HIPAA Breach News

WindRose Health Network Discloses Data Breach Affecting 33K Individuals

Data breaches have been announced by WindRose Health Network and Advantage Home Health Care in Indiana, Camden-on-Gauley Medical Center in West Virginia, and Lakes Region Visiting Nursing Association in New Hampshire.

WindRose Health Network, Indiana

WindRose Health Network, a network of Federally Qualified Health Centers that provide primary care and behavioral health services at several locations in central Indiana, has started notifying 33,158 individuals about a cybersecurity incident that exposed limited patient data. An unauthorized third party gained access to a limited part of its network by exploiting a previously undisclosed vulnerability in a remote access tool used by one of its vendors. The vendor informed WindRose Health Network about the vulnerability on August 4, 2026. Immediate action was taken to secure its environment, and cybersecurity experts were engaged to investigate.

The investigation determined that the vulnerability had been exploited, resulting in unauthorized network access between August 3 and August 4, 2026. The remote access tool could not be used to access patients’ medical records; however, patient data was stored in files on the affected parts of its network. The data review determined that patient names, patient ID numbers, health insurance information, dates of service, and provider names were potentially accessed or copied. The affected patients have been advised to remain vigilant against identity theft and fraud.

Advantage Home Care, Missouri

Advantage Home Health Care (AHHC), one of the largest home healthcare providers in the state of Indiana, has notified 19,851 individuals about a recent cybersecurity incident. The home health care agency learned on June 16, 2026, that an unauthorized third party had gained access to one of its computer servers. The forensic investigation determined that its systems were first accessed on June 9, 2026. On June 26, 2026, AHCC learned that the files containing patient data had been acquired in the incident, including patients’ first and last names, birth dates, addresses, phone numbers, Social Security numbers, and medical information related to the care received.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Employee data was also compromised related to the AHHC employee health plan, including health insurance and plan enrolment information, claims information, healthcare provider information, and health benefits information. Adults and minors affected by the incident have been offered 12 months of complimentary single-bureau credit monitoring, credit report, and credit score services. While not specifically mentioned in the notification letter, the group behind the attack appears to be The Gentlemen, a prolific ransomware group that has claimed many healthcare victims.

Camden-on-Gauley Medical Center, West Virginia

Camden Family Health, a network of community health centers serving the Mountain Lake Region in West Virginia, has identified unauthorized access to parts of its computer network. Suspicious activity was identified on July 18, 2026; steps were immediately taken to secure its systems, and an investigation was launched to determine the cause of the activity.

The investigation confirmed that an unauthorized third party accessed its network on July 18, 2026, and potentially viewed or obtained files containing the information of patients of Camden-on-Gauley Medical Center. The review of the affected files confirmed that patients’ medical information and health insurance information were potentially accessed or acquired. The number of affected individuals has not yet been publicly disclosed. The incident has been reported to the HHS’ Office for Civil Rights using an estimate of at least 501 individuals.

Lakes Region Visiting Nursing Association, New Hampshire

Lakes Region Visiting Nursing Association, a non-profit Medicare-certified home health and hospice agency based in Meredith, New Hampshire, has notified 1,274 individuals about a recent security incident. Suspicious activity was identified within its email environment on June 2, 2026. Its incident response protocols were immediately implemented, and third-party cybersecurity specialists were engaged to investigate the activity. They confirmed that an unauthorized third party had gained access to a single employee email account.

The account was reviewed, and on August 13, 2026, it was confirmed that patient data had been exposed. The exact types of data are not detailed in the substitute breach notification letter on its website. The affected individuals have been offered complimentary credit monitoring and identity theft protection services, and steps have been taken to improve security. In addition to a password reset, multifactor authentication has been implemented throughout its email tenant.

The post WindRose Health Network Discloses Data Breach Affecting 33K Individuals appeared first on The HIPAA Journal.

Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents

AngMar Management Services, a Mansfield, Texas-based home health and hospice management company, has identified unauthorized access to its information technology systems. The incident was identified on July 20, 2026, and the forensic investigation determined that an unauthorized individual potentially accessed and/or acquired files containing patient information on or around July 18, 2026.

The review of the affected data was completed on September 8, 2026, when it was confirmed that the data compromised in the incident included names, addresses, dates of birth, Social Security numbers, patient IDs, medical record numbers, health insurance information, dates of service, diagnosis/condition information, provider names, prescription information, and/or medical history information. AngMar Management Services said it has implemented additional security measures to reduce the risk of similar incidents in the future. The affected individuals have been offered complimentary credit monitoring services.

The incident appears to have been a ransomware attack by the Interlock ransomware group, which added AngMar Management Services to its dark web data leak site in August 2026. The group claims to have exfiltrated 710 GB of data in the incident. The total number of affected individuals has yet to be publicly disclosed; however, the Texas Attorney General was informed that the personal and protected health information of 35,916 Texas residents was potentially compromised in the incident.

