HIPAA Breach News

Hacking Incident Affects 46,000 Hawaii Family Dental Patients

A hacking incident at Hawaii Family Dental has affected almost 46,000 individuals. Data breaches have also been announced by Life Bridges in Tennessee, Westchester Institute for Human Development in New York, Community Health Care in Ohio, and Shoshone Medical Center in Idaho.

Hawaii Family Dental

Hawaii Dental Group, Inc., doing business as Hawaii Family Dental, a Honolulu-based operator of a dozen dental clinics in Hawaii, has started notifying 45,853 individuals about a July 2026 hacking incident that involved unauthorized access to their personal and protected health information.

Suspicious activity was identified within its computer network on July 20, 2026. The forensic investigation confirmed that an unauthorized third party accessed its systems between July 19 and July 20, 2026, including systems where patient information was stored. Files exposed and potentially copied in the incident included names, phone numbers, addresses, email addresses, dates of birth, medical and dental treatment information, and health insurance information. Patients were informed that financial information and Social Security numbers were not involved.

Hawaii Family Dental is reviewing and enhancing its data privacy and security safeguards to better protect against similar incidents in the future. While the name of the hacking group was not disclosed, the Qilin data theft and extortion group claimed responsibility for the attack and maintains that it exfiltrated sensitive data.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Life Bridges

Life Bridges, Inc., a Cleveland, Tennessee-based provider of residential, medical, and community support for individuals with intellectual and developmental disabilities, has reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 5,194 individuals.

In its substitute data breach notice, Life Bridges explained that unauthorized activity was identified within its computer systems on June 22, 2026. Containment measures were deployed, systems were taken offline, passwords were changed, and third-party cybersecurity experts were engaged to investigate the activity. The investigation confirmed that its systems were accessed by an unauthorized third party between June 17, 2026, and June 22, 2026, during which time files containing protected health information were copied from its systems.

The data review confirmed that the compromised information included names, addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnosis/condition information, lab results, treatment information, dates of service, insurance claims information, financial account information, debit card information, medical record numbers, Medicare numbers, Medicaid numbers, and managed care organization numbers. The types of data involved varied from individual to individual.

At the time of issuing notification letters, no misuse of the affected information had been identified. Life Bridges has confirmed that steps have been taken to reduce the risk of similar incidents in the future.

Westchester Institute for Human Development

Westchester Institute for Human Development, Inc., a Valhalla, New York-based provider of support services for individuals with disabilities and vulnerable children, has reported a breach of the protected health information of 938 individuals. On or around April 8, 2026, unauthorized activity was identified within its email environment. Steps were immediately taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed that an unauthorized third party had access to certain files within its environment between March 23, 2026, and April 14, 2026.

The file review found that the exposed data included names, Social Security numbers, driver’s license numbers, dates of birth, dates of medical service, health insurance policy numbers, provider information, medical condition/diagnosis, treatment information, medical record numbers, Medicare/ Medicaid numbers, financial account information, patient account numbers, full face photographs, and referral information. The types of information involved varied from individual to individual.

Westchester Institute for Human Development said the affected individuals have been notified, and it will continue to evaluate and modify its security measures to enhance the privacy and security of the information it maintains.

Community Health Care

Community Health Care, Inc., a healthcare provider with 19 practice locations in Northeastern Ohio, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on June 12, 2026. The incident was identified quickly and contained, limiting the unauthorized access to a single email account.

The affected account was found to contain the protected health information of 808 individuals, including names, phone numbers, dates of birth, dates of service, provider names, diagnostic/treatment information, and health insurance information. At the time of issuing notification letters, no misuse of the affected information had been identified. As a precaution, the affected individuals have been advised to remain vigilant against identity theft and fraud. Since the incident was identified, Community Health Care said it has been working with cybersecurity experts to further strengthen its existing, significant safeguards.

Shoshone Medical Center

Shoshone Medical Center, a Kellogg, Idaho-based critical access hospital, has identified unauthorized access to an employee’s email account. The unauthorized activity was identified on or around May 27, 2026, and an investigation was launched to determine the nature and scope of the activity.

On July 29, 2026, Shoshone Medical Center confirmed that personal and protected health information had been exposed, including names, addresses, dates of birth, phone numbers, patient identification numbers, medical record numbers, Medicare/Medicaid numbers, diagnosis/treatment information, treatment cost information, admission/discharge dates, and health insurance information. Notification letters have been mailed to the 553 affected individuals, and steps have been taken to reduce the risk of similar incidents in the future.

The post Hacking Incident Affects 46,000 Hawaii Family Dental Patients appeared first on The HIPAA Journal.

Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data

The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).

According to the September 8, 2026, filing, Veradigm recently learned that one of its third-party vendors had experienced a cybersecurity incident that impacted a small number of Veradigm’s customers. Veradigm explained that a threat actor obtained credentials from the vendor’s environment for a Veradigm Application Programming Interface (API) used for customer services. The threat actor was able to use the access to copy patient data.

The threat actor only had access to the API, and no other parts of its network were compromised, including servers, databases, or other systems. Veradigm determined that data stolen in the incident included the personal information of patients, which for certain patients may have involved their Social Security numbers; however, the company has determined that clinical and medical information was not involved and remained secure. As a precaution against data misuse, Veradigm is offering the affected individuals complimentary credit monitoring services.

