HIPAA Breach News

Data Breaches Announced by Gastroenterology Practice and Hospice Companies

Data breaches have been announced by Gastroenterology & Hepatology of Central New York, Three Oaks Hospice, and Doctor’s Choice Home Care.

Gastroenterology & Hepatology of Central New York

Gastroenterology & Hepatology of Central New York, a medical practice specializing in digestive disorders and liver disease with locations in Liverpool and Syracuse, has started notifying patients about a cybersecurity incident first identified on March 6, 2026. Immediate action was taken to contain the threat, and third-party cybersecurity and digital forensics experts were engaged to investigate the activity. The forensic investigation confirmed unauthorized access to certain systems and the exfiltration of files from its network on or around March 6, 2026.

The stolen files contained full names, addresses, phone numbers, dates of birth, Social Security numbers, and medical record numbers. The affected individuals were notified on September 17, 2026, and complimentary credit monitoring and identity theft protection services have been made available. At the time of issuing the notifications, no misuse of the affected data had been identified. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Three Oaks Hospice / Elevation Hospice

Dallas, Texas-based Three Oaks Hospice, a medical service provider specializing in hospice care, identified unauthorized access to its email environment on August 8, 2025. Assisted by cybersecurity experts, Three Oaks Hospice determined that limited email accounts had been accessed by an unauthorized third party and personal information was exposed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Three Oaks Hospice, along with its sister companies Agape Hospice Care, Elevation Hospice of Colorado, and Sage Hospice of Arizona, provides hospice and palliative care services in 9 U.S. states. It took more than a year for its affiliated hospices to be notified that they had been affected. The affected hospices were notified on August 17, 2026, and the affected individuals were notified on September 17, 2026.

Data exposed in the incident includes names, dates of birth, Social Security numbers, driver’s license numbers, medical information, and health insurance information. The number of affected individuals has yet to be publicly disclosed. The Texas attorney general was notified that 3,034 Texas residents were affected.

Doctor’s Choice Home Care (WellSky)

Houston, Texas-based Doctor’s Choice Home Care, a home care and hospice provider, has been affected by a data breach at its electronic medical record vendor, WellSky. WellSky identified the incident on July 21, 2026, and its forensic investigation determined that an unauthorized third party gained access to a WellSky clinical user account within the electronic medical record system between June 5, 2026, and July 24, 2026.

Data exposed and potentially stolen included names, addresses, birth dates, Social Security numbers, scheduling information, clinical information, treatment information, and health insurance information. Doctor’s Choice Home Care confirmed that its internal systems were unaffected. The incident is not yet shown on the HHS’ Office for Civil Rights website. The Texas Attorney General was notified that 14,333 Texas residents have been affected.

The post Data Breaches Announced by Gastroenterology Practice and Hospice Companies appeared first on The HIPAA Journal.

Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident

Texas-based Oculus Pathology has disclosed a data breach affecting more than 20,000 patients. Data breaches have also been announced by Paradigm Healthcare Services in California and LeMaitre Vascular in Massachusetts.

Oculus Pathology, Texas

Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology laboratory that provides services to hospitals, ambulatory surgery centers, and physician groups, has notified 20,040 patients that some of their protected health information has been exposed and potentially stolen.

On April 1, 2026, suspicious activity was identified related to an employee’s email account. Action was taken to secure its email system, and third-party cybersecurity specialists were engaged to investigate the activity and determine the nature and scope of the incident. The investigation determined that the account had been accessed by an unauthorized third party, and other email accounts were also compromised between March 31, 2026, and April 2, 2026.