Eskenazi Health

Eskenazi Health, an Indianapolis, Indiana-based safety net health system, has announced a cybersecurity incident involving unauthorized access to certain patient data. A threat actor had gained access to the email account of a trusted business contact and used that account to send thousands of emails to contacts in the address book, including to an Eskenazi Health employee. The email appeared to have been sent by a trusted contact and contained a document notification. The employee clicked the link in the email and entered their contact details as part of the authentication process. The threat actor captured the credentials and used them to access the employee’s cloud-based work account.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The employee responded to the email on June 3, 2026, and the compromised account was identified by Eskenazi Health on July 27, 2026. During that time, emails and attachments in the account may have been accessed or acquired. The review of the account determined that it contained patients’ demographic and contact information, health insurance and billing information, internal identifiers such as medical record numbers, medical and treatment information, Social Security numbers, and sensitive health information such as substance use disorder diagnosis and treatment information.

The account has been secured, additional protective measures have been implemented, and employee education about cyber threats is being enhanced to prevent similar incidents in the future. The affected individuals have been notified and offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

Suffolk County House of Correction | Nashua Street Jail

Inmates at Suffolk County House of Correction and Nashua Street Jail in Boston, Massachusetts, have been affected by a cybersecurity incident at Computer Systems Integrated Inc. Computer Systems Integrated is a technology company affiliated with Correctional Psychiatric Services, a healthcare provider serving inmates at several correctional facilities in the state. Computer Systems Integrated runs the electronic health record system used by the correctional facilities.

The cybersecurity incident is under investigation, and it is currently unclear how many inmates have been affected or what types of information were involved. The incident appears to be limited to Suffolk County House of Correction and Nashua Street Jail.

The post Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents appeared first on The HIPAA Journal.

Data Breaches Announced by Saber Healthcare & Buchalter

Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to Arrowhead Regional Medical Center.  Bright Smile Dental Care in Indiana has fallen victim to a ransomware attack, although unauthorized access to patient data is considered unlikely.

Saber Healthcare

Saber Healthcare, a Beachwood, Ohio-based skilled nursing, long-term, and senior rehabilitation care provider, has started notifying individuals about unauthorized access to one of its computer servers. The incident was identified on July 27, 2026, and immediate action was taken to secure its systems and prevent further unauthorized access. Third-party cybersecurity experts were engaged to assist with the investigation, which indicated that data stored on the server may have been accessed or acquired.

On August 19, 2026, the review of the server was completed, and up-to-date address information was obtained to allow notification letters to be mailed. Data compromised in the incident varies from individual to individual and may include names in combination with one or more of the following: date of birth, driver’s license/state issued identification number, health insurance information, medical information, financial account information, passport number, and/or Social Security number.

Additional network security measures have been implemented, and data security policies and procedures are being reviewed. No evidence has been found to indicate any misuse of the exposed data; however, the affected individuals have been advised to remain vigilant against identity theft and fraud. The number of affected individuals has yet to be publicly disclosed, although based on disclosures to state attorneys general, the incident has affected more than 3,000 individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Buchalter, LLP (Arrowhead Regional Medical Center)

Patients of Arrowhead Regional Medical Center (ARMC) in Colton, California, have been affected by a cybersecurity incident at the law firm Buchalter, LLP. Buchalter provides legal services to the hospital and was provided with limited patient data in connection with those services. On August 28, 2026, Buchalter discovered that limited data was accessed by an unauthorized third party. An internal investigation was launched, with assistance provided by third-party cybersecurity experts to determine the nature and scope of the unauthorized activity.

On September 4, 2026, it was confirmed that certain ARMC patients had data compromised in the incident, and on September 21, 2026, contact information was obtained to allow notification letters to be mailed. At the time of issuing the notification letters, no misuse of the affected data had been identified.  The data types involved are detailed in the individual notification letters. Buchalter said it has taken steps to improve data security to prevent similar incidents in the future. The number of affected individuals has not yet been publicly disclosed.

Bright Smile Dental Care

Bright Smile Dental Care, a Fishers, Indiana-based dental practice, has experienced a ransomware attack involving a server containing its practice management, dental imaging, and electronic health record software. The incident was identified on August 3, 2026, and third-party cybersecurity experts were engaged to investigate the incident and mitigate its impact.

Bright Smile Dental Care said patient data on the server was protected with encryption, and the keys to decrypt the data are not believed to have been obtained by the ransomware group. While there is a low likelihood of unauthorized data access, patients have been warned that the server contained their names, dates of birth, addresses, email addresses, phone numbers, insurance information, information about dependents, health information, and in some cases, Social Security numbers.

Notification letters have been mailed to the affected individuals, and complimentary credit monitoring services have been offered to individuals whose Social Security numbers were present on the server. The number of affected individuals has yet to be publicly disclosed.

The post Data Breaches Announced by Saber Healthcare & Buchalter appeared first on The HIPAA Journal.

H1 2026 Healthcare Data Breach Report

There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023. While the year-over-year reduction in healthcare data breaches is a step in the right direction, healthcare data breaches continue to be reported in high numbers. In the first six months of the year, large healthcare data breaches were reported at a rate of more than 2.2 per day.

