Healthcare Cybersecurity

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.

Large Healthcare data breaches in the past 12 months - June 2026

The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023.

Year to date figures for large healthcare data breaches - June 2026

Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals. While June’s victim total is substantial, the victim count is down 36.3% month-over-month, and 58.7% lower than the 12-month average of 10,906,096 individuals per month. It should be noted that the 12-month average is skewed by an unusually high total for October 2025.

Individuals affected by large healthcare data breaches in the past 12 months - June 2026

The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.7% from a high of 54.4 million individuals in 2024, and down 22.1% from 2025.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Year to date figures for individuals affected by healthcare data breaches - June 2026

The Biggest Healthcare Data Breaches Reported in June 2026

In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS. The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1.4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management. The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.

The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1.25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company. A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.

A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025. Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information.

HIPAA-Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Xsolis, Inc. TN Business Associate 1,396,519 Network server hacking incident
MCBS, LLC GA Business Associate 1,261,464 Data theft and extortion incident (PEAR)
Centers Lab NJ LLC NJ Healthcare Provider 542,377 Data theft and extortion incident (Worldleaks)
Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Network server hacking incident
Operation PAR, Inc. FL Business Associate 145,714 Data theft and extortion incident (Worldleaks)
Chicago Family Health Center IL Healthcare Provider 90,000 Network server hacking incident
Aitkin County Health and Human Services MN Business Associate 83,114 Phishing incident
Minnesota Epilepsy Group, P.A. MN Healthcare Provider 80,061 Network server hacking incident
Gay & Lesbian Community Services Center of Orange County, Inc. CA Healthcare Provider 75,532 Network server hacking incident
Colorado Health Network Inc. CO Healthcare Provider 68,212 Network server hacking incident – data theft confirmed
Women’s Center for Radiology FL Healthcare Provider 66,422 Network server hacking incident
Blue Fish Pediatrics TX Healthcare Provider 62,150 Network server hacking incident
NYC Health + Hospitals NY Healthcare Provider 58,778 Hacking incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 37,384 Phishing incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 34,574 Network server hacking incident
Kentucky Mountain Health Alliance KY Healthcare Provider 30,830 Network server hacking incident – data theft confirmed
Center for Hearing and Speech dba Texas Hearing Institute TX Healthcare Provider 29,774 Ransomware attack (Interlock) – data theft confirmed
Waveny LifeCare Network, Inc. CT Healthcare Provider 27,113 Network server hacking incident
Elara Caring TX Healthcare Provider 22,172 Hacking incident at third party vendor – data theft confirmed
Minidoka Memorial Hospital ID Healthcare Provider 22,000 Data theft and extortion incident (Blackwater)
Meridian Health Plan of Illinois IL Health Plan 21,027 Employee errors – Impermissible granting certain providers access to its network
City of Middletown OH Healthcare Provider 20,608 Ransomware attack – data theft confirmed
McLeod Physician Associates II SC Healthcare Provider 19,553 Malware identified on network server awaiting decommissioning
Optalis Management Solutions MI Healthcare Provider 13,723 Network server hacking incident
All About Women’s Care CO Healthcare Provider 12,000 Hacking incident via an employee VPN account – data theft confirmed

In June, nine healthcare data breaches were reported to HHS with totals of 500 or 501 affected individuals. These totals are often used as placeholder figures when data reviews are ongoing and the 60-day reporting deadline under the HIPAA Breach Notification Rule is reached. HIPAA requires an estimate to be provided if the total number of affected individuals has yet to be determined. The data breaches in the table below may prove to be far larger than the initial breach report indicates. It may be several weeks or even months before the total number of affected individuals is confirmed.