The affected email accounts were reviewed to determine the individuals affected and types of data involved. The data review determined that personally identifiable information and protected health information were exposed, including names, dates of birth, Social Security numbers, driver’s license/ state identification numbers, individual tax identification numbers, financial account numbers (with or without access information), payment card numbers (with or without access information), clinical information, provider names, health insurance information, diagnoses, prescription information, medical treatment/procedure information, medical record numbers, Medicare numbers, and patient IDs. No misuse of the exposed information has been detected; however, the affected individuals have been advised to remain vigilant against identity theft and fraud.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Paradigm Healthcare Services, California

Paradigm Healthcare Services, a San Francisco, California-based third-party school Medi-Cal billing company, identified unauthorized access to its local computer network on October 13, 2025. Third-party cybersecurity professionals were engaged to investigate the incident and determine the nature and scope of the activity.

The investigation confirmed that the unauthorized access was limited to its local network between October 8, 2025, and October 15, 2025. The online service documentation and billing platform and Student Health Network were not affected. Data exposed in the incident included names, dates of birth, gender information, and Medi-Cal member identification numbers. The data breach has been reported to the California Attorney General. The number of affected individuals has yet to be publicly disclosed.

LeMaitre Vascular, Massachusetts

LeMaitre Vascular, a Burlington, Massachusetts-based medical device company that makes products for treating peripheral vascular disease, has notified regulators about a breach of patient information. The company experienced a network disruption that confirmed that its network was accessed by an unauthorized third party, who may have viewed or obtained sensitive information. It is unclear when the breach occurred and when it was detected; however, the review of the exposed files was completed on September 14, 2026.

Data compromised in the incident included names, Social Security numbers, USCIS Alien Registration numbers, driver’s license numbers, financial account numbers, and medical records. The number of affected individuals has yet to be publicly disclosed, although almost 1,000 Massachusetts residents are known to have been affected.

The post Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident appeared first on The HIPAA Journal.

Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members

Data breaches have been announced by United Language Group in Minnesota, Desert Pulmonary & Sleep Consultants in Arizona, and Azle Cube Smiles in Texas.

United Language Group, Minnesota

United Language Group, LLC, a Minneapolis, Minnesota-based provider of translation, localization, and interpretation services, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 4,649 individuals. Suspicious activity was identified within certain parts of its network on July 9, 2025. The forensic investigation confirmed that parts of its network were accessed by unauthorized individuals between July 8, 2025, and July 9, 2025

According to its notification letters, the breach involved unauthorized access to data provided by clients UnitedHealthcare and UnitedHealthcare Global related to claims, billing, and other member/provider communications. The impacted data included names, contact information, health insurance information, health information ( diagnoses, treatment information, prescriptions, and provider and related information), Social Security numbers, financial account information, driver’s license information, passports, military IDs, residence permit information, and financial account information, including credit or debit card numbers. The types of data involved varied from individual to individual.

Additional monitoring tools have been implemented, and security measures will continue to be assessed and enhanced. The affected individuals have been offered 24 months of credit monitoring and identity theft protection services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Desert Pulmonary & Sleep Consultants, Arizona

Desert Pulmonary & Sleep Consultants, a Gilbert, Arizona-based medical practice specializing in pulmonary disease and sleep medicine, has notified the HHS Office for Civil Rights about a data privacy incident. A former physician partner left Desert Pulmonary & Sleep Consultants to practice elsewhere. On or around July 13, 2026, Desert Pulmonary & Sleep Consultants identified suspicious activity related to the physician. An investigation was launched, which revealed the former partner copied patient data during his transition period, starting on June 29, 2026. Over the course of three days, he accessed more than 3,000 names and addresses, as well as protected health information of patients – information collected as part of patient visits and information provided by other medical service providers.

The data was accessed with a view to contacting the patients by mail to inform them about his new practice. The data was disclosed to another individual to assist with the mailing of the letters. The physician was contacted by legal counsel of Desert Pulmonary & Sleep Consultants and was informed not to engage in such activity; however, no response was received from the physician or his legal counsel.

