HIPAA Breach News

Data Breaches Announced by Five HIPAA-Regulated Entities

Data breaches have recently been announced by the Women’s Center for Radiology in Florida, Optalis Management Solutions in Michigan, the Association for Neurologically Impaired Brain Injured in New York, the Cardiovascular Institute of New England in Rhode Island, and the Kubota Tractor Corporation in Texas.

Women’s Center for Radiology, Florida

Women’s Center for Radiology, a Florida-based women’s radiology practice with two centers in Orlando, has notified 66,422 patients about a data security incident identified on April 29, 2026. Assisted by third-party cybersecurity specialists, the Women’s Center for Radiology determined that an unauthorized third party had access to its network between April 26, 2026, and April 28, 2026, and accessed or downloaded files containing patient information.

After securing its network, the files were reviewed and found to contain patient information such as names, addresses, dates of birth, contact information, diagnosis/condition information, lab test results, treating/referring physician names, medical record numbers, driver’s license numbers, and health insurance information. Data privacy and security policies, procedures, and processes are being reviewed to reduce the likelihood of similar incidents in the future. While data misuse has not been identified, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

Optalis Management Solutions, Michigan

Optalis Management Solutions, a Michigan-based management company that operates Optalis Health & Rehabilitation’s skilled nursing, rehabilitation, assisted living, and independent living facilities, has notified 13,723 individuals about a breach of some of their protected health information. Suspicious activity was identified within its computer network, and the investigation confirmed unauthorized access occurred between April 14, 2025, and April 19, 2025. After a breach was confirmed by third-party cybersecurity specialists, a document review was initiated to determine the individuals and data types involved. That process concluded on June 10, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Data potentially viewed or obtained in the incident included full names in combination with one or more of the following: Social Security number, driver’s license number/state ID number, credit/debit card information, financial account information, diagnosis and treatment information, and/or health insurance policy number. Notifications were mailed to the affected individuals on June 29, 2026, and individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services.

Kubota Tractor Corporation, Texas

Kubota Tractor Corporation, a Japanese company that makes agricultural and construction equipment, has recently confirmed that hackers gained access to certain parts of its network earlier this year. The forensic investigation determined that its network was first compromised on March 16, 2026, and the hackers maintained access for more than a month. The unauthorized access was detected and blocked on April 20, 2026. The company, which has its U.S. HQ in Grapevine, Texas, determined that this was a reportable breach under HIPAA, as the incident involved unauthorized access to the protected health information of beneficiaries of its Employee Welfare Benefit Plan.

Employee data potentially compromised in the incident includes names in combination with one or more of the following: Social Security number, date of birth, taxpayer identification number, driver’s license or other government-issued identification number, financial account information for direct deposit, payment card information for corporate cards, benefit enrollment information, and limited claims information. For dependents of employees, the exposed data may have included names in combination with one or more of the following: Social Security number, date of birth, benefit enrollment information, and limited claims information. Notification letters were mailed to the 5,891 affected individuals on June 30, 2026, and complimentary identity monitoring services have been offered.

Cardiovascular Institute of New England, Rhode Island

The Cardiovascular Institute of New England, a heart care practice with seven locations in Rhode Island, started mailing notification letters to patients on July 28, 2026, about a data security incident identified on or around February 12, 2026. Suspicious activity was identified within its email environment, and the investigation confirmed unauthorized email access, which may have resulted in patient data being viewed or acquired.

The review of the affected email accounts was completed on or around July 14, 2026, when the practice learned that names, phone numbers, dates of birth, financial account numbers, medical information, medical diagnoses, treatment information, treatment locations, clinical information, prescription information, and medical insurance provider information had been exposed. No evidence has been found to suggest that any patient data has been misused.

Email security policies, procedures, and security measures are being reviewed, and steps are being taken to reduce the risk of similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

The Association for Neurologically Impaired Brain Injured, New York

The Association for Neurologically Impaired Brain Injured (ANIBIC), a New York-based not-for-profit agency that provides services to individuals with developmental and neurological disabilities, has recently informed the HHS’ Office for Civil Rights about a breach of the protected health information of 1,918 individuals. According to its substitute breach notice, suspicious activity was identified within its computer network on or around March 8, 2026. The investigation determined that an unauthorized third party accessed files containing program member information between March 7, 2026, and March 8, 2026.

