Author Archives: Steve Alder

Nationwide Home Health Care Provider Announces Major Data Breach

Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir Medical Corporation in California, and Central Arkansas Pediatrics.

LHC Group

LHC Group, a Lafayette, Louisiana-based provider of home health, hospice, and home- and community-based services in 28 U.S. states and the District of Columbia, has been affected by a data security incident involving a third-party technology vendor. The unnamed vendor assisted LHC Group with referral management, care coordination, and clinical workflows, and the provision of those services required access to patients’ personal and protected health information.

LHC Group said it became aware on April 7, 2026, that an employee may have fallen victim to a voice phishing attack. LHC’s vendor subsequently reported suspicious activity within the vendor’s platform associated with an LHC user account. LHC worked closely with its vendor to secure systems and investigate the activity, and third-party cybersecurity experts were engaged to assist with those processes. LHC Group determined that the threat actor stole credentials in the vishing attack and accessed a large volume of files on the vendor’s platform, including files containing patients’ protected health information.  The threat actor had access from April 7, 2026, through April 15, 2026.

The impacted data was reviewed, and LHC started confirming the identities of the impacted individuals on July 9, 2026. The data types involved varied from individual to individual and included full names, addresses, dates of birth, demographic information, clinical summaries, treatment plans, diagnosis codes, dates of service, physician/provider information, Medicare/Medicaid numbers, health insurance information, and, in limited cases, Social Security numbers and/or financial information.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

LHC Group said it disabled the compromised account, reviewed security measures to identify potential areas for improvement, enhanced authentication and monitoring, and strengthened other security controls. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for two years.

It is currently unclear how many individuals have been affected in total, but based on the breach notifications sent to state attorneys general, more than 28,000 individuals have been affected. The total is likely to be considerably higher, as not all state attorneys general publicly disclose how many state residents have been affected. This is the second data breach to be announced by LHC Group this year. LHC Group was also impacted by a breach at vendor Doctor Alliance.

Provident Behavioral Health

Provident Behavioral Health, a nonprofit provider of mental health care services in St. Louis, Missouri, has notified certain patients about a potential breach of their protected health information. Suspicious activity was identified within its computer network on April 3, 2026. The affected systems were isolated, and a third-party cybersecurity firm was engaged to investigate the activity and determine the nature and scope of the activity.

The investigation confirmed that an unauthorized third party had accessed its network and acquired data stored on the impacted systems. The data review concluded on September 4, 2026, when it was confirmed that patient data was present in the copied files, including names, contact information, demographic information, dates of birth, Social Security numbers, driver’s license numbers/state ID numbers, medical information, and health insurance information.

Provident Behavioral Health has confirmed there has been no further unauthorized access, and additional security measures have been implemented to prevent similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident has been reported to state attorneys general and the HHS’ Office for Civil Rights; however, it is currently unclear how many individuals have been affected.

Central Arkansas Pediatrics

Central Arkansas Pediatrics, P.A., a Conway, Arkansas-based medical practice that provides healthcare services for infants, children, and adolescents, has notified 1,500 current and former patients about a recent hacking incident that involved some of their personal and protected health information.

The data breach has been reported to the Department of Health and Human Services’ Office for Civil Rights; however, there is currently no substitute breach notice on the practice website, and no press release appears to have been released, so the exact types of data impacted are unknown, and the exact nature of the hacking incident has yet to be confirmed. This appears to have been a ransomware attack by a prolific ransomware-as-a-service group known as The Gentlemen. The group has conducted many attacks on healthcare providers and added Central Arkansas Pediatrics to its dark web data leak site on June 8, 2026, claiming data was exfiltrated in the attack

Elixir Medical Corporation

Elixir Medical Corporation, a Milpitas, California-based medical device company specializing in products for treating heart and vascular disease, has notified the California Attorney General about a recent security incident that exposed the data of current and former employees, consultants, and certain beneficiaries and dependents.

According to the notice, an unauthorized third party gained access to parts of its computer network between July 20, 2026, and July 21, 2026. The investigation confirmed that human resources files were exposed in the incident, which contained names and Social Security numbers, along with some or all of the following: driver’s license number, credit/debit card number, medical information, and/or direct deposit bank account information.