Azle Cube Smiles, Texas

Azle Cube Smiles, a dental practice in Azle, Texas, has notified the Texas Attorney General about a data security incident affecting 2,940 Texas residents. On May 26, 2026, the practice was notified by its IT support company about suspicious activity related to remote access session hosts. Its remote desktop web services infrastructure was locked down, including terminating all external connections. An investigation was launched to determine the nature and scope of the activity, and it was quickly determined that a cyberattack had occurred.

An office-wide password reset was performed, and no further unauthorized access has been detected.  Azle Cube Smiles said it was rapidly able to restore its patient record platform. The investigation determined that some patient data was potentially accessed or copied, including names, addresses, dates of birth, driver’s license numbers, government-issued IDs, and medical information. Financial information was not involved, nor was information about the dental care provided to patients. Azle Cube Smiles said its IT support company has been conducting regular security inspections and is continuously monitoring its systems to protect against further breaches.

The post Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members appeared first on The HIPAA Journal.

Hacking Group Claims Attack on Cedar County Memorial Hospital

A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported by Next Level Medical in Texas and Grafton City Hospital in West Virginia.

Cedar County Memorial Hospital

Cedar County Memorial Hospital in El Dorado Springs, Missouri, disclosed on August 23, 2026, that it was the victim of a cyberattack that disrupted its IT systems. The affected computer systems were taken offline, and network access was paused to ensure the integrity of hospital systems. The measures taken to contain the attack and protect its systems resulted in an outage of its patient portal and electronic health record system, and the latter affected all hospital and Medical Mall Clinic services. To ensure patient safety, the emergency department was placed on partial diversion since medical imaging systems were unable to transmit medical images to radiologists.

An update was issued by Cedar County Memorial Hospital on August 28, 2026, confirming that the hospital had returned to routine operations after internal and external teams had completed all system reviews and safety checks. The EHR system was brought back online after two weeks offline, and manually recorded information is now being transferred to the EHR.

In a September 10, 2026, update, Cedar County Memorial Hospital explained that the investigation and review of exposed data are continuing, and it has yet to be confirmed to what extent patient data had been compromised. When the investigation and data review processes are completed, patients will be notified if their personal and/or protected health information was exposed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

A relatively new cyber extortion and ransomware group called Wallstreet claimed responsibility for the attack. The group added Cedar County Memorial Hospital to its dark web data leak site in late August and threatened to publish data stolen in the attack. The group’s claim has yet to be verified.

Next Level Medical

Next Level Medical, a Texas-based primary and urgent care provider with more than 45 clinics across the state, has recently disclosed a data security incident that was first identified on July 11, 2026. Steps were taken to secure its environment and investigate the activity; however, further suspicious activity was identified on July 29, 2026. Assisted by third-party cybersecurity experts, further steps were taken to secure its environment and bring systems back online safely and securely.

Next Level Medical determined that an unauthorized third party had accessed its network and copied files, some of which contained patient information. The investigation and file review are ongoing to determine the extent to which patient data was involved and the individuals affected. Next Level Medical said that the initial findings of the investigation indicate that data compromised in the incident includes names, dates of birth, demographic information, Social Security numbers, health information, and health insurance information. This appears to have been a data theft and extortion incident by the PEAR threat group. Ransomware Live identified a listing on the PEAR data leak site; however, it appears to have now been removed.

Grafton City Hospital

Grafton City Hospital (now Vandalia Health Grafton Hospital), a critical access hospital in West Virginia, has notified 1,215 individuals that some of their protected health information was exposed in a recent cybersecurity incident. The incident occurred at Monongalia County General Hospital Company, part of the Vandalia Health network, and was due to a phishing attack.

The incident was detected on May 6, 2026, the same day of the attack, and the investigation determined that several email accounts were compromised. The investigation was completed in late June and confirmed that data compromised in the incident included names, birth dates, addresses, phone numbers, Social Security numbers, health information, and health insurance information. Technical safeguards have been enhanced to prevent similar incidents in the future, and the affected individuals have been offered two years of complimentary credit monitoring services.

