HIPAA Breach News

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate the unauthorized access, with third-party cybersecurity experts engaged to help with the investigation.

They confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, and confirmed that the information potentially compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical histories, mental/physician condition information, diagnosis information, medical treatment information, health plan beneficiary information, health insurance policy numbers/subscriber numbers, and other health insurance information.

MCBS said it continually assesses and enhances its security policies and procedures and will continue to do so. The following HIPAA-covered entities have been affected:

  • C&C MD PC
  • Nuclear Medicine and Pathology Associates
  • Radiation Oncology Associates, LLP
  • SkinPath Solutions, LLC
  • South Georgia Radiology Consultants PC
  • Stephen W. Brown & Radiology Associates of Augusta, LLP
  • Vascular Radiology Associates II, LLP

While the threat group behind the attack was not disclosed by MCBS in the data breach notice, the PEAR threat group claimed responsibility for the attack. PEAR, which stands for Pure Extortion and Ransom, engages in data theft and extortion and does not use ransomware to encrypt files. PEAR claimed to have exfiltrated 3 TB of data in the attack and published the stolen data on its data leak site when the ransom was not paid.

The post MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals appeared first on The HIPAA Journal.

Data Breaches Announced by Four Hospitals and Surgery Centers

Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital.

Wildwood Surgical Center

Wildwood Surgical Center in Ohio has announced a June 2025 cybersecurity incident that involved the removal of patient data from its network. Suspicious activity was identified within its network on June 26, 2025, and the forensic investigation determined that an unauthorized third party had access to its network from June 24 to June 26, 2025.

It has taken more than a year to review the affected data and issue notifications to the affected individuals. Notification letters were mailed on or around July 13, 2026, informing patients that their names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, diagnostic and treatment information, medical billing information such as bank account or debit/credit card numbers, and health insurance information were exposed or stolen in the incident.

Wildwood Surgical Center said it has implemented additional tools to enhance the security of its systems and prevent similar incidents in the future. The data breach is not currently showing on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has not yet been publicly disclosed.

Penobscot Valley Hospital

Penobscot Valley Hospital in Lincoln, Maine, identified suspicious activity within its computer network on January 28, 2026. An investigation was launched, which revealed on February 12, 2026, that there had been unauthorized access to its network, and patient data was potentially accessed or acquired.

The review of the affected data was completed on June 4, 2026, confirming that the exposed data included names, addresses, birth dates, Social Security numbers, financial information, and medical information. Notifications are being mailed to the affected individuals, who have been offered complimentary credit monitoring and identity theft protection services. Additional technical security measures and other safeguards have been implemented to prevent similar incidents in the future.

Regulators have been notified, but the incident is yet to be added to the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

Whitfield Regional Hospital

Whitfield Regional Hospital in Demopolis, Alabama has experienced a cybersecurity incident that involved unauthorized access to parts of its network where patient information was stored. The incident was detected on June 8, 2025, and the forensic investigation confirmed unauthorized access occurred between May 15, 2025, and June 8, 2025.

A review was initiated to determine the individuals affected and types of data involved. That process took more than a year, with the review completed on June 26, 2026. Tombigbee Healthcare Authority, which operates the hospital, has confirmed that the data included first and last names, dates of birth, Social Security numbers, driver’s license numbers, medical information, financial account information, and health insurance information.

Notification letters started to be mailed to the affected individuals on July 17, 2026, and complimentary credit monitoring and identity theft protection services have been offered. The number of affected individuals has yet to be publicly disclosed.

Michigan Surgical Center

Michigan Surgical Center in East Lansing, MI, has confirmed it experienced a cybersecurity incident that impacted some of its patients. While there is currently no substitute breach notice on its website, the breach was confirmed in a notice to the Massachusetts Office of Consumer Affairs and Business Regulation. The types of information involved and the number of affected individuals have yet to be publicly disclosed. The affected individuals have been offered complimentary single-bureau credit monitoring, credit report, and credit score services for 12 months.

This appears to have been a ransomware attack by a prolific ransomware group called the Gentlemen – A group that has been aggressively targeting healthcare organizations and has grown into one of the most active ransomware groups. Michigan Surgical Center was added to the group’s dark web data leak site in early June.