HIPAA Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Gail J May Ltd d/b/a/ Insight Optical IL Healthcare Provider 501 Network server hacking incident at business associate
Community Health Center of Buffalo Inc. NY Healthcare Provider 501 Network server hacking incident
Cherry Street Services, Inc. MI Healthcare Provider 501 Network server hacking incident
Northeast Professional Caregivers OH Healthcare Provider 500 Email compromise
Columbia Orthopaedic Group MO Healthcare Provider 500 Network server hacking incident
Decatur Diagnostic Laboratory Inc. AL Healthcare Provider 500 Network server hacking incident
Ohio Living OH Healthcare Provider 500 Network server hacking incident
Signature Healthcare Corporation MA Healthcare Provider 500 Network server hacking incident
MVP VIP Holdco dba Heart of America Eye Care MO Healthcare Provider 500 Network server hacking incident

Causes of June 2026 Healthcare Data Breaches

Out of the 25 data breaches affecting 10,000 or more individuals, all but one was due to hacking. Across all of June’s reported data breaches, 81.8% of the breaches were hacking/IT incidents, and 1,481,468 individuals were affected by those incidents – 89.7% of all individuals affected by data breaches in June. The average breach size was 81,091 individuals, and the median breach size was 6,504 individuals.

Causes of June 2026 healthcare data breaches

The largest unauthorized access/disclosure incident of the month – Meridian Health Plan of Illinois – affected 21,027 individuals and was due to employees granting healthcare providers access to a portal for managing patient information and processing claims that should not have been given access. There were 11 unauthorized access/disclosure incidents in June, accounting for 16.7% of the month’s data breaches, and 10,914 individuals were affected – 2.7% of the month’s affected individuals. The average breach size was 10,914 individuals, and the median breach size was 6,721 individuals. One improper disposal incident was reported affecting an estimated 1,000 patients. Paper records were disposed of along with regular trash, rather than being sent for shredding. No loss or theft incidents were reported in June.

Location of Breached Protected Health Information

The bar chart below shows the locations of breached protected health information in June 2026 healthcare data breaches. Network servers were the most common location of breached protected health information, followed by email accounts and electronic health records.

Location of breached protected health information - June 2026

Data Breaches at HIPAA Regulated Entities

When a data breach occurs at a HIPAA-covered entity – healthcare provider, health plan, or healthcare clearinghouse – the HIPAA Breach Notification Rule requires them to report the breach within 60 days of discovery. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within the same time frame.

The affected covered entities are ultimately responsible for ensuring that notifications are issued to the HHS, individuals, and in some cases the media, within 60 days of being notified. A HIPAA-covered entity may delegate the notification responsibilities to the business associate. Some choose to issue notifications themselves. The raw breach data on the OCR breach portal shows data breaches based on the reporting entity, not where the data breach occurred. In June, healthcare providers reported 45 breaches, business associates reported 14 breaches, and 7 breaches were reported by health plans. The pie charts below show where the breach actually occurred rather than the reporting entity to better reflect breaches at business associates.

June 2026 data breaches at HIPAA-regulated entities

Individuals affected by June 2026 data breaches at HIPAA-regulated entities

Geographical Distribution of Healthcare Data Breaches

In June, HIPAA-regulated entities based in 24 U.S. states reported large healthcare data breaches. Florida and Texas were the worst affected states with seven reported breaches per state.

State Breaches
Florida & Texas 7
Illinois 5
Colorado, Michigan & New York 4
California, Connecticut, Minnesota, Missouri, Ohio & Tennessee 3
Idaho, Kentucky, Massachusetts, South Carolina & Washington 2
Alabama, Georgia, Indiana, Kansas, New Jersey, Oklahoma & Pennsylvania 1

While Florida and Texas ranked top for breaches, they ranked 4th and 6th in terms of the number of affected individuals. Tennessee, Georgia, and New Jersey topped the list for affected individuals, with each state only registering one large data breach.