H1, 2026 Healthcare data breaches

Across the 397 reported data breaches, the protected health information of 33.77 million individuals was exposed or impermissibly disclosed. That represents a 22.6% reduction in affected individuals compared to H1 2025, and it is the lowest number of affected individuals in H1 since 2023.

H1 2026 healthcare data breaches: individuals affected

If data breaches continue to be reported at a similar rate in the second half of the year, the end-of-year healthcare data breach total is likely to be lower than 2025, which was a record-breaking year with 804 data breaches currently listed on the OCR breach portal for 2025. The current total also suggests that this year could see a major reduction in affected individuals, as more than 140 million individuals were affected in 2025. That said, several very large data breaches have yet to be added to the OCR breach portal for this year.

The Biggest Healthcare Data Breaches in H1 2026

In the first half of the year, nine healthcare data breaches were reported that affected more than 1 million individuals, the largest breach of which affected more than 5.8 million individuals. All but two of the top twenty data breaches were due to hacking incidents or ransomware attacks. The two non-hacking breaches were unauthorized access/disclosure incidents, and both occurred at state departments of human services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Rank Regulated Entity State Covered Entity Type Individuals Affected Type of Breach
1 Lumexa Imaging NC Healthcare Provider 5,830,949 Hacking Incident
2 TriZetto Provider Solutions MO Business Associate 3,433,965 Hacking Incident
3 QualDerm Partners, LLC TN Healthcare Provider 2,951,318 Hacking Incident
4 Nacogdoches Memorial Hospital TX Healthcare Provider 2,507,073 Hacking Incident
5 Navia Benefit Solutions, Inc. WA Business Associate 2,151,330 Hacking Incident
6 Insightin Health, Inc. MD Business Associate 1,949,534 Hacking Incident
7 New York City Health and Hospitals Corporation NY Healthcare Provider 1,800,000 Hacking Incident
8 Xsolis, Inc. TN Business Associate 1,396,519 Hacking Incident
9 MCBS, LLC GA Business Associate 1,261,464 Hacking Incident
10 OpenLoop Health, Inc. IA Business Associate 716,000 Hacking Incident
11 Illinois Department of Human Services IL Health Plan 705,017 Unauthorized Disclosure Incident
12 ApolloMD Business Services, LLC GA Business Associate 626,540 Hacking Incident (Ransomware)
13 Erie Family Health Centers IL Healthcare Provider 570,000 Hacking Incident
14 Centers Lab NJ LLC NJ Healthcare Provider 542,377 Hacking Incident
15 Networking Technology, Inc. (RXNT) NC Business Associate 353,844 Hacking Incident
16 Minnesota Department of Human Services MN Health Plan 303,965 Unauthorized Access Incident
17 North Texas Behavioral Health Authority TX Healthcare Provider 285,086 Hacking Incident
18 Florida Physician Specialists FL Healthcare Provider 276,498 Hacking Incident
19 Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking Incident
20 Anatomic and Clinical Laboratory Associates, P.C. TN Healthcare Provider 169,626 Hacking Incident

The majority of the data breaches reported in H1 2026 were relatively small, affecting fewer than 10,000 individuals. Currently, 37 healthcare data breaches are listed as affecting 500 or 501 individuals. These are commonly used placeholder figures when data reviews are incomplete by the breach reporting deadline. The majority of those 37 data breaches are likely to see the totals increased, potentially significantly. The Change Healthcare data breach in 2024 was initially reported to OCR as affecting at least 500 individuals but was subsequently increased to 192.7 million individuals!

Scale of Breach – Affected Individuals Data Breaches
Over 1,000,000 9
100,000 – 999,999 21
10,000 – 99,999 102
1000 – 9,999 175
Under 1000 90

Causes of H1 2026 Healthcare Data Breaches

While the number of large healthcare data breaches has fallen year-over-year, the lower H1 figures this year are due to fewer unauthorized access/disclosure and loss/theft incidents, rather than hacking/IT incidents, which increased for the third consecutive year.

H1 Healthcare data breach causes 2022-2026

H1 2026 Hacking/IT Incidents

Hacking/IT incidents remain the leading cause of healthcare data breaches and increased again in 2026. Ransomware groups continue to attack the healthcare sector, and there has been an increasing trend of data theft and extortion incidents, where data is stolen and threats are issued to publish the stolen data, but files are not encrypted.

As also observed by the Identity Theft Resource Center, there has been a growing trend of breached entities failing to disclose the nature of data breaches, including the cause, whether ransomware was involved, and, concerningly, if data was stolen in the incident. The lack of a breach cause makes it difficult to assess trends, while the failure to disclose whether data has been stolen makes it difficult for individuals to gauge the level of risk they face.

In H1, 343 hacking/IT incidents were reported, affecting an average of 94,167 individuals (median breach size: 4,800 individuals). Hacking/IT incidents have increased by 2.1% year-over-year increase in hacking/IT incidents, although the number of affected individuals has reduced by 14.7% year-over-year.

