HIPAA Breach News

Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals

Lifespan Physicians Group of Massachusetts, doing business as Brown Health Medical Group-MA, has confirmed that the protected health information of almost 312,000 individuals was potentially compromised in a December 2025 security incident.

There is currently no substitute breach notice on the medical group’s website; however, the data breach was reported to the Vermont and Massachusetts Attorneys General. The breach notices issued to those regulators explain that unauthorized activity was identified in a legacy file server at the practice on December 16, 2025. The server was isolated, and an investigation was launched to determine the nature and scope of the unauthorized activity. The forensic investigation confirmed that the breach was limited to the file server, which was accessed by an unauthorized third party between December 15 and December 16, 2026. The electronic medical record system was not involved.

The server was reviewed to determine the exact types of information stored on the server. The file review determined on June 22, 2026, that the following categories of data were impacted – names, dates of birth, contact information, Social Security numbers, driver’s license numbers or other government-issued identification numbers, credit or debit card numbers, financial account information, and personnel and human resources records. The latter may have included information such as compensation or payroll information, licensure or credentialing information, and medical or disability-related records.

Steps have been taken to improve security to prevent similar incidents in the future, including implementing enhanced technical safeguards. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 24 months. The incident affected 290,357 Massachusetts residents and 86 Vermont residents. According to the HHS’ Office for Civil Rights data breach portal, the protected health information of 311,760 individuals was potentially stolen in the incident.

The post Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals appeared first on The HIPAA Journal.

AmGen Announces Cyberattack and Data Breach Involving Patient Data

Amgen Inc., a Thousand Oaks, CA-based biopharmaceutical company that develops and manufactures pharmaceutical products for oncological, hematological, and cardiovascular diseases, has recently disclosed a cybersecurity incident involving unauthorized access to third-party-hosted cloud storage systems.

In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), Amgen explained that it determined in July 2026 that hackers gained access to certain cloud systems. Amgen immediately implemented its cybersecurity response plan, deployed containment measures, and engaged third-party digital forensics experts to determine the nature and scope of the unauthorized activity.

The investigation determined that proprietary data, patients’ protected health information, and other data had been exfiltrated from the cloud environment, and on July 29, 2026, determined that the incident was material and informed the SEC. Amgen said it does not believe the incident is reasonably likely to have an impact on its financial position, nor any of its products, manufacturing operations, financial reporting systems, or its ability to meet patient needs.

Amgen is in the process of assessing the extent to which patient information, confidential business information, intellectual property, research and development, and other information was exfiltrated in the attack and will be unable to accurately determine the impact to the company until those processes have concluded. At present, the exact nature of the attack, such as how the cloud systems were compromised, has yet to be made public. Amgen said it takes the protection of its systems and data very seriously and is in the process of determining the applicable regulatory and legal notification requirements, including its responsibilities under HIPAA.

As of the date of the SEC filing, the threat group behind the attack is unclear. Several pharmaceutical, biotechnology, and medtech firms have fallen victim to cyberattacks in recent months, including Novo Nordisk, Medtronic, Stryker, Abbott Laboratories, West Pharmaceutical Services, and Brainyx AI. The attacks have been conducted by several threat actors, including the Iran-linked hacktivist group Handala and the data theft and extortion groups FulcrumSec and ShinyHunters. The latter was the subject of a recent cybersecurity alert by Health-ISAC after a string of successful hacks on the healthcare sector.

The post AmGen Announces Cyberattack and Data Breach Involving Patient Data appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.

Soniva Dental Care Data Breach Affects At Least 30,000 Patients

Data breaches have been announced by Soniva Dental Care in Texas, Optalis Management Solutions in Michigan, CareCloud in New Jersey, and Hudson Valley Medical Billing & Credentialing in New York.

Soniva Dental Care

Soniva Dental Care, a San Antonio, Texas-headquartered provider of dental services, orthodontics, and cosmetic dentistry across 14 locations, has recently disclosed a cybersecurity incident affecting patients of several of its practices. On May 26, 2026, Soniva Dental Care was informed by its IT support company about suspicious remote access sessions. It rapidly became apparent that its remote desktop web services infrastructure was under attack, and IT resources were shifted to containing the incident, terminating all external communications, disabling accounts with remote desktop access, and locking down its infrastructure. Soniva Dental Care said its patient record system was quickly restored and its archive data was unaffected.