State Individuals Affected State Individuals Affected
Tennessee 1,567,038 Michigan 24,396
Georgia 1,261,464 Idaho 22,750
New Jersey 542,377 Ohio 21,608
Florida 233,367 South Carolina 20,690
Minnesota 164,893 Washington 9,825
Texas 124,459 Missouri 3,311
Illinois 120,089 Indiana 3,070
Connecticut 99,071 Pennsylvania 2,720
Colorado 87,814 Oklahoma 1,607
California 80,783 Massachusetts 1,506
New York 74,733 Kansas 534
Kentucky 31,367 Alabama 500

HIPAA Enforcement Activity in June 2026

In June, OCR announced a single enforcement action to resolve potential violations of the HIPAA Rules by the American mall-based retailer, Spencer Gifts. Retailers are not typically HIPAA-covered entities, but Spencer Gifts is a health plan under HIPAA as it sponsors employee benefits and welfare benefit plans. Spencer Gifts was investigated after OCR received a report about a breach of the protected health information of 10,023 members of its flexible benefits and welfare benefit plans. The OCR investigation determined that Spencer Gifts failed to conduct a HIPAA-compliant risk analysis and failed to implement HIPAA Privacy, Security, and Breach Notification Rule policies and procedures. The alleged HIPAA violations were resolved with a settlement that includes a $450,000 financial penalty and a corrective action plan.

In the year to June 30, 2026, OCR resolved seven HIPAA investigations with financial penalties with penalties totaling $1,728,000. All seven of the investigations found risk analysis failures, and two involved breach notification failures. State attorneys general may also investigate data breaches and impose financial penalties for HIPAA violations, although no cases were announced in June 2026.

About this Report

The HIPAA Journal monthly data breach reports are based on data obtained from the HHS Office for Civil Rights and have been combined with breach report data from other sources. The data breaches included in this report were reported in June 2026 but occurred weeks or months previously. The figures in this report may increase or decrease as HIPAA-regulated entities complete their breach investigations, and will be reflected in our healthcare data breach statistics page and our annual HIPAA data breach reports. Further information about HIPAA enforcement actions can be found in our HIPAA violations cases page.

The post June 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Survey Reveals Patients Want to Know When and How AI is Used in Healthcare

A recent survey has revealed that patients are concerned about the use of AI tools by doctors’ offices and other healthcare providers, and the vast majority of patients believe that they should be informed if their healthcare provider is using AI tools in connection with their healthcare. The survey also indicates that more than half of patients are unaware whether AI is currently being used in relation to their healthcare.

The survey was conducted on almost 5,000 U.S. adults in late June 2026 by the Pew Research Center. The survey revealed that 72% of patients believe it is extremely important or very important for their healthcare providers to disclose whether they are using AI tools in connection with healthcare, with 16% of respondents believing that it is somewhat important. Only 7% of respondents said they are not too bothered or not at all bothered about being informed about the use of AI.

Concern varied across different uses of AI, with the greatest concern expressed about AI being used to make diagnostic decisions (81%), analyze medical scans (81%), explain medical test results (80%), and take notes during a medical appointment (72%).  More than half of patients believe that they should be informed about behind-the-scenes administrative services such as getting prescription refills (64%) and scheduling medical appointments (56%), although the latter had the largest percentage of patients who do not feel that disclosure is needed (33%). Across all areas of questioning, 9% or 10% of patients were not sure if they should be informed, potentially indicating they are unaware of any risks involved.

While most patients believe that they should be informed about the use of AI in healthcare, almost half of all surveyed patients (46%) said they were unaware whether their doctor’s office and other healthcare providers were using AI solutions, with only 16% of patients saying a doctor has actually told them that AI was used in their care. Adoption of AI in healthcare has grown considerably, with ONC’s figures showing that 71% of hospitals were using AI tools in 2024, up from 66% in 2023. Despite the high level of AI adoption, 33% of respondents believe their healthcare providers are not using AI tools, which suggests a lack of transparency.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While patients want to be informed and have a say in how AI is used in healthcare, many Americans do not believe they have control over how AI is used. The survey revealed that more than half of respondents (53%) believe they either have no say or not much say in the use of AI in healthcare, with 16% believing they have some say. 63% of respondents to the survey would like more say in how AI is used, and only 21% of respondents said they are comfortable with how much say they currently have.