H1 2026 individuals affected by healthcare hacking/IT incidents

H1 2026 Unauthorized Access/Disclosure Incidents

Unauthorized access and disclosure incidents were the second leading cause of healthcare data breaches in H1 2026. These incidents include any unauthorized access to and disclosure of patient records that are not hacking- or IT-related. They include snooping incidents by insiders, misdirected emails and mailings, and unauthorized data sharing between HIPAA-regulated entities and third parties.

These incidents tend to affect far fewer individuals than hacking and IT incidents, although not always. Incidents involving website tracking tools such as pixels, for example, can affect millions of individuals. The two largest unauthorized access/disclosure incidents made it into the top 20 largest breaches of the first half of the year and occurred at the Illinois Department of Human Services and Minnesota Department of Human Services. The former involved data uploaded to a website for internal use that was accessible via the public internet, and the latter involved a user associated with an authorized healthcare provider accessing data without authorization.

In H1, 51 unauthorized access/disclosure incidents were reported, affecting an average of 28,710 individuals (median breach size: 2,315 individuals).  That represents a 3.8% year-over-year decline in unauthorized access/disclosure incidents, and a 74.2% decline in affected individuals.

H1 2026 individuals affected by healthcare unauthorized access/disclosure

H1 2026 Loss/Theft Incidents

Loss and theft of electronic devices containing protected health information and paper records used to be a leading cause of data breaches; however, the adoption of digital records, data encryption, and cloud storage of protected health information has helped reduce these incidents. In H1 2026, only two such incidents were reported – one loss and one theft incident, both involving a relatively small number of paper records. That equates to a 75% year-over-year reduction in data breaches, and a 96.7% reduction in affected individuals.

H1 2026 individuals affected by healthcare unauthorized loss/theft incidents

H1, 2026 Improper Disposal Incidents

Improper disposal incidents are rarely reported, and when they are, they almost always involve paper records inadvertently disposed of with regular trash. Only one such incident was reported by a HIPAA-regulated entity in H1 2026 – a relatively small data breach affecting an estimated 1,000 individuals. A single improper disposal incident was also reported in H1 2025, althopugh the number of affected individuals has fallen by 97% year-over-year.

H1 2026 individuals affected by healthcare unauthorized improper disposal incidents

Data Breaches at HIPAA Regulated Entities

Healthcare providers were the worst affected HIPAA-regulated entities in H1 2026 (290 data breaches), followed by business associates (59 data breaches), and health plans (48 data breaches). Healthcare clearinghouses survived the first 6 months of the year without any data breaches. The same order applies in terms of individuals affected by those breaches, with healthcare providers topping the list (19,701,297 individuals), followed by business associates (12,505,090 individuals), and health plans (1,559,474 individuals).

Those figures do not tell the full story, as when a data breach occurs at a business associate, it is not always the business associate that reports the data breach. When a data breach occurs at a business associate, the business associate must notify each affected covered entity, and the covered entity may delegate the reporting and notification requirements to the business associate or may choose to report the data breach and/or send notification letters themselves. If a breach occurs at a business associate, some affected covered entities may delegate the reporting and notification responsibilities to the business associates while others may not. As such, business associate data breaches are often underrepresented in the raw breach data.

The charts below are based on where the data breach occurred, rather than the reporting entity. While the same order applies to both data breaches and affected individuals, almost 100 more breaches occurred at business associates than the raw data suggests.

H1 2026 healthcare data breaches at HIPAA-regulated entities

H1 2026 healthcare data breaches at HIPAA-regulated entities - individuals affected

Based on the adjusted data, the average size of a data breach at a healthcare provider (87,629 individuals) and a business associate (87,643 individuals) was virtually identical, although the median size of a data breach at a healthcare provider (6,323 individuals) is twice that of a business associate (3,086 individuals). In H1 2026, health plan breaches were less severe. The average breach size was less than half the size at other entities at 41,042 individuals, and the median breach size was 2,871 individuals.

Location of Breached Protected Health Information

Given the high number of hacking incidents, it is unsurprising that the most common location of breached protected health information is network servers, as has been the case for several years. Email remains a common location of breached healthcare data due to a relatively high prevalence of phishing and social engineering incidents. While not infallible, multifactor authentication would have prevented many of these data breaches.

A small but significant number of healthcare data breaches involved paper records, although the number of incidents involving physical records is falling. Breaches of protected health information in “other” locations – including the cloud – are on the rise.  Widespread adoption of encryption and use of the cloud have helped to drastically reduce the number of loss and theft incidents.

H1 2026 healthcare data breaches: location of breached protected health information

Geographic Distribution of Healthcare Data Breaches

In H1 2026, large healthcare data breaches were reported by HIPAA-regulated entities in 44 U.S. states, the District of Columbia, and Puerto Rico. The only states to escape the first half of the year unscathed were Hawaii, Montana, New Mexico, North Dakota, South Dakota, and Wyoming.

As a general rule, the states with the biggest populations experience the most data breaches, and vice versa for the states with the fewest number of breaches. California, Texas, Florida, and New York are the most heavily populated states in that order, and the same order applies in H1 2026 in terms of data breaches.

