HIPAA Breach News

Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach

Wellesley, MA-based DentaQuest, a dental benefits administrator that manages the benefits for 32 million Americans, has announced it is actively managing a cybersecurity incident involving unauthorized access to a limited part of its network. According to its website notice, immediate action was taken to contain and mitigate the threat, and the company is working with a leading cybersecurity expert, forensic investigators, and law enforcement authorities.

DentaQuest, part of Sun Life U.S. Dental, is the largest Medicaid and Children’s Health Insurance Program dental benefits administrator in the country, operating in 50 U.S. states. The company has yet to determine the exact scope of the incident and the extent to which sensitive data has been compromised. The company has promised to update clients and ensure that they receive information as quickly and transparently as possible.

The digital extortion group ShinyHunters has claimed responsibility for the incident and has added DentaQuest to its dark web data leak site. The group specializes in data theft and extortion and claims to have exfiltrated 234 GB of data from DentaQuest systems. ShinyHunters explained on its data leak site that it has attempted to negotiate a ransom payment with DentaQuest to prevent the publication of stolen data, but despite exercising considerable patience and making multiple offers, it failed to reach an agreement with DentaQuest. As a result of the failure, ShinyHunters proceeded to leak the stolen data.

Have I Been Pwned (HIBP) has analyzed the leaked data, which contains the unique email addresses of 2.6 million individuals, along with names, addresses, phone numbers, dates of birth, and genders. HIBP said the leaked data appears in healthcare enrollment files (ASC X12 transaction sets), some of which include information such as Medicaid IDs, other government-issued IDs, and health insurance information. Around 66% of the records exposed were already in its database, having been breached in previous incidents.

Social Security numbers do not appear to have been stolen or leaked, so the affected individuals do not face an immediate threat of identity theft; however, since email addresses and contact information have been leaked, they do face an increased risk of social engineering and phishing attacks. If the data breach is confirmed as affecting 2.6 million individuals, it will rank as one of the largest healthcare data breaches of the year to date.

The post Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach appeared first on The HIPAA Journal.

Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients

Data breaches have been announced by Clarinda Regional Health Center in Iowa, Community Connections in DC, Waveny Lifecare Network in Connecticut, and NJ Pain Care Specialists in New Jersey.

Clarinda Regional Health Center

Clarinda Regional Health Center, a Clarinda, IA-based non-profit hospital, has started notifying 24,341 individuals about a recent cybersecurity incident that exposed sensitive data. Suspicious activity was identified within its computer network on December 15, 2026, and the forensic investigation determined that files containing patient data may have been accessed or acquired without authorization in October 2025. The LockBit5 ransomware group claimed responsibility for the incident.

The file review confirmed that the exposed data included first and last names, dates of birth, medical information, health insurance information, financial account numbers, Social Security numbers, driver’s license numbers, and taxpayer identification numbers. The types of data varied from individual to individual.

The review of the affected files was completed on May 21, 2026, and notification letters started to be mailed to the affected individuals on June 2, 2026. Individuals whose Social Security numbers were exposed in the incident have been offered complimentary credit monitoring and identity theft protection services. Clarinda Regional Health Center has confirmed that additional security measures have been implemented to reduce the risk of similar incidents in the future.

Community Connections

Community Connections, a Washington D.C.-based non-profit provider of behavioral health, residential, and primary health care coordination services, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 18,943 individuals.

The breach was reported to OCR on May 18, 2026. Details about the data breach have yet to be publicly disclosed; however, a ransomware group – Inc Ransom – claimed responsibility for the incident and listed Community Connections to its dark web data leak site in late March, although it does not appear to have leaked the stolen data.

A similarly sized data breach was experienced in 2024, affecting 18,943 individuals. According to the notifications issued on August 27, 2025. The incident was detected on October 21, 2024, and full names, addresses, dates of birth, Social Security numbers, financial information, driver’s license or state identification information, medical information, and health insurance information were potentially involved. Following that incident, multiple steps were taken to reduce the risk of similar incidents in the future, including implementing new technical safeguards and retraining members of its workforce.