As AI adoption grows, it is important for healthcare providers to explain to patients how the tools are used and to obtain patient consent in order to maintain trust. It is also important for the tools, including transcription tools and chatbots, to be continuously evaluated to ensure they are fit for purpose and are generating accurate results.

The post Survey Reveals Patients Want to Know When and How AI is Used in Healthcare appeared first on The HIPAA Journal.

SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances

Two remotely exploitable zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together to achieve remote code execution, according to a recent SonicWall security alert. SMA1000 appliances are used for secure remote access and VPN connections and, as such, are commonly exposed to the Internet.

One of the vulnerabilities, tracked as CVE-2026-83548, is a critical pre-authentication server-side request forgery issue in the Appliance Work Place interface that allows command injection. The vulnerability has been assigned a maximum CVSS v 3.1 severity score of 10. Successful exploitation allows a remote attacker to access sensitive functions and perform unauthorized actions.

The vulnerability is being chained with an exploit for a high-severity (CVSS v3.1: 7.8) OS command injection vulnerability – CVE-2026-83549 – in the Appliance Management Console. Attackers with admin privileges can exploit the vulnerability and execute OS commands. The vulnerability is due to improper neutralization of special elements used in an OS command.

The SonicWall PSIRT has investigated a case where the threat actor chained the two vulnerabilities in an attack on a customer. The Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerability (KEV) Catalog, and federal civilian Executive Branch agencies have been given until Saturday to upgrade to the latest hotfix.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, but not SSL-VPN running on SonicWall firewalls or SMA 100 Series products. The affected software versions are 12.4.3-03453 (platform-hotfix) and older versions, and 12.5.0-02835 (platform-hotfix) and older versions.

The extent to which the vulnerabilities are being exploited is unclear. The latest attack(s) come just two months after a different pair of vulnerabilities in SMA1000 appliances were exploited to install malware, enabling ransomware attacks. Since threat actors actively target vulnerabilities in remote access and VPN appliances, users of vulnerable devices are strongly advised to upgrade to the latest hotfix as soon as possible. Currently, there are approximately 400 SMA1000 devices worldwide that are exposed online, the majority of which are in the United States.

The post SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances appeared first on The HIPAA Journal.

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

More than a dozen U.S. health care systems have issued warnings to patients about an ongoing phishing campaign involving emails purporting to be legitimate communications sent via their MyChart patient portal. Many of the emails claim that the recipient is a winner of a MyChart Medicare Kit, although other healthcare benefits, Medicare packages, free gifts, or rewards may be offered. Texas Health Resources has warned patients that some email communications offered a “Senior Health Package.”

Healthcare providers that use Epic Systems’ electronic health records and MyChart portals, including Methodist Health System, Premier Health, Sentara Health, Metro Health, and Texas Health Resources, have added scam warnings to their websites about the campaign. The scammer most likely seeks MyChart credentials, Medicare information, financial account information, or other sensitive data.

The emails are not sent from legitimate healthcare provider email addresses or domains, and while they include a MyChart logo, they have not been sent by Epic Systems. The logo is used to make the messages appear legitimate. An example of one of the phishing emails is detailed below, although other messages may also be used in this campaign.

Epic Systems MyChart phishing scam

Example of a phishing email impersonating MyChart

“We’ve seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official,” explained Trevor Berceau, Director R&D, Epic Systems. “Some might try to steal your login information or promise free gifts if you enter payment details. The increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal. If something doesn’t feel right, however, stop and check.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The threat actor behind the campaign has yet to be identified, and it is unclear how the cybercriminal or group behind the scam obtained patients’ contact information. It is likely that email addresses were obtained in a previous data breach, although that data breach may not necessarily have occurred at their healthcare provider.