The affected individuals have been notified, and complimentary credit monitoring and identity theft protection services have been offered. Additional safeguards have been implemented, along with further security awareness training for the workforce. The number of affected individuals has not yet been publicly disclosed.

The post Nationwide Home Health Care Provider Announces Major Data Breach appeared first on The HIPAA Journal.

Hacking Incident Affects 46,000 Hawaii Family Dental Patients

A hacking incident at Hawaii Family Dental has affected almost 46,000 individuals. Data breaches have also been announced by Life Bridges in Tennessee, Westchester Institute for Human Development in New York, Community Health Care in Ohio, and Shoshone Medical Center in Idaho.

Hawaii Family Dental

Hawaii Dental Group, Inc., doing business as Hawaii Family Dental, a Honolulu-based operator of a dozen dental clinics in Hawaii, has started notifying 45,853 individuals about a July 2026 hacking incident that involved unauthorized access to their personal and protected health information.

Suspicious activity was identified within its computer network on July 20, 2026. The forensic investigation confirmed that an unauthorized third party accessed its systems between July 19 and July 20, 2026, including systems where patient information was stored. Files exposed and potentially copied in the incident included names, phone numbers, addresses, email addresses, dates of birth, medical and dental treatment information, and health insurance information. Patients were informed that financial information and Social Security numbers were not involved.

Hawaii Family Dental is reviewing and enhancing its data privacy and security safeguards to better protect against similar incidents in the future. While the name of the hacking group was not disclosed, the Qilin data theft and extortion group claimed responsibility for the attack and maintains that it exfiltrated sensitive data.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Life Bridges

Life Bridges, Inc., a Cleveland, Tennessee-based provider of residential, medical, and community support for individuals with intellectual and developmental disabilities, has reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 5,194 individuals.

In its substitute data breach notice, Life Bridges explained that unauthorized activity was identified within its computer systems on June 22, 2026. Containment measures were deployed, systems were taken offline, passwords were changed, and third-party cybersecurity experts were engaged to investigate the activity. The investigation confirmed that its systems were accessed by an unauthorized third party between June 17, 2026, and June 22, 2026, during which time files containing protected health information were copied from its systems.

The data review confirmed that the compromised information included names, addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnosis/condition information, lab results, treatment information, dates of service, insurance claims information, financial account information, debit card information, medical record numbers, Medicare numbers, Medicaid numbers, and managed care organization numbers. The types of data involved varied from individual to individual.

At the time of issuing notification letters, no misuse of the affected information had been identified. Life Bridges has confirmed that steps have been taken to reduce the risk of similar incidents in the future.

Westchester Institute for Human Development

Westchester Institute for Human Development, Inc., a Valhalla, New York-based provider of support services for individuals with disabilities and vulnerable children, has reported a breach of the protected health information of 938 individuals. On or around April 8, 2026, unauthorized activity was identified within its email environment. Steps were immediately taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed that an unauthorized third party had access to certain files within its environment between March 23, 2026, and April 14, 2026.

The file review found that the exposed data included names, Social Security numbers, driver’s license numbers, dates of birth, dates of medical service, health insurance policy numbers, provider information, medical condition/diagnosis, treatment information, medical record numbers, Medicare/ Medicaid numbers, financial account information, patient account numbers, full face photographs, and referral information. The types of information involved varied from individual to individual.

Westchester Institute for Human Development said the affected individuals have been notified, and it will continue to evaluate and modify its security measures to enhance the privacy and security of the information it maintains.

Community Health Care

Community Health Care, Inc., a healthcare provider with 19 practice locations in Northeastern Ohio, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on June 12, 2026. The incident was identified quickly and contained, limiting the unauthorized access to a single email account.

The affected account was found to contain the protected health information of 808 individuals, including names, phone numbers, dates of birth, dates of service, provider names, diagnostic/treatment information, and health insurance information. At the time of issuing notification letters, no misuse of the affected information had been identified. As a precaution, the affected individuals have been advised to remain vigilant against identity theft and fraud. Since the incident was identified, Community Health Care said it has been working with cybersecurity experts to further strengthen its existing, significant safeguards.

