HIPAA Breach News

Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack

Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US).

Midwest Spine and Brain Institute (3C Care Systems)

Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems. According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation.

The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C Care Systems. The investigation concluded on June 18, 2026, revealing that personally identifiable information and protected health information was potentially involved, including first and last names in combination with one or more of the following: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service, and health insurance claim and/or policy information.

MSBI is mailing notification letters to the affected individuals and has offered complimentary identity monitoring and protection services to individuals whose Social Security numbers were involved. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many MSBI patients have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

No information was provided as to the nature of the data breach, but this appears to have been a ransomware attack by the now-disbanded RansomHub ransomware operation on or around November 21, 2024. RansomHub claimed it had exfiltrated 100 GB of data from 3C Care Systems, although no separate breach announcement appears to have been made by the IT company, and those claims remain unverified. It is unclear if clients other than MSBI had data compromised in the incident.

Brookhaven ENT Allergy and Facial Surgery

Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, has notified 30,403 individuals that some of their personal and protected health information was compromised in a recent cybersecurity incident. The incident involved a third-party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. The CareCloud breach listing on the OCR data breach portal indicates that 3.75 million individuals were affected.

The incident occurred between March 10, 2026, and March 16, 2026, and the file review determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information had potentially been compromised. You can read more about the CareCloud data breach in this post. At the time of issuing notifications, no actual or attempted misuse of the impacted data had been identified.

Silver Summit Medical Corporation (Digestive Disease Center and Heart Vascular & Leg Center), California

Silver Summit Medical Corporation, doing business as the Digestive Disease Center and Heart Vascular & Leg Center, has notified certain patients about a cybersecurity incident at a third-party vendor that exposed some of their protected health information. The Bakersfield, California-based ambulatory surgical center learned about the incident on or around July 20, 2026. The investigation determined that an unauthorized third party accessed the unnamed vendor’s systems from November 27, 2025, to November 30, 2025, and exfiltrated files containing personal and protected health information.

The data review determined that the exfiltrated files contained names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, taxpayer identification numbers, passport numbers, and/or other government identifiers. Protected health information included diagnoses, treatment information, prescription information, and health insurance information. The affected individuals were notified on August 19, 2026, and complimentary credit monitoring and identity theft protection services have been made available. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so the number of affected individuals is not yet known.

Premier Medical Group of the Hudson Valley, New York

Premier Medical Group of the Hudson Valley, a Poughkeepsie, New York-based multispecialty practice, has started notifying patients impacted by a cybersecurity incident this summer. The incident disrupted certain IT systems, and the forensic investigation determined that there was unauthorized access to files containing patient information on June 14, 2026. The substitute data breach notice on the practice’s website does not state when the incident was detected.

The review of the affected data determined on July 14, 2026, that the exposed files included patient names, contact information, dates of birth, health insurance information, provider names, patient identification numbers, dates of service, medications, and diagnostic and treatment information. Premier Medical Group said it will continue to evaluate and implement enhanced safeguards and security measures to protect its systems from unauthorized access and continue to provide security training to its workforce. The number of affected individuals has yet to be publicly disclosed.

Risk Program Administrators

Risk Program Administrators LLC (RPA), a California-based insurance program administration and management firm, has notified 8,309 individuals about the exposure of some of their personal and protected health information earlier this year. On or around June 16, 2026, RPA identified suspicious activity within an employee’s email account. The account was secured, and an investigation was launched, which confirmed that the account, and certain emails within that account, had been accessed by an unauthorized third party between May 27, 2025, and June 16, 2025.

The account was reviewed and found to contain information such as names, dates of birth, Social Security numbers, financial account information, health insurance information, and medical information, including treatment types, locations, costs, physician information, mental or physical condition, subscriber member numbers, and admission dates.