Rank State Data Breaches State Individuals Affected
1 California 38 North Carolina 6,358,110
2 Texas 36 Tennessee 4,635,531
3 Florida 24 Missouri 3,468,743
4 New York 20 Texas 3,188,111
5 Illinois 16 Washington 2,270,117
6 Michigan 15 New York 2,113,172
7 North Carolina 14 Georgia 2,005,142
8 Pennsylvania 13 Maryland 1,968,198
9 Washington 13 Illinois 1,756,341
10 Massachusetts 12 Florida 846,997
11 Colorado 11 Iowa 767,730
12 Tennessee 11 New Jersey 702,065
13 Virginia 11 Minnesota 486,202
14 Minnesota 10 Virginia 458,060
15 Ohio 10 California 430,336
16 Georgia 9 Colorado 324,483
17 Indiana 9 South Carolina 318,963
18 Kentucky 9 Pennsylvania 213,188
19 Maryland 9 Michigan 207,522
20 New Jersey 9 Ohio 139,151
21 Oklahoma 9 Connecticut 133,735
22 South Carolina 8 Puerto Rico 116,236
23 Alabama 7 Alabama 103,406
24 Connecticut 7 Kentucky 89,363
25 Missouri 7 Utah 82,335
26 Iowa 6 Arizona 76,546
27 Oregon 6 Idaho 66,625
28 Utah 6 Massachusetts 66,382
29 Idaho 5 Mississippi 60,133
30 Kansas 5 Indiana 49,271
31 Maine 5 Maine 45,932
32 Louisiana 4 Kansas 40,760
33 Arizona 3 Louisiana 37,963
34 District of Columbia 3 Nevada 37,796
35 Arkansas 2 Nebraska 26,937
36 Mississippi 2 District of Columbia 21,481
37 Puerto Rico 2 Oklahoma 18,392
38 West Virginia 2 Oregon 10,278
39 Wisconsin 2 Vermont 5,892
40 Alaska 1 Arkansas 5,800
41 Delaware 1 Rhode Island 5,630
42 Nebraska 1 Wisconsin 2,654
43 Nevada 1 West Virginia 1,500
44 New Hampshire 1 New Hampshire 1,221
45 Rhode Island 1 Delaware 908
46 Vermont 1 Alaska 523

HIPAA Enforcement Activity in H1 2026

OCR has increased the number of penalties imposed for HIPAA violations in recent years, although financial penalties are still relatively rare. OCR investigates all data breaches affecting 500 or more individuals, and when potential HIPAA violations are identified, they are typically resolved through voluntary compliance or by providing technical assistance.

Financial penalties are typically reserved for egregious or particularly impactful HIPAA violations, when there has been a history of noncompliance, and when OCR has an enforcement initiative targeting a specific aspect of the HIPAA regulations. Currently, OCR has two main enforcement initiatives, one targeting noncompliance with the HIPAA Right of Access of the HIPAA Privacy Rule, and another targeting noncompliance with the risk analysis implementation specification of the HIPAA Security Rule.

The HIPAA Right of Access enforcement initiative has been active since late 2019 and has resulted in more than 55 financial penalties. The risk analysis enforcement initiative is more recent and was formally launched in October 2024 in response to widespread noncompliance with this specific security rule provision and its importance for cybersecurity. To date, OCR has imposed 14 financial penalties under this initiative. The risk analysis enforcement initiative has been expanded this year to include risk management. In addition to demonstrating that a HIPAA-compliant risk analysis has been conducted, OCR requires evidence that the identified risks have been properly managed and reduced to a low and acceptable level in a reasonable time frame.

Between January 1 and June 30, 2026, OCR announced seven settlements to resolve alleged violations of the HIPAA Rules, all seven of which included a financial penalty for a risk analysis violation. While OCR has not announced a specific initiative targeting noncompliance with the HIPAA Breach Notification Rule, two of the seven penalties this year included a fine for breach notification failures. Five of the fourteen penalties imposed in 2025 also included penalties for breach notification failures, which suggests OCR is paying close attention to the time taken to issue breach notifications to OCR, the affected individuals, and the media.

H1 2026 HIPAA Settlements and Civil Monetary Penalties

Covered Entity Type of Entity Amount Settlement / Civil Monetary Penalty Reason
Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans Health Plan $450,000 Settlement Risk analysis failure; failure to implement Privacy, Security, and Breach Notification Rule policies and procedures.
Regional Women’s Health Group (Axia Women’s Health) Healthcare Provider $320,000 Settlement Risk analysis failure; impermissible disclosure of the ePHI of 10,023 individuals.
Assured Imaging Affiliated Covered Entities Healthcare Provider $375,000 Settlement Risk analysis failure (never conducted); breach notification failure.
Consociate, Inc. (Consociate Health) Business Associate $225,000 Settlement Risk analysis failure.
Star Group, L.P. Health Benefits Plan Health Plan $245,000 Settlement Risk analysis failure.
MMG Fusion Business Associate $10,000 Settlement Risk analysis failure; impermissible use/disclosure of PHI; breach notification rule failure.
Top of the World Ranch Treatment Center Healthcare Provider $103,000 Settlement Risk analysis failure

OCR is the main enforcer of the HIPAA Rules, although state attorneys general are also authorized to enforce HIPAA compliance and can impose financial penalties in their respective states. In H1 2026, only one penalty was announced at the state level. Massachusetts and Connecticut participated in a joint investigation of Comstar LLC over a data breach affecting 585,621 individuals (326,426 Massachusetts residents & 22,829 Connecticut residents). The investigation identified violations of the HIPAA Security Rule and the Massachusetts Data Security Regulations. The case was settled with a $515,000 financial penalty.