Shoshone Medical Center

Shoshone Medical Center, a Kellogg, Idaho-based critical access hospital, has identified unauthorized access to an employee’s email account. The unauthorized activity was identified on or around May 27, 2026, and an investigation was launched to determine the nature and scope of the activity.

On July 29, 2026, Shoshone Medical Center confirmed that personal and protected health information had been exposed, including names, addresses, dates of birth, phone numbers, patient identification numbers, medical record numbers, Medicare/Medicaid numbers, diagnosis/treatment information, treatment cost information, admission/discharge dates, and health insurance information. Notification letters have been mailed to the 553 affected individuals, and steps have been taken to reduce the risk of similar incidents in the future.

The post Hacking Incident Affects 46,000 Hawaii Family Dental Patients appeared first on The HIPAA Journal.

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA). On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having been superseded by rulemaking.

The Health Breach Notification Rule was issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act and applies to vendors of personal health records (PHRs) and related entities that are not subject to HIPAA. In 2021, the FTC determined that because health apps were mainstream and increasingly collected consumers’ sensitive health and personal information, the developers of the apps should have a responsibility to ensure that the data they collect is secured, protected against unauthorized access, and that consumer notifications are required when there is a breach of that information or an unauthorized disclosure.

Per the 2021 policy statement, the FTC viewed the developers of health apps and other connected devices to be vendors of personal health records, if an app or device had the capability to draw data from multiple sources and was not covered by a similar rule issued by the Department of Health and Human Services. The change in position was contentious at the time, and while the policy statement received majority FTC backing, it was only approved with a 3-2 vote. Commissioners Noah Joshua Philips and Christin S. Wilson voted against the policy statement, with both believing that the FTC’s interpretation of applicability for the Health Breach Notification Rule stretched the statutory text beyond its terms.

In 2024, the FTC updated its Health Breach Notification Rule, significantly expanding its scope. The definition of health information was broadened to make it clear that the rule applies to data collected via health apps, connected devices, and any other technology that draws health inferences from user data. The update also clarified that breaches that trigger the notification requirements include cybersecurity incidents and unauthorized disclosures to third parties.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

In its September 9, 2026, statement, the FTC said the 2024 update the Health Breach Notification Rule rendered the policy statement unnecessary and that pursuant to an Executive Order by President Trump, agencies have been directed to eliminate obsolete guidance documents, policy statements, and unnecessary rules that provide no benefit to Americans, hence the decision to withdraw the policy statement.

The post FTC Rescinds 2021 Policy Statement on Health App Data Breaches appeared first on The HIPAA Journal.

Conti Ransomware Member Sentenced to 4 Years in Jail

A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and other countries has been sentenced to four years in jail for his role in the attacks. The Conti ransomware group was a major ransomware operation that engaged in double extortion tactics, breaching victims’ networks, stealing sensitive data, and encrypting devices for financial gain. The Conti ransomware operation emerged after the shutdown of the Ryuk ransomware group in 2020 and was active until 2022. During that time, the group conducted ransomware attacks on an estimated 1,000 entities in 31 foreign countries, 47 U.S. states, the District of Columbia, and Puerto Rico.

While some ransomware groups prohibited attacks on healthcare providers, Conti had no such restrictions and actively targeted healthcare organizations. The group reached peak activity in 2021, when many critical infrastructure entities were attacked, including the Health Service Executive in Ireland and many U.S. hospitals, such as Scripps Health in San Diego. According to the U.S. Department of Justice (DoJ), the Conti ransomware group collected an estimated $150 million in ransom payments as of January 2022.

Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, was arrested in Ireland in July 2023 by the Irish national police and was extradited to the United States last year to face trial. Lytvynenko was accused of being a developer of malicious tools used by the Conti ransomware operation, breaching the networks of at least 12 companies, and exfiltrating and storing stolen data.

Lytvynenko admitted to being a member of the Conti ransomware operation since September 2021, controlling stolen data from eight victims in the United States and four victims in foreign countries, and issuing ransom demands. Lytvynenko was a member of a team run by a co-conspirator and developed loader malware, which was used by the group to load malicious software on victims’ networks. In June 2026, Lytvynenko pleaded guilty to one count of conspiracy to commit wire fraud and has been awaiting sentencing, which could have been a maximum of 20 years in jail. On September 10, 2026, Lytvynenko was sentenced to four years in federal prison.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“Ransomware attacks like Conti cause real harm to businesses, institutions, and families here at home and around the world,” said U.S. Attorney Braden H. Boucek for the Middle District of Tennessee. “Today’s sentence demonstrates that cybercriminals cannot hide behind borders or a keyboard to escape justice. We are grateful to our law enforcement and international partners whose work made this result possible.”