The post Hacking Group Claims Attack on Cedar County Memorial Hospital appeared first on The HIPAA Journal.

xHealth Data Breach Affects 118,000 Individuals

A data breach at zHealth, a practice management and EHR software provider, has affected 118,000 individuals. Data breaches have also been announced by Bridgeway Benefit Technologies, Longview ER Operations, and HealthStream.

zHealth

zHealth, Inc., a San Francisco, California-based cloud-based practice management and electronic health records (EHR) software provider, has disclosed a cybersecurity incident that may have involved data being acquired by an unauthorized third party. According to the breach notice provided to the California Attorney General, zHealth became aware that certain information may have been copied on or around June 15, 2026. An investigation was launched, which confirmed that its network had been accessed by an unauthorized third party between January 20 and January 21, 2026. The review of the impacted data was completed on September 3, 2026.

The substitute breach notice on the zHealth website states that the impacted information varies from individual to individual and may include names, medical information, and health insurance information. The affected individuals have been offered single-bureau credit monitoring, credit report, and credit score services for 12 months. Data privacy and security policies and procedures have been reviewed and enhanced to prevent similar incidents in the future. The incident is not currently shown on the HHS’ Office for Civil Rights website; however, the Oregon Attorney General has been informed that the data breach affected 118,563 individuals.

Bridgeway Benefit Technologies

Bridgeway Benefit Technologies, a Baltimore, Maryland-headquartered third-party health plan administrator that provides software for managing multiemployer health, welfare, and retirement benefits, has notified the HHS Office for Civil Rights about a breach of the protected health information of 9,268 individuals. The company explained that it experienced a cybersecurity incident involving an employee email account that exposed data provided to the company in connection with the administration services it provides to its clients. The unauthorized activity was identified on May 18, 2026, and the forensic investigation determined that the account was accessed between March 5, 2026, and May 19, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Bridgeway Benefit Technologies confirmed that the breach was limited to its own email system. No client systems were compromised in the incident. The exact types of data involved are detailed in the individual notification letters. Attorneys General have been notified that the compromised data includes Social Security numbers. Steps have been taken to improve security to prevent similar incidents in the future, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

Longview ER Operations

Longview ER Operations, LLC, doing business as Hospitality Health ER, a full-service emergency room operator with facilities in Longview, Tyler, and Galveston, Texas, has experienced a cybersecurity incident that involved patient data. Suspicious network activity was identified on July 22, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity professionals.

The investigation confirmed that an unauthorized third party had accessed its network and copied files. The file review is ongoing, and patients will be notified by mail as soon as the review is concluded. The notification letters will explain the types of information involved for each patient. The incident was limited to the Longview network. The facilities in Tyler and Galveston were unaffected. The number of affected individuals has not yet been determined. The incident has been reported to the HHS’ Office for Civil Rights using an estimate of at least 501 individuals. The total will be updated when the review is completed.

HealthStream

HealthStream Inc., a Nashville, Tennessee-based healthcare technology company that provides software and training solutions for the healthcare industry, has notified the Massachusetts Attorney General about a recent security incident. The letter provides no information about the nature of the data breach, other than stating that some “information” was involved and complimentary credit monitoring and identity theft protection services have been offered for 24 months. “Due to requirements imposed by Massachusetts law, we are unable to provide you with the details about the nature of this incident,” states the notification letter.

The notification letters appear to be about a cybersecurity incident reported to the U.S. Securities and Exchange Commission (SEC) on July 29, 2026. According to the Form 8-K filing, the incident involved unauthorized access to corporate file servers and does not appear to have involved protected health information. Data compromised in the incident included employee data, customer and vendor billing data, and legal information. Around 75 of its credentialing customers have been affected. HealthStream said no customer-facing systems were involved, there was no file encryption, operations were not disrupted, and the incident is unlikely to affect its financial position or results.

The post xHealth Data Breach Affects 118,000 Individuals appeared first on The HIPAA Journal.