While the incident was rapidly detected and contained, it was not possible to rule out unauthorized access to patient data. Files exposed in the incident were reviewed and found to contain names, addresses, dates of birth, driver’s license numbers, government-issued IDs, and medical information. Soniva Dental Care said its incident response was effective, and it has not identified any further suspicious activity. While Soniva Dental Care is unaware of any instances of data misuse, the affected individuals have been advised to place a fraud alert on their accounts with any of the three major credit bureaus. Security inspections are being conducted by its IT support company, which will continue to monitor for unauthorized activity.

Regulators have been notified about the data breach, but the incident is not yet shown on the HHS Office for Civil Rights breach portal. The Texas Attorney General was informed that up to 30,000 Texas residents were potentially affected. Affected practices include, but may not be limited to, Agave Dental Floresville, Allwyn Dental, Azle Smiles, Kashi Dental, Mysa Dental, and Wilson Dental.

A ransomware-as-a-service group called TheGentlemen claimed responsibility for the attack. The group is currently one of the most prolific ransomware groups, having attracted affiliates from other groups by offering a 90% split on ransom payments.

Optalis Management Solutions

Optalis Management Solutions, a Michigan-based operations management company specializing in the management of senior living and healthcare facilities, has reported a data breach to the HHS Office for Civil Rights involving the protected health information of 13,723 individuals.

Suspicious activity was identified within its computer network on or around April 19, 2025. The forensic investigation confirmed unauthorized access between April 14, 2025, and April 19, 2025, and on June 10, 2025, it was confirmed that files had been exfiltrated from its network. The review of the affected data has recently been completed, confirming that the following types of information were compromised in the incident: full names, Social Security numbers, driver’s license/state ID numbers, credit/debit card information, financial account information, diagnosis and treatment information, and health insurance information.

Notification letters started to be mailed to the affected individuals on June 29, 2026. While no evidence has been found to indicate any actual or attempted misuse of the stolen data, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services.

CareCloud

CareCloud Inc., a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined that data was exfiltrated from its systems in a recent security incident. CareCloud said it experienced a network disruption on March 16, 2026, that impacted one of its electronic health record environments. Third-party cybersecurity experts were engaged to assist with the investigation, who determined that the impacted AWS environment was accessed by an unauthorized third party between March 10 and March 16, 2026. The threat actor claimed to have exfiltrated databases from that environment.

The data was reviewed, and on June 24, 2026, CareCloud confirmed the data types involved. The affected individuals are now being notified, and the individual notification letters state the exact types of data involved. Complimentary identity theft protection services have been offered to the affected individuals. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

Hudson Valley Medical Billing & Credentialing

Hudson Valley Medical Billing & Credentialing, LLC, a New York-based provider of patient billing and accounts receivable services, has identified unauthorized access to computer systems containing the protected health information of 5,459 patients of its healthcare clients. The intrusion was first identified on March 6, 2026, and immediate action was taken to contain the incident and terminate the unauthorized access. The investigation was unable to determine whether patient data was accessed or copied, so notification letters have been mailed to individuals who have potentially been affected.

The company said it has enhanced its technical safeguards to strengthen system security, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The exact data types involved are detailed in the individual notification letters.

The post Soniva Dental Care Data Breach Affects At Least 30,000 Patients appeared first on The HIPAA Journal.

Global Data Breach Cost Rises 12% to Almost $5 Million

The IBM 2026 Cost of a Data Breach Study shows data breach costs have risen by 12% in a year to almost $5 million, with the United States facing the highest breach costs. In 2026, the average cost of a data breach in the United States was $11.5 million – more than double the average global data breach cost. Healthcare continues to face the highest breach costs, with an average cost of $6.64 million per incident, although healthcare data breach costs have fallen by 10.5% year-over-year from a global average of $7.42 million in 2025. Data breach costs increased in all sectors represented in the study, with the rise largely driven by increases in detection, escalation, and lost business costs.

In healthcare, 59% of breaches were malicious or criminal attacks, 26% were due to IT failures, and 13% were due to human error. Across all sectors, phishing (voice and SMS phishing) accounted for 17% of breaches and was the most common initial access vector and had an average breach cost of $5.9 million. The next most common vectors were supply chain compromise, abuse of valid accounts, drive-by compromise attacks, and social engineering.

For the first time in five years, the average time to identify and contain a breach increased, rising 2.5% from 2025. The attack vectors that proved most difficult to identify and contain were removable media and supply chain compromises, as they do not show up in malware scans or inbound traffic. Breaches involving either of these attack vectors took an average of 258 days to identify and resolve, compared to an average of 247 days across all attack types.