Waveny Lifecare Network

Waveny Lifecare Network, a New Canaan, CT-based community-focused non-profit providing residential care, skilled nursing, and in-home care services to seniors, has recently reported a data security incident to the Maine Attorney General that has affected 8,548 individuals. Suspicious activity was identified within its computer systems on May 28, 2025. Third-party cybersecurity specialists were engaged to investigate the incident and confirmed that a limited amount of data was accessed by an unauthorized third party on May 28, 2025.

Waveny Lifecare Network conducted a time-consuming review of the affected data, and that process was completed on March 23, 2026. Up-to-date contact information was then obtained to allow notification letters to be mailed, which were sent on June 2, 2026. The notification letter to the Maine AG has the data types redacted, although they are detailed in the individual notification letters. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

NJ Pain Care Specialists

NJ Pain Care Specialists, LLC, an interventional spine and pain management practice in Ocean Township, New Jersey, has announced a data security incident. Unauthorized activity was identified within its computer network on or around February 28, 2026. The investigation confirmed unauthorized access to its network occurred between February 25, 2026, and February 28, 2026, during which time, files may have been removed from its network.

The investigation to date has determined that data compromised in the incident includes names, addresses, dates of birth, medical record numbers, driver’s license numbers or other ID numbers, clinical or treatment information, medical procedure information, medical provider names, prescription information, and health insurance information.

NJ Pain Care Specialists said it has reviewed and enhanced its data security policies and procedures, and its technical, administrative, and physical safeguards. The investigation is ongoing, and the number of individuals has yet to be determined. The breach has been reported to the HHS’ Office for Civil Rights using an interim total of at least 501 individuals. The total will be updated when the investigation is concluded.

The post Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients appeared first on The HIPAA Journal.

Singing River Health System: 54K Individuals Affected by December Cyberattack

Singing River Health System in Mississippi has issued an update on a cybersecurity incident that was first announced in December 2025, shortly after the attack was detected. In the updated breach notice, Singing River Health System explained that its investigation revealed an unauthorized third party had access to certain computer systems between December 19, 2025, and December 21, 2025. On February 10, 2026, Singing River Health System confirmed that the unauthorized individual had access to files containing patient information.

The file review has recently concluded and revealed that the exposed data included names in combination with one or more of the following: contact information, Social Security numbers, driver’s license numbers, dates of birth, diagnostic/treatment information, medication information, dates of service, bank account information, health insurance information, provider names, and internal patient identification numbers.

Singing River Health System said it will continue to implement and evaluate enhanced safeguards and security measures to further protect its systems. The affected individuals have been advised to review the statements they receive from their healthcare providers and insurers for any services that have not been received. The incident has recently been reported to the HHS’ Office for Civil Rights as affecting 53,888 individuals.

Adams County Memorial Hospital

Adams County Memorial Hospital has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 5,305 individuals. The data was exposed as a result of an employee responding to a phishing email, which allowed an unauthorized third party to gain access to the employee’s email account on December 22, 2026. The breach was confined to the email account. The electronic medical record system was not affected. The investigation confirmed that the account contained personal and protected health information such as names, addresses, dates of birth, Social Security numbers, dates of service, diagnoses, charges, and health insurance information.

In response to the incident, additional security protocols have been implemented to protect against future phishing incidents, and additional education has been provided to employees on phishing and malicious email identification. As a precaution against identity theft and fraud, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months.

Central Kansas Mental Health Center

Central Kansas Mental Health Center in Salina, KS, has experienced a cybersecurity incident that exposed patient data. The incident was first identified on September 26, 2025, when suspicious activity was observed within its computer network. Immediate action was taken to contain the incident, and an investigation was launched to determine the nature and scope of the unauthorized activity.