The post Data Breaches Announced by Four Hospitals and Surgery Centers appeared first on The HIPAA Journal.

Tennessee Pathology Group Announces 170K-record Data Breach

Anatomic and Clinical Laboratory Associates is notifying almost 170,000 patients about a recent cybersecurity incident. Data breaches have also been announced by ZenPatient, Saint Pete MRI, Carlyle Senior Care, SportsMed Physical Therapy, and Lifeways Inc.

Anatomic and Clinical Laboratory Associates

Anatomic and Clinical Laboratory Associates, P.C., a Nashville, TN-based physician-owned pathology group, has announced a significant data breach involving the protected health information of 169,626 current and former patients.

An investigation was launched on December 1, 2025, when anomalous activity was identified within its computer network. Third-party cybersecurity experts were engaged to assist with the investigation and ensure the security of its computer systems. During the course of the investigation, unauthorized network access was confirmed. It is unclear from the breach notice when the unauthorized access occurred or for how long its network was compromised.

The review of the exposed data was completed on April 27, 2026, when it was confirmed that personal and protected health information had been exposed. The affected individuals had their names exposed, along with one or more of the following data elements: date of birth, Social Security number, taxpayer identification number, date(s) of service, medical provider name(s), mental/physical condition, medical treatment/procedure information, diagnosis or clinical information, medical history, patient account number, and/or medical record number.

Notification letters were mailed to the affected individuals on June 23, 2026, and complimentary credit monitoring and identity theft protection services have been offered to certain individuals, dictated by the types of information involved. Anatomic and Clinical Laboratory Associates have implemented additional security measures to prevent similar incidents in the future.

ZenPatient

ZenPatient, Inc., a Santa Monica, CA-based provider of telehealth and messaging software platform, has announced a cybersecurity incident that involved unauthorized access to its network between December 2025 and February 2026. Suspicious activity was identified within its computer network on February 27, 2026. Assisted by third-party cybersecurity professionals, the incident was investigated, and it was confirmed that an unauthorized third party had access to its network between December 5, 2025, and February 12, 2026, during which time certain files were exfiltrated from its network.

The compromised files were reviewed and found to contain names, addresses, birth dates, and medical information. Notification letters were sent to the affected individuals on July 17, 2026. ZenPatient said it is unaware of any misuse of patient data as a result of the incident; however, as a precaution against data misuse, complimentary credit monitoring services have been made available to the affected individuals for 12 months. Additional cybersecurity measures have been implemented to reduce the risk of similar incidents in the future. The data breach has been reported to regulators, but the number of affected individuals has yet to be publicly disclosed.

Saint Pete MRI

Saint Pete MRI, a St. Petersburg, FL-based full-service diagnostic imaging and sleep lab, is notifying certain patients about a cybersecurity incident it identified on or around February 23, 2025. Immediate action was taken to investigate the incident and secure its computer systems, and a third-party cybersecurity firm was engaged to assist with those processes.

The investigation confirmed that electronic patient care and imaging systems were not subject to unauthorized access; however, the unauthorized party behind the incident may have acquired certain scanned data. The affected files were reviewed, and on April 7, 2026, Saint Pete MRI confirmed that they contained names, dates of birth, Social Security numbers, driver’s license numbers or state identification numbers, medical information, and/or health insurance information.

Notification letters were mailed to the affected individuals on July 22, 2026, around 17 months after the incident was first identified. The incident is not currently shown on the HHS’ Office for Civil Rights data breach portal, so it is unclear how many individuals have been affected.

Carlyle Senior Care Management Company

Carlyle Senior Care Management Company, a South Carolina-based management company for Carlyle Senior Care independent living, senior living, and skilled nursing care facilities in the state, has reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 4,060 individuals.

There is currently no substitute data breach notice on the Carlyle Senior Care website, and no press release appears to have been issued, so it is unclear what data types were involved. This appears to have been a ransomware attack conducted by the Insomnia ransomware group, which claimed on its data leak site to have stolen data from Carlyle Senior Care of Florence. Insomnia claimed to have notified Carlyle Senior Care about the breach on October 31, 2025, then proceeded to leak the stolen data. Insomnia claimed to have stolen patient records, internal documents, and sensitive information.