The advice to patients is to delete any such messages immediately and not click on any links, including the “unsubscribe” link. It is important not to reply to the email, and to never disclose personal or financial information in response to one of these communications or attempt to log in to the patient portal using the link in the message. If any action has been taken, such as logging in via the link, patients should immediately reset their MyChart portal password and contact their healthcare provider’s MyChart support team.

Patients should remain vigilant against any unsolicited emails, text messages, or phone calls claiming to offer free gifts or rewards. Recipients of emails or text messages should carefully check the sender’s information to ensure that it has come from a legitimate email address or domain. These messages often include spelling and grammatical errors, unusual requests, free gifts or rewards, and often advise the recipient to take immediate action. If in any doubt about the legitimacy of any request, patients should contact the relevant healthcare provider using verified contact information. Never use any contact information included in the suspicious communication.

The post Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam appeared first on The HIPAA Journal.

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 500 critical infrastructure victims.

When the cybersecurity advisory was first issued in March 2025, the authorizing agencies determined that Medusa had conducted more than 300 attacks on critical infrastructure entities between 2021 and February 2025. The Medusa ransomware operation emerged in June 2021 and initially operated as a closed ransomware group, with the developers conducting all aspects of the operation, including development, ransomware campaigns, and ransom negotiations.

In early 2023, Medusa morphed into a RaaS operation, using affiliates to conduct attacks for a percentage of the ransom payments. The group also launched a data leak site in 2023 and adopted double extortion tactics, issuing threats to publish stolen data to pressure victims into paying to prevent data leaks as well as to obtain the keys to decrypt data. Since the transformation into a RaaS group, attacks have increased substantially, with the developers and the group’s affiliates conducting attacks. In a little over a year, the group has claimed more than 200 victims in critical infrastructure sectors, compared to 300 in the previous four years.

Affiliates are given various levels of control based on their experience and profitability, with newer and less experienced affiliates having lower levels of trust. For instance, the developers retain control of important aspects of campaigns such as ransom negotiations for newer and less experienced affiliates. The developers recruit initial access brokers (IABs) on cybercriminal forums to provide access to victims’ networks, typically paying between $100 and $1 million to the IAB for access.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While some RaaS groups have a policy of not attacking healthcare organizations, that is certainly not true of Medusa, which has frequently attacked the healthcare and public health (HPH) sector. While the group is largely believed to operate opportunistically, conducting attacks by focusing on organizations with unpatched, remotely exploitable software vulnerabilities, the high percentage of victims in the HPH sector could indicate targeting of the sector.

Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.  No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.

Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.

The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.

March 13, 2025: Critical Infrastructure Entities Warned About Medusa Ransomware as Victim Count Hits 300

A warning has been issued about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 300 victims in critical infrastructure sectors including healthcare, education, and manufacturing. The group has been active since June 2021 when it started as a closed group, before adopting the RaaS model, where affiliates are recruited to conduct attacks for a percentage of any ransom payments they generate.

Around two years after the group formed, Medusa launched a data leak site where victims are named and stolen data is published if the ransom is not paid. This double extortion method, where the ransom must be paid to obtain the decryption keys and prevent the publication of stolen data, is common among RaaS groups, although in the case of Medusa, its core members have retained control of ransom negotiations.

According to the joint cybersecurity alert from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), the Medusa developers recruit initial access brokers (IABs) on cybercriminal forums and marketplaces and incentivize them to work solely with Medusa. The authoring agencies have observed affiliates using phishing to obtain credentials to access victims’ networks, as well as exploiting unpatched software vulnerabilities, including last year’s ScreenConnect vulnerability CVE-2024-1709 and the Fortinet EMS SQL injection vulnerability CVE-2023-48788.

Once access to a victim’s network has been gained, Medusa actors use living off the land techniques for user, system, network, and file system enumeration, including legitimate tools such as Advanced IP Scanner, SoftPerfect Network Scanner, PowerShell, Windows Command Prompt, and Ingress Tool Transfer capabilities, as well as Windows Management Instrumentation (WMI) for querying system information.