The investigation confirmed that an unauthorized third party accessed its network and likely exfiltrated files containing patient data. The files are being reviewed to determine the types of data involved and the individuals affected. Central Kansas Mental Health Center first announced the data breach via its website in November 2025, confirming that credit monitoring and identity theft protection services are being made available.  Central Kansas Mental Health Center has not identified any misuse of the exposed data to date. The incident has yet to be added to the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

The post Singing River Health System: 54K Individuals Affected by December Cyberattack appeared first on The HIPAA Journal.

Patient Data Exposed in Cyberattacks on Dental Practices

Data breaches have been announced by Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics. Across the three incidents, the protected health information of more than 32,700 individuals was exposed and potentially stolen.

Bridle Trails Family Dentistry

Bridle Trails Family Dentistry, a dental practice in Kirkland, Washington, has notified 20,976 current and former patients about a cybersecurity incident that occurred in the Fall of 2024 that exposed some of their personal and protected health information. According to the April 10, 2026, breach notification letters, an investigation was launched into a potential breach of its email environment, which confirmed that an employee’s email account was accessed by an unauthorized individual between November 19, 2024, and November 25, 2024. The account was reviewed, and Bridle Trails Family Dentistry learned on March 12, 2026, that the account contained a limited amount of personal and health information.

Data potentially compromised in the incident included full names, birth dates, Social Security numbers, reason for visit, medical provider name, clinical/treatment information, driver’s license numbers, taxpayer ID numbers, medical record numbers, and health insurance information. The impacted information varied from individual to individual. At the time of issuing notifications, Bridle Trails Family Dentistry was unaware of any misuse of data as a direct result of the incident. Bridle Trails Family Dentistry said it has taken many precautions to safeguard the personal and protected health information in its possession and continually evaluates and modifies its practices and internal controls.

Verber Dental Group

Verber Dental Group PC, a Camp Hill, Pennsylvania-based network of 14 dental practices, has announced a breach of the protected health information of up to 8,598 individuals. Suspicious activity was identified within its network environment on January 27, 2026. Immediate action was taken to ensure its network environment was secure, and an investigation was launched to determine whether sensitive data had been exposed.

The forensic investigation determined that an unauthorized third party had access to files containing patient data, which may have been viewed or acquired between January 26, 2026, and January 27, 2026. The files on the compromised parts of its network were reviewed and found to contain names, Social Security numbers, dates of birth, driver’s license numbers, medical information, and health insurance information. Notification letters are being mailed to the affected individuals, and steps have been taken to reduce the risk of similar incidents in the future.

Bronsky Orthodontics

Bronsky Orthodontics, an orthodontic practice in New York City, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 3,183 individuals. Suspicious activity was identified within an employee’s email account on October 16, 2025. The account was immediately secured, and an investigation was launched to determine the nature and scope of the activity. Assisted by third-party cybersecurity specialists, Bronsky Orthodontics determined that a limited number of email accounts had been accessed by an unknown actor between August 18, 2025, and October 16, 2025.

The accounts were reviewed, and on March 11, 2026, Bronsky Orthodontics determined that they contained patient information such as names, dates of birth, contact information, dental and orthodontic treatment information, and insurance information. A limited number of individuals also had their financial account information, Social Security numbers, driver’s licenses, and/or other government-issued identification numbers exposed.   Policies and procedures related to data privacy and security are being reviewed as a result of the incident.

The post Patient Data Exposed in Cyberattacks on Dental Practices appeared first on The HIPAA Journal.

Medical Billing Company Data Breach Affects 7 Medical Groups

The Las Vegas medical billing and coding management company, La Perouse, has announced a data breach that has affected seven of its medical group clients. Data breaches have also been announced by Acadia Healthcare Company, Harbor Regional Center, United Medical Systems, and Ohio ENT & Allergy Physicians.