SportsMed Physical Therapy

SportsMed Physical Therapy, a physical therapy clinic with locations in New Jersey and Connecticut, has identified unauthorized access to a single email account. The breach was identified on May 8, 2026, and the account was secured. An investigation was launched to determine the individuals affected and the types of data involved.

The review has recently been completed and confirmed that names had been compromised in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information. SportsMed Physical Therapy said it is unaware of any misuse of patient information as a result of the incident. The incident is not currently shown on the HHS’ Office for Civil Rights website, so it is currently unclear how many individuals have been affected.

Lifeways

Lifeways Inc., a nonprofit provider of mental health counseling and addiction services to patients in Idaho and Oregon, identified unauthorized access to an employee’s email account. The email account breach was identified on January 21, 2026, and after securing the account, an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation revealed several employee email accounts had been compromised.

The incident was limited to its email environment. On May 8, 2026, Lifeways confirmed that the exposed information included names, birth dates, Social Security numbers, driver’s license/state identification numbers, financial account numbers, patient account numbers, medical record numbers, diagnoses, treatment and procedure information, prescription information, treatment locations, provider names, Medicare and Medicaid numbers, clinical information, and health insurance information. At the time of issuing notification letters, Lifeways was unaware of any misuse of the exposed information. The Oregon Attorney General was informed that 343 individuals have been affected.

The post Tennessee Pathology Group Announces 170K-record Data Breach appeared first on The HIPAA Journal.

Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches

There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.

Annual data compromises. Source: ITRC

Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.

Victim Count from data compromises. Source: ITRC

As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million of those notices. A mega data breach at Under Armour involved more than 72.7 million notices, while the SoundCloud data breach saw 29.8 million victim notices issued.

There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare. In H1 2026, only 7 healthcare data breaches required more than 1 million notices.

HIPAA-Regulated Entity State Entity Type Type of Breach Individuals Affected
TriZetto Provider Solutions MO Business Associate Hacking/IT Incident 3,433,965
QualDerm Partners, LLC TN Healthcare Provider Hacking/IT Incident 3,117,874
Nacogdoches Memorial Hospital n TX Healthcare Provider Hacking/IT Incident 2,507,073
Navia Benefit Solutions, Inc. WA Business Associate Hacking/IT Incident 2,151,330
Insightin Health, Inc. MD Business Associate Hacking/IT Incident 1,949,534
New York City Health and Hospitals Corporation NY Healthcare Provider Hacking/IT Incident 1,800,000
Xsolis, Inc. TN Business Associate Hacking/IT Incident 1,396,519

While very large data breaches may have been reported in lower numbers in the first half of the year, healthcare data breaches continue to be reported in volume. The ITRC tracking data show 281 healthcare data compromises in the first half of the year, which puts the industry in second spot behind financial services with 387 compromises. The data for 2025 show a slight year-over-year fall in financial services data breaches, from 396 in H1, 2025, and a slight increase in healthcare data breaches, rising from 270 in H1, 2025. Across the 281 healthcare data breaches, more than 11.7 million patients have been affected. Current OCR data (from July 23, 2026) show that number has already more than doubled to over 28.8 million victims, although the total is still well below last year’s H1, 2026 count of 42.8 million healthcare victims.

Data compromises by Industry. Source ITRC

As ITRC has reported for several years, the trend of withholding important information from breach notices has continued. ITRC reports that 76% of all notices failed to include information about the attack vector (1,378 notices). Only 24% of notices contained information about the attack vector – the lowest ever rate since ITRC has been producing its data breach reports. “This opacity prevents consumers, businesses and policymakers from understanding their true risk exposure or taking meaningful preventive action,” explained ITRC. To put that total into perspective, 93% of victim notices included information about the attack vector in 2021.

The ITRC data show a significant increase in insider wrongdoing incidents, with 21 such incidents identified in H1, 2026, compared to just 3 in all of 2025 – a sevenfold increase.  ITRC tracked 14 zero-day attacks in H1 2026, which is close to the total of 17 for all of 2025. While there were only 38 tracked supply chain incidents in H1 2026, they required more than 280.6 million victim notices. “Supply chain cyberattacks alone accounted for 199 of 206 affected entities and 280.6 million of 280.6 million combined victim notices,” explained ITRC in the report.