The compromised information included names, contact information, Social Security numbers, dates of birth, health insurance information, and service details such as diagnoses, treatment information, and prescriptions. Notification letters were mailed to the affected individuals on July 17, 2026, and complimentary identity monitoring services have been offered to individuals whose Social Security numbers were involved.

The post Data Breaches Announced by Five HIPAA-Regulated Entities appeared first on The HIPAA Journal.

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times.

The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time.

This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class action lawsuits filed by patients who had their data stolen and healthcare providers seeking compensation for the financial and operational disruptions they experienced. On June 7, 2024, the Judicial Panel on Multidistrict Litigation consolidated an initial 49 lawsuits, including 19 consumer complaints and 30 healthcare provider complaints, although the number of lawsuits included in the action has grown to more than 150. The consolidated lawsuit – In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation – was centralized in the U.S. District Court for the District of Minnesota.

The stolen data files are designated discovery material, and due to the sensitive nature of the data and the volume of records, heightened security practices are required to protect against unauthorized access and data theft. The rules concerning the stolen dataset were approved by the plaintiffs’ attorneys and were verified by a cybersecurity expert as being sufficient to ensure the security of the data before being sent to the judge for approval. The stipulated protective order has recently been approved by Magistrate Judge Dulce Foster.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UHG will provide a single copy of the data on an encrypted hard drive built to a federal security standard, and must provide the key to decrypt the data separately, to ensure that in the event of loss or theft of the drive, the data cannot be accessed. The plaintiffs’ attorneys are required to encrypt the data again once they have received the hard drive, using industry-standard encryption. No copies may be made of the data, and the data cannot be saved to the shared file library used by all individuals involved in the case. The plaintiffs’ attorneys are prohibited from using the dataset to identify or locate potential class members.

The hard drive must only be used on computers that are air-gapped – disconnected from the Internet and all networks, with no Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated prior to use, and when the computers are used, no cables, phones, or storage devices are permitted nearby.  When data access is required, only small samples may be accessed, and no more than 25 people are permitted access at any one time. All samples must be encrypted with strong encryption and a complex password set of at least 16 characters.

An audit trail must be maintained, including a detailed chain of custody of the drive and data, and the log must be provided to UHG on request. When the case ends, or if the plaintiffs’ claims are thrown out, the data must be securely destroyed within 30 days, using a government-approved data wiping method – NIST SP 800-88 – or the hard drive must be physically destroyed, and a detailed certificate of destruction obtained under penalty of perjury.

In the event of a security incident or unauthorized data access or data sharing, UHG must be notified within 48 hours. Should it turn out to be a genuine security incident, both sides are required to engage an external digital forensic firm, and if the plaintiffs are found to be at fault, they must pay the full investigation costs.

The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal.

Data Breaches Announced by Five Small Healthcare Organizations

Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of Raleigh; Arkansas Oral & Maxillofacial Surgeons; Alpine Agency of the Midlands; Princeton Family Eye Care; and James C. Standring, DDS.

Family Medical Associates of Raleigh, North Carolina

Family Medical Associates of Raleigh, a multi-provider family medical practice in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, and activated its incident response protocol. Steps were immediately taken to investigate, contain, and remediate the incident; law enforcement was notified, and third-party cybersecurity professionals were engaged. The investigation and data review are ongoing; however, it has been confirmed that certain systems were intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026, who potentially downloaded internal data, including files containing patients’ protected health information.

The data review has not yet been completed, but the types of data exposed in the incident include names, demographic information, contact information, medical and treatment information, health insurance information, financial/payment-related information, government-issued ID numbers, and other data related to the medical services provided. Family Medical Associates of Raleigh said it is unaware of any actual or attempted misuse of patient data as a result of the incident; however, patients have been advised to remain vigilant against identity theft and fraud by monitoring their accounts, free credit reports, and explanation of benefits statements.