TELUS Health (US)

TELUS Health (US) LTD., a Canton, Massachusetts-based digital health and wellness provider part of the Canadian telecommunications company TELUS, has disclosed a data breach that involved unauthorized access to systems containing protected health information. Telus Health’s announcement on its website states that the investigation is ongoing, and it has yet to publicly disclose the types of information compromised in the incident. It is unclear exactly when the attack occurred; however, it appears to have occurred in January 2026. The ShinyHunters threat group claimed responsibility for the attack and the exfiltration of 1 petabyte (1,000 TB) of data.

The threat group communicated with Bleeping Computer, which reported in March 2026 that systems were breached using compromised Google Cloud credentials obtained in the Salesloft Drift breach. While the breach had the potential to be massive, it was recently reported to the HHS’ Office for Civil Rights as involving the protected health information of just 2,641 individuals. TELUS Health said it has implemented additional security safeguards to better safeguard the data within its environment.

The post Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack appeared first on The HIPAA Journal.

Five Healthcare Providers Report Ransomware-Related Data Breaches

Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.

Alta Orthopaedics Medical Group, California

Alta Orthopaedics, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, has recently confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen in a cybersecurity incident earlier this year. Unusual network activity was identified on March 10, 2026, and the investigation determined that an unauthorized third party had accessed information on its network between February 3, 2026, and February 6, 2026.

The review of the affected data was completed on June 24, 2026. Personally identifiable information potentially compromised in the incident included names, contact information, Social Security numbers, driver’s licence numbers/state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth, and login information. Protected health information compromised in the incident included diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information, and biometric data.

Notification letters have been mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been made available for 24 months. While not mentioned in the notification letters, this appears to have been a ransomware attack. The INC Ransom ransomware group claimed responsibility for the attack and said 26 GB of data was exfiltrated. The data was subsequently leaked.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Cornerstone Behavioral Healthcare, Maine

Cornerstone Behavioral Healthcare, a Worcester, Maine-based mental health and substance use disorder treatment provider, has notified patients that some of their protected health information may have been compromised in a May 2026 ransomware attack. Cornerstone identified the attack on May 26, 2026, the same day that the attackers gained access to its network. The attacker’s access to its network was blocked within an hour of discovery, and computers on the affected parts of the network were powered down rapidly, limiting the extent of file encryption. Cornerstone said it believes that less than 10% of the data on the affected computers and servers was encrypted.

The initial findings of the investigation indicated that the protected health information of approximately 2,830 patients was compromised as a result of the attack, including names, addresses, other contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare information, and Social Security numbers. Further investigation determined on July 22, 2026, that a log of appointment reminders was also compromised, which included the protected health information of approximately 12,000 patients. The log data included names, birth dates, appointment times, and reminders of documentation due.

The investigation has now been completed, and the HHS’ Office for Civil Rights has been informed that, in total, the protected health information of 14,830 patients was potentially compromised in the incident. Cornerstone explained in its refreshingly detailed breach notification letter that it received a ransom demand but did not pay. All affected computers were wiped, new computers were purchased, and all systems, policies, and procedures have been reviewed. Additional security measures have been implemented on its servers, and special training has been provided to the workforce on ransomware.

Cameron Regional Medical Center, Missouri

Cameron Regional Medical Center, a 60-bed acute care hospital in Cameron, Missouri, announced in August 2026 that it recently discovered that it was the victim of a sophisticated ransomware attack. The attack was detected on June 18, 2026, when files on its network were encrypted. In an announcement on August 18, 2026, the hospital explained that the investigation into the attack is ongoing; however, the initial findings indicate that patients’ protected health information was subject to unauthorized access and may have been exfiltrated from its network.

While the specific types of data involved for each patient have yet to be determined, Cameron Regional Medical Center said the information likely compromised includes names plus some or all of the following:  home addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient ID numbers, agency-assigned identification numbers, treatment cost information, health insurance information, electronic/digital signatures, and/or employer-assigned identification numbers.