La Perouse

La Perouse LLC, a Las Vegas, NV-based medical billing and coding management company, has notified the California Attorney General about a breach of one of its third-party billing platforms. Potential unauthorized activity was first identified on July 8, 2025. The platform and its network environment were secured, and an investigation was launched to determine the nature and scope of the unauthorized activity.

The investigation confirmed that the unauthorized access was confined to the third-party billing platform and that sensitive data stored within that platform had been copied by the attacker. The review of the affected data was completed in the Spring of 2026, and notification letters were mailed to the affected individuals on April 17, 2026. The data compromised in the incident varies from individual to individual and may have included names, dates of birth, Social Security numbers, driver’s license or state identification card numbers, patient identification and medical record numbers, medical information, and health insurance information.

La Perouse worked with its third-party billing platform provider to implement additional technical safeguards, enhance security measures, and update security policies and procedures. The affected individuals have been offered at least 12 months of complimentary credit monitoring services. The affected individuals had received medical services from one or more of the following healthcare providers;

  • Beach Emergency Medical Associates
  • Centinela Freeman Emergency Medical Associates
  • Chino Emergency Medical Associates
  • Hollywood Presbyterian Emergency Medical Associates
  • Montclair Emergency Medical Associates
  • Tarzana Emergency Medical Associates
  • Temecula Valley Hospitalist Medical Group

The incident was reported to the HHS’ Office for Civil Rights in September 2025 using a placeholder estimate of at least 501 individuals. The total has yet to be updated.

Acadia Healthcare Company

Acadia Healthcare Company, the operator of a network of almost 280 behavioral healthcare facilities in 40 U.S. states and Puerto Rico, has recently disclosed a data security incident that was first identified in March 2026. Suspicious activity was observed within an employee’s email account. The email account was secured, and an investigation was launched to determine the nature and scope of the activity. The forensic investigation determined that the account and an associated SharePoint account were accessed by an unauthorized third party between March 21 and March 25, 2026, as a result of social engineering attacks. No other systems were involved.

The data review was completed on May 15, 2026, and confirmed that the information compromised in the incident included names, addresses, dates of birth, treatment information, health insurance information, admission dates, diagnosis codes, patient statuses, Medicare insurance claim numbers, and, for some individuals, Social Security numbers. Notification letters started to be mailed to the affected individuals on May 22, 2026. Acadia Healthcare Company said additional cybersecurity measures have been implemented to prevent similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights website, so it is currently unclear how many individuals have been affected.

Harbor Regional Center

Harbor Developmental Disabilities Foundation, doing business as Harbor Regional Center, a Long Beach, CA-based provider of services to individuals with developmental disorders, identified suspicious activity within its computer network on or around March 7, 2026. The forensic investigation confirmed unauthorized access to its computer network between March 6 and March 7, during which time, files may have been viewed or copied from the network.

On May 15, 2026, Harbor Regional Center completed its review of the exposed files. The exact types of information involved are detailed in the individual notification letters that have recently been mailed to the affected individuals. The number of affected individuals has yet to be publicly disclosed. The affected individuals have been offered single-bureau credit monitoring and identity theft protection services, and steps have been taken to improve security to prevent similar breaches in the future.

Ohio ENT & Allergy Physicians

Ohio ENT & Allergy Physicians in Columbus, Ohio, has recently reported a data breach to the Maine Attorney General that involved unauthorized access to the personal and protected health information of 324 individuals, including 1 Maine resident. A cybersecurity incident was detected on March 30, 2026, when suspicious activity was identified on a workstation within its network environment. The forensic investigation confirmed unauthorized access between March 29, 2026, and March 30, 2026. The review of all potentially exposed files was completed on May 18, 2026. Data exposed in the incident included full names and Social Security numbers. Notification letters were mailed to the affected individuals on May 29, 2026.

Ohio ENT & Allergy Physicians has implemented additional technical safeguards and has enhanced its security measures to prevent similar incidents in the future, and complementary credit monitoring services have been offered to the affected individuals.