Attackers have embraced AI tools in all areas of their attacks, including scanning for vulnerabilities, crafting phishing and social engineering lures, and automating attacks at scale. There has been a 56% year-over-year increase in AI-driven attacks, with one in four organizations having experienced an AI-driven breach in the past year.

AI deepfake and impersonation accounted for 45% of AI-driven attacks, with AI-generated malware becoming more common, accounting for 19% of AI-generated attacks. AI-generated phishing or other communications accounted for 17% of attacks. AI-driven attacks have an increased financial impact, adding around $1 million to average data breach costs. Most AI-driven attacks targeted critical infrastructure, with the financial services and energy sectors the most targeted.

There has also been an increase in shadow AI incidents – AI applications used by employees that have not been approved for use. Incidents more than doubled to 43% of security incidents this year from 20% last year. IBM notes a lack of governance policies to mitigate or manage the risk to AI, with only around one third of organizations having a strict approval for deploying AI tools. The average breach cost was $5.39 million, and one in five of these breaches resulted in a regulatory fine.

There is growing concern about new threats from frontier AI models. Out of all breached organizations, 85% of organizations that were aware of frontier models said they were increasing their security spending to combat the threat. IBM notes that experts believe that AI will favor attackers over defenders by 31.7% within two years, highlighting the pressing need for speed in security.

While organizations are adopting AI for security, most are only using AI agents for detection and containment. Only a small fraction use AI agents for vulnerability management. That means exposures are available for exploitation for much longer, and given that attackers are using AI tools for vulnerability discovery, this is one of the key areas where organizations can make significant security gains. IBM recommends leveraging AI to analyze exposures, enforce policies, and coordinate detection and containment with minimal human intervention.

Ransomware attacks have continued to increase due to ransomware-as-a-service. Over the past 12 months, 39% of breached organizations said they experienced at least one ransomware attack, up from 24% in 2023 – a 62.5% increase over the past four years.  Attackers are increasingly threatening public shaming and data leaks to pressure victims into paying, rather than simply encrypting files. In 2026, 41% of ransomware attacks included brand reputation threats, such as data leaks and public shaming, with 35% of attacks targeting employee data and health records.

The post Global Data Breach Cost Rises 12% to Almost $5 Million appeared first on The HIPAA Journal.

Florida SUD Treatment Provider Announces 145,700-record Data Breach

Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have also been announced by Vanderbilt Health in Tennessee, Averhealth Holdings in Virginia, and the Texas-based nationwide optical and optometric service provider Eyemart Express.

Operation PAR, Florida

Operation PAR, Inc., a Pinellas Park, Florida-based addiction treatment and mental health service provider, has identified unauthorized access to its computer network and the exposure of the protected health information of 145,714 current and former clients. Suspicious activity was identified within its computer network on June 10, 2025. Immediate steps were taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity.

A year to the day after the incident was identified, Operation PAR confirmed that the impacted files contained personal and protected health information. Data compromised in the incident included first and last names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. Steps have since been taken to augment security and prevent similar incidents in the future.

Notification letters started to be mailed to the affected individuals on June 25, 2026, who were provided with information on best practices to protect their information and prevent fraud and misuse. Credit monitoring and identity theft protection services do not appear to have been offered. While not stated in the notification letters, this appears to have been an attack by the Worldleaks threat group, which added Operation PAR to its dark web data leak site in July 2025. The group proceeded to leak the stolen data.

Eyemart Express, Texas

Farmers Branch, Texas-based Eyemart Express, a nationwide provider of optical and optometric services, has disclosed further information about a data breach reported to the HHS’ Office for Civil Rights on May 18, 2026. Unauthorized access to parts of the Eyemart Express network was discovered on February 13, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity.

The investigation confirmed that an unauthorized third party breached its network the previous day (February 12, 2026), and gained access to files containing names, addresses, dates of birth, Social Security numbers, prescription information, insurance information, and information about eyeglass purchases. Eyemart Express has reviewed its policies and procedures related to data security and is implementing additional measures to reduce the risk of similar incidents in the future. The protected health information of up to 25,000 individuals was potentially compromised in the incident. Individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring and identity theft protection services.

While not stated in the breach notice, this was a cyberattack by the PayoutsKing threat group. The threat group claimed to have exfiltrated 435 GB of data in the attack, including customer and employee information. The group proceeded to leak the stolen data when the ransom was not paid.