Third-party cybersecurity experts have been engaged to investigate the attack and assist with evaluating and reinforcing its security measures to ensure optimal data security. At the time of issuing the notification, no actual or attempted misuse of patient data had been identified. Individual notification letters will be mailed to the affected individuals when the data review is concluded. While the name of the ransomware group was not disclosed, the Anubis ransomware group claimed responsibility and leaked some of the stolen data as proof of the attack, including patient information. The group claimed to have exfiltrated around 500 GB of data.

Suntree Internal Medicine, Florida

Suntree Internal Medicine, an internal medicine practice in Melbourne, Florida, has notified 9,810 individuals about a cybersecurity incident first identified on September 28, 2025. Unusual activity was identified in certain systems, and immediate action was taken to contain the incident. An investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts.

The investigation confirmed unauthorized network access and the exposure of files containing patient information. Those files may have been copied from its network, although at the time of issuing the breach notice, no misuse of patient information had been identified. The data review confirmed that the following information was exposed: names, addresses, treatment information, and health insurance information. Suntree Internal Medicine has implemented additional security measures to reduce the risk of similar incidents in the future. While the incident was not described as a ransomware attack, a ransomware group called INC Ransom claimed responsibility for the attack on its dark web data leak site. The listing states that data was exfiltrated.

Associated Endocrinologists, Michigan

Associated Endocrinologists, a consultative endocrinology practice with locations in Farmington Hills and Clarkston, Michigan, has started notifying 4,979 patients about a cybersecurity incident earlier this year. There is currently no substitute breach notice on the practice website, and the HIPAA Journal has been unable to find a press release about the incident, which was reported to the HHS’ Office for Civil Rights on July 29, 2026. It is currently unclear exactly what types of information were exposed or stolen in the incident. The RansomHouse ransomware group claimed responsibility for the attack on its data leak site in early February and claimed to have exfiltrated data and encrypted files on January 31, 2025

The post Five Healthcare Providers Report Ransomware-Related Data Breaches appeared first on The HIPAA Journal.

Nutex Health Confirms Sensitive Data Stolen in August Cyberattack

Nutex Health, a Houston, Texas-based healthcare management and operations company that delivers care through 27 micro-hospitals, specialty hospitals, and outpatient departments in 12 U.S. states, has disclosed a cyberattack involving the exfiltration of data from some of its servers. Nutex is currently investigating the incident to determine the extent of data theft, including whether provider, employee, or patient data were exposed or stolen.

The incident was disclosed in an August 24, 2026, Item 8.01 Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). Nutex explained that it recently learned of unauthorized activity related to data stored on its computer network. The company activated its incident response plan, implemented containment measures, and engaged an independent third-party cybersecurity response team and forensics experts to assist with the investigation and determine the extent to which data was exposed or stolen.

Per that filing, Nutex said the incident is still being assessed, and it has yet to determine whether private and confidential data was compromised in the incident. At the time, Nutex said it did not believe that the unauthorized access has, had, or is reasonably likely to have a material impact on the company’s business strategy, operations, financial condition or results of operations. Nutex did not disclose the name of the threat group behind the attack or whether it received a ransom demand, but it was aware that private and/or confidential information may be disclosed by the threat actor. At the time, no cybercriminal group had claimed responsibility for the attack.

Then, on August 31, 2026, Nutex filed an Item 1.05 Form 8-K filing with the SEC confirming that this is a material cybersecurity incident. The August 31, 2026, filing states that, “Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business, and financial information that is private and/or confidential.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Nutex also confirmed that the threat actor has threatened to publish the stolen data; however, the company has not yet identified any material impact on its business operations or financial reporting systems. Nutex is continuing to assess the impacted data and the extent to which patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated.

The threat group behind the attack on Nutex appears to be The Gentlemen, a ransomware-as-a-service (RaaS) operation that first appeared in mid-2025 and significantly ramped up attacks in 2026. While the group’s attacks appear to be opportunistic, the healthcare sector accounts for around 9% of its attacks. The Gentlemen engages in double extortion tactics, exfiltrating sensitive data and demanding a ransom to decrypt files and prevent the release of stolen data.