HIPAA Regulatory Updates

There were no new updates to the HIPAA Rules in the first half of 2026, although there are two pending final rules. During President Trump’s first term in December 2020, OCR proposed an update to the HIPAA Privacy Rule to support coordinated care and improve individual engagement in healthcare. The proposed rule was formally introduced in the Federal Register in January 2021, but a final rule stalled, as OCR had other priorities under the Biden Administration. The return of President Trump for a second term has seen the proposed rule rekindled. OCR set a target of August 2026 for the release of a final rule, although it has yet to be issued.

The other pending final rule is for proposed changes to the HIPAA Security Rule. A notice of proposed rulemaking was announced by OCR in the final days of the Biden administration in late December 2024 and was published in the Federal Register on January 6, 2025. OCR received several thousand comments from industry stakeholders about the proposed changes, including a significant amount of criticism. OCR set a target release date of May 2026 for a final rule; however, it has now been pushed back until July 2027, although a final decision about whether to issue a final rule has yet to be made by the Trump administration.

While there were no new HIPAA updates in H1 2026, the compliance date for updates to the HIPAA Notice of Privacy Practices requirements was February 16, 2026 – the only surviving part of the now vacated HIPAA update to strengthen reproductive healthcare privacy. The Notice of Privacy Practices compliance deadline aligned with the compliance deadline for changes to the 42 CFR Part 2 regulations concerning substance use disorder (SUD) patient records to align those regulations more closely with HIPAA.

About this Report

This report is based on healthcare data breaches affecting 500 or more individuals that were reported to the HHS’ Office for Civil Rights in H1 2026. The data for this report was obtained from OCR on September 10, 2026, and includes supplemental information from data breach reporting from the HIPAA Journal.

You can view more comprehensive healthcare data breach facts and statistics from 2009 to the present on our data breach statistics page, and more comprehensive and up-to-date information on HIPAA enforcement actions on our HIPAA violation cases page, both of which are regularly updated. Information on the latest regulatory changes can be found on our HIPAA Updates/HIPAA Changes page.

The post H1 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure

Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency. On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) said it discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals.

The reports showed aggregate statistics related to Medicaid and the DC Healthcare Alliance (Alliance) programs, including enrollment counts and other aggregate data. While only aggregate statistics were displayed on screen, the underlying personal information that supported the reports was contained in hidden fields that could potentially be accessed by unauthorized individuals.

When DHCF learned about the issue, the reports were immediately removed from its website, and an investigation was launched to determine the extent to which personal data had been exposed. The investigation determined that the personal and protected health information of 399,086 Medicaid and DC Healthcare Alliance beneficiaries may have been accessed by unauthorized individuals, including the following data elements: Medicaid ID number, date of birth, provider name, race, gender, ward, or ethnicity.

Beneficiary names were not accessible, nor were Social Security numbers or financial account information, which limits the potential for data misuse. The reports were accessible on the DHCF website between 2023 and July 2026, and the data related to individuals enrolled in the Medicaid or Alliance programs between those dates.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026. The data breach has been added to the OCR data breach portal in the past couple of days. Individual notification letters are being mailed to all affected individuals, and DHCF said it has taken steps to strengthen internal processes to ensure that similar incidents are prevented in the future.

The post DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure appeared first on The HIPAA Journal.

Astrana Health Notifies SEC About Social Engineering Incident

Astrana Health, a managed services organization that helps healthcare providers deliver value-based, coordinated care to patients, has notified the U.S. Securities and Exchange Commission (SEC) about a material cybersecurity incident that exposed patient, employee, and provider information.

According to the Form 8-K filing, Astrana Health subsidiary Astrana Health Management identified unusual activity within its information technology environment. The forensic investigation found that threat actors had conducted a series of social engineering attempts against employees. The threat actors impersonated company personnel and spoofed the company’s main telephone number and tricked employees into providing them with access to company systems.

The company engaged a third-party cybersecurity and digital forensics firm to assist with the investigation and notified law enforcement. Steps have been taken to bolster security to prevent similar incidents in the future, including resetting all affected credentials, restricting the use of remote access tools, restoring systems from clean backups, and enhancing monitoring.

The investigation and data review are ongoing; however, Astrana Health believes that certain private and/or confidential information stored on the affected servers has been accessed and/or acquired. Data is being reviewed to determine what patient, employee, credentialed provider, intellectual property, and confidential business and financial information may be involved. On September 22, 2026, the company determined that it constitutes a material cybersecurity incident due to the confidential and sensitive nature of the data involved.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

At the time of issuing the Form 8-K filing, Astrana Health was unable to estimate the full impact of the incident on the company’s business strategy, operations, financial condition, or results of operations. The company holds a cyber insurance policy that may cover certain losses associated with the incident. Currently, no ransomware or cybercriminal group appears to have claimed responsibility for the cyberattack.