United Medical Systems

Westborough, Massachusetts-based mobile specialty healthcare service provider United Medical Systems has disclosed a data breach affecting 485 individuals. According to the notification letters, which were mailed to the affected individuals on May 20, 2026. The forensic investigation confirmed that names, driver’s license numbers, and Social Security numbers were exposed in the incident. As a precaution against identity theft and fraud, the affected individuals have been offered complimentary single-bureau credit monitoring and identity theft protection services for 24 months, and steps have been taken to enhance security to prevent similar incidents in the future.

The post Medical Billing Company Data Breach Affects 7 Medical Groups appeared first on The HIPAA Journal.

Lakeview Health Systems Settles Class Action Data Breach Lawsuit

A settlement has been negotiated to resolve a class action lawsuit against Lakeview Health Systems LLC. The lawsuit stemmed from a January 2024 cyberattack that exposed the personal and protected health information of 10,772 individuals. Hackers breached its network and accessed and potentially obtained files containing names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account numbers, patient IDs, diagnoses, treatment information, prescription information, and health insurance information.

Shortly after being notified about the breach, some of the affected individuals filed lawsuits against Lakeview Health, alleging negligence for failing to adequately protect sensitive data stored on its network. The plaintiffs claimed the data breach could have been and should have been prevented. Lakeview Health maintains that there was no wrongdoing and is no liability.

The lawsuits made similar claims and were consolidated – Skov et al., v. Lakeview Health Systems, L.L.C – in the Circuit Court of Duval County, Florida. The lawsuit is pending; however, the defendants and the plaintiffs agreed to settle the lawsuit to avoid the costs, risks, disruptions, and uncertainties from continuing with the litigation.

The defendant has agreed to pay attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives. Class members may submit a claim for reimbursement of documented, unreimbursed ordinary losses due to the data breach up to a maximum of $2,000 per class member and reimbursement of up to $5,000 in extraordinary losses. A claim may also be submitted for up to 4 hours of lost time at $20 per hour, and one year of credit monitoring services. If none of those options are claimed, class members may claim a one-time cash payment of $50.

The deadline for objection and exclusion is July 23, 2026. Claims must be submitted by August 24, 2026, and the final fairness hearing has been scheduled for October 8, 2026.

The post Lakeview Health Systems Settles Class Action Data Breach Lawsuit appeared first on The HIPAA Journal.

Connecticut Medicaid Portal Breach Affects 22,500 Hartford HealthCare Patients

The personal and protected health information of approximately 22,500 Hartford HealthCare patients has been exposed in a security incident. Data breaches have also been announced by the New York City cosmetic surgery practice of Ira L. Savetsky, MD, and the mobility and rehabilitation product provider ERMI, LLC.

Hartford HealthCare

The Connecticut Department of Social Services and Gainwell Technologies, a vendor that provides fiscal agent and account administration services for the Connecticut Medicaid program (HUSKY), have identified unauthorized access to certain payment accounts on the HUSKY provider portal website.

Suspicious activity was identified on March 25, 2026, and the forensic investigation confirmed unauthorized access to a small number of Hartford HealthCare’s payment accounts on the website. The accounts were accessed on March 4, 2026, using the compromised credentials of Hartford Healthcare employees. Immediate action was taken to prevent further unauthorized access, and assisted by third-party cybersecurity experts, the incident was determined to have been contained and further unauthorized access blocked; however, the threat actor had downloaded files containing the data of approximately 22,500 individuals.

The review of those files revealed they contained information such as full names, ID numbers associated with Hartford HealthCare accounts or Medicaid claims, dates of medical services, information about services received and how they were billed, payment information including amounts paid, and information about applicable non-Medicaid health insurance, including policy and group number. Social Security numbers were not stored in the system, and were not obtained in the attack.