The investigation is ongoing, and Veradigm has yet to publicly disclose how many individuals have been affected. The company said the incident did not impact its operations, and while the extent of any potential liabilities associated with the incident has not yet been determined, the company does not believe the incident is reasonably likely to have a material impact on the company’s business, operations, financial condition, or results of operations.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Veradigm did not disclose the name of the threat actor behind the attack, which appears to be a prolific threat group called The Gentlemen. The Gentlemen added Veradigm to its dark web data leak site on September 5, 2026. The posting alleges that data exfiltrated in the attack includes names, addresses, phone numbers, email addresses, and other personally identifiable information, and that 3.5 million patient records have been obtained. A threat has been issued to publish the stolen data if the ransom is not paid.

The post Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data appeared first on The HIPAA Journal.

Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider

Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by Crystal Coast Pain Management, Golden State Orthopedics & Spine, Gardiner Family Chiropractic, and BestCare Treatment Services.

Interim HealthCare of Oklahoma City

Interim HealthCare, a home healthcare provider operating in 40 U.S. states, has been added to the data leak sites of two ransomware groups. The first listing was added to the Genesis ransomware group’s data leak site on August 10, 2026. Genesis claimed to have exfiltrated data in the incident and threatened to publish it if the ransom was not paid. Genesis claims the stolen data relates to Interim Healthcare of Oklahoma and Tulsa, and that 1TB of data was exfiltrated, including medical records, healthcare data, personal data, patient lists, clinical data, and company data. While a list of the compromised files was added to the data leak site, the data allegedly stolen has yet to be published.

Then on August 21, 2026, a second ransomware group listed Interim HealthCare as one of its victims. Anubis claims to have exfiltrated 530 GB of data in the attack, including “financial information about franchisees, details of internal and external audits, discussions of operational issues, as well as memoranda covering all kinds of day-to-day business matters.” Samples of the stolen data were added to the listing, and the stolen data has been published, indicating the ransom was not paid.

While Interim HealthCare has yet to confirm the validity of either claim, Interim HealthCare of Oklahoma City, Inc. reported a network server hacking incident to the HHS’ Office for Civil Rights on July 31, 2026, using a placeholder estimate of 500 affected individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Crystal Coast Pain Management

Crystal Coast Pain Management in North Carolina, a division of East Carolina Anesthesia Associates ECAA), has started notifying patients that some of their personal and protected health information was obtained by an unauthorized third party in a cybersecurity incident earlier this year.

Suspicious network activity was identified on or around January 11, 2026, and third-party digital forensics and cybersecurity experts were engaged to investigate the activity. On April 20, 2026, it was determined that files containing patient information had been copied by the attackers. The file review was completed on June 24, 2026, when it was confirmed that the stolen data included first and last names, dates of birth, medical information, and Social Security numbers.

The cybersecurity experts confirmed the security of its network; however, as a precaution, all affected systems were wiped and rebuilt, and additional security measures have been implemented. No evidence has been found to indicate any misuse of the affected data, but as a precaution, the affected individuals have been offered single-bureau credit monitoring, credit report, and credit score services. A ransomware group called Devman 2.0 claimed it was behind the attack.

Golden State Orthopedics & Spine

Golden State Orthopedics & Spine (GSOS), an orthopedics practice with 13 locations in the San Francisco Bay Area in California, has announced a recent cybersecurity incident. Suspicious network activity was identified on July 2, 2026, and a third-party team of forensics experts was engaged to assist with the investigation and determine the nature and scope of the activity.

GSOS confirmed that its network had been accessed by an unauthorized third party, who may have viewed or obtained files containing patient information. The data review confirmed that the exposed data included first and last names, addresses, dates of birth, Social Security numbers, health insurance information, and medical diagnosis information.

The review of the affected data is ongoing, and the number of affected individuals has yet to be disclosed. GSOS is reviewing its data security policies, procedures, and practices and is taking steps to prevent similar incidents in the future. This appears to have been a ransomware or data theft and extortion incident. A ransomware group called Brain Cipher claimed responsibility for the attack, in which it alleged that 150 GB of data was stolen.

Gardiner Family Chiropractic

Gardiner Family Chiropractic, a chiropractic clinic in Gardiner, Maine, has notified the HHS’ Office for Civil Rights about a network server hacking incident that has affected up to 5,000 patients. Suspicious activity was identified within its computer network on July 17, 2026. An investigation was launched, which confirmed unauthorized network access and the exposure of patient data. Data potentially compromised in the incident includes names, contact information, birth dates, health information, and health insurance/Medicaid information.

According to the substitute breach notice, this was a ransomware attack involving file encryption and data theft. A ransom demand was received; however, the attack was blocked, and the ransom was not paid. The Interlock ransomware group claimed responsibility for the attack. Gardiner Family Chiropractic has taken several steps in response to the attack to strengthen security. In addition to wiping the affected devices and purchasing new computers for its employees, security policies, procedures, and practices have been reviewed, additional security measures have been implemented, and special training has been provided to its workforce on ransomware.

BestCare Treatment Services

BestCare Treatment Services, Inc., an Oregon-based behavioral healthcare provider, has experienced a data security incident involving unauthorized access to parts of its network containing patient information. Unauthorized network activity was identified on June 15, 2026, and a third-party cybersecurity firm was engaged to assist with the investigation and confirm the security of its network.