Cyberattacks accounted for 69.7% of data breaches in H1, 2026, and 92.3% of all victim notices. System and human error accounted for 6.9% of breaches and 0.9% of victim notices. By far the main cause of cyberattacks was phishing/smishing/BEC, with 157 incidents, followed by system & human error (125 incidents), and ransomware attacks (76 incidents), although 402 events remain unclassified due to the lack of transparency about breach causes.  Total cyberattacks are down 7.8% compared to H1, 2025, with ransomware attacks up by 4.1%.

The post Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches appeared first on The HIPAA Journal.

Colorado Behavioral Healthcare Provider Discovers Insider Data Breach

Data breaches have been announced by NAS Recovery Solutions, Entyre Care Massachusetts, Carle Health, and Brown Health Medical Group-MA.

NAS Recovery Solutions

NAS Recovery Solutions, a Lakewood, Colorado-based substance use disorder treatment and behavioral health services provider, has announced a data breach affecting up to 7,000 current and former clients. According to the company’s breach notice, this was an insider breach rather than a hacking incident. The company learned on May 13, 2026, that certain workforce members had downloaded client data without authorization.

The investigation revealed only limited information had been copied, such as first and last names, dates of birth, and telephone numbers; however, since NAS Recovery Solutions is a substance use disorder (SUD) treatment provider, it could be inferred that the individuals were receiving SUD treatment. There are no indications that any other information was obtained by the workforce members. The breach notice does not provide any clue as to why that information was obtained.

NAS Recovery Solutions said it has reviewed workforce access and security controls and is implementing additional safeguards to prevent similar incidents in the future. Additional training has been provided to the workforce on HIPAA and patient privacy, and appropriate corrective action has been taken against the workforce members involved. The sanctions imposed were not disclosed in the notice.

Entyre Care Massachusetts

Entyre Care Massachusetts Inc., a Boston, MA-based home healthcare company, has discovered that an employee accidentally published files containing personal information in a publicly accessible online repository on March 2, 2026. The exposed files were identified on March 12, 2026, and were immediately secured.

The investigation uncovered no evidence to suggest that the files had been accessed or downloaded; however, it was not possible to rule out unauthorized access during the period of exposure. The files only contained limited information, such as names, ages, and Medicaid IDs; however, out of an abundance of caution, the affected individuals have been offered 24 months of complementary credit monitoring and identity theft protection services.

Carle Health

Carle Health, an Illinois nonprofit health system, has confirmed that 1,444 of its patients were affected by a data breach at its vendor Xsolis in January 2026. Xsolis is a vendor that provides an AI-powered software platform to healthcare providers to improve case and utilization management. We have covered the data breach, which affected more than 1.4 million individuals, in this post. Carle Health said the compromised information included names, birth dates, diagnoses, treatment dates and locations, medical record numbers, doctors’ names, Social Security numbers, and health insurance information.

Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts)

Lifespan Physicians Group of Massachusetts Inc., which does business as Brown Health Medical Group-MA, has recently announced that the sensitive data of certain patients has been exposed. According to the notification to the Vermont Attorney General, the impacted data includes names, Social Security numbers, government identification numbers, financial account codes, and health records. The incident affected 86 Vermont residents, but it is currently unclear how many individuals have been affected in total.

The post Colorado Behavioral Healthcare Provider Discovers Insider Data Breach appeared first on The HIPAA Journal.

Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data

The cardiovascular medical practice, Heart Care Centers of Illinois (HCCI), announced on July 18, 2026, that certain patients had some of their personal and protected health information exposed in a phishing attack.

HCCI said it launched an investigation into an unsuccessful phishing attempt and discovered a historical suspicious activity within an employee’s email account on January 15, 2026. Third-party digital forensics experts were engaged to investigate the activity and confirmed that an unauthorized third party gained access to the account between August 22, 2024, and November 6, 2024.

A data analytics firm was engaged to review the account. On June 11, 2026, the review was completed, confirming that the following types of information were present in the account: names, addresses, telephone/fax numbers, Social Security numbers, dates of birth, driver’s license numbers/state identification numbers, payment card information, financial account numbers, passport numbers, diagnosis/condition information, prescription information, treatment information, health insurance information, and provider information.