Vanderbilt Health, Tennessee

Nashville, Tennessee-based Vanderbilt Health, the operator of 8 hospitals and more than 180 ambulatory, primary care, and specialty clinics in the state, has identified unauthorized access to an employee’s email account. An employee was tricked by a phishing attempt into clicking a malicious link, resulting in the theft of their credentials. Unauthorized account access was detected on March 27, 2026, and the forensic investigation confirmed that the account was compromised on March 23, 2026. An unauthorized individual had access to emails and associated documents containing patient information such as names, medical record numbers, diagnoses, procedure information, provider/facility names, and admission, discharge, and visit dates.

The breach was confined to the email account. There was no unauthorized access to electronic medical records, and financial information and Social Security numbers were not involved. In response to the incident, Vanderbilt Health is enhancing its email and digital security measures and has provided additional security awareness training to the workforce. The number of affected individuals has yet to be publicly disclosed.

Averhealth Holdings, Virginia

Averhealth Holdings, the parent company of Avertest, a provider of drug testing services for substance use monitoring, diagnostic laboratory testing, and random drug-testing programs, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,909 individuals.

Suspicious activity was identified within its email environment on January 20, 2026. Steps were taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity professionals. The investigation determined that there had been unauthorized access to parts of its network between December 19, 2025, and January 21, 2026. On May 6, 2026, Averhealth Holdings discovered that the threat actor behind the attack had obtained files containing personal information and protected health information.

The types of information varied from individual to individual and included names in combination with one or more of the following: clinical information, diagnosis, digital/electronic signature, date of birth, driver’s license number, health insurance policy-related number, medical cost, medical dates of service, medical history, medical provider name, medical record number, medical treatment/procedure information, mental or physical condition, minor, patient account number, and/or Social Security number.

Notification letters were mailed to the affected individuals on July 2, 2026. At the time of issuing notifications, Averhealth Holdings was unaware of any misuse of the impacted information. As a precaution against data misuse, complimentary credit monitoring services have been offered to individuals who had their Social Security numbers exposed or stolen.

The post Florida SUD Treatment Provider Announces 145,700-record Data Breach appeared first on The HIPAA Journal.

Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities

The Anderson, South Carolina-based nonprofit health system AnMed said it is continuing to make progress restoring its systems after a malware-related cyberattack on July 26, 2026. The health system is operating under established downtime procedures and is continuing to provide care at its locations, although some patients are facing delays. The health system is keeping patients up to date on its recovery and available services via its website. AnMed has confirmed that its doctors have access to medical records and the provision of safe care is the highest priority. In some cases, appointments have been rescheduled, and some transfers and diversions remain in place, with decisions guided by patient safety.

On July 30, 2026, AnMed issued a warning about communications that appear to have been sent by AnMed, such as MyChart appointment reminders. According to the warning, “During our response to the cybersecurity incident, certain appointment reminders generated outside of our internal systems may continue to be delivered by text message. Patients are not required to confirm appointments electronically at this time.”

AnMed said it has not found any evidence to suggest that patients are being targeted with malicious intent as a result of the security incident, although patients have been advised to remain cautious with any electronic messages that appear to originate from AnMed.

July 27, 2026: AnMed Closes 83 Facilities While It Grapples with Cyberattack

AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced to temporarily close 83 of its 106 facilities while it deals with cyberattack-related disruption to its IT systems. Computer systems, phone lines, and Internet connectivity are down.

On Sunday, July 26, 2026, the health system confirmed that it had experienced “a cybersecurity disruption involving malware,” which forced it to close AnMed Medical Group offices and AnMed Imaging Services on Monday. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will open as scheduled on Monday. While offices have been temporarily closed, AnMed said its care teams remain on site and will continue to see patients in the emergency room.

The attack has resulted in disruption to patient services, with some scheduled appointments postponed. Patients who had elective procedures scheduled for Monday are being contacted directly to advise them if their procedures will go ahead as planned or will have to be postponed. Decisions about procedures, patient transfers, diversions, and operational processes are being made with patient safety as the guiding principle.

AnMed said it is coordinating with the emergency medical services, regional hospitals, and public safety partners to ensure that patients receive the care they need in the most appropriate setting. AnMed is currently unable to provide a timeline for when computer systems will be recovered, when its offices will reopen, and when normal services will resume.

Updates will be provided via its website, including operational plans for the coming days. Cybersecurity partners are working on restoring access to systems and data as quickly as possible. An investigation has been launched to determine the nature and scope of the incident, but it is too early to tell to what extent, if any, patient data was involved. No threat group appears to have claimed responsibility for the incident.