The investigation confirmed that files had been exposed containing names, dates of birth, contact information, demographic information, medical information, and other patient identifying information. Notification letters were mailed to the affected individuals on August 10, 2026. The data breach was recently reported to the HHS Office for Civil Rights as affecting 4,216 individuals.

The post Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider appeared first on The HIPAA Journal.

NFI North Data Breach Affects Almost 50,000 Individuals

Data breaches have been announced by NFI North in New Hampshire, Nephrology Associates in Kansas, PAMCAH-UA Local 675 Health and Welfare Fund in Hawaii, and Indico Data Solutions in Massachusetts.

NFI North, Inc.

NFI North, Inc., a Contoocook, New Hampshire-based nonprofit human services organization that provides mental health, behavioral, and educational support services in New Hampshire and Maine, has notified the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) about a breach of the protected health information of 49,540 individuals.

According to the NFI North substitute breach notice, suspicious activity was identified within its network on or around September 6, 2025. The investigation and data review concluded on July 6, 2026, when it was confirmed that data compromised in the incident included names, addresses, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. NFI North engaged cybersecurity professionals to assist with the investigation, and additional technical safeguards have been implemented to prevent similar incidents in the future.

Nephrology Associates

Nephrology Associates, M.D., P.A., a network of clinics in Kansas and Missouri that provide care to patients with chronic kidney disease and other kidney disorders, has announced a data security incident that has affected 24,088 individuals. Suspicious network activity was identified on or around April 9, 2026. Assisted by third-party cybersecurity experts, the practice determined that its network had been accessed by an unauthorized third party between January 17, 2026, and April 9, 2026. The affected systems were reviewed and, on July 1, 2026, the practice confirmed that data exposed in the incident included names, birth dates, Social Security numbers, driver’s license numbers/state identification numbers, other government identifiers, diagnosis and treatment information, and health insurance information.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

On or around July 30, 2026, notification letters started to be mailed to the affected individuals. At the time of issuing the notifications, Nephrology Associates was unaware of any actual or attempted misuse of the exposed data. As a precaution against identity theft and fraud, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While not mentioned in the data breach notice, this appears to have been an attack by the cybercriminal group called The Gentlemen. No data appears to have been leaked; however, the group has offered the data for sale.

PAMCAH-UA Local 675 Health and Welfare Fund

PAMCAH-UA Local 675 Health and Welfare Fund, a multiemployer trust fund in Honolulu, Hawaii, that provides medical, dental, vision, and welfare benefits to union plumbers and fitters and their families, has identified unauthorized access to the email accounts of some of its employees.

The forensic investigation determined that certain employee email accounts were accessed by an unauthorized third party between September 23, 2025, and October 9, 2025. During that time, emails and files in the account may have been viewed or acquired. The accounts were reviewed and found to contain the personal and protected health information of 8,319 individuals, including names, dates of birth, medical information, health insurance information, driver’s license numbers, and Social Security numbers. Notification letters have now been mailed to the affected individuals with information on how they can protect themselves against data misuse.

Indico Data Solutions

Indico Data Solutions, Inc., a Massachusetts-based AI-powered software company whose products include an intake and orchestration platform, has announced a data security incident involving the protected health information of 4,840 individuals. It is unclear from the data breach notice when the incident was detected or for how long unauthorized individuals had access to its systems, only that a cybersecurity incident was confirmed by Indico Data Solutions on May 7, 2026. Data potentially compromised in the incident includes names, addresses, and Social Security numbers.

Indico Data Solutions has taken several steps in response to the incident, including rotating access credentials, tightening access controls, and implementing additional monitoring tools. The affected corporate customers have been notified, and Indico Data Solutions has mailed notification letters to the affected individuals and has offered complimentary credit monitoring and identity restoration services.

The post NFI North Data Breach Affects Almost 50,000 Individuals appeared first on The HIPAA Journal.

Luminis Health Working to Restore Systems After Cyberattack

Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M.D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey.

Luminis Health, Maryland

Luminis Health, a nonprofit health system that includes Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, announced on September 4, 2026, that it has fallen victim to a cyberattack. The incident has affected both hospitals, which continue to serve patients, although certain appointments have had to be rescheduled. Currently, the phone system and MyChart patient portal remain offline.

Luminis Health said the priority continues to be providing safe, high-quality care to patients; meanwhile, third-party cybersecurity and legal experts have been engaged to investigate and rectify the incident and safely and securely restore access to the affected systems. The health system is currently unable to provide a timeline for how long those processes will take, and it is too soon to tell what extent, if any, that patient data was involved. Should it be determined that patient data was exposed or stolen, patients will be notified in due course. At present, no ransomware or data extortion group appears to have claimed responsibility for the attack.

Jeffrey David Reuben, M.D.

Jeffrey David Reuben, M.D., a Texas-based orthopedic surgeon serving patients at NW Surgery in Houston and medical centers in Bellaire, has recently reported a data security incident that has affected 17,017 current and former patients. The incident was identified on or around April 27, 2026, and assisted by third party cybersecurity professionals, it was confirmed that an unauthorized third party accessed systems containing patient information between April 18 and April 19, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The investigation and data review were completed on or around July 15, 2026, when it was confirmed that the exposed data included names, Social Security numbers, driver’s license numbers, government-issued ID numbers, and financial information. While no actual or attempted misuse of the affected data has been identified, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months.