Nationwide Home Health Care Provider Announces Major Data Breach

Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir Medical Corporation in California, and Central Arkansas Pediatrics.

LHC Group

LHC Group, a Lafayette, Louisiana-based provider of home health, hospice, and home- and community-based services in 28 U.S. states and the District of Columbia, has been affected by a data security incident involving a third-party technology vendor. The unnamed vendor assisted LHC Group with referral management, care coordination, and clinical workflows, and the provision of those services required access to patients’ personal and protected health information.

LHC Group said it became aware on April 7, 2026, that an employee may have fallen victim to a voice phishing attack. LHC’s vendor subsequently reported suspicious activity within the vendor’s platform associated with an LHC user account. LHC worked closely with its vendor to secure systems and investigate the activity, and third-party cybersecurity experts were engaged to assist with those processes. LHC Group determined that the threat actor stole credentials in the vishing attack and accessed a large volume of files on the vendor’s platform, including files containing patients’ protected health information.  The threat actor had access from April 7, 2026, through April 15, 2026.

The impacted data was reviewed, and LHC started confirming the identities of the impacted individuals on July 9, 2026. The data types involved varied from individual to individual and included full names, addresses, dates of birth, demographic information, clinical summaries, treatment plans, diagnosis codes, dates of service, physician/provider information, Medicare/Medicaid numbers, health insurance information, and, in limited cases, Social Security numbers and/or financial information.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

LHC Group said it disabled the compromised account, reviewed security measures to identify potential areas for improvement, enhanced authentication and monitoring, and strengthened other security controls. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for two years.

It is currently unclear how many individuals have been affected in total, but based on the breach notifications sent to state attorneys general, more than 28,000 individuals have been affected. The total is likely to be considerably higher, as not all state attorneys general publicly disclose how many state residents have been affected. This is the second data breach to be announced by LHC Group this year. LHC Group was also impacted by a breach at vendor Doctor Alliance.

Provident Behavioral Health

Provident Behavioral Health, a nonprofit provider of mental health care services in St. Louis, Missouri, has notified certain patients about a potential breach of their protected health information. Suspicious activity was identified within its computer network on April 3, 2026. The affected systems were isolated, and a third-party cybersecurity firm was engaged to investigate the activity and determine the nature and scope of the activity.

The investigation confirmed that an unauthorized third party had accessed its network and acquired data stored on the impacted systems. The data review concluded on September 4, 2026, when it was confirmed that patient data was present in the copied files, including names, contact information, demographic information, dates of birth, Social Security numbers, driver’s license numbers/state ID numbers, medical information, and health insurance information.

Provident Behavioral Health has confirmed there has been no further unauthorized access, and additional security measures have been implemented to prevent similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident has been reported to state attorneys general and the HHS’ Office for Civil Rights; however, it is currently unclear how many individuals have been affected.

Central Arkansas Pediatrics

Central Arkansas Pediatrics, P.A., a Conway, Arkansas-based medical practice that provides healthcare services for infants, children, and adolescents, has notified 1,500 current and former patients about a recent hacking incident that involved some of their personal and protected health information.

The data breach has been reported to the Department of Health and Human Services’ Office for Civil Rights; however, there is currently no substitute breach notice on the practice website, and no press release appears to have been released, so the exact types of data impacted are unknown, and the exact nature of the hacking incident has yet to be confirmed. This appears to have been a ransomware attack by a prolific ransomware-as-a-service group known as The Gentlemen. The group has conducted many attacks on healthcare providers and added Central Arkansas Pediatrics to its dark web data leak site on June 8, 2026, claiming data was exfiltrated in the attack

Elixir Medical Corporation

Elixir Medical Corporation, a Milpitas, California-based medical device company specializing in products for treating heart and vascular disease, has notified the California Attorney General about a recent security incident that exposed the data of current and former employees, consultants, and certain beneficiaries and dependents.