The post Astrana Health Notifies SEC About Social Engineering Incident appeared first on The HIPAA Journal.

California Critical Access Hospital Announces Cybersecurity Incident

Data breaches have been announced by Modoc Medical Center and Vista Del Mar Child and Family Services in California, Park Place Behavioral Healthcare in Florida, and Millstone Medical Outsourcing in Massachusetts.

Modoc Medical Center

Modoc Medical Center, a 12-bed critical access hospital and rural healthcare system based in Alturas, California, has identified unauthorized access to its computer network. The unauthorized access was detected on January 27, 2026, and cybersecurity specialists were engaged to help secure its systems and investigate and determine the nature and scope of the incident. The investigation confirmed that an unknown actor had access to parts of its computer network between January 19, 2026, and January 27, 2026, and downloaded certain files, some of which contained patients’ personal and protected health information.

The review of the data has been completed, and notification letters are now being sent to the affected individuals. The data types involved varied from individual to individual and are detailed in the individual notification letters. The data involved included names in combination with one or more of the following: Social Security number, driver’s license or state identification number, financial account information, payment card information, passport number, military identification number, medical information, and/or health insurance information.

The affected individuals have been offered 12 or 24 months of complimentary credit monitoring and identity theft protection services, and steps have been taken to strengthen security to prevent similar incidents in the future. The Worldleaks ransomware and data extortion group claimed responsibility for the attack. It is unclear whether ransomware was involved.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Vista Del Mar Child and Family Services

Vista Del Mar Child and Family Services, a Los Angeles, California-based nonprofit provider of mental health, education, and social services to children, adolescents, and their families, is reviewing the data exposed in a recent cybersecurity incident. Suspicious activity was identified within its computer systems on June 30, 2026, indicative of an intrusion. Its incident response protocols were activated, containment measures deployed, and an investigation was launched. Third-party cybersecurity professionals were engaged to help determine the nature and scope of the incident and confirmed that an unauthorized third party had accessed systems containing personal and protected health information.

There was no impact on its operations, and services continued to be provided to all individuals as scheduled. The data review is ongoing, and it is too early to confirm the number of individuals affected or the data types involved. Notification letters will be mailed to the affected individuals when those processes are completed. In the meantime, the data breach has been reported to the HHS’ Office for Civil Rights as involving the protected health information of at least 500 individuals. Vista Del Mar Child and Family Services said law enforcement has been notified, it is reviewing its security policies, protocols, and procedures, has implemented additional security controls, and is working on optimizing its endpoint monitoring software.

Park Place Behavioral Healthcare

Park Place Behavioral Healthcare (formerly Osceola Mental Health Inc.), a community behavioral health provider in Osceola County, Florida, that provides mental health and substance use services, has notified patients about a recent cybersecurity incident. Suspicious activity was identified within its computer network on July 23, 2026. Third-party cybersecurity experts were engaged to investigate the activity, and on August 19, 2026, the investigation was completed and confirmed that its network had been accessed by an unauthorized third party.

A file review was initiated, and on September 17, 2026, Park Place Behavioral Healthcare obtained the final list of individuals to notify. The data involved varied from person to person and may have included names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers/other government-issued ID numbers, financial account information, health information, and/or health insurance information.

Park Place Behavioral Healthcare said several steps have been taken in response to the incident, including resetting user account credentials, installing endpoint detection and response software for continuous monitoring, and refining the security of its remote access methods. The number of affected individuals has not currently been publicly disclosed. The Insomnia ransomware group claimed responsibility for the attack and listed the stolen data on its dark web data leak site, which indicates that the ransom was not paid.

Millstone Medical Outsourcing

Millstone Medical Outsourcing, a Fall River, Massachusetts-based medical device outsourcing company, has identified a cybersecurity incident that exposed personal and health information. The forensic investigation determined that an unauthorized third party first accessed parts of its network on December 15, 2025. The intrusion was detected on December 16, 2025, and the forensic investigation determined that its network had been accessed by an unauthorized third party between December 15, 2025, and December 19, 2025, during which time files were acquired.

The data review confirmed on July 15, 2026, that the stolen data included Social Security numbers, government identification numbers, financial account codes, credit/debit card information, and health records. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 24 months. No misuse of the affected information had been identified at the time of issuing notification letters. The number of affected individuals has not been publicly disclosed at the time of publication of this article.

The post California Critical Access Hospital Announces Cybersecurity Incident appeared first on The HIPAA Journal.

Labcorp Settles Multistate Data Breach Investigation for $2.3 Million

A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp) regarding a 2019 data breach at its debt collection company, American Medical Collection Agency (AMCA). Labcorp has agreed to pay $2,287,455, which will be divided among the 44 states participating in the action.