Well Child

Well Child, a provider of school-based healthcare services through partnerships with school districts in Tennessee and Mississippi, has announced a cybersecurity incident that was first identified on June 1, 2026. All servers were immediately taken offline when the incident was identified to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. On June 5, 2026, the investigation confirmed that files containing sensitive personal information had been exfiltrated from a temporary storage server.

The investigation and data review are ongoing; however, it has been determined that the exfiltrated data included Vision Screening Reports, Vision Screening Data Files, Available Students Lists, and PEDS (Parents’ Evaluation of Developmental Status) assessment documents. In addition to student names, the files contained protected health information such as birth dates, medical record numbers, provider names, diagnoses, assessment/test results, treatment dates, and billing and/or procedure codes. For a limited number of individuals, Social Security numbers were also involved. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 500 individuals. The total will be updated when the data review is concluded.

Horizon Eye Care Laser & Eye Surgery Center

Horizon Eye Care Laser & Eye Surgery Center, an ophthalmology practice and eye surgery center with six locations in New Jersey, is investigating a network server hacking incident. Suspicious network activity was identified on or around June 8, 2026. Immediate action was taken to isolate the affected systems, and third-party cybersecurity experts were engaged to investigate the incident.

The investigation and data review are ongoing; however, it has now been confirmed that patient data was compromised in the incident, including names, demographic information, treatment information, and health insurance information. The breach has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 501 affected individuals, as the number of affected individuals has yet to be determined.

The post Luminis Health Working to Restore Systems After Cyberattack appeared first on The HIPAA Journal.

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.

Large Healthcare data breaches in the past 12 months - June 2026

The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023.

Year to date figures for large healthcare data breaches - June 2026

Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data, on average, 68,181 individuals were affected by each breach. The median data breach size was 6,306 individuals. While June’s victim total is substantial, the victim count is down 36.3% month-over-month, and 58.7% lower than the 12-month average of 10,906,096 individuals per month. It should be noted that the 12-month average is skewed by an unusually high total for October 2025.

Individuals affected by large healthcare data breaches in the past 12 months - June 2026

The year-to-date figures for 2026 show a substantial improvement compared to recent years, and while almost 34 million individuals have had their protected health information exposed, stolen, or impermissibly disclosed so far in 2026, the victim count is down 37.7% from a high of 54.4 million individuals in 2024, and down 22.1% from 2025.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Year to date figures for individuals affected by healthcare data breaches - June 2026

The Biggest Healthcare Data Breaches Reported in June 2026

In June, 25 healthcare data breaches affecting 10,000 or more individuals were reported to the HHS. The two largest data breaches of the month occurred at business associates of HIPAA-covered entities, the largest of which was reported by Xsolis and affected almost 1.4 million individuals. Xsolis is a technology company that provides healthcare organizations with AI-powered solutions for case and utilization management. The incident occurred in January 2026 and started with a phishing email. The phishing attack provided the threat actor with access to systems and data for four days. Files exposed in the incident contained names, dates of birth, Social Security numbers, health insurance information, and medical treatment information.

The second-largest data breach of the month occurred at MCBS (Medical Computer Business Services) and affected more than 1.25 million individuals. MCBS is a healthcare billing, management, and revenue cycle management company. A data theft and extortion group called PEAR breached its network, exfiltrated files, and demanded a ransom to prevent the publication of the data. The threat group had access to the network for four days in September 2025 and stole files containing names, addresses, dates of birth, Social Security numbers, medical histories, health insurance information, and other sensitive data.

A significant breach was reported by the New Jersey-based Centers Lab NJ, a diagnostic testing laboratory for hospitals and other healthcare providers. This was also a data theft and extortion incident, involving the protected health information of more than 542,000 individuals. A threat group called Worldleaks claimed responsibility for the incident and had access to its network for 5 days in August 2025. Data stolen in the incident included names, dates of birth, Social Security numbers, passport numbers, driver’s license number/state ID numbers, medical information, and health insurance information.

HIPAA-Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Xsolis, Inc. TN Business Associate 1,396,519 Network server hacking incident
MCBS, LLC GA Business Associate 1,261,464 Data theft and extortion incident (PEAR)
Centers Lab NJ LLC NJ Healthcare Provider 542,377 Data theft and extortion incident (Worldleaks)
Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Network server hacking incident
Operation PAR, Inc. FL Business Associate 145,714 Data theft and extortion incident (Worldleaks)
Chicago Family Health Center IL Healthcare Provider 90,000 Network server hacking incident
Aitkin County Health and Human Services MN Business Associate 83,114 Phishing incident
Minnesota Epilepsy Group, P.A. MN Healthcare Provider 80,061 Network server hacking incident
Gay & Lesbian Community Services Center of Orange County, Inc. CA Healthcare Provider 75,532 Network server hacking incident
Colorado Health Network Inc. CO Healthcare Provider 68,212 Network server hacking incident – data theft confirmed
Women’s Center for Radiology FL Healthcare Provider 66,422 Network server hacking incident
Blue Fish Pediatrics TX Healthcare Provider 62,150 Network server hacking incident
NYC Health + Hospitals NY Healthcare Provider 58,778 Hacking incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 37,384 Phishing incident at business associate
UnitedHealth Care Services, Inc. Single Affiliated Covered Entity CT Health Plan 34,574 Network server hacking incident
Kentucky Mountain Health Alliance KY Healthcare Provider 30,830 Network server hacking incident – data theft confirmed
Center for Hearing and Speech dba Texas Hearing Institute TX Healthcare Provider 29,774 Ransomware attack (Interlock) – data theft confirmed
Waveny LifeCare Network, Inc. CT Healthcare Provider 27,113 Network server hacking incident
Elara Caring TX Healthcare Provider 22,172 Hacking incident at third party vendor – data theft confirmed
Minidoka Memorial Hospital ID Healthcare Provider 22,000 Data theft and extortion incident (Blackwater)
Meridian Health Plan of Illinois IL Health Plan 21,027 Employee errors – Impermissible granting certain providers access to its network
City of Middletown OH Healthcare Provider 20,608 Ransomware attack – data theft confirmed
McLeod Physician Associates II SC Healthcare Provider 19,553 Malware identified on network server awaiting decommissioning
Optalis Management Solutions MI Healthcare Provider 13,723 Network server hacking incident
All About Women’s Care CO Healthcare Provider 12,000 Hacking incident via an employee VPN account – data theft confirmed