The affected individuals were notified on July 10, 2026, and complimentary credit monitoring and identity restoration services have been offered. HCCI has reviewed its existing policies and procedures and has taken steps to reduce the risk of similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Madera Community Hospital

Madera Community Hospital in California has notified the California Attorney General about a security incident involving unauthorized access to its network between May 28 and May 29, 2025. The unauthorized access was identified on May 29, 2025, and action was immediately taken to secure its network and prevent further unauthorized access.

Third-party cybersecurity experts were engaged to investigate the incident. No evidence was found to indicate any removal of data; however, the hospital said, “based on subsequent developments, we have reason to believe that a third party acquired files from a portion of its network.” No further information was provided on what that evidence was. The hospital did state that it has not found definitive proof that any data was removed, and none of the impacted data appears to have been published or otherwise shared.

The data review was completed in April 2026, contact information was verified, and notification letters have now been mailed to the affected individuals. Data exposed in the incident includes names, birthdates, contact information, login credentials, government identification numbers (such as Social Security numbers), financial account information, and limited medical information and limited biometric information. The affected individuals have been offered complementary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have potentially been affected.

The post Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data appeared first on The HIPAA Journal.

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients

On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based provider of revenue cycle management services. At the time, the scale of the data breach had yet to be made public, but it has recently been confirmed to be the largest healthcare data breach of the year to date, ahead of the 3.4 million-record data breach at Trizetto Provider Solutions.

According to the breach summary on the HHS’ Office for Civil Rights data breach portal, the Unlimited Technology Systems data breach involved the protected health information of 3,803,750 individuals. While the incident was confirmed in July, it was first identified in October 2025. The threat actor had access to its network between October 5 and October 10, 2025, and potentially exfiltrated files containing patient data (as detailed below). No threat group appears to have claimed responsibility for the cyberattack.

Business associates of healthcare organizations are attractive targets for cybercriminals. If their systems are compromised, hackers can gain access to highly sensitive patient data from many different healthcare companies. Six of the top ten data breaches reported this year occurred at business associates, as did 50% of the largest healthcare data breaches of all time. The proposed update to the HIPAA Security Rule includes several measures to tighten security at business associates and strengthen vendor oversight by HIPAA-covered entities. While planned for a mid-2026 release, the final rule has been delayed, with OCR now expecting to release the final rule by July 2027.

July 23, 2026: Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company

Unlimited Technology Systems LLC (UTS), a Montgomery, Ohio-based revenue cycle management company and practice management software provider, has identified unauthorized activity within a commercial data center that contained the personal and protected health information of patients of its healthcare provider clients.

According to its data breach notification letter, unauthorized activity was identified on October 19, 2025. Assisted by a third-party cybersecurity and digital forensics company, UTS determined that an unauthorized third party may have obtained a copy of files from that environment between October 5 and October 10, 2025.

The data review has recently been completed, and UTS has confirmed that the following types of information may have been involved: name, address, email address, phone number, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned documents such as driver’s license or other government ID documents. UTS said full medical records, medical images, and financial information were not involved.

As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring services for 24 months, and UTS has implemented enhanced security measures to prevent similar incidents in the future.  The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

The post Unlimited Technology Systems Data Breach Affects 3.8 Million Patients appeared first on The HIPAA Journal.

TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries

Data breaches have been announced by TriWest Healthcare Alliance, Texas Medicaid and Healthcare Partnership, the Minnesota Health Insurance Network, and Secure Health Plans of Georgia.

TriWest Healthcare Alliance

TriWest Healthcare Alliance, a contractor that manages care for active duty, retired, and National Guard and Reserve military personnel and their family members under the United States Department of Veterans Affairs VAPCCC program, has shared information on a data breach reported to the HHS’ Office for Civil Rights on May 21, 2026. According to the OCR breach report, the protected health information of 11,848 individuals was potentially compromised in the incident.

The security incident was first identified on April 16, 2026. The forensic investigation confirmed that an unauthorized third party gained limited access to parts of its network and downloaded files containing protected health information. Data compromised in the incident includes names, Department of Defense Benefits Numbers, beneficiaries’ ZIP codes, and health-related information. Only 5 individuals had their addresses, dates of birth, and Social Security numbers stolen.