The post Nutex Health Confirms Sensitive Data Stolen in August Cyberattack appeared first on The HIPAA Journal.

Oncology Firm Novocure Announces Cyberattack and Data Breach

The medical technology and oncology company Novocure has recently confirmed that patient and employee data were exposed in a recent cyberattack. Novocure is a publicly traded company with approximately 1,300 employees worldwide. Its global HQ is in Baar, Switzerland, and its U.S. headquarters is in Portsmouth, New Hampshire. The company has developed a novel non-invasive cancer treatment called Tumor Treating Fields (TTFields), which uses low-intensity, alternating electrical fields to disrupt the division of cancer cells.

Novocure explained in a September 1, 2026, Form-8K filing with the U.S. Securities and Exchange Commission (SEC), that it became aware of unauthorized access to some of its information systems via a subsidiary in mid-August 2026. Its incident response plan was activated, along with containment measures, and an investigation was launched, with assistance provided by third-party cybersecurity forensics experts.

While employee and patient data were stored on the compromised systems, the impact of the data breach was limited. Based on the investigation to date, approximately 1,400 U.S. patients had data exposed in the incident. The breach was limited to internal company ID numbers – no patient names or other identifying data were exposed. Fewer than 50 other patients in the Western United States had additional identifying information exposed, along with general contact information for all U.S. healthcare providers that the company works with, and general contact information for Novocure employees, including job titles and phone numbers. Novocure did not disclose how many employees had their contact information exposed in the incident.

Novocure said there was no unauthorized access to any of its medical treatment devices, no impact to operations, and all systems are fully functional. At the time of issuing the filing, Novocure said it does not believe that the incident will have any material impact or reasonably likely impact on its financial condition or results of operations, although the investigation into the incident is ongoing.  The threat group behind the attack and the nature of the incident were not disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Several medical technology companies have experienced cyberattacks this year, including Unlimited Technology Systems, CareCloud, Boston Scientific, Medtronic, Stryker, Abbot Laboratories, and iRhythm, although in this case, the impact appears to be limited. Other medtech companies have not been so fortunate. The cyberattacks on Unlimited Technology Systems and CareCloud involved unauthorized access to systems containing 3.8 million and 3.7 million patient records respectively, and the cyberattack on Boston Scientific disrupted operations globally.

The post Oncology Firm Novocure Announces Cyberattack and Data Breach appeared first on The HIPAA Journal.

Hacking Incidents Announced by Rehabilitative Care Providers and Senior Living Facilities

Data breaches have been announced by multiple North Carolina rehabilitative care practices, senior living and skilled nursing care providers in Ohio and Washington, and the California-based nonprofit foundation The Health Trust and its subsidiary, FASS.

North Carolina Rehabilitation Practices Notify Patients About November Hacking Incident

The operator of multiple clinical, long-term, and rehabilitative care practices in North Carolina has reported a data security incident that has affected almost 4,000 patients of Elevate Health & Rehabilitation, Bear Mountain Health and Rehabilitation, and Swannanoa Valley Health and Rehabilitation.

On June 1, 2026, the operator learned that there had been unauthorized access to files maintained by an unnamed third-party vendor, and some of those files had been copied by a bad actor.  The unauthorized third party used stolen credentials to log in to its system between November 25, 2025, and November 28, 2025. The obtained files contained patient information such as names, addresses, email addresses, dates of birth, Social Security numbers, driver’s license numbers, patient account numbers, diagnoses, and other health information.