The authoring agencies have observed Medusa actors using several different PowerShell detection evasion techniques, and they are known to hide their activities by deleting the PowerShell command line history. Endpoint detection and response tools are disabled by using vulnerable or signed drivers to kill processes, and legitimate remote access software is often used to evade detection and assist with lateral movement, along with Remote Desktop Protocol (RDP) and PsExec. Rclone is used to facilitate data exfiltration, and the encryptor is deployed across the network using tools such as Sysinternals PsExec, PDQ Deploy, and BigFix. Windows Defender and other security tools are also disabled on specific targets, backup processes are terminated, and shadow copies are deleted to prevent restoration of encrypted files without paying the ransom. Victims are given 48 hours to make contact to negotiate the ransom payment, with Medusa actors also known to reach out to victims via phone or email. There has been at least one instance where a further ransom demand was issued after the initial payment was made, where the affiliate behind the attack claimed not to have been paid.

The cybersecurity alert shares indicators of Compromise (IOCs), known MITRE ATT&CK tactics and techniques, and recommended mitigations, the most important of which are mitigating known vulnerabilities promptly, segmenting networks to restrict lateral movement, filtering network traffic to prevent unknown or untrusted origins from accessing remote services on internal systems, implementing multifactor authentication for webmail, VPNs, and all accounts that access critical systems, and educating the workforce about phishing identification and avoidance.

The post Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs appeared first on The HIPAA Journal.

Critical Vulnerabilities Identified in Popular Consumer Fertility Device

Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking device, and the Pulsetto Vagus Nerve Stimulator. Vulnerabilities in the former could result in sensitive data exposure and data manipulation. The latter has a vulnerability that poses a safety risk to users.

Mira Hormone Monitor & Mira Android App

Multiple vulnerabilities have been identified in the Mira Hormone Monitor and its associated Android app that could expose sensitive health data, cause a denial-of-service condition, and allow an unauthorized individual to take control of user accounts and manipulate data, potentially resulting in failed fertility treatments, missed fertility windows, or unwanted pregnancies.

The vulnerabilities were identified by a team of researchers at Northeastern University SPQR Lab. The research was partly funded by the Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) through a grant issued under the Universal Patching and Remediation for Autonomous Defense program. The vulnerabilities were reported to the device manufacturer, Quanovate Tech, which has taken steps to address the vulnerabilities.

The researchers conducted a full-chain security assessment of the Mira Ultra 5 fertility hormone analyzer and associated Android app and cloud infrastructure. The researchers identified 20 vulnerabilities in the device, app, and cloud infrastructure, including two critical vulnerabilities. The most serious vulnerabilities could be exploited by an attacker to gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information, and to gain control of cloud accounts and access hormone record information and account settings.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key Vulnerabilities

The vulnerabilities include weak or missing authentication, transmission of user data to third parties through analytics code and SDKs, hard-coded API keys, a lack of rate-limiting/IP-throttling, and publicly accessible firmware. The vulnerabilities affect Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4.

Vulnerability CVSS v3.1 Base Score CVSS v4.0 Base Score Outcome of Successful Exploitation
CVE-2026-68067 9.8 (Critical) 9.8 (Critical) Gain control of cloud accounts and access hormone record information and account settings.
CVE-2026-67568 9.1 (Critical) 9.3 (Critical) Gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information.
CVE-2026-66875 8.8 (High) 8.7 (High) Extract stored hormone measurements; denial-of-service; passively track the user.
CVE-2026-67558 7.4 (High) 8.2 (High) Capture live session token information; inject forged hormone measurements into the victim’s cloud record and clinical trend view.
CVE-2026-66098 6.5 (Medium) 7.1 (High) Denial-of-service; disrupt ovulation tracking and fertility monitoring workflow.
CVE-2026-66832 6.5 (Medium) 6.9 (Medium) Obtain live session token.
CVE-2026-66340 5.3 (Medium) 6.9 (Medium) Brute force access to user account
CVE-2026-64934 4.3 (Medium) 5.3 (Medium) Submission of arbitrary firmware version strings for their own device; evade vendor-side vulnerable-fleet analytics; suppress security update prompts to the user; misrepresent patch-adoption metrics.