In June, nine healthcare data breaches were reported to HHS with totals of 500 or 501 affected individuals. These totals are often used as placeholder figures when data reviews are ongoing and the 60-day reporting deadline under the HIPAA Breach Notification Rule is reached. HIPAA requires an estimate to be provided if the total number of affected individuals has yet to be determined. The data breaches in the table below may prove to be far larger than the initial breach report indicates. It may be several weeks or even months before the total number of affected individuals is confirmed.

HIPAA Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Gail J May Ltd d/b/a/ Insight Optical IL Healthcare Provider 501 Network server hacking incident at business associate
Community Health Center of Buffalo Inc. NY Healthcare Provider 501 Network server hacking incident
Cherry Street Services, Inc. MI Healthcare Provider 501 Network server hacking incident
Northeast Professional Caregivers OH Healthcare Provider 500 Email compromise
Columbia Orthopaedic Group MO Healthcare Provider 500 Network server hacking incident
Decatur Diagnostic Laboratory Inc. AL Healthcare Provider 500 Network server hacking incident
Ohio Living OH Healthcare Provider 500 Network server hacking incident
Signature Healthcare Corporation MA Healthcare Provider 500 Network server hacking incident
MVP VIP Holdco dba Heart of America Eye Care MO Healthcare Provider 500 Network server hacking incident

Causes of June 2026 Healthcare Data Breaches

Out of the 25 data breaches affecting 10,000 or more individuals, all but one was due to hacking. Across all of June’s reported data breaches, 81.8% of the breaches were hacking/IT incidents, and 1,481,468 individuals were affected by those incidents – 89.7% of all individuals affected by data breaches in June. The average breach size was 81,091 individuals, and the median breach size was 6,504 individuals.

Causes of June 2026 healthcare data breaches

The largest unauthorized access/disclosure incident of the month – Meridian Health Plan of Illinois – affected 21,027 individuals and was due to employees granting healthcare providers access to a portal for managing patient information and processing claims that should not have been given access. There were 11 unauthorized access/disclosure incidents in June, accounting for 16.7% of the month’s data breaches, and 10,914 individuals were affected – 2.7% of the month’s affected individuals. The average breach size was 10,914 individuals, and the median breach size was 6,721 individuals. One improper disposal incident was reported affecting an estimated 1,000 patients. Paper records were disposed of along with regular trash, rather than being sent for shredding. No loss or theft incidents were reported in June.

Location of Breached Protected Health Information

The bar chart below shows the locations of breached protected health information in June 2026 healthcare data breaches. Network servers were the most common location of breached protected health information, followed by email accounts and electronic health records.

Location of breached protected health information - June 2026

Data Breaches at HIPAA Regulated Entities

When a data breach occurs at a HIPAA-covered entity – healthcare provider, health plan, or healthcare clearinghouse – the HIPAA Breach Notification Rule requires them to report the breach within 60 days of discovery. When a data breach occurs at a business associate of a HIPAA-covered entity, the business associate must notify each affected covered entity within the same time frame.

The affected covered entities are ultimately responsible for ensuring that notifications are issued to the HHS, individuals, and in some cases the media, within 60 days of being notified. A HIPAA-covered entity may delegate the notification responsibilities to the business associate. Some choose to issue notifications themselves. The raw breach data on the OCR breach portal shows data breaches based on the reporting entity, not where the data breach occurred. In June, healthcare providers reported 45 breaches, business associates reported 14 breaches, and 7 breaches were reported by health plans. The pie charts below show where the breach actually occurred rather than the reporting entity to better reflect breaches at business associates.

June 2026 data breaches at HIPAA-regulated entities

Individuals affected by June 2026 data breaches at HIPAA-regulated entities

Geographical Distribution of Healthcare Data Breaches

In June, HIPAA-regulated entities based in 24 U.S. states reported large healthcare data breaches. Florida and Texas were the worst affected states with seven reported breaches per state.

State Breaches
Florida & Texas 7
Illinois 5
Colorado, Michigan & New York 4
California, Connecticut, Minnesota, Missouri, Ohio & Tennessee 3
Idaho, Kentucky, Massachusetts, South Carolina & Washington 2
Alabama, Georgia, Indiana, Kansas, New Jersey, Oklahoma & Pennsylvania 1

While Florida and Texas ranked top for breaches, they ranked 4th and 6th in terms of the number of affected individuals. Tennessee, Georgia, and New Jersey topped the list for affected individuals, with each state only registering one large data breach.