Assurances were received that the stolen data has been deleted and was not published online, which suggests that the vendor paid a ransom. The compromised credentials have been disabled, passwords reset, and additional steps have been taken to strengthen security and the privacy of patient information. The data breach was reported to the HHS’ Office for Civil Rights by Asheville Victoria NC Opco LLC as affecting 1,551 patients of Elevate Health & Rehabilitation; Asheville Beaverdam NC Opco LLC, as affecting 1,397 patients of Bear Mountain Health and Rehabilitation; and Asheville US Seventy NC Opco LLC, as affecting 1,045 patients of Swannanoa Valley Health and Rehabilitation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Ohio Skilled Nursing Care Provider Hit with Medusa Ransomware Attack

Atrium Centers Inc., a Columbus, Ohio-based skilled nursing and rehabilitation care provider, has alerted patients about an October 2025 cybersecurity incident. Unusual activity was identified within certain computer systems on or around October 13, 2026. Assisted by third-party cybersecurity experts, Atrium Centers determined that an unauthorized third party had accessed certain computer systems between October 8, 2025, and October 12, 2025. During that time, files containing patient and employee data were viewed or copied.

The files were reviewed and found to contain names, contact information, demographic information, dates of birth, Social Security numbers, driver’s license numbers, patient ID numbers, medical record numbers, medical information, health insurance information, financial account information, claims information. The file review is ongoing, and the number of affected individuals has yet to be publicly disclosed. Notification letters will be mailed to the affected individuals when that process is completed. Atrium Centers said it is enhancing its technical safeguards to prevent similar incidents in the future.

Rockwood Retirement Communities Discloses February 2026 Hacking Incident

Spokane United Methodist Homes, doing business as Rockwood Retirement Communities, a Spokane, Washington-based senior living organization, has started notifying individuals impacted by a February 2026 hacking incident. Suspicious network activity was identified on or around February 16, 2026. Immediate action was taken to secure its systems, and third-party cybersecurity and digital forensics experts were engaged to investigate the activity.  The investigation confirmed unauthorized network access and the exfiltration of files from its network.

Third-party data review experts conducted a comprehensive and time-consuming review of the affected data, contact information was verified, and notification letters were sent to the affected individuals. Those processes were completed on July 27, 2026. Data compromised in the incident included personal and protected health information such as names, Social Security numbers, dates of birth, driver’s license numbers/state identification numbers, passport numbers, financial account information, Medicaid/Medicare numbers, medical information, and/or health insurance information. Rockwood Retirement Communities is unaware of any actual or attempted misuse of that data.

The HHS’ Office for Civil Rights (OCR) has been informed, but the data breach has yet to be added to the OCR data breach portal, so it is currently unclear how many individuals have been affected.

Qilin Claims Responsibility for The Health Trust Hacking Incident

The Health Trust, a San Jose, California-based nonprofit foundation that provides services to governmental and non-governmental organizations to help build health equity and improve health outcomes, has identified a hacking incident that also affected its subsidiary, Financial Administrative Support Services (FASS).

On May 26, 2025, FASS identified suspicious activity within its computer network. Steps were immediately taken to secure its network; however, on June 11, 2025, further suspicious activity was identified. All systems were immediately taken offline while security was assessed and the activity was investigated. The forensic investigation determined that there had been unauthorized access to certain systems prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025.

Files on the compromised parts of the network were accessed or copied. The review determined that they contained names, Social Security numbers, financial account information, government-issued identification numbers, medical information, and health insurance information. Internal data privacy and security policies, procedures, and protocols have been reviewed, and additional security measures have been implemented to prevent similar incidents in the future.  The affected individuals have been offered complimentary credit monitoring services.  The Qilin threat group claimed responsibility for the incident and said it exfiltrated 408 gigabytes of data.

The post Hacking Incidents Announced by Rehabilitative Care Providers and Senior Living Facilities appeared first on The HIPAA Journal.

ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson

The healthcare giant McKesson recently disclosed a cyberattack in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).  While the investigation is still in its early stages, McKesson has confirmed that data was exfiltrated, although the extent of data theft has yet to be determined.