This appears to have been a financially motivated attack, and the primary purpose does not appear to have been patient data theft; however, patient information was compromised and, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. DSS and Gainwell Technologies began sending notification letters to the affected Hartford HealthCare patients on May 22, 2026.

Ira L. Savetsky, MD

The New York City cosmetic surgery practice of Ira L. Savetsky, MD, has experienced a breach of its email environment. The security incident was detected in January 2026, and the forensic investigation confirmed that a single employee’s email account had been accessed by an unauthorized third party. The first instance of unauthorized access occurred in November 2024, and access to the account remained possible until January 2026. Over that 14-month period, information in the account may have been viewed or copied. The account was reviewed and found to contain patient information such as scheduling information and correspondents related to patient care, along with first and last names, birth dates, telephone numbers, driver’s license numbers, medical records, health information, health insurance information, and photographs.

Notification letters started to be mailed to the affected individuals on May 21, 2026. Complimentary credit monitoring and identity theft protection services do not appear to have been offered. The incident has been reported to regulators, but it is not yet shown on the HHS’ Office for Civil Rights website, so it is currently unclear how many individuals have been affected.

ERMI LLC

ERMI LLC, an Atlanta, GA-based provider of mobility and rehabilitation products, has identified a cybersecurity incident that exposed sensitive data. Unauthorized access to certain employee email accounts was identified on or around August 14, 2025. The accounts were secured, and an investigation was launched to determine the nature and scope of the unauthorized activity.

The forensic investigation confirmed unauthorized access to a limited number of employee email accounts between February 15, 2025, and August 14, 2025. The review of the accounts was completed on or around April 17, 2026. Individual notification letters are being sent to the affected individuals, which detail the exact types of data exposed in the incident. As a precaution against data misuse, the affected individuals have been offered complimentary single-bureau credit monitoring, credit score, and credit report services. The number of affected individuals has yet to be publicly disclosed.

The post Connecticut Medicaid Portal Breach Affects 22,500 Hartford HealthCare Patients appeared first on The HIPAA Journal.

The Oncology Institute Confirms Unauthorized Access to Systems Due to Vendor Breach

The Oncology Institute, a publicly traded provider of cancer care through more than 100 clinics in California, Oregon, Nevada, Arizona, and Florida, has recently confirmed that patient data was potentially accessed by an unauthorized third party as a result of a security incident at one of its vendors.

In a November 3, 2025, filing with the U.S. Securities and Exchange Commission (SEC), The Oncology Institute said that it determined on November 3, 2025, that a cybersecurity incident at one of its information technology software providers would potentially delay fee-for-service collections. At the time of the notice, The Oncology Institute said its vendor was unable to confirm whether patient data had been accessed in the attack, and that at the time of issuing the filing, it was unaware of any unauthorized access to patient data as a result of the incident, but the investigation into the incident was ongoing.

In an updated SEC filing, the Oncology Institute said further information has come to light indicating that certain Oncology Institute systems were subject to unauthorized access by a third party as a result of the incident, including systems containing patient data.  Kroll, the third-party administrator for the vendor, had made that determination and notified the Oncology Institute on May 20, 2026.

The Oncology Institute said it is working with its vendor to provide complimentary credit monitoring and identity theft protection services to the affected individuals. At the time of issuing the SEC filing on May 20, 2026, The Oncology Institute said the cybersecurity incident had not had a material impact on the company’s operations, financial systems, or the quality of care provided to patients. The Oncology Institute has yet to publicly disclose the types of data potentially compromised in the incident.

The Oncology Institute provides cancer care to around 2 million patients. It is currently unclear how many of those patients have been affected by the incident. The Oncology Institute has not disclosed the name of the vendor that experienced the cybersecurity incident, although certain media outlets have suggested that the vendor was TriZetto Provider Solutions, which experienced a major data breach last year affecting many of its healthcare provider clients.

The post The Oncology Institute Confirms Unauthorized Access to Systems Due to Vendor Breach appeared first on The HIPAA Journal.