Since the investigation has yet to conclude, the number of affected individuals is currently unknown. While the name of the threat actor behind the attack was not disclosed, the Genesis ransomware group claimed responsibility for the attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Arkansas Oral & Maxillofacial Surgeons, Arkansas

Arkansas Oral & Maxillofacial Surgeons, a Hot Springs, Arkansas-based provider of oral surgery, dental implants, and other dental and cosmetic dentistry services, has announced a data security incident that was first identified on April 7, 2026.

An investigation was initiated, and on June 2, 2026, it was confirmed that an unauthorized third party had accessed its network and exfiltrated files containing patient information. The files have been reviewed and were found to contain information such as names, contact information, birth dates, medical record numbers, government identification numbers (including Social Security numbers), diagnoses, treatment records, health insurance information, prescription histories, and payment information.

The affected individuals have been notified by mail and provided with recommendations on how to protect themselves against data misuse. Based on the substitute breach notice on the Arkansas Oral & Maxillofacial Surgeons website, credit monitoring and identity theft protection services do not appear to have been offered. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many patients have been affected.

This appears to have been a data theft and extortion attempt. The PEAR threat group claimed responsibility. PEAR does not encrypt files, as the group engages in data theft and extortion, threatening to publish stolen data if the ransom is not paid.

Alpine Agency of the Midlands, South Carolina

Alpine Agency of the Midlands, LLC, a small, independent health and benefits insurance company based in Columbia, South Carolina, has recently disclosed a security incident involving unauthorized access to its email system. Alpine provides services to insurance carriers, employers, and health plans, and is provided with certain health data by its clients in connection with the services it provides.

Unusual activity was identified within an employee email account in November 2025. The account was secured, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that the incident affected a single email account, which was first accessed by an unauthorized third party on October 28, 2026. Emails and associated attachments may have been copied by the attacker.

The account was reviewed and found to contain first and last names, addresses, dates of birth, health insurance information, and limited Social Security numbers. Notifications will be mailed to the affected individuals when the review is completed. In the meantime, the breach has been reported to the HHS’ Office for Civil Rights as affecting at least 500 individuals. The total will be updated when the file review is concluded.

Princeton Family Eye Care, Texas

Princeton Family Eye Care, a small optometry practice in Princeton, Texas, has notified certain patients about a recent data breach. On May 4, 2026, suspicious activity was identified within its email environment. Assisted by third-party cybersecurity experts, the practice secured its email systems, investigated the activity, and confirmed that a company email account had been accessed by an unauthorized third party.

A data review firm was engaged to determine the types of data involved and the individuals affected, and that process has recently been completed. The data exposed in the incident varied from individual to individual and may have included names in combination with one or more of the following: date of birth, contact information, government identification numbers (such as a driver’s license, passport, or Social Security number), and limited medical information (such as treatment details, health insurance records, or a medical record number).

No misuse of the affected information has been identified; however, the affected patients have been advised to remain vigilant against misuse of their information. The breach was reported to the Texas Attorney General as involving the data of 933 Texas residents.

James C. Standring, DDS, California

James C. Standring, DDS, a dental practice in Crescent City, California, has notified 6,658 patients about a data security incident involving unauthorized access to its computer systems. While the data breach was reported to the HHS’ Office for Civil Rights on July 17, 2026, this appears to have been a historical data breach.

According to the breach explanation on the dental practice website, unauthorized access to certain computer systems was first identified on September 2, 2024. Assisted by third-party cybersecurity specialists, the practice determined that the incident resulted in the exposure of the data of current and former patients, including names, addresses, email addresses, Social Security numbers, driver’s license/state ID numbers, medical information, health insurance information, financial account/payment card information, and other personal information maintained by the practice.

No misuse of the affected data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. No explanation was provided about why it took 22 months from the date of discovery to issue notification letters.

The post Data Breaches Announced by Five Small Healthcare Organizations appeared first on The HIPAA Journal.

Data Breaches Reported by Sunshine Health; Health Payment Systems

A vishing attack on Sunshine Health, a Florida-based Medicaid and health insurance agency, involved the theft of the PHI of more than 41,000 individuals. Health Payment Systems, a Wisconsin healthcare billing company, has experienced an email security incident affecting more than 8,000 patients.