McKesson is a large, publicly traded U.S. healthcare and pharmaceutical company that supplies hospitals, health systems, pharmacies, and physician offices with medications, medical-surgical equipment, and specialized oncology and prescription technology solutions. McKesson has not disclosed the name of the group behind the attack, but it appears to be the ShinyHunters extortion group. ShinyHunters added McKesson to its data leak site, and the listing claims that 284 million patient data records were exfiltrated. The claim of 284M patient records relates to rows of raw data, not unique patients. Even so, this is clearly a significant data breach.

McKesson announced the incident on August 28, 2026, explaining that an investigation had been launched following “a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.” Incident response protocols were activated, and leading cybersecurity experts were engaged to assist with the company’s response. The McKesson cybersecurity team and third-party experts are working to minimize the impact on system availability, determine the nature and scope of the unauthorized activity, and the extent of data theft. Customers have been warned that there may be an impact on system availability and business operations, including intermittent service degradation.

McKesson said it does not believe that customers need to take any action, and that the company is not proactively disconnecting systems within its environment. In an August 29 update, McKesson said the company continues to serve customers across all lines of business, orders are being accepted, and its distribution centers remain open, with products continuing to be shipped across its distribution network.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Based on early investigation results, McKesson said the incident appears to involve data relating to a subset of customers of its Oncology & Multispecialty and Medical-Surgical business units. The initial actions to prevent further unauthorized access appear to have been successful, with no further unauthorized activity detected. According to the SEC filing, the cybersecurity incident was first detected on August 25, 2026. The company has yet to determine whether the incident is material and will have a material impact on the company, its financial condition, or the results of operations.

ShinyHunters is a prolific threat group that engages in data theft and extortion, typically gaining access to victims’ systems through voice phishing/vishing and social engineering. Previous healthcare victims include Medtronic, Abbott Laboratories, iRhythm, AdaptHealth, and DentaQuest. In the past few days, ShinyHunters also claimed responsibility for data theft incidents at Baxter International and Boston Scientific.

According to BleepingComputer, which has been in contact with the group, around 1 terabyte of data was exfiltrated between August 21 and August 25, 2026, and a ransom demand of more than $55 million was issued. ShinyHunters claims that the stolen data includes names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication/allergy information, diagnoses, appointment information, and other sensitive data. The data appears to relate to its Salesforce environment and Snowflake.

The post ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson appeared first on The HIPAA Journal.

Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack

It has been two weeks since a cyberattack on the Massachusetts-based medical device manufacturer Boston Scientific prevented access to critical information systems and caused major disruption to operations globally. The attack was detected on August 25, 2026, and the company quickly activated its incident response protocol, contained the attack, and has been working round the clock to investigate the unauthorized activity and safely and securely bring systems back online.

Boston Scientific notified the U.S. Securities and Exchange Commission (SEC) about the attack on August 26, 2026, although at the time it was unclear to what extent, if any, the incident would impact its financial position. On September 8, 2026, Boston Scientific submitted another Form 8-K filing with the SEC providing further information on the attack and recovery progress, confirming that the incident is likely to have a material impact on the company’s results of operations for the third quarter and the full year. Boston Scientific explained that the company is unlikely to meet its net sales growth and adjusted EPS guidance ranges for the third quarter and full year 2026, which it provided in late July, around a month before the cyberattack; however, the company does not expect the incident to have an impact on its long-term financial condition.

Boston Scientific confirmed that the cyberattack and subsequent outage affected its ability to manufacture products and ship customer orders. No evidence has been found to indicate any further unauthorized system activity since it implemented its initial containment and remediation measures. Its investigation into the cause of the attack, the extent of compromise, and the nature of data access/exfiltration is continuing.

The company is making progress in its recovery, and a substantial part of its distribution network has been restored. The company’s sterilization facilities are operational, as are most of its manufacturing facilities. Progress is being made to address the backlog of customer orders, which are being shipped above normal operating levels, and the company continues to ramp up operations globally, which should allow it to recover a portion of the impacted revenue and reduce the remaining backlogs.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Boston Scientific cannot provide a timeline for when it will achieve full operational recovery, and the full impact of the incident has yet to be determined. The company will provide an update on the operational and financial outlook for the remainder of fiscal year 2026 in its planned conference call to discuss financial results and business highlights for the third quarter 2026 on Wednesday, October 28, 2026.