The researchers coordinated with the device manufacturer and CISA and previewed the findings after Quanovate had completed two rounds of remediation. Quanovate has released updates to fix these vulnerabilities, and users should upgrade to the latest firmware/app versions: iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No evidence has been found of any actual or attempted exploitation of the vulnerabilities.

Pulsetto Vagus Nerve Stimulator

A high-severity vulnerability has been identified in the firmware of the Pulsetto Vagus Nerve Stimulator. Successful exploitation could allow an attacker to disable electrical safety mechanisms or modify other stimulation output settings.

The issue is due to the firmware accepting hidden commands over its Bluetooth Low Energy (BLE) interface. The commands are sent without authorization or encryption and are never issued by the companion mobile application; however, they are fully processed when the device is powered on.

The vulnerability is tracked as CVE-2026-18844 and affects all current versions. The vulnerability has been assigned a CVSS v3.1 base score of 8.1, and a v4.0 base score of 7.2.  The vulnerability was identified by researcher and security author A.C. Buglione, who reported the vulnerability to CISA.  CISA reached out to Pulsetto regarding the vulnerability but did not receive a response. CISA has therefore advised users to contact Pulsetto directly for information on how the issue can be remediated.

The post Critical Vulnerabilities Identified in Popular Consumer Fertility Device appeared first on The HIPAA Journal.

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is targeting government and critical infrastructure entities, including healthcare organizations, and organizations in other sectors. The group has conducted attacks in the Americas, Europe, Middle East, Africa, and Asia-Pacific, with attacks accelerating in 2026.

Gunra ransomware was first identified as a financially motivated threat group in April 2025; however, in 2026, it transitioned into a RaaS group. The group is attempting to recruit experienced affiliates from other groups by offering an 80% cut of any generated ransoms, as well as initial access brokers who can deliver enterprise-scale footholds.

The group primarily targets Windows systems and uses advanced encryption methods. In late 2025, the group also developed a Linux variant of its encryptor to allow cross-platform targeting. The encryptor is based on leaked Conti ransomware source code. The group engages in double extortion attacks, stealing sensitive data before encrypting files. After file encryption, victims receive a ransom note in each affected directory and are required to initiate negotiations via a Tor-based negotiation panel. Victims are provided with unique login credentials to access the negotiation panel and are given between 5 and 10 days to commence negotiations.

The group has been observed gaining access to victims’ networks by exploiting known vulnerabilities in Internet-facing devices, including firewalls and VPN appliances, such as the CVE-2024-55591 and CVE-2025-24472 authentication bypass vulnerabilities in FortiOS/FortiProxy. The group has also been observed exploiting Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.

Multiple stealth and defense impairment techniques are used to hinder detection and analysis. Data collected and exfiltrated includes business-critical documents, databases, personally identifiable information (PII), and internal email communications, including from Microsoft OneDrive and SharePoint. The stolen data is used as leverage to pressure victims into paying the ransom. Threats are issued to publish or sell the stolen data on a dedicated dark web data leak site if the ransom is not paid. The group’s data leak site currently lists more than 30 worldwide victims.

The #StopRansomware cybersecurity advisory recommends taking immediate action to reduce the risk of an attack, including prioritizing patching for known exploited vulnerabilities, especially vulnerabilities in VPNs and RDP-exposed infrastructure. Networks should be segmented to hamper lateral movement from initially compromised devices to other organizational systems, and immutable backups should be created and stored in physically separate, segmented locations to ensure data can be recovered without paying the ransom.

Full details of the group’s tactics, techniques, and procedures (TTPs), Indicators of Compromise (IoC), and recommended mitigations are detailed in the cybersecurity advisory.