According to the notice, an unauthorized third party gained access to parts of its computer network between July 20, 2026, and July 21, 2026. The investigation confirmed that human resources files were exposed in the incident, which contained names and Social Security numbers, along with some or all of the following: driver’s license number, credit/debit card number, medical information, and/or direct deposit bank account information.

The affected individuals have been notified, and complimentary credit monitoring and identity theft protection services have been offered. Additional safeguards have been implemented, along with further security awareness training for the workforce. The number of affected individuals has not yet been publicly disclosed.

The post Nationwide Home Health Care Provider Announces Major Data Breach appeared first on The HIPAA Journal.

Hacking Incident Affects 46,000 Hawaii Family Dental Patients

A hacking incident at Hawaii Family Dental has affected almost 46,000 individuals. Data breaches have also been announced by Life Bridges in Tennessee, Westchester Institute for Human Development in New York, Community Health Care in Ohio, and Shoshone Medical Center in Idaho.

Hawaii Family Dental

Hawaii Dental Group, Inc., doing business as Hawaii Family Dental, a Honolulu-based operator of a dozen dental clinics in Hawaii, has started notifying 45,853 individuals about a July 2026 hacking incident that involved unauthorized access to their personal and protected health information.

Suspicious activity was identified within its computer network on July 20, 2026. The forensic investigation confirmed that an unauthorized third party accessed its systems between July 19 and July 20, 2026, including systems where patient information was stored. Files exposed and potentially copied in the incident included names, phone numbers, addresses, email addresses, dates of birth, medical and dental treatment information, and health insurance information. Patients were informed that financial information and Social Security numbers were not involved.

Hawaii Family Dental is reviewing and enhancing its data privacy and security safeguards to better protect against similar incidents in the future. While the name of the hacking group was not disclosed, the Qilin data theft and extortion group claimed responsibility for the attack and maintains that it exfiltrated sensitive data.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Life Bridges

Life Bridges, Inc., a Cleveland, Tennessee-based provider of residential, medical, and community support for individuals with intellectual and developmental disabilities, has reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 5,194 individuals.

In its substitute data breach notice, Life Bridges explained that unauthorized activity was identified within its computer systems on June 22, 2026. Containment measures were deployed, systems were taken offline, passwords were changed, and third-party cybersecurity experts were engaged to investigate the activity. The investigation confirmed that its systems were accessed by an unauthorized third party between June 17, 2026, and June 22, 2026, during which time files containing protected health information were copied from its systems.

The data review confirmed that the compromised information included names, addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnosis/condition information, lab results, treatment information, dates of service, insurance claims information, financial account information, debit card information, medical record numbers, Medicare numbers, Medicaid numbers, and managed care organization numbers. The types of data involved varied from individual to individual.

At the time of issuing notification letters, no misuse of the affected information had been identified. Life Bridges has confirmed that steps have been taken to reduce the risk of similar incidents in the future.

Westchester Institute for Human Development

Westchester Institute for Human Development, Inc., a Valhalla, New York-based provider of support services for individuals with disabilities and vulnerable children, has reported a breach of the protected health information of 938 individuals. On or around April 8, 2026, unauthorized activity was identified within its email environment. Steps were immediately taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed that an unauthorized third party had access to certain files within its environment between March 23, 2026, and April 14, 2026.

The file review found that the exposed data included names, Social Security numbers, driver’s license numbers, dates of birth, dates of medical service, health insurance policy numbers, provider information, medical condition/diagnosis, treatment information, medical record numbers, Medicare/ Medicaid numbers, financial account information, patient account numbers, full face photographs, and referral information. The types of information involved varied from individual to individual.

Westchester Institute for Human Development said the affected individuals have been notified, and it will continue to evaluate and modify its security measures to enhance the privacy and security of the information it maintains.