May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities

A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, Tampa Bay Dental Implants & Prosthetics, Aligned Orthopedic Partners, South Alabama Regional Planning Commission, Pivot Health, LHC Group, Mays Housecall Home Health, and the World Trade Center Health Program.

University of Nebraska Medical Center

University of Nebraska Medical Center (UNMC) has discovered that a vulnerability in a third-party software application has been exploited by a threat actor, exposing patient information. UNMC learned about the vulnerability in the REDCap software application in February 2026. REDCap software is used by UNMC to support its research studies and public health activities. When UNMC learned about the vulnerability, the software was taken offline, and an investigation was launched to determine if the vulnerability had already been exploited. Assisted by third-party cybersecurity experts, UNMC determined that the vulnerability had been exploited on September 20, 2023, and access remained possible until February 3, 2026.

The data review confirmed that the system contained a range of sensitive data, which varied from individual to individual depending on the nature of the research study/public health activities. That information may have included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and information created or collected in connection with a research study. Such information may have included visit dates, diagnoses, medications, laboratory results, imaging or procedure information, questionnaire responses, or other health-related information. A subset of individuals also had their Social Security numbers exposed. In total, 26,937 individuals had data exposed. Individuals whose Social Security numbers were impacted have been offered complimentary credit monitoring services.

Singing River Health System

Singing River Health System, a non-profit health system with three hospitals and more than 50 clinics serving the Mississippi Gulf Coast, has started notifying patients about a hacking incident identified on or around December 21, 2025. The forensic investigation confirmed unauthorized access to its computer network between December 19, 2025, and December 21, 2025, and on February 10, 2026, it was confirmed that files containing patient information were viewed and potentially copied.

Data exposed varied from individual to individual and may have included names in combination with one or more of the following: contact information, Social Security numbers, driver’s license numbers, dates of birth, bank account information, health insurance information, provider names, internal patient identification numbers, dates of service, medication information, and treatment and/or diagnostic information.

Singing River Health System said, “We will continue to implement and evaluate enhanced safeguards and security measures to further protect our systems and continue to provide security training to our employees.” The affected individuals have been advised to monitor their accounts and explanation of benefits statements for data misuse. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Tampa Bay Dental Implants & Prosthetics

Tampa Bay Dental Implants & Prosthetics, which also does business as Tampa Bay Dental Implants, Periodontics & Oral Surgery, a dental care provider serving the St. Petersburg and Tampa Bay area in Florida, has recently disclosed a data breach affecting 6,400 individuals. Tampa Bay Dental discovered unauthorized access to its network on January 19, 2026, when ransomware was used to encrypt files. The attack affected a legacy server that contained a backup of electronic medical records.

The file review confirmed that patient data was exposed, including names, contact information, birth dates, treatment notes, and clinical histories, and for a limited number of individuals, Social Security numbers. Tampa Bay Dental has implemented additional security measures to prevent similar incidents in the future, including enhancing its security logging, strengthening server encryption, and updating access controls. Credit monitoring and identity theft protection services do not appear to have been offered to the affected individuals.

World Trade Center Health Program

The World Trade Center (WTC) Health Program, which provides no-cost healthcare services to individuals harmed by the 9/11 attack on the World Trade Center, has reported a data security incident to the HHS’ Office for Civil Rights affecting 1,071 individuals. Highly sensitive data was compromised in the incident, which occurred at a vendor, Managed Care Advisors/Sedgwick Government Solutions.

Hackers accessed a server containing files associated with the WTC Health Program and exfiltrated sensitive data before encrypting files. The TridentLocker ransomware group claimed responsibility for the attack. The attack was detected by Managed Care Advisors/Sedgwick Government Solutions on December 4, 2025, and the forensic investigation confirmed that the server was first breached on November 16, 2025. Data compromised in the incident includes names, addresses, Social Security numbers, dates of birth, and protected health information. TridentLocker proceeded to leak the stolen data on its dark web data site when the ransom was not paid. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months.