The post Healthcare Orgs Warned About Gunra Ransomware Attacks appeared first on The HIPAA Journal.

California Child Care Company Discovers 9-Year Employee Data Leak

A data breach has recently been announced by Child Care Resource Center that shows how even well-intentioned employee practices can result in the exposure of sensitive data. Child Care Resource Center is a California-based non-profit organization, and while it does not appear to be a HIPAA-covered entity, similar data breaches have occurred at entities subject to the HIPAA Rules.

Child Care Resource Center recently learned that one of its employees had been forwarding internal files containing personal data to an external email account. While sending emails containing internal data outside the organization could indicate data theft, in this case, Child Care Resource Center was satisfied that the files were being emailed in an effort to fulfil tasks associated with the employee’s role.

The employee had been emailing data to the external email account for many years before their actions were discovered. The investigation determined that the first instance occurred on October 4, 2016, and continued until October 15, 2025. It took until June 3, 2026, to complete the investigation and review the data involved. The affected individuals are now being notified and have been offered complimentary credit monitoring and identity theft protection services.

The breach notification letter sent to the California Attorney General does not state the exact types of data involved, nor the number of affected individuals; however, considering the practice spanned 9 years, it could be an extensive data breach. When files are forwarded to an external email account, the company loses control of the data and is unable to protect the information against unauthorized access.

In this case, the company found no evidence to suggest unauthorized data access, nor that any information had been misused. Since unauthorized data access cannot be ruled out in these circumstances, breach notifications are required. Child Care Resource Center said it has implemented additional safeguards to prevent similar incidents in the future.

Healthcare organizations can reduce the risk of incidents such as this by providing regular security awareness and HIPAA training, emphasizing the risks associated with emailing or otherwise copying data to complete work duties out of the office. Technical security measures should be configured to either block the emailing of internal data to external email accounts or, if not practical, to ensure that email security solutions are configured to flag anomalous behavior and closely monitor alerts for potential data security incidents.

The post California Child Care Company Discovers 9-Year Employee Data Leak appeared first on The HIPAA Journal.

CISA Issues Updated Guidance on Minimum Elements of an SBOM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international cybersecurity authorities have published joint guidance on the minimum elements of a Software Bill of Materials (SBOM). An SBOM is a detailed list of software components, including open-source libraries and hidden dependencies, together with the creators or vendors associated with those components.

Software supply chains are often large and complex, and vendors can be slow to release patches to address vulnerabilities, especially when those vulnerabilities affect third-party components. Cybercriminals target software supply chains as they often have ample time to exploit vulnerabilities before patches are released. Keeping up to date with vendor patches is important; however, simply applying vendor patches does not guarantee that the software is secure. If an SBOM is obtained from a software vendor, users will be able to identify vulnerable or risky components long before patches are released by vendors, allowing them to implement temporary solutions to protect against software supply chain attacks.

In 2021, the National Telecommunications and Information Administration (NTIA) published guidance on the minimum elements for an SBOM, and the latest guidance replaces that document, incorporating stakeholder feedback obtained following the publication of draft guidance in 2025. “SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs,” wrote the authoring agencies. “These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021.”

The latest guidance applies to all software solutions, although additional requirements may be necessary for certain types of software, such as AI-based software systems and software-as-a-service (SaaS) solutions in cloud environments. The authoring agencies recommend using the guidance to ensure that their SBOMs include the minimum requirements and then assessing each software solution to determine if any further efforts are required to improve software transparency.

The update includes an additional ten data fields, updates to eight components to clarify scope and specify expectations, and five minor updates to improve information quality and align the guidance with the latest technical developments. The guidance is aimed at organizations that produce, procure, or operate software, and will allow them to better understand the makeup of their software components and supply chains and make more risk-informed decisions.

The post CISA Issues Updated Guidance on Minimum Elements of an SBOM appeared first on The HIPAA Journal.