Sunshine Health

Sunshine Health, a Broward County, Florida-based Medicaid and health insurance agency, has recently discovered a vishing incident involving the impermissible disclosure of the protected health information of 41,569 individuals.

Vishing, or voice phishing, takes place over the phone and involves tricking an individual into providing the attacker with access to their device or sensitive information. In this case, an employee was tricked into sharing a limited number of health plan files by a caller pretending to be a trusted individual. The incident occurred on May 6, 2026, and was identified the same day. An investigation was launched, and the shared files were reviewed and were found to include names, dates of birth, medical information/histories, and health plan coverage information.

Sunshine Health said it has not found any evidence to suggest that the disclosed information has been misused at this time; however, to protect against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. Additional training has been provided to the workforce to raise awareness of the techniques that threat actors may use to gain access to internal systems and sensitive data.

Health Payment Systems

Health Payment Systems, Inc., a Wisconsin-based healthcare technology and billing software company, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,380 individuals.

On or around June 27, 2025, the company identified suspicious activity within its email environment. Immediate action was taken to secure the accounts and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident. Assisted by third-party cybersecurity specialists, Health Payment Systems confirmed that certain employee email accounts had been accessed by an unauthorized third party between June 24, 2025, and June 27, 2025, and certain emails were copied.

It has taken more than a year to investigate the incident and review the affected data. The HHS’ Office for Civil Rights was informed about the data breach on July 10, 2026, and notification letters are now being mailed to the affected individuals. Data exposed in the incident included names, addresses, birth dates, IDs, subscription IDs, and subscriber person IDs. For certain individuals, medical information, health insurance information, and Social Security numbers were also involved.

The affected individuals have been offered complimentary credit monitoring and identity theft protection services, and have been advised to monitor their explanation of benefits statements and account statements for signs of data misuse. Health Payment Systems said it has strengthened its security policies and has implemented additional cybersecurity measures to prevent similar incidents in the future.

The post Data Breaches Reported by Sunshine Health; Health Payment Systems appeared first on The HIPAA Journal.

Data Breaches Announced by Loma Linda University Health & UCLA Health

Data security incidents have recently been announced by Loma Linda University Health and UCLA Health.

Loma Linda University Health

Loma Linda University Health has recently announced a data breach involving an external AI platform. The incident involved patient information from an Institutional Review Board-approved research study. During the course of the study, A dataset including limited patient information was inadvertently uploaded to an AI platform.

When the incident was identified, an investigation was launched to determine the extent of data exposure. The investigation determined that the dataset included medical record numbers, dates of birth, and limited clinical information related to orthopedic care.  The breach did not include complete treatment records, nor Social Security numbers, financial information, or insurance information.

The academic medical center said it takes the privacy and security of patient information seriously and is reviewing its policies, procedures, and workforce training on the use of external technologies such as AI platforms. The number of affected individuals has yet to be publicly disclosed.

UCLA Health

UCLA Health is notifying an unspecified number of patients about an improper disclosure of some of their personal and protected health information. According to the breach notice provided to the California Attorney General, UCLA Health determined on July 2, 2026, that patient information was accessed and disclosed to an outside healthcare provider in a manner inconsistent with its HIPAA policies.

The notice indicates that the disclosures occurred between December 27, 2024, and April 21, 2026. The investigation confirmed that the information involved was limited to names, dates of birth, health insurance information, and clinical information, such as referral orders. For a limited number of individuals, the last four digits of their Social Security numbers were also included.

UCLA Health said it has implemented additional measures to prevent similar breaches in the future, including enhanced system controls and increased monitoring. UCLA Health said it is unaware of any actual or attempted misuse of patient data as a result of the incident.

The post Data Breaches Announced by Loma Linda University Health & UCLA Health appeared first on The HIPAA Journal.

Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals

Lifespan Physicians Group of Massachusetts, doing business as Brown Health Medical Group-MA, has confirmed that the protected health information of almost 312,000 individuals was potentially compromised in a December 2025 security incident.

