies wrongdoing and liability; however, it agreed to settle the lawsuit to avoid the litigation costs and expenses, distractions, burden, and disruption to its business operations associated with further litigation.

Western Montana Clinic has agreed to pay attorneys’ fees and expenses, settlement administration costs, $2,500 service awards to the two named plaintiffs, and class member benefits. Class members may claim a one-year membership to a medical data monitoring service, up to three hours of lost time at $20 per hour, and reimbursement of documented, unreimbursed out-of-pocket losses up to a maximum of $5,000 per class member. The deadline for exclusion and objection is August 17, 2026. Claims must be submitted by September 15, 2026, and the final fairness hearing has been scheduled for September 9, 2026.

The post Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic appeared first on The HIPAA Journal.

Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data

The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts to track consumer product-related injuries. By the end of the year, CPSC hopes that more than 100 hospitals will provide the requested records to the Kansas-based government contractor Konza Health, which was awarded a $15.9 million contract last year to support the National Electronic Injury Surveillance System (NEISS) Remodel project.

NEISS has been in operation for more than 5 decades, and its primary purpose is to collect data on consumer product-related injuries in the United States. NEISS is an important public health research tool; however, data collection is labor-intensive and involves a manual review and coding of medical records from around 70 of the nation’s 5,000+ hospital emergency departments. Currently, 14 states do not have any participating hospitals, which limits the geographic reach of the system and has reduced CPSC’s ability to identify rare and emerging product hazards.

Under the planned NEISS Remodel (NEISS-R) project, coverage will be expanded to all 50 states to ensure data is collected from currently underrepresented and non-represented states. The plan involves automating data collection by leveraging modem technology and the country’s electronic health record infrastructure. In so doing, CPSC said it will be able to identify rare and emerging hazards much more rapidly than the legacy system allows.

NEISS-R will see data exchanged through a federally designated Qualified Health Information Network (QHIN), which CPSC claims “is supported by contractual privacy requirements and standardized security safeguards.” The data collected will be limited, as will data retention, to the minimum necessary information to support CPSC’s statutory mission, and will support de-identification before the data reaches CPSC. CPSC says the project will result in a more timely, more accurate, and more cost-effective system, which will better protect American families.

Under the current system, emergency department nurses are required to review patient charts, manually identify consumer-related accidents, and enter that information into a national database. Under the new system, data collection would be automated, and it would be the responsibility of Konza Health, a TEFCA QHIN, to strip out identifying information prior to data transfers to CPSC.

According to the letters sent by Konza Health to hospitals, “Using accident-related diagnosis codes, Konza Health will identify patients that may have experienced a consumer product-related accident. For identified accidents, Konza Health will gather additional patient clinical information and provide it to CPSC for follow-up.” The letters request meetings with the selected hospitals to establish connectivity methods to allow secure data exchange for the project.

The NEISS-R project has sparked privacy fears, as under the manual system, nurses were instructed not to provide identifiable information such as patient names, addresses, or birth dates; however, the automated system would involve sending identifiable patient data Konza Health. While it is claimed that the data provided to CPSC will be unchanged from the information it has obtained for the past five decades, far broader access to patient data is sought.

KFF Health News reports that, based on emails shared by hospitals and interviews with people involved or familiar with the discussions between the hospitals and Konza Health, the data requested falls well outside of the CPSC’s consumer product safety mission. “In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt,” explained KFF Health News. “A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information — such as names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis.” According to communications between Konza Health and technology officials at one hospital, ER data is requested for more than 10,000 conditions, including injuries totally unrelated to consumer products.

CPSC and Konza Health have faced resistance from some hospitals over the mandatory provision of the data, and have suggested that refusing to provide the required data could be viewed as information blocking, potentially leading to significant penalties; however, the information being sought raises HIPAA concerns. Under HIPAA, hospitals are permitted, but not required, to submit data to CPSC for public health purposes, but any disclosure should be limited to the minimum necessary information to achieve the purpose for the disclosure. Since CPSC is collecting data to fulfil its consumer product safety mission, any data disclosed should be limited to that purpose. Should CPSC require more data than it has previously collected, further rulemaking would be necessary.

Participating hospitals could find themselves between a rock and a hard place – potential fines for information blocking if they do not agree to provide the requested data and potential HIPAA fines if they do. However, under the current information blocking regulations, there is a privacy exception, the purpose of which is to ensure that health information is not required to be disclosed in a way that is prohibited under state or federal privacy laws, and under the HIPAA minimum necessary standard, disclosures should be restricted to information required for CPSC’s public health activities, which concern consumer product safety.

The post Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data appeared first on The HIPAA Journal.

Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals

Lifespan Physicians Group of Massachusetts, doing business as Brown Health Medical Group-MA, has confirmed that the protected health information of almost 312,000 individuals was potentially compromised in a December 2025 security incident.

There is currently no substitute breach notice on the medical group’s website; however, the data breach was reported to the Vermont and Massachusetts Attorneys General. The breach notices issued to those regulators explain that unauthorized activity was identified in a legacy file server at the practice on December 16, 2025. The server was isolated, and an investigation was launched to determine the nature and scope of the unauthorized activity. The forensic investigation confirmed that the breach was limited to the file server, which was accessed by an unauthorized third party between December 15 and December 16, 2026. The electronic medical record system was not involved.

The server was reviewed to determine the exact types of information stored on the server. The file review determined on June 22, 2026, that the following categories of data were impacted – names, dates of birth, contact information, Social Security numbers, driver’s license numbers or other government-issued identification numbers, credit or debit card numbers, financial account information, and personnel and human resources records. The latter may have included information such as compensation or payroll information, licensure or credentialing information, and medical or disability-related records.

Steps have been taken to improve security to prevent similar incidents in the future, including implementing enhanced technical safeguards. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 24 months. The incident affected 290,357 Massachusetts residents and 86 Vermont residents. According to the HHS’ Office for Civil Rights data breach portal, the protected health information of 311,760 individuals was potentially stolen in the incident.

The post Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals appeared first on The HIPAA Journal.

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the states of Utah and California over the company’s business and data sharing practices, which are alleged to violate the Federal Trade Act, Restore Online Shoppers’ Confidence Act, Utah Consumer Sales Practices Act, and California’s False Advertising and Unfair Competition Laws.

Him & Hers is a direct-to-consumer business that provides prescription and over-the-counter medications. According to the complaint, filed last week in the U.S. District Court for the Northern District of California, the company claims to maintain consumers’ privacy yet discloses their sensitive data to third-party advertising platforms, without consumers’ knowledge or consent. In addition, the complaint alleges that the company deceives consumers about its billing and cancellation policies.

Him & Hers used tracking technologies such as Meta Pixel and the Meta Conversions API, which automate the recording of user data based on the Him & Hers website and transmit that information to Meta in response to certain events. Him & Hers also used a variety of advertising tools from companies such as Snap, Microsoft, Google, Criteo, Pinterest, TikTok, Trade Desk, and X, which also collected sensitive consumer information and transferred the information to third-party companies for advertising purposes. Him & Hers is also alleged to have sent lists of certain customers to the Meta and Snap custom audience systems.

Oftentimes, consumers use Him & Hers to obtain medications for sensitive medical conditions such as mental health issues, erectile dysfunction, and premature ejaculation. According to the complaint, until at least mid-2023, Him & Hers claimed that “medical records and sensitive information are only accessed by the medical providers managing your care,” and has claimed in its online advertising that consumers are provided with a “100% online, private, and secure process,” yet sensitive information was being shared with third parties for advertising purposes.

In addition to the unlawful data transfers, the complaint alleges that Him & Hers failed to clearly disclose that consumer prescriptions are charged almost immediately after completing an intake form. Consumers were informed that they could consult with a medical provider to find a suitable treatment and would not be charged unless and until their prescriptions are prescribed. The FTC alleges that Him & Hers rarely provides medical consultations, enrolls customers almost immediately into recurring subscription plans, and makes it difficult for consumers to cancel their subscriptions. For instance, consumers are not informed clearly and conspicuously when their recurring prescriptions will be refilled, which makes it difficult for them to cancel before the next billing cycle. Consumers are also not permitted to cancel subscriptions online, only via the phone, email, or chat, and the complaint alleges that consumers must navigate other hurdles, making it “extremely difficult” to cancel subscriptions.

The lawsuit seeks a permanent injunction preventing the company from engaging in unfair and deceptive business practices, civil penalties, and monetary awards. “The FTC’s complaint lays out a troubling scenario—consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers’ most private health information without their consent,” said Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection. “The FTC will not hesitate to act on behalf of consumers deprived of their ability to choose which products they want and whether to keep their most sensitive health information private.”

This is not the first time that the FTC has taken action against telehealth companies over the use of tracking technologies. Enforcement actions have previously been filed against the fertility tracking app Premom, BetterHelp, and GoodRx. In each case, the complaints were resolved with financial penalties.

The post FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices appeared first on The HIPAA Journal.

AmGen Announces Cyberattack and Data Breach Involving Patient Data

Amgen Inc., a Thousand Oaks, CA-based biopharmaceutical company that develops and manufactures pharmaceutical products for oncological, hematological, and cardiovascular diseases, has recently disclosed a cybersecurity incident involving unauthorized access to third-party-hosted cloud storage systems.