The post Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities appeared first on The HIPAA Journal.

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate the unauthorized access, with third-party cybersecurity experts engaged to help with the investigation.

They confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, and confirmed that the information potentially compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical histories, mental/physician condition information, diagnosis information, medical treatment information, health plan beneficiary information, health insurance policy numbers/subscriber numbers, and other health insurance information.

MCBS said it continually assesses and enhances its security policies and procedures and will continue to do so. The following HIPAA-covered entities have been affected:

  • C&C MD PC
  • Nuclear Medicine and Pathology Associates
  • Radiation Oncology Associates, LLP
  • SkinPath Solutions, LLC
  • South Georgia Radiology Consultants PC
  • Stephen W. Brown & Radiology Associates of Augusta, LLP
  • Vascular Radiology Associates II, LLP

While the threat group behind the attack was not disclosed by MCBS in the data breach notice, the PEAR threat group claimed responsibility for the attack. PEAR, which stands for Pure Extortion and Ransom, engages in data theft and extortion and does not use ransomware to encrypt files. PEAR claimed to have exfiltrated 3 TB of data in the attack and published the stolen data on its data leak site when the ransom was not paid.

The post MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals appeared first on The HIPAA Journal.

Data Breaches Announced by Four Hospitals and Surgery Centers

Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital.

Wildwood Surgical Center

Wildwood Surgical Center in Ohio has announced a June 2025 cybersecurity incident that involved the removal of patient data from its network. Suspicious activity was identified within its network on June 26, 2025, and the forensic investigation determined that an unauthorized third party had access to its network from June 24 to June 26, 2025.

It has taken more than a year to review the affected data and issue notifications to the affected individuals. Notification letters were mailed on or around July 13, 2026, informing patients that their names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, diagnostic and treatment information, medical billing information such as bank account or debit/credit card numbers, and health insurance information were exposed or stolen in the incident.

Wildwood Surgical Center said it has implemented additional tools to enhance the security of its systems and prevent similar incidents in the future. The data breach is not currently showing on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has not yet been publicly disclosed.

Penobscot Valley Hospital

Penobscot Valley Hospital in Lincoln, Maine, identified suspicious activity within its computer network on January 28, 2026. An investigation was launched, which revealed on February 12, 2026, that there had been unauthorized access to its network, and patient data was potentially accessed or acquired.

The review of the affected data was completed on June 4, 2026, confirming that the exposed data included names, addresses, birth dates, Social Security numbers, financial information, and medical information. Notifications are being mailed to the affected individuals, who have been offered complimentary credit monitoring and identity theft protection services. Additional technical security measures and other safeguards have been implemented to prevent similar incidents in the future.

Regulators have been notified, but the incident is yet to be added to the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

Whitfield Regional Hospital

Whitfield Regional Hospital in Demopolis, Alabama has experienced a cybersecurity incident that involved unauthorized access to parts of its network where patient information was stored. The incident was detected on June 8, 2025, and the forensic investigation confirmed unauthorized access occurred between May 15, 2025, and June 8, 2025.

A review was initiated to determine the individuals affected and types of data involved. That process took more than a year, with the review completed on June 26, 2026. Tombigbee Healthcare Authority, which operates the hospital, has confirmed that the data included first and last names, dates of birth, Social Security numbers, driver’s license numbers, medical information, financial account information, and health insurance information.

Notification letters started to be mailed to the affected individuals on July 17, 2026, and complimentary credit monitoring and identity theft protection services have been offered. The number of affected individuals has yet to be publicly disclosed.

Michigan Surgical Center

Michigan Surgical Center in East Lansing, MI, has confirmed it experienced a cybersecurity incident that impacted some of its patients. While there is currently no substitute breach notice on its website, the breach was confirmed in a notice to the Massachusetts Office of Consumer Affairs and Business Regulation. The types of information involved and the number of affected individuals have yet to be publicly disclosed. The affected individuals have been offered complimentary single-bureau credit monitoring, credit report, and credit score services for 12 months.

This appears to have been a ransomware attack by a prolific ransomware group called the Gentlemen – A group that has been aggressively targeting healthcare organizations and has grown into one of the most active ransomware groups. Michigan Surgical Center was added to the group’s dark web data leak site in early June.

The post Data Breaches Announced by Four Hospitals and Surgery Centers appeared first on The HIPAA Journal.