Community Health Care

Community Health Care, Inc., a healthcare provider with 19 practice locations in Northeastern Ohio, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on June 12, 2026. The incident was identified quickly and contained, limiting the unauthorized access to a single email account.

The affected account was found to contain the protected health information of 808 individuals, including names, phone numbers, dates of birth, dates of service, provider names, diagnostic/treatment information, and health insurance information. At the time of issuing notification letters, no misuse of the affected information had been identified. As a precaution, the affected individuals have been advised to remain vigilant against identity theft and fraud. Since the incident was identified, Community Health Care said it has been working with cybersecurity experts to further strengthen its existing, significant safeguards.

Shoshone Medical Center

Shoshone Medical Center, a Kellogg, Idaho-based critical access hospital, has identified unauthorized access to an employee’s email account. The unauthorized activity was identified on or around May 27, 2026, and an investigation was launched to determine the nature and scope of the activity.

On July 29, 2026, Shoshone Medical Center confirmed that personal and protected health information had been exposed, including names, addresses, dates of birth, phone numbers, patient identification numbers, medical record numbers, Medicare/Medicaid numbers, diagnosis/treatment information, treatment cost information, admission/discharge dates, and health insurance information. Notification letters have been mailed to the 553 affected individuals, and steps have been taken to reduce the risk of similar incidents in the future.

The post Hacking Incident Affects 46,000 Hawaii Family Dental Patients appeared first on The HIPAA Journal.

Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data

The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).

According to the September 8, 2026, filing, Veradigm recently learned that one of its third-party vendors had experienced a cybersecurity incident that impacted a small number of Veradigm’s customers. Veradigm explained that a threat actor obtained credentials from the vendor’s environment for a Veradigm Application Programming Interface (API) used for customer services. The threat actor was able to use the access to copy patient data.

The threat actor only had access to the API, and no other parts of its network were compromised, including servers, databases, or other systems. Veradigm determined that data stolen in the incident included the personal information of patients, which for certain patients may have involved their Social Security numbers; however, the company has determined that clinical and medical information was not involved and remained secure. As a precaution against data misuse, Veradigm is offering the affected individuals complimentary credit monitoring services.

The investigation is ongoing, and Veradigm has yet to publicly disclose how many individuals have been affected. The company said the incident did not impact its operations, and while the extent of any potential liabilities associated with the incident has not yet been determined, the company does not believe the incident is reasonably likely to have a material impact on the company’s business, operations, financial condition, or results of operations.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Veradigm did not disclose the name of the threat actor behind the attack, which appears to be a prolific threat group called The Gentlemen. The Gentlemen added Veradigm to its dark web data leak site on September 5, 2026. The posting alleges that data exfiltrated in the attack includes names, addresses, phone numbers, email addresses, and other personally identifiable information, and that 3.5 million patient records have been obtained. A threat has been issued to publish the stolen data if the ransom is not paid.

The post Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data appeared first on The HIPAA Journal.

Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider

Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by Crystal Coast Pain Management, Golden State Orthopedics & Spine, Gardiner Family Chiropractic, and BestCare Treatment Services.

Interim HealthCare of Oklahoma City

Interim HealthCare, a home healthcare provider operating in 40 U.S. states, has been added to the data leak sites of two ransomware groups. The first listing was added to the Genesis ransomware group’s data leak site on August 10, 2026. Genesis claimed to have exfiltrated data in the incident and threatened to publish it if the ransom was not paid. Genesis claims the stolen data relates to Interim Healthcare of Oklahoma and Tulsa, and that 1TB of data was exfiltrated, including medical records, healthcare data, personal data, patient lists, clinical data, and company data. While a list of the compromised files was added to the data leak site, the data allegedly stolen has yet to be published.

Then on August 21, 2026, a second ransomware group listed Interim HealthCare as one of its victims. Anubis claims to have exfiltrated 530 GB of data in the attack, including “financial information about franchisees, details of internal and external audits, discussions of operational issues, as well as memoranda covering all kinds of day-to-day business matters.” Samples of the stolen data were added to the listing, and the stolen data has been published, indicating the ransom was not paid.