There is currently no substitute breach notice on the medical group’s website; however, the data breach was reported to the Vermont and Massachusetts Attorneys General. The breach notices issued to those regulators explain that unauthorized activity was identified in a legacy file server at the practice on December 16, 2025. The server was isolated, and an investigation was launched to determine the nature and scope of the unauthorized activity. The forensic investigation confirmed that the breach was limited to the file server, which was accessed by an unauthorized third party between December 15 and December 16, 2026. The electronic medical record system was not involved.

The server was reviewed to determine the exact types of information stored on the server. The file review determined on June 22, 2026, that the following categories of data were impacted – names, dates of birth, contact information, Social Security numbers, driver’s license numbers or other government-issued identification numbers, credit or debit card numbers, financial account information, and personnel and human resources records. The latter may have included information such as compensation or payroll information, licensure or credentialing information, and medical or disability-related records.

Steps have been taken to improve security to prevent similar incidents in the future, including implementing enhanced technical safeguards. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 24 months. The incident affected 290,357 Massachusetts residents and 86 Vermont residents. According to the HHS’ Office for Civil Rights data breach portal, the protected health information of 311,760 individuals was potentially stolen in the incident.

The post Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals appeared first on The HIPAA Journal.

AmGen Announces Cyberattack and Data Breach Involving Patient Data

Amgen Inc., a Thousand Oaks, CA-based biopharmaceutical company that develops and manufactures pharmaceutical products for oncological, hematological, and cardiovascular diseases, has recently disclosed a cybersecurity incident involving unauthorized access to third-party-hosted cloud storage systems.

In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), Amgen explained that it determined in July 2026 that hackers gained access to certain cloud systems. Amgen immediately implemented its cybersecurity response plan, deployed containment measures, and engaged third-party digital forensics experts to determine the nature and scope of the unauthorized activity.

The investigation determined that proprietary data, patients’ protected health information, and other data had been exfiltrated from the cloud environment, and on July 29, 2026, determined that the incident was material and informed the SEC. Amgen said it does not believe the incident is reasonably likely to have an impact on its financial position, nor any of its products, manufacturing operations, financial reporting systems, or its ability to meet patient needs.

Amgen is in the process of assessing the extent to which patient information, confidential business information, intellectual property, research and development, and other information was exfiltrated in the attack and will be unable to accurately determine the impact to the company until those processes have concluded. At present, the exact nature of the attack, such as how the cloud systems were compromised, has yet to be made public. Amgen said it takes the protection of its systems and data very seriously and is in the process of determining the applicable regulatory and legal notification requirements, including its responsibilities under HIPAA.

As of the date of the SEC filing, the threat group behind the attack is unclear. Several pharmaceutical, biotechnology, and medtech firms have fallen victim to cyberattacks in recent months, including Novo Nordisk, Medtronic, Stryker, Abbott Laboratories, West Pharmaceutical Services, and Brainyx AI. The attacks have been conducted by several threat actors, including the Iran-linked hacktivist group Handala and the data theft and extortion groups FulcrumSec and ShinyHunters. The latter was the subject of a recent cybersecurity alert by Health-ISAC after a string of successful hacks on the healthcare sector.

The post AmGen Announces Cyberattack and Data Breach Involving Patient Data appeared first on The HIPAA Journal.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules.

OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files.

The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and individual notification letters started to be sent on the same date.

As with all breaches of the PHI of 500 or more individuals, OCR initiated an investigation to assess compliance with the HIPAA Rules. OCR determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of patients’ PHI, as required by 45C.F.R. § 164.308(a)(l)(ii)(A), and that there had been an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OCR also determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b). OCR determined that the alleged HIPAA violations were severe enough to warrant a financial penalty, and after advising OSF Healthcare System of the findings of the investigation and the intention to impose a financial penalty, a settlement was agreed to resolve the alleged violations informally.

Under the terms of the settlement, in addition to the $552,250 financial penalty, OSF Healthcare agreed to implement a corrective action plan and will be monitored for compliance with the plan for a period of two years. The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA-regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”

OCR has resolved eight HIPAA investigations with settlements so far this year, collecting $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty of the year to date. All eight investigations identified risk analysis failures, and this is the second case involving a penalty to resolve breach notification failures.

The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal.