State Individuals Affected State Individuals Affected
Tennessee 1,567,038 Michigan 24,396
Georgia 1,261,464 Idaho 22,750
New Jersey 542,377 Ohio 21,608
Florida 233,367 South Carolina 20,690
Minnesota 164,893 Washington 9,825
Texas 124,459 Missouri 3,311
Illinois 120,089 Indiana 3,070
Connecticut 99,071 Pennsylvania 2,720
Colorado 87,814 Oklahoma 1,607
California 80,783 Massachusetts 1,506
New York 74,733 Kansas 534
Kentucky 31,367 Alabama 500

HIPAA Enforcement Activity in June 2026

In June, OCR announced a single enforcement action to resolve potential violations of the HIPAA Rules by the American mall-based retailer, Spencer Gifts. Retailers are not typically HIPAA-covered entities, but Spencer Gifts is a health plan under HIPAA as it sponsors employee benefits and welfare benefit plans. Spencer Gifts was investigated after OCR received a report about a breach of the protected health information of 10,023 members of its flexible benefits and welfare benefit plans. The OCR investigation determined that Spencer Gifts failed to conduct a HIPAA-compliant risk analysis and failed to implement HIPAA Privacy, Security, and Breach Notification Rule policies and procedures. The alleged HIPAA violations were resolved with a settlement that includes a $450,000 financial penalty and a corrective action plan.

In the year to June 30, 2026, OCR resolved seven HIPAA investigations with financial penalties with penalties totaling $1,728,000. All seven of the investigations found risk analysis failures, and two involved breach notification failures. State attorneys general may also investigate data breaches and impose financial penalties for HIPAA violations, although no cases were announced in June 2026.

About this Report

The HIPAA Journal monthly data breach reports are based on data obtained from the HHS Office for Civil Rights and have been combined with breach report data from other sources. The data breaches included in this report were reported in June 2026 but occurred weeks or months previously. The figures in this report may increase or decrease as HIPAA-regulated entities complete their breach investigations, and will be reflected in our healthcare data breach statistics page and our annual HIPAA data breach reports. Further information about HIPAA enforcement actions can be found in our HIPAA violations cases page.

The post June 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident

Data breaches have been announced by Resource Center of Dallas, Kern Psychiatric Health and Wellness Center, The Asthma Center, Integrative Emergency Services, and Psychiatry of Texas (PsychPlus).

Resource Center of Dallas

Resource Center of Dallas, Inc., a provider of health, wellness, and advocacy services to the LGBTQIA+ community in North Texas, is notifying 12,490 individuals about a data security incident earlier this year. Third-party cybersecurity professionals were engaged to investigate suspicious network activity and determined that certain systems within its computer network were accessed by an unauthorized third party between February 4, 2026, and February 12, 2026. The threat actor accessed or removed files that contained personal and/or protected health information.

The data review was completed on or around July 2, 2026, when it was confirmed that the impacted data included names, dates of birth, medical information, health insurance information, financial account information, and other identification information. For certain individuals, the exposed data included Social Security numbers. The Resource Center of Dallas said it takes the security of personal and health information very seriously and had taken many precautions to safeguard it and continually evaluates and modifies its practices to enhance privacy and security. Since the incident, privacy and security protocols and practices have been reviewed and additional safeguards implemented to reduce the risk of similar incidents in the future.

Kern Psychiatric Health and Wellness Center (Genesis Healthcare Management)

Kern Psychiatric Health and Wellness Center, a Bakersfield, California-based psychiatric and behavioral care provider, has recently notified the California Attorney General about a data breach involving its management company, Genesis Healthcare Management. Genesis Healthcare Management identified suspicious activity within its computer network on June 22, 2026. Third-party cybersecurity specialists were engaged to assist with the investigation and confirmed that its network had been accessed by an unauthorized third party.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The compromised parts of the network contained the personal and protected health information of Kern Psychiatric Health and Wellness Center patients, including names, dates of birth, Social Security numbers, medical record numbers, driver’s license numbers, government-issued ID numbers, Medicare/Medicaid numbers, diagnoses, treatment information, lab results, patient account numbers, provider names and locations, and health insurance information.

Notification letters are being mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been offered for 12 months. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Allergic Disease Associates (The Asthma Center)

Philadelphia-based Allergic Disease Associates, P.C., doing business as The Asthma Center, has started notifying certain patients about a data security incident identified in November 2025. An investigation was launched to determine the cause of anomalous network activity, which determined that its network had been accessed by an unauthorized third party between October 28, 2025, and November 17, 2025. During that time, files containing patient information may have been copied from its network.

A comprehensive review was initiated to determine the patients affected and data types involved, and that process was recently completed. The Asthma Center has confirmed that data compromised in the incident included names, dates of birth, health insurance member numbers, provider names, limited clinical information, diagnosis information, prescription information, and treatment information. The Asthma Center is reviewing its policies, procedures, and practices related to data privacy and security to prevent similar incidents in the future. The number of affected individuals has yet to be publicly disclosed.

Integrative Emergency Services

Integrative Emergency Services, LLC, a Dallas, Texas-based physician-led acute care and emergency medicine group, has notified 2,009 patients about a June 2026 security incident. Suspicious activity was identified within an employee’s email account on June 16, 2026, and the account was rapidly secured. The investigation revealed that the account had been accessed by an unauthorized third party for a period of four hours.