In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), Amgen explained that it determined in July 2026 that hackers gained access to certain cloud systems. Amgen immediately implemented its cybersecurity response plan, deployed containment measures, and engaged third-party digital forensics experts to determine the nature and scope of the unauthorized activity.

The investigation determined that proprietary data, patients’ protected health information, and other data had been exfiltrated from the cloud environment, and on July 29, 2026, determined that the incident was material and informed the SEC. Amgen said it does not believe the incident is reasonably likely to have an impact on its financial position, nor any of its products, manufacturing operations, financial reporting systems, or its ability to meet patient needs.

Amgen is in the process of assessing the extent to which patient information, confidential business information, intellectual property, research and development, and other information was exfiltrated in the attack and will be unable to accurately determine the impact to the company until those processes have concluded. At present, the exact nature of the attack, such as how the cloud systems were compromised, has yet to be made public. Amgen said it takes the protection of its systems and data very seriously and is in the process of determining the applicable regulatory and legal notification requirements, including its responsibilities under HIPAA.

As of the date of the SEC filing, the threat group behind the attack is unclear. Several pharmaceutical, biotechnology, and medtech firms have fallen victim to cyberattacks in recent months, including Novo Nordisk, Medtronic, Stryker, Abbott Laboratories, West Pharmaceutical Services, and Brainyx AI. The attacks have been conducted by several threat actors, including the Iran-linked hacktivist group Handala and the data theft and extortion groups FulcrumSec and ShinyHunters. The latter was the subject of a recent cybersecurity alert by Health-ISAC after a string of successful hacks on the healthcare sector.

The post AmGen Announces Cyberattack and Data Breach Involving Patient Data appeared first on The HIPAA Journal.

CISA Issues Updated Guidance on Minimum Elements of an SBOM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international cybersecurity authorities have published joint guidance on the minimum elements of a Software Bill of Materials (SBOM). An SBOM is a detailed list of software components, including open-source libraries and hidden dependencies, together with the creators or vendors associated with those components.

Software supply chains are often large and complex, and vendors can be slow to release patches to address vulnerabilities, especially when those vulnerabilities affect third-party components. Cybercriminals target software supply chains as they often have ample time to exploit vulnerabilities before patches are released. Keeping up to date with vendor patches is important; however, simply applying vendor patches does not guarantee that the software is secure. If an SBOM is obtained from a software vendor, users will be able to identify vulnerable or risky components long before patches are released by vendors, allowing them to implement temporary solutions to protect against software supply chain attacks.

In 2021, the National Telecommunications and Information Administration (NTIA) published guidance on the minimum elements for an SBOM, and the latest guidance replaces that document, incorporating stakeholder feedback obtained following the publication of draft guidance in 2025. “SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs,” wrote the authoring agencies. “These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021.”

The latest guidance applies to all software solutions, although additional requirements may be necessary for certain types of software, such as AI-based software systems and software-as-a-service (SaaS) solutions in cloud environments. The authoring agencies recommend using the guidance to ensure that their SBOMs include the minimum requirements and then assessing each software solution to determine if any further efforts are required to improve software transparency.

The update includes an additional ten data fields, updates to eight components to clarify scope and specify expectations, and five minor updates to improve information quality and align the guidance with the latest technical developments. The guidance is aimed at organizations that produce, procure, or operate software, and will allow them to better understand the makeup of their software components and supply chains and make more risk-informed decisions.

The post CISA Issues Updated Guidance on Minimum Elements of an SBOM appeared first on The HIPAA Journal.

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to ransomware actors, ShinyHunters conducts supply chain and identity attacks, targeting cloud SaaS and storage platforms. The group is focused on cloud-scale data exfiltration, with initial access typically achieved by voice-based social engineering (vishing) to reset passwords, MFA, or enroll new devices, according to a recent Health-ISAC cybersecurity alert.

Once account access is gained, they log in to the organization’s Okta, Microsoft Entra, or Google SSO dashboard, which lists all applications the account holder has access to, such as Microsoft 365, Salesforce, Dropbox, Google Drive, and other third-party platforms.  Data is rapidly exfiltrated, and victims are advised about the data theft. ShinyHunters demands a ransom payment to prevent the stolen data from being leaked on the group’s dark web data leak site.

In recent months, ShinyHunters has conducted successful attacks on several healthcare and medtech companies, including the medical device manufacturers Medtronic and iRhythm, and OneMedical, DentaQuest, AdaptHealth, and Him & Hers. Health-ISAC explained that in a recent attack on a health sector organization, ShinyHunters claimed to have conducted vishing attacks on multiple employees, allowing a Microsoft Entra account to be compromised and a significant amount of company data to be exfiltrated from SaaS and internal platforms such as Microsoft 365 and SharePoint.