AMCA is a subsidiary of the debt collection company Retrieval-Masters Creditors Bureau (RMCB) and provides small debt collection services to healthcare organizations, including laboratories and medical testing facilities. The hacking incident was identified by RMCB on March 19, 2029, and the forensic investigation determined that a hacker breached the AMCA network around 8 months before the intrusion was detected. The hacker had access to the network from August 1, 2018, until March 30, 2019, and exfiltrated sensitive data including names, personal information, Social Security numbers, financial information, medical test information, and diagnostic codes.

The AMCA data breach was the largest data breach reported in 2019 by a HIPAA-regulated entity, affecting more than 27.5 million individuals, including more than 10.2 million Labcorp patients. The high cost of remediation forced AMCA to file for bankruptcy protection. AMCA was also investigated by the coalition, led by the Indiana, Texas, Connecticut, and New York attorneys general, and received permission from the bankruptcy court to settle the multistate action, filing for dismissal of the bankruptcy on December 9, 2020.

The settlement required AMCA to develop, implement, and maintain an information security program and implement a range of data security measures, including developing an incident response plan and appointing a qualified Chief Information Security Officer (CISO). A financial penalty of $21 million was suspended due to the financial position of the company.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The investigation of Burlington, NC-based Labcorp was led by the attorneys general of Connecticut, Florida, Indiana, Illinois, Michigan, and Texas and identified potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state consumer protection and breach notification laws. The Labcorp settlement includes a financial penalty and injunctive relief. Labcorp must ensure that it does not misrepresent the extent to which it maintains and protects the privacy, security, and confidentiality of personal information (PI) and protected health information (PHI) and must implement a range of security measures, including but not limited to the following:

  • Review, revise, and update its information security program.
  • Employ an executive or officer as a CISO to oversee the implementation and maintenance of its information security program.
  • Provide security awareness training to all personnel who have access to or responsibility for PI and/or PHI.
  • Implement an incident response plan, which must include a plan for vendor security incidents.
  • Ensure procedures are implemented for reporting vendor security incidents internally to senior management.
  • Develop policies and procedures governing the collection, use, disclosure, and retention of PI and PHI, including specific policies and procedures for PI and PHI shared with debt collectors.
  • Minimize the PI and PHI shared with debt collectors.
  • Develop, implement, and maintain a vendor risk management program; maintain a vendor risk management team; and use security assessment and management tools for vendor assessment and monitoring, with specific requirements for debt collectors.
  • Require all debt collectors to conduct risk assessments, and contractually require debt collectors to conduct penetration tests of systems containing PI and PHI, and annual SOC 2 Type 2 audits.
  • Labcorp must also engage a third-party assessor to perform an information security assessment, with a focus on vendor risk management.

Labcorp was also named as a defendant in class action litigation against AMCA and other AMCA clients, and agreed to a $35,000,000 settlement earlier this year. The class action lawsuit is ongoing against other AMCA clients.

The post Labcorp Settles Multistate Data Breach Investigation for $2.3 Million appeared first on The HIPAA Journal.

Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems

Notification letters are being mailed to individuals affected by data breaches at the pharmacy benefit management service provider MedImpact Healthcare Systems and the healthcare software company Rosch Visionary Systems.

MedImpact Healthcare Systems

MedImpact Healthcare Systems, a provider of pharmacy benefit management services to health plans, government entities, and self-insured employers, identified unauthorized activity within its computer network in October 2025. Immediate action was taken to secure its computer systems and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident.

The investigation was finalized on July 17, 2026, and the affected clients were informed about the data breach on August 13, 2026. Notification letters started to be sent to the affected individuals by MedImpact Healthcare on behalf of its affected clients on September 23, 2026. Data compromised in the incident included names in combination with some or all of the following: address, date of birth, subscriber number, Social Security numbers, health insurance information, health-related information such as prescription information, treatment information, dates of service, service locations, and provider names. The affected clients and number of affected individuals have not been publicly disclosed.

Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services. At the time of issuing notification letters, no misuse of the affected data had been identified. The Qilin ransomware group claimed responsibility for the data breach and added MedImpact Healthcare to its dark web data leak site in October 2025. Qilin claimed to have exfiltrated sensitive data in the incident and threatened to leak the data if the ransom was not paid.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Rosch Visionary Systems

Rosch Visionary Systems, a Pennsylvania-based software company that provides allergy and immunotherapy management software for medical practices, has experienced a cybersecurity incident that compromised part of its computer network. The breach notifications sent to state attorneys general do not state when the breach occurred, when it was detected, or the nature of the unauthorized activity. Healthcare providers that use its software have been notified, and individual notification letters are being mailed to the affected individuals. Complimentary credit monitoring and identity theft protection services have been offered for 24 months.

The scale of the data breach and specific types of information involved are unclear. Healthcare provider clients known to have been affected include Allergy, Asthma and Food Allergy Centers and Texas Regional Asthma, Allergy & Immunology Center. This appears to have been a ransomware attack or data theft and extortion incident. A threat group called Lynx claimed responsibility for the cyberattack and alleged that sensitive data was stolen from Rosch Visionary Systems. The company is no longer listed on the Lynx data leak site, which suggests that a ransom payment was negotiated.

The post Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems appeared first on The HIPAA Journal.