The account was reviewed, and on July 9, 2026, Integrative Emergency Services identified an email in the account that contained patient information, which may have been viewed by an unauthorized third party. The email contained patient names, medical record identifiers, and certain health information. No Social Security numbers, financial information, or patient addresses were involved. Integrative Emergency Services has increased its employee training to help employees recognize and avoid phishing attempts.

Psychiatry of Texas (PsychPlus)

Psychiatry of Texas, aka PsychPlus, a psychiatric medical practice based in Houston, Texas, has identified a breach of the protected health information of 4,565 patients. The incident was first identified on March 31, 2026. The network anomaly was investigated, with assistance provided by third-party cybersecurity experts. The investigation determined that its network was accessed by an unauthorized third party on March 31, 2026, and that files containing patient data may have been acquired on that date.

The exposed files were reviewed and found to contain names, dates of birth, Social Security numbers, diagnoses, treatment information, health insurance information, electronic identification/account numbers, usernames, email addresses, passwords, and parents’ premarital surnames. While no misuse of the exposed data has been identified, patients have been advised to remain vigilant against identity theft and fraud. As a precaution, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services.

The post Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident appeared first on The HIPAA Journal.

Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack

Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US).

Midwest Spine and Brain Institute (3C Care Systems)

Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems. According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation.

The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C Care Systems. The investigation concluded on June 18, 2026, revealing that personally identifiable information and protected health information was potentially involved, including first and last names in combination with one or more of the following: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service, and health insurance claim and/or policy information.

MSBI is mailing notification letters to the affected individuals and has offered complimentary identity monitoring and protection services to individuals whose Social Security numbers were involved. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many MSBI patients have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

No information was provided as to the nature of the data breach, but this appears to have been a ransomware attack by the now-disbanded RansomHub ransomware operation on or around November 21, 2024. RansomHub claimed it had exfiltrated 100 GB of data from 3C Care Systems, although no separate breach announcement appears to have been made by the IT company, and those claims remain unverified. It is unclear if clients other than MSBI had data compromised in the incident.

Brookhaven ENT Allergy and Facial Surgery

Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, has notified 30,403 individuals that some of their personal and protected health information was compromised in a recent cybersecurity incident. The incident involved a third-party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. The CareCloud breach listing on the OCR data breach portal indicates that 3.75 million individuals were affected.

The incident occurred between March 10, 2026, and March 16, 2026, and the file review determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information had potentially been compromised. You can read more about the CareCloud data breach in this post. At the time of issuing notifications, no actual or attempted misuse of the impacted data had been identified.

Silver Summit Medical Corporation (Digestive Disease Center and Heart Vascular & Leg Center), California

Silver Summit Medical Corporation, doing business as the Digestive Disease Center and Heart Vascular & Leg Center, has notified certain patients about a cybersecurity incident at a third-party vendor that exposed some of their protected health information. The Bakersfield, California-based ambulatory surgical center learned about the incident on or around July 20, 2026. The investigation determined that an unauthorized third party accessed the unnamed vendor’s systems from November 27, 2025, to November 30, 2025, and exfiltrated files containing personal and protected health information.

The data review determined that the exfiltrated files contained names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, taxpayer identification numbers, passport numbers, and/or other government identifiers. Protected health information included diagnoses, treatment information, prescription information, and health insurance information. The affected individuals were notified on August 19, 2026, and complimentary credit monitoring and identity theft protection services have been made available. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so the number of affected individuals is not yet known.

Premier Medical Group of the Hudson Valley, New York

Premier Medical Group of the Hudson Valley, a Poughkeepsie, New York-based multispecialty practice, has started notifying patients impacted by a cybersecurity incident this summer. The incident disrupted certain IT systems, and the forensic investigation determined that there was unauthorized access to files containing patient information on June 14, 2026. The substitute data breach notice on the practice’s website does not state when the incident was detected.

The review of the affected data determined on July 14, 2026, that the exposed files included patient names, contact information, dates of birth, health insurance information, provider names, patient identification numbers, dates of service, medications, and diagnostic and treatment information. Premier Medical Group said it will continue to evaluate and implement enhanced safeguards and security measures to protect its systems from unauthorized access and continue to provide security training to its workforce. The number of affected individuals has yet to be publicly disclosed.

Risk Program Administrators

Risk Program Administrators LLC (RPA), a California-based insurance program administration and management firm, has notified 8,309 individuals about the exposure of some of their personal and protected health information earlier this year. On or around June 16, 2026, RPA identified suspicious activity within an employee’s email account. The account was secured, and an investigation was launched, which confirmed that the account, and certain emails within that account, had been accessed by an unauthorized third party between May 27, 2025, and June 16, 2025.

The account was reviewed and found to contain information such as names, dates of birth, Social Security numbers, financial account information, health insurance information, and medical information, including treatment types, locations, costs, physician information, mental or physical condition, subscriber member numbers, and admission dates.

TELUS Health (US)

TELUS Health (US) LTD., a Canton, Massachusetts-based digital health and wellness provider part of the Canadian telecommunications company TELUS, has disclosed a data breach that involved unauthorized access to systems containing protected health information. Telus Health’s announcement on its website states that the investigation is ongoing, and it has yet to publicly disclose the types of information compromised in the incident. It is unclear exactly when the attack occurred; however, it appears to have occurred in January 2026. The ShinyHunters threat group claimed responsibility for the attack and the exfiltration of 1 petabyte (1,000 TB) of data.