The nature of the attack, such as whether ransomware was involved, data was exfiltrated, and a ransom demand was received, has yet to be confirmed, and no threat group appears to have claimed responsibility for the attack.

August 27, 2026: Boston Scientific Cyberattack Impacting Operations

The Massachusetts-based biotechnology and biomedical engineering firm Boston Scientific has disclosed a major cyber incident that is affecting certain information technology systems. The incident has caused a network outage, prevented access to certain business applications, and is disrupting company operations.

Boston Scientific is a medical device company that operates in 127 countries, employs around 59,000 individuals globally, and has annual revenues of around $20.1 billion. The company manufactures devices for interventional cardiology such as pacemakers and cardiac ablation systems, and a range of devices and products for neuromodulation, neurological surgery, urology and pelvic health, endoscopy, pulmonology, interventional radiology, and vascular surgery. The company’s products are used to treat more than 48 million patients a year.

According to the August 26, 2026, announcement, the company identified the incident on August 25, 2026. The company also filed a Form 8-K report with the U.S. Securities and Exchange Commission (SEC) to alert shareholders. At the time of the filing, Boston Scientific had yet to determine if the incident is reasonably likely to have a material impact on the company.

Boston Scientific immediately implemented its incident response procedures and engaged a third-party cybersecurity company to assist with assessment, containment, and to determine the nature and scope of the unauthorized activity. Boston Scientific said the incident has prevented access to certain operating systems and business applications, and is affecting the company’s ability to process and ship customer orders. The disruption is global, with employees in its manufacturing facilities in Cork, Ireland, sent home as they are unable to work. Work is ongoing to safely and securely restore the affected functions and systems, and investigate the incident to determine the extent, if any, of data theft. Boston Scientific is currently unable to provide a timeline of when systems will be fully restored and normal business operations will resume.

Boston Scientific has not publicly disclosed information about the exact nature of the attack, such as whether ransomware was involved, how access to its systems occurred, if a ransom demand was received, and if the company is aware of any data theft claims. The threat actor behind the attack does not appear to have claimed responsibility, which, given that the attack occurred only two days ago, is not unusual.

The Boston Scientific cyberattack is the latest in a string of attacks on medical technology and biotechnology firms. Previous attacks include the recently disclosed ShinyHunters attack on Baxter International, and cyberattacks on Medtronic, Stryker, Abbott Laboratories, iRhythm, and AdaptHealth.  Several threat groups were behind those attacks, including financially motivated data theft and extortion operations, ransomware groups, and, in the case of Stryker, an Iran-linked threat group.

Cyberattacks on medtech companies typically involve data theft and extortion, but as this incident shows, they can cause major disruption to business operations, which can impact patients. “A cardiac device that misses its ship date can mean a cancelled surgery. That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for,” said Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs.

“Medical devices also aren’t something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them,” Krell said. “Disrupt order processing and shipping, and the consequences show up in hospitals pretty quickly. The harder problem is getting manufacturing back online. These aren’t ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another.”

The post Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack appeared first on The HIPAA Journal.

ShinyHunters Leaks 7.1 Million Baxter International Records

The ShinyHunters data theft and extortion group recently claimed responsibility for an intrusion at the medical device manufacturer Baxter International (Baxter). Baxter was added to its dark web data leak site a day after Baxter issued a statement about a cybersecurity incident. ShinyHunters proceeded to leak around 7.1 million records allegedly stolen in the incident. The data leak suggests that Baxter refused to negotiate payment or that negotiations broke down.