At the time of issuing notification letters, some of which were sent on July 2, 2026, no misuse of the impacted information had been identified; however, as a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring services for 24 months. Security controls have been enhanced, system monitoring tools have been strengthened, and additional security awareness training has been provided to its workforce.

Texas Medicaid and Healthcare Partnership

Texas Medicaid and Healthcare Partnership (TMHP), a state Medicaid contractor, has recently reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 2,045 individuals.  According to the TMHP substitute data breach notice, this was a fraud-related incident that involved unauthorized access to certain internal systems between February 5, 2026, and March 26, 2026.

When the unauthorized access was detected, immediate action was taken to contain the incident and secure its network, and additional security measures have been implemented to harden security. The forensic investigation determined on April 20, 2026, that personal and protected health information of 1,828 Medicaid clients and 217 healthcare providers had been exposed.

For Medicaid clients, the data compromised in the incident included full names, addresses, dates of birth, Social Security numbers, Medicaid numbers, Medicaid benefits information, Medicaid card information, and health information. Healthcare provider information included full names, addresses, emails, medical license information, financial information, driver’s license numbers, Social Security numbers, tax identification numbers, and other provider enrollment management system information.

Notification letters were mailed to the affected individuals on June 18, 2026, who have been offered complimentary identity theft protection and identity recovery services. TMHP said that at the time of issuing notifications, no information had been found to indicate any actual or attempted misuse of the impacted information.

Minnesota Health Insurance Network

Minnesota Health Insurance Network, a Burnsville, MN-based health insurance brokerage, has started notifying individuals about a recent security incident that exposed personal and protected health information. The security incident was identified on March 17, 2026, and its forensic investigation determined that there had been unauthorized access to parts of its network between March 16 and March 17, 2026, during which time files were exfiltrated from its network.

The affected data has been reviewed and found to include names, dates of birth, Social Security numbers, driver’s license/state ID numbers, other government-issued ID numbers, financial account numbers, credit/debit card information, diagnosis and treatment information, and health insurance information. Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While regulators have been notified, the incident is not currently listed on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.

Secure Health Plans of Georgia

Secure Health Plans of Georgia (Secure Health), a provider of administrative services, care management, and healthy lifestyle programs to employers with self-funded health benefit plans, is reviewing files that were exposed in a recent cybersecurity incident. The incident was identified on February 12, 2026, and the forensic investigation confirmed unauthorized access to its systems on or before February 3, 2026, until February 12, 2026. During that time, files containing individuals’ protected health information may have been viewed or copied. Secure Health has not yet confirmed the exact types of information exposed in the incident, although protected health information was exposed.

The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 individuals. The total will be updated when the data review is concluded, and notification letters will be mailed stating the types of data involved. Secure Health has taken steps to strengthen security to prevent similar incidents in the future.

The post TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries appeared first on The HIPAA Journal.

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Investments has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident first identified on July 4, 2026. Clover Health Investments is a publicly traded health insurer that provides Medicare Advantage plans, directly contracts with the U.S. government, and manages care for Medicare beneficiaries in 11 states. The company also provides technology and software tools to physicians.

Unusual login activity was identified, and its forensic investigation confirmed that a hacker had accessed three employee email accounts after the employees had been tricked by social engineering into disclosing their credentials. Clover Health activated its incident response plan to contain the incident and believes that unauthorized access has been terminated.

Clover Health said the compromised accounts belonged to non-managerial health plan employees who were responsible for handling member visit scheduling and broker-facing sales work. The accounts did not have permissions to access corporate financial or claims systems, but they could access some personal and protected health information.

The volume of exposed data has yet to be determined, and Clover Health has not publicly confirmed whether sensitive data was exfiltrated from its systems. Clover Health has reported the incident to law enforcement and is working with third-party cybersecurity experts to investigate the incident and review the information that was exposed, viewed, or exfiltrated.

Clover Health said it does not believe that the incident has had a material impact on business operations, its financial condition, or results of operations. Notifications will be mailed to the affected individuals if it is determined that HIPAA-protected data has been exposed or stolen, and Clover Health has confirmed that steps are being taken to strengthen security to prevent similar incidents in the future.

The post Clover Health Assessing Impact of Social Engineering Incident appeared first on The HIPAA Journal.