Four other Conti co-conspirators – Russian nationals Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev, and Andrey Yuryevich Zhuykov – have also been indicted for their role in Conti ransomware attacks and have criminal charges pending in the Middle District of Tennessee.

The post Conti Ransomware Member Sentenced to 4 Years in Jail appeared first on The HIPAA Journal.

FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices

The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI (GenAI)-enabled medical devices. As a regulator of all medical devices, the FDA is considering whether new regulations are required for GenAI-enabled medical devices to ensure patients are provided with timely access to safe and effective devices.

GenAI-enabled medical devices have the potential to transform patient care, yet the devices may introduce unique risks compared to traditional software and artificial intelligence (AI)-enabled medical devices. Current regulatory frameworks, such as those used for traditional medical devices, may not be appropriate for GenAI-enabled devices, which present unique challenges and risks.

The devices have unique characteristics and behaviours, including the capability to produce variable outputs, which change over time as the devices incorporate continuously learning systems. GenAI devices can accept open-ended inputs, and it is not feasible to test the full range of inputs and assess outputs using traditional premarket testing methodologies. The FDA notes that many devices are built on general-purpose foundation models, which have been developed by third parties that have varying levels of transparency into training data, architecture, and evaluation methods. As such, specific behaviors and errors are difficult to attribute to the underlying model used by the devices.

While GenAI-enabled devices offer a wide range of benefits over and above what can be gained from traditional and AI-enabled medical devices, the characteristics that provide those benefits also present unique risks. For instance, GenAI systems may misinterpret or distort data, filling in knowledge gaps with plausible but invented information (confabulations), such as associating a symptom with the wrong condition. There is also a risk of hallucinations – the generation of false facts – on which output is based and presented as fact. GenAI tools may provide outputs that are plausible and sound authentic to end users, which may be questionable at best and potentially dangerous to health.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The discussion paper, published by the FDA’s Center for Devices and Radiological Health (CDRH) –  Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback – delves into the challenges associated with premarket evaluation and postmarket monitoring of GenAI-enabled medical devices. The aim of the paper is to guide discussion and focus feedback ahead of the potential development of guidance and future regulations. No decision has been made about whether FDA regulation is required, or areas where guidance may be necessary.  The feedback obtained in response to the discussion paper will guide future FDA decisions, including new methodologies for premarket evaluation and the postmarket assessment of the performance of GenAI-enabled medical devices to ensure they remain safe and effective throughout the entire product lifecycle.

The paper discusses the possibility of competency-based testing of GenAI-enabled medical devices for premarket evaluations, using an approach modelled on medical training, licensure examinations, supervised practice, periodic reevaluation, and public reporting, and device benchmarking to assess whether a device demonstrates the necessary clinical knowledge, analytic capabilities, safety behavior, communication, and generalizability to support reasonable assurance of safety and effectiveness of the device for its intended use. Potentially, clinical confirmation will be required, as a competency-based approach may not fully assess performance in a clinical setting.

The FDA anticipates a risk-based approach will be necessary for regulation, taking into consideration the intended use and device characteristics. For instance, certain action-directing functions may be classed as higher risk than functions that provide non-directive information, as well as agentic AI systems capable of autonomous actions.

The FDA said it wishes to work collaboratively with the full range of stakeholders to develop efficient, scientifically sound, and least burdensome approaches to the premarket evaluation and postmarket monitoring of GenAI-enabled devices. Feedback on the discussion draft is requested from medical device manufacturers, clinicians, researchers, and the general public by October 19, 2026.

The post FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices appeared first on The HIPAA Journal.

HHS Updates Security Risk Assessment Tool

The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.

The SRA Tool was developed by the Department of Health and Human Services Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the Office for Civil Rights (OCR). The downloadable tool was first released in March 2014 to help small- and medium-sized HIPAA-regulated entities navigate the risk analysis requirement of the HIPAA Security Rule.