Baxter is a Deerfield, Illinois-based manufacturer of medical devices for renal care, IV solutions & infusion pumps, surgical products, inhaled anesthetics, and a range of patient monitoring devices and digital health tools. According to an August 13, 2026, statement from Baxter, unauthorized activity was detected within certain third-party applications. The company immediately activated its cybersecurity response procedures and launched an investigation, with assistance provided by third-party cybersecurity and digital forensics experts. The investigation is ongoing to determine the types and amount of information that may have been accessed or acquired.

Baxter said the incident did not have any impact on patient services or business continuity, and the company continues to operate normally. The incident has not had any impact on its products, connected solutions, or technologies used by customers to deliver patient care. Baxter said it does not anticipate the incident having a material impact on financials or the results of operations. The name of the threat group behind the incident was not publicly disclosed.

On August 14, 2026, ShinyHunters added an entry to its dark web data leak site claiming responsibility for the attack. ShinyHunters gave Baxter an August 17, 2026, deadline to negotiate payment, and threatened to leak the stolen data if payment was not made. On August 19, 2026, ShinyHunters released the stolen data for download.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Baxter has not confirmed the nature of the stolen data, only stating that the attack involved certain third-party applications. ShinyHunters claims that 7.1 million Salesforce records were exfiltrated in the attack, some of which contained personally identifiable information. While the group claims to have obtained 7.1 million records, that does not necessarily mean that 7.1 million patients have been affected. Baxter said it will provide updates as appropriate as additional information is confirmed.

ShinyHunters is one of the most active data theft and extortion groups. The group targets large organizations and has claimed several healthcare victims. In June 2026, ShinyHunters claimed to have exfiltrated 8.8 terabytes of data from Amazon-owned OneMedical, including the protected health information of 153,000 patients. Also in June, the group claimed to have exfiltrated 234 GB of data from DentaQuest, including the protected health information of approximately 2.6 million individuals. ShinyHunters was also behind an incident at another medical device manufacturer earlier this year. In July, Medtronic confirmed that the protected health information of 3.8 million patients was stolen in the attack. Other healthcare victims include iRhythm, AdaptHealth, and Him & Hers.

ShinyHunters has targeted companies across a range of different sectors, and while the group’s attacks appear to be opportunistic, the list of victims includes many healthcare organizations. The increasing number of attacks on healthcare organizations prompted Health-ISAC to issue an alert to the healthcare and public health sector in July about the ShinyHunters group.

The post ShinyHunters Leaks 7.1 Million Baxter International Records appeared first on The HIPAA Journal.

Baylor Genetics: ePHI of 2.8M Patients Exposed in Cybersecurity Incident

On August 19, 2026, we reported on a cybersecurity incident at the clinical genomics company Baylor Genetics. At the time, it was clear that this was a significant breach, based on reports submitted to state attorneys general; however, the scale of the breach was unknown.

The Baylor Genetics data breach has recently been added to the HHS’ Office for Civil Rights website, which shows that the electronic protected health information (ePHI) of 2,810,878 individuals was exposed or stolen in the incident.

August 19, 2026: Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident

Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.

Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston.  The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity.  The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.

Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.

Baylor Genetics said the incident did not impact its laboratory operations, which continued without interruption throughout the investigation, and there was no impact on the company’s ability to provide genetic testing services. Baylor Genetics has enhanced its security and monitoring controls, strengthened identity and access management, and has implemented additional security controls to prevent similar incidents in the future.  Complimentary credit monitoring and identity theft protection services have been offered to at least some patients.

The data breach has been reported to regulators; however, it is currently unclear how many patients and employees had data compromised in the incident. What is known is that almost 250,000 Texas residents, around 57,000 Massachusetts residents, and 2,630 Vermont residents have been affected, bringing the total to around 310,000 patients. Other states, such as California, have been notified that some state residents have been affected, so the final victim count is likely to be considerably higher.

The post Baylor Genetics: ePHI of 2.8M Patients Exposed in Cybersecurity Incident appeared first on The HIPAA Journal.