While Interim HealthCare has yet to confirm the validity of either claim, Interim HealthCare of Oklahoma City, Inc. reported a network server hacking incident to the HHS’ Office for Civil Rights on July 31, 2026, using a placeholder estimate of 500 affected individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Crystal Coast Pain Management

Crystal Coast Pain Management in North Carolina, a division of East Carolina Anesthesia Associates ECAA), has started notifying patients that some of their personal and protected health information was obtained by an unauthorized third party in a cybersecurity incident earlier this year.

Suspicious network activity was identified on or around January 11, 2026, and third-party digital forensics and cybersecurity experts were engaged to investigate the activity. On April 20, 2026, it was determined that files containing patient information had been copied by the attackers. The file review was completed on June 24, 2026, when it was confirmed that the stolen data included first and last names, dates of birth, medical information, and Social Security numbers.

The cybersecurity experts confirmed the security of its network; however, as a precaution, all affected systems were wiped and rebuilt, and additional security measures have been implemented. No evidence has been found to indicate any misuse of the affected data, but as a precaution, the affected individuals have been offered single-bureau credit monitoring, credit report, and credit score services. A ransomware group called Devman 2.0 claimed it was behind the attack.

Golden State Orthopedics & Spine

Golden State Orthopedics & Spine (GSOS), an orthopedics practice with 13 locations in the San Francisco Bay Area in California, has announced a recent cybersecurity incident. Suspicious network activity was identified on July 2, 2026, and a third-party team of forensics experts was engaged to assist with the investigation and determine the nature and scope of the activity.

GSOS confirmed that its network had been accessed by an unauthorized third party, who may have viewed or obtained files containing patient information. The data review confirmed that the exposed data included first and last names, addresses, dates of birth, Social Security numbers, health insurance information, and medical diagnosis information.

The review of the affected data is ongoing, and the number of affected individuals has yet to be disclosed. GSOS is reviewing its data security policies, procedures, and practices and is taking steps to prevent similar incidents in the future. This appears to have been a ransomware or data theft and extortion incident. A ransomware group called Brain Cipher claimed responsibility for the attack, in which it alleged that 150 GB of data was stolen.

Gardiner Family Chiropractic

Gardiner Family Chiropractic, a chiropractic clinic in Gardiner, Maine, has notified the HHS’ Office for Civil Rights about a network server hacking incident that has affected up to 5,000 patients. Suspicious activity was identified within its computer network on July 17, 2026. An investigation was launched, which confirmed unauthorized network access and the exposure of patient data. Data potentially compromised in the incident includes names, contact information, birth dates, health information, and health insurance/Medicaid information.

According to the substitute breach notice, this was a ransomware attack involving file encryption and data theft. A ransom demand was received; however, the attack was blocked, and the ransom was not paid. The Interlock ransomware group claimed responsibility for the attack. Gardiner Family Chiropractic has taken several steps in response to the attack to strengthen security. In addition to wiping the affected devices and purchasing new computers for its employees, security policies, procedures, and practices have been reviewed, additional security measures have been implemented, and special training has been provided to its workforce on ransomware.

BestCare Treatment Services

BestCare Treatment Services, Inc., an Oregon-based behavioral healthcare provider, has experienced a data security incident involving unauthorized access to parts of its network containing patient information. Unauthorized network activity was identified on June 15, 2026, and a third-party cybersecurity firm was engaged to assist with the investigation and confirm the security of its network.

The investigation confirmed that files had been exposed containing names, dates of birth, contact information, demographic information, medical information, and other patient identifying information. Notification letters were mailed to the affected individuals on August 10, 2026. The data breach was recently reported to the HHS Office for Civil Rights as affecting 4,216 individuals.

The post Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider appeared first on The HIPAA Journal.