The tool guides regulated entities through the process of conducting and documenting risk analyses, the aim of which is to identify potential weaknesses and gaps in security policies and all risks and vulnerabilities to ePHI. Only by conducting a comprehensive and accurate risk analysis will HIPAA- regulated entities be able to identify all risks and vulnerabilities to ePHI. If risks and vulnerabilities remain unknown, regulated entities will not be able to take the necessary steps to reduce them to a low and acceptable level and comply with the Risk Management standard of the HIPAA Security Rule.

The SRA Tool has received many upgrades over the years to improve usability and add compliance features. The latest release –September 2026 –includes content improvements in questions, responses, and education, expanding the tool to make it more comprehensive and ensure it remains relevant in an evolving cybersecurity environment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key updates include the addition of new technologies that have been adopted by regulated entities; a new assessment-scope question to ensure that risk assessments account for every location that creates, receives, maintains, or transmits ePHI; new remote access and telework questions; modernization of the asset inventory to cover technologies that practices are now using; and an update to the system-activity logging question to reflect the varied systems used by regulated entities.  The new version also includes updated software libraries, bug fixes, and tweaks in response to feedback to make the application and Excel workbook easier to use.

OCR Actively Enforcing Risk Analysis and Risk Management Compliance

HIPAA-regulated entities have long struggled with conducting risk analyses, and 12 years after the tool was first released, OCR still frequently identifies noncompliance in this area. OCR often finds that risk analyses have never been completed, that they are incomplete or inaccurate, or that there is a lack of documentation of risk analysis processes and procedures.

Widespread noncompliance with this vital Security Rule implementation specification prompted OCR to launch a new risk analysis enforcement initiative in 2024 to encourage and improve compliance. To date, OCR has imposed 14 financial penalties under this initiative, which remains a key enforcement priority for OCR. Further, the planned update to the HIPAA Security Rule, which now has a July 2027 proposed release date, will increase the risk analysis requirements further.

The risk analysis is only the first step in the risk management process. HIPAA-regulated entities must ensure that the identified risks and vulnerabilities are managed effectively and reduced to a low and acceptable level. At the 2026 NIST/OCR conference, Safeguarding Health Information: Building Assurance through HIPAA Security 2026, OCR Director Paula Stannard explained that many regulated entities appear to be confusing risk management with the cybersecurity performance goals (CPGs) issued by OCR in January 2024.

While the CPGs can be adopted by regulated entities to improve their security posture and prevent cyberattacks and data breaches, simply implementing those measures does not satisfy the risk management requirements of the HIPAA Security Rule. The risk management standard requires specific risk management measures to be implemented to address the risks and vulnerabilities identified by the risk analysis.

OCR has confirmed that the risk analysis enforcement initiative has been expanded to cover risk management. In addition to requiring evidence showing that an accurate and comprehensive risk analysis has been conducted, OCR requires evidence that identified risks have been subjected to a HIPAA-compliant risk management process. OCR wants to ensure that regulated entities are acting on the results of their risk analyses and are taking appropriate actions to reduce risks and vulnerabilities to ePHI.

The post HHS Updates Security Risk Assessment Tool appeared first on The HIPAA Journal.

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to write past the end of a heap allocation and crash an Orthanc process in a denial-of-service attack.

Orthanc DICOM Server is a free-to-use, standalone, open-source, lightweight DICOM server that is used in both clinical and research environments. It can complement or act as a gateway to existing PACS systems, and was developed to improve interoperability and workflow efficiency.

An integer overflow in a specified pitch and buffer-size computation results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image file, causing a crash and denial-of-service condition.

The vulnerability is tracked as CVE-2026-87020 and has been assigned a CVSS v3.1 base score of 8.1 and a CVSS v4.0 base score of 7.2. The vulnerability was identified by penetration tester Andrej Tomci, who reported the issue to the Cybersecurity and Infrastructure Security Agency.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The vulnerability affects all Orthanc DICOM Server prior to 1.13.0. Orthanc has fixed the vulnerability in version 1.13.0. and later versions.  Users are advised to verify the installed Orthanc DICOM Server version and download the latest version if a vulnerable version is in use. It is also recommended to restrict network access to Orthanc instances to trusted hosts only.