Soniva Dental Care Data Breach Affects At Least 30,000 Patients

Data breaches have been announced by Soniva Dental Care in Texas, Optalis Management Solutions in Michigan, CareCloud in New Jersey, and Hudson Valley Medical Billing & Credentialing in New York.

Soniva Dental Care

Soniva Dental Care, a San Antonio, Texas-headquartered provider of dental services, orthodontics, and cosmetic dentistry across 14 locations, has recently disclosed a cybersecurity incident affecting patients of several of its practices. On May 26, 2026, Soniva Dental Care was informed by its IT support company about suspicious remote access sessions. It rapidly became apparent that its remote desktop web services infrastructure was under attack, and IT resources were shifted to containing the incident, terminating all external communications, disabling accounts with remote desktop access, and locking down its infrastructure. Soniva Dental Care said its patient record system was quickly restored and its archive data was unaffected.

While the incident was rapidly detected and contained, it was not possible to rule out unauthorized access to patient data. Files exposed in the incident were reviewed and found to contain names, addresses, dates of birth, driver’s license numbers, government-issued IDs, and medical information. Soniva Dental Care said its incident response was effective, and it has not identified any further suspicious activity. While Soniva Dental Care is unaware of any instances of data misuse, the affected individuals have been advised to place a fraud alert on their accounts with any of the three major credit bureaus. Security inspections are being conducted by its IT support company, which will continue to monitor for unauthorized activity.

Regulators have been notified about the data breach, but the incident is not yet shown on the HHS Office for Civil Rights breach portal. The Texas Attorney General was informed that up to 30,000 Texas residents were potentially affected. Affected practices include, but may not be limited to, Agave Dental Floresville, Allwyn Dental, Azle Smiles, Kashi Dental, Mysa Dental, and Wilson Dental.

A ransomware-as-a-service group called TheGentlemen claimed responsibility for the attack. The group is currently one of the most prolific ransomware groups, having attracted affiliates from other groups by offering a 90% split on ransom payments.

Optalis Management Solutions

Optalis Management Solutions, a Michigan-based operations management company specializing in the management of senior living and healthcare facilities, has reported a data breach to the HHS Office for Civil Rights involving the protected health information of 13,723 individuals.

Suspicious activity was identified within its computer network on or around April 19, 2025. The forensic investigation confirmed unauthorized access between April 14, 2025, and April 19, 2025, and on June 10, 2025, it was confirmed that files had been exfiltrated from its network. The review of the affected data has recently been completed, confirming that the following types of information were compromised in the incident: full names, Social Security numbers, driver’s license/state ID numbers, credit/debit card information, financial account information, diagnosis and treatment information, and health insurance information.

Notification letters started to be mailed to the affected individuals on June 29, 2026. While no evidence has been found to indicate any actual or attempted misuse of the stolen data, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services.

CareCloud

CareCloud Inc., a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined that data was exfiltrated from its systems in a recent security incident. CareCloud said it experienced a network disruption on March 16, 2026, that impacted one of its electronic health record environments. Third-party cybersecurity experts were engaged to assist with the investigation, who determined that the impacted AWS environment was accessed by an unauthorized third party between March 10 and March 16, 2026. The threat actor claimed to have exfiltrated databases from that environment.

The data was reviewed, and on June 24, 2026, CareCloud confirmed the data types involved. The affected individuals are now being notified, and the individual notification letters state the exact types of data involved. Complimentary identity theft protection services have been offered to the affected individuals. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

Hudson Valley Medical Billing & Credentialing

Hudson Valley Medical Billing & Credentialing, LLC, a New York-based provider of patient billing and accounts receivable services, has identified unauthorized access to computer systems containing the protected health information of 5,459 patients of its healthcare clients. The intrusion was first identified on March 6, 2026, and immediate action was taken to contain the incident and terminate the unauthorized access. The investigation was unable to determine whether patient data was accessed or copied, so notification letters have been mailed to individuals who have potentially been affected.

The company said it has enhanced its technical safeguards to strengthen system security, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The exact data types involved are detailed in the individual notification letters.

The post Soniva Dental Care Data Breach Affects At Least 30,000 Patients appeared first on The HIPAA Journal.