Aligned Orthopedic Partners

Bethesda, Maryland-based ASC Ortho Management Company, LLC, doing business as Aligned Orthopedic Partners, has discovered unauthorized access to its email environment and the exposure of the protected health information of 7,213 individuals. The forensic investigation determined unauthorized access occurred between November 16, 2025, and December 16, 2025, during which time, emails and files may have been accessed or acquired.

The file review determined on February 17, 2026, that the exposed data included names in combination with one or more of the following: date of birth, Social Security number, driver’s license or state identification number, Medicaid or Medicare number, financial account number, date(s) of service, medical provider name, mental or physical condition, medical treatment information, diagnosis or clinical information, prescription information, health insurance information, patient account number, and or medical record number. The affected individuals were notified on April 17, 2026, and complimentary identity protection services have been made available. Aligned Orthopedic Partners said steps have been taken to augment security to prevent similar incidents in the future.

Pivot Health

Pivot Health, a health insurance company specializing in short-term and supplemental health insurance products, has identified unauthorized access to its Amazon Web Services cloud environment. The unauthorized access was detected and blocked on March 13, 2026. The investigation confirmed that its AWS environment was accessed by an unauthorized third party at various points over a two-week period between February 26, 2026, and March 13, 2026. During that time, files containing member data were viewed or copied.

The digital forensic investigation confirmed that the exposed data included names, birth dates, member identification numbers, person identification, certificate identification, coverage identification, insurance billing and payment information, and, for certain individuals, financial account information. Data security policies and procedures are being reviewed, and additional cybersecurity protections have been implemented. The incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected, although the Texas Attorney General was informed that 1,172 Texas residents had their data exposed in the incident.

LHC Group / Mays Housecall Home Health

Two more healthcare providers have notified patients that some of their protected health information was compromised in a security incident at vendor Doctor Alliance: The home healthcare providers LHC Group in Louisiana and Mays Housecall Home Health, an Oklahoma-based provider of community and home health care services throughout Oklahoma, Kansas, and Texas.

The data breach did not involve unauthorized access to the home healthcare providers’ systems, as the incident was confined to the web-based portal used in connection with the services provided by their technology vendor. Doctor Alliance provides a platform that physicians and healthcare providers use to exchange and sign documentation related to patient care. The Doctor Alliance web portal was accessed by an unauthorized third party between October 31, 2026, and November 17, 2026. Doctor Alliance discovered the unauthorized access on November 12, 2025.

LHC Group said 8,644 individuals were affected and had the following types of information exposed: names, dates of birth, demographic information, health information, including clinical summaries and diagnosis codes, provider information, and health insurance information. Mays Housecall Home Health said 5,208 individuals were affected. Data compromised in the incident included names, demographic information, dates of birth, clinical information, diagnosis information, physician information, insurance-related information, and other information related to patient care documentation.

No data misuse has been detected. Both home healthcare providers are conducting additional oversight and review procedures related to third-party providers, and Doctor Alliance has implemented additional security safeguards and monitoring capabilities.

The South Alabama Regional Planning Commission

The South Alabama Regional Planning Commission has reported a data breach to the HHS’ Office for Civil Rights involving unauthorized access to the protected health information of 3,043 individuals. The substitute data breach notice does not state when the unauthorized access was detected, nor when its systems were accessed by unauthorized individuals, only that the investigation determined on August 6, 2025, that certain files were copied from its systems.

The files were reviewed and found to contain client names, Medicaid numbers, Social Security numbers, and medical information related to eligible services. The Alabama Department of Senior Services was notified about the breach on January 28, 2026, and the HHS’ Office for Civil Rights was notified on March 18, 2026. Notification letters have now been mailed to the affected individuals, and complimentary credit monitoring services have been offered.

The post May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities appeared first on The HIPAA Journal.