Health-ISAC has shared practical, high-impact recommendations for healthcare and medtech companies to improve defenses against these types of campaigns, the most important of which involves breaking the attack chain between the vishing call and the SSO account takeover. Helpdesk and IAM support workflows can be hardened by requiring out-of-band identity proofing for any password or MFA reset, or device reenrollment. Procedures should be implemented that require verification of the request by a callback to a previously verified number, and manager approval for any privileged user. It should not be possible to perform the password/MFA reset or device re-enrolment on the same inbound call.

To harden MFA security against reset abuse, phishing-resistant MFA (FIDO2/WebAuthn security keys or equivalent) should be implemented for admins and high-risk groups, and ideally for all users. SMS/voice MFA and weak fallback methods should be disabled or tightly restricted, and strict controls should be implemented for MFA factor registration.

Since the target is SSO, which provides the keys to the kingdom, Health-ISAC recommends classifying these systems as Tier 0 – the most critical company assets. As such, MFA and compliant devices should be required for accessing sensitive cloud services, legacy authentication should be blocked, administrative portals should be limited to managed devices, and geo-velocity/impossible travel checks implemented.

Extortion is only possible with data exfiltration, so it is vital to closely monitor logs for signs of account takeover and large-scale data access. Health-ISAC recommends centralizing Microsoft Entra sign-in logs, audit logs, and SaaS audit logs into an SIEM and configuring alerts for new device enrolments, MFA factor registration OAuth reset events, new OAuth apps or unusual consent grants, unusual bulk downloads, atypical API calls, and new forwarding rules and mailbox delegation changes.

Healthcare employees may be familiar with traditional phishing attacks, but less familiar with vishing. Vishing should be incorporated into security awareness training programs, and consider running vishing simulations on the workforce, especially on individuals with privileged accounts, helpdesk IT staff, new hires, and remote workers.

Health-ISAC recommends a 30- to 60-day time frame for implementing the recommendations, starting with phishing-resistant MFA for high-risk users, strengthening helpdesk reset procedures, and enforcing conditional access policies. In addition, tabletop exercises should be conducted for containing compromised cloud accounts (token/session revocation).

The post Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.

Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds

A business email compromise (BEC) attack on a vendor of Children’s Healthcare of Atlanta in 2023 resulted in $5.3 million in funds being stolen. While it is unclear if the hacker has been identified and will face justice, a former certified public accountant who conspired with the hacker has been sentenced for attempting to launder the stolen funds.

The hacker compromised the email account of a vendor of Children’s Healthcare of Atlanta that provided furniture and other supplies. On or around June 13, 2023, the hacker impersonated the vendor and requested a change to the vendor’s automatic clearinghouse electronic payment instructions. When the vendor was paid, the funds were directed to a bank account belonging to former CPA and Atlanta business owner Ronald Deabler, 66.

According to court documents, Deabler conspired with the hacker to distribute the stolen funds in exchange for a commission. Deabler opened a second account and tried to transfer the funds; however, the bank would not transfer the entire amount, and only around $1 million of the funds were transferred. Around $3.5 million of the funds obtained from Children’s Healthcare of Atlanta were converted to cashiers’ checks, which were mailed out to a range of different entities and individuals at the direction of the hacker.

Fraudulent transfers are usually identified quickly when the intended recipient of the funds contacts their client to find out why the transfer has not been made. In this case, the vendor contacted Children’s Healthcare of Atlanta within a few days when the expected payment was not received. The fraudulent transfer was quickly identified and traced to Deabler.

Deabler was convicted by a federal jury in February, and this month, a judge sentenced Deabler to four years in prison, followed by two years of supervised release, and ordered him to pay more than $682,000 in restitution. Around $4 million was recovered from Deabler’s accounts and the accounts that received the cashier’s checks.

“Deabler used his knowledge of the banking system to launder millions of dollars stolen from a not-for-profit pediatric healthcare system that is dedicated to the welfare of Georgia’s infants, children, and teens,” said U.S. Attorney Theodore S. Hertzberg. “Scammers, swindlers, and thieves who target our vital healthcare institutions, and their associates who launder stolen money, will face the full consequences of their actions.”

BEC scams are among the costliest types of cybercrime, second only to investment fraud. The FBI’s Internet Crime Complaint Center (IC3) received 24,768 BEC complaints about BEC attacks in 2025, with losses to the scams totaling more than $3.046 billion. In the past three years alone, more than $8.5 billion has been lost to BEC scams.

The post Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds appeared first on The HIPAA Journal.