The post Orthanc DICOM Server Vulnerability Can Lead to Denial of Service appeared first on The HIPAA Journal.

Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits

Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data security incidents that exposed patient information.

Central Maine Medical Center Data Breach Settlement

Central Maine Medical Center, a Lewiston, Maine-based nonprofit healthcare provider, has agreed to pay $1,368,025 to settle a consolidated class action lawsuit stemming from a 2025 cyberattack and data breach.

The attack was identified on June 1, 2026, and caused the shutdown of IT systems, network servers, and its phone system. The forensic investigation determined that hackers had access to its network between March 19, 2025, and June 1, 2025, and potentially obtained personal and protected health information. According to the lawsuit, notification letters were mailed to 218,884 individuals.

Six putative class action lawsuits were filed in response to the data breach, alleging that Central Maine Healthcare was at fault as reasonable and appropriate cybersecurity measures had not been implemented. The lawsuits were consolidated into a single complaint – In re Central Maine Data Security Litigation – naming the defendants Central Maine Healthcare Corporation and Central Maine Medical Center. The defendants deny all claims and contentions in the lawsuit, including claims of fault, wrongdoing, and liability. The lawsuit was settled to avoid the time, cost, and uncertainty of continued litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement fund will be used to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The remainder of the settlement fund will be used to pay benefits to the class members. Class members may claim one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be around $60 per class member.  In addition to one of those payments, class members may claim a one-year membership to a medical record monitoring service. The deadline for objection and opting out is September 13, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 28, 2026.

Susan B. Allen Memorial Hospital Data Breach Settlement

A settlement has been agreed to resolve class action litigation against the Butler, Kansas acute-care medical facility, Susan B. Allen Memorial Hospital, to resolve claims stemming from a July 2025 cyberattack and data breach. Hackers gained access to its network and potentially obtained personal and protected health information. The data breach was initially reported to the HHS’ Office for Civil Rights as affecting up to 12,097 individuals, although the HHS’ Office for Civil Rights breach portal has since been updated to indicate that only 11,866 individuals had protected health information compromised in the incident.

Four putative class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims and classes. The consolidated lawsuit, In Re: Susan B. Allen Data Security Litigation, is pending in the District Court of Butler County, Kansas. The plaintiffs allege that the hospital was at fault for the data breach as it failed to implement appropriate cybersecurity measures, and the defendant maintains there was no wrongdoing. A settlement was agreed to avoid the cost, time, distraction, and uncertainty of continued litigation.

The settlement provides two years of credit monitoring and identity theft protection services for all class members. In addition, a claim may be submitted for reimbursement of out-of-pocket losses due to the data breach up to a maximum of $100 per class member. In addition, a claim may be submitted for reimbursement of up to four hours of lost time at $25 per hour. Claims have been capped at an aggregate of $100 per class member. Claims must be submitted by November 12, 2026. Individuals wishing to object to the settlement or exclude themselves must do so by October 13, 2026. The final fairness hearing has been scheduled for December 7, 2026.

The post Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect

Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration.

CVE-2026-82583 could be exploited by an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in the disclosure of stored credentials for connected systems, allow arbitrary file write, and trigger a denial-of-service condition. The vulnerability has been assigned a CVSS v3.1 severity score of 8.3 (v4:0: 7.2)

CVE-2026-78224 is due to the XSLT Transformer Step building a bare TransformerFactory without the proper security options set, which could allow data exfiltration and denial-of-service attacks via XXE injection. The vulnerability has a CVSS v3.1 severity score of 8.2 (v4.0: 8.8)

CVE-2026-82578 can also allow data exfiltration and denial-of-service attacks via XXE injection. When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions. The vulnerability has a CVSS v3.1 severity score of 7.5 (v4.0: 8.7)

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All three vulnerabilities affect v4.7.1 and earlier versions. NextGen has fixed all three vulnerabilities in Mirth Connect v4.7.2. Customers have been advised to update to the latest fixed version as soon as possible. The latest version can be downloaded from the NextGen Healthcare customer portal.

The post High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect appeared first on The HIPAA Journal.