The threat group communicated with Bleeping Computer, which reported in March 2026 that systems were breached using compromised Google Cloud credentials obtained in the Salesloft Drift breach. While the breach had the potential to be massive, it was recently reported to the HHS’ Office for Civil Rights as involving the protected health information of just 2,641 individuals. TELUS Health said it has implemented additional security safeguards to better safeguard the data within its environment.

The post Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack appeared first on The HIPAA Journal.

Five Healthcare Providers Report Ransomware-Related Data Breaches

Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.

Alta Orthopaedics Medical Group, California

Alta Orthopaedics, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, has recently confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen in a cybersecurity incident earlier this year. Unusual network activity was identified on March 10, 2026, and the investigation determined that an unauthorized third party had accessed information on its network between February 3, 2026, and February 6, 2026.

The review of the affected data was completed on June 24, 2026. Personally identifiable information potentially compromised in the incident included names, contact information, Social Security numbers, driver’s licence numbers/state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth, and login information. Protected health information compromised in the incident included diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information, and biometric data.

Notification letters have been mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been made available for 24 months. While not mentioned in the notification letters, this appears to have been a ransomware attack. The INC Ransom ransomware group claimed responsibility for the attack and said 26 GB of data was exfiltrated. The data was subsequently leaked.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Cornerstone Behavioral Healthcare, Maine

Cornerstone Behavioral Healthcare, a Worcester, Maine-based mental health and substance use disorder treatment provider, has notified patients that some of their protected health information may have been compromised in a May 2026 ransomware attack. Cornerstone identified the attack on May 26, 2026, the same day that the attackers gained access to its network. The attacker’s access to its network was blocked within an hour of discovery, and computers on the affected parts of the network were powered down rapidly, limiting the extent of file encryption. Cornerstone said it believes that less than 10% of the data on the affected computers and servers was encrypted.

The initial findings of the investigation indicated that the protected health information of approximately 2,830 patients was compromised as a result of the attack, including names, addresses, other contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare information, and Social Security numbers. Further investigation determined on July 22, 2026, that a log of appointment reminders was also compromised, which included the protected health information of approximately 12,000 patients. The log data included names, birth dates, appointment times, and reminders of documentation due.

The investigation has now been completed, and the HHS’ Office for Civil Rights has been informed that, in total, the protected health information of 14,830 patients was potentially compromised in the incident. Cornerstone explained in its refreshingly detailed breach notification letter that it received a ransom demand but did not pay. All affected computers were wiped, new computers were purchased, and all systems, policies, and procedures have been reviewed. Additional security measures have been implemented on its servers, and special training has been provided to the workforce on ransomware.

Cameron Regional Medical Center, Missouri

Cameron Regional Medical Center, a 60-bed acute care hospital in Cameron, Missouri, announced in August 2026 that it recently discovered that it was the victim of a sophisticated ransomware attack. The attack was detected on June 18, 2026, when files on its network were encrypted. In an announcement on August 18, 2026, the hospital explained that the investigation into the attack is ongoing; however, the initial findings indicate that patients’ protected health information was subject to unauthorized access and may have been exfiltrated from its network.

While the specific types of data involved for each patient have yet to be determined, Cameron Regional Medical Center said the information likely compromised includes names plus some or all of the following:  home addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient ID numbers, agency-assigned identification numbers, treatment cost information, health insurance information, electronic/digital signatures, and/or employer-assigned identification numbers.

Third-party cybersecurity experts have been engaged to investigate the attack and assist with evaluating and reinforcing its security measures to ensure optimal data security. At the time of issuing the notification, no actual or attempted misuse of patient data had been identified. Individual notification letters will be mailed to the affected individuals when the data review is concluded. While the name of the ransomware group was not disclosed, the Anubis ransomware group claimed responsibility and leaked some of the stolen data as proof of the attack, including patient information. The group claimed to have exfiltrated around 500 GB of data.

Suntree Internal Medicine, Florida

Suntree Internal Medicine, an internal medicine practice in Melbourne, Florida, has notified 9,810 individuals about a cybersecurity incident first identified on September 28, 2025. Unusual activity was identified in certain systems, and immediate action was taken to contain the incident. An investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts.

The investigation confirmed unauthorized network access and the exposure of files containing patient information. Those files may have been copied from its network, although at the time of issuing the breach notice, no misuse of patient information had been identified. The data review confirmed that the following information was exposed: names, addresses, treatment information, and health insurance information. Suntree Internal Medicine has implemented additional security measures to reduce the risk of similar incidents in the future. While the incident was not described as a ransomware attack, a ransomware group called INC Ransom claimed responsibility for the attack on its dark web data leak site. The listing states that data was exfiltrated.

Associated Endocrinologists, Michigan

Associated Endocrinologists, a consultative endocrinology practice with locations in Farmington Hills and Clarkston, Michigan, has started notifying 4,979 patients about a cybersecurity incident earlier this year. There is currently no substitute breach notice on the practice website, and the HIPAA Journal has been unable to find a press release about the incident, which was reported to the HHS’ Office for Civil Rights on July 29, 2026. It is currently unclear exactly what types of information were exposed or stolen in the incident. The RansomHouse ransomware group claimed responsibility for the attack on its data leak site in early February and claimed to have exfiltrated data and encrypted files on January 31, 2025

The post Five Healthcare Providers Report Ransomware-Related Data Breaches appeared first on The HIPAA Journal.