HIPAA Breach News

Colorado Behavioral Healthcare Provider Discovers Insider Data Breach

Data breaches have been announced by NAS Recovery Solutions, Entyre Care Massachusetts, Carle Health, and Brown Health Medical Group-MA.

NAS Recovery Solutions

NAS Recovery Solutions, a Lakewood, Colorado-based substance use disorder treatment and behavioral health services provider, has announced a data breach affecting up to 7,000 current and former clients. According to the company’s breach notice, this was an insider breach rather than a hacking incident. The company learned on May 13, 2026, that certain workforce members had downloaded client data without authorization.

The investigation revealed only limited information had been copied, such as first and last names, dates of birth, and telephone numbers; however, since NAS Recovery Solutions is a substance use disorder (SUD) treatment provider, it could be inferred that the individuals were receiving SUD treatment. There are no indications that any other information was obtained by the workforce members. The breach notice does not provide any clue as to why that information was obtained.

NAS Recovery Solutions said it has reviewed workforce access and security controls and is implementing additional safeguards to prevent similar incidents in the future. Additional training has been provided to the workforce on HIPAA and patient privacy, and appropriate corrective action has been taken against the workforce members involved. The sanctions imposed were not disclosed in the notice.

Entyre Care Massachusetts

Entyre Care Massachusetts Inc., a Boston, MA-based home healthcare company, has discovered that an employee accidentally published files containing personal information in a publicly accessible online repository on March 2, 2026. The exposed files were identified on March 12, 2026, and were immediately secured.

The investigation uncovered no evidence to suggest that the files had been accessed or downloaded; however, it was not possible to rule out unauthorized access during the period of exposure. The files only contained limited information, such as names, ages, and Medicaid IDs; however, out of an abundance of caution, the affected individuals have been offered 24 months of complementary credit monitoring and identity theft protection services.

Carle Health

Carle Health, an Illinois nonprofit health system, has confirmed that 1,444 of its patients were affected by a data breach at its vendor Xsolis in January 2026. Xsolis is a vendor that provides an AI-powered software platform to healthcare providers to improve case and utilization management. We have covered the data breach, which affected more than 1.4 million individuals, in this post. Carle Health said the compromised information included names, birth dates, diagnoses, treatment dates and locations, medical record numbers, doctors’ names, Social Security numbers, and health insurance information.

Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts)

Lifespan Physicians Group of Massachusetts Inc., which does business as Brown Health Medical Group-MA, has recently announced that the sensitive data of certain patients has been exposed. According to the notification to the Vermont Attorney General, the impacted data includes names, Social Security numbers, government identification numbers, financial account codes, and health records. The incident affected 86 Vermont residents, but it is currently unclear how many individuals have been affected in total.

The post Colorado Behavioral Healthcare Provider Discovers Insider Data Breach appeared first on The HIPAA Journal.

Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data

The cardiovascular medical practice, Heart Care Centers of Illinois (HCCI), announced on July 18, 2026, that certain patients had some of their personal and protected health information exposed in a phishing attack.

HCCI said it launched an investigation into an unsuccessful phishing attempt and discovered a historical suspicious activity within an employee’s email account on January 15, 2026. Third-party digital forensics experts were engaged to investigate the activity and confirmed that an unauthorized third party gained access to the account between August 22, 2024, and November 6, 2024.

A data analytics firm was engaged to review the account. On June 11, 2026, the review was completed, confirming that the following types of information were present in the account: names, addresses, telephone/fax numbers, Social Security numbers, dates of birth, driver’s license numbers/state identification numbers, payment card information, financial account numbers, passport numbers, diagnosis/condition information, prescription information, treatment information, health insurance information, and provider information.

The affected individuals were notified on July 10, 2026, and complimentary credit monitoring and identity restoration services have been offered. HCCI has reviewed its existing policies and procedures and has taken steps to reduce the risk of similar incidents in the future. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Madera Community Hospital

Madera Community Hospital in California has notified the California Attorney General about a security incident involving unauthorized access to its network between May 28 and May 29, 2025. The unauthorized access was identified on May 29, 2025, and action was immediately taken to secure its network and prevent further unauthorized access.

Third-party cybersecurity experts were engaged to investigate the incident. No evidence was found to indicate any removal of data; however, the hospital said, “based on subsequent developments, we have reason to believe that a third party acquired files from a portion of its network.” No further information was provided on what that evidence was. The hospital did state that it has not found definitive proof that any data was removed, and none of the impacted data appears to have been published or otherwise shared.

The data review was completed in April 2026, contact information was verified, and notification letters have now been mailed to the affected individuals. Data exposed in the incident includes names, birthdates, contact information, login credentials, government identification numbers (such as Social Security numbers), financial account information, and limited medical information and limited biometric information. The affected individuals have been offered complementary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have potentially been affected.

The post Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data appeared first on The HIPAA Journal.

Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company

Security incidents have resulted in the exposure of patient data at United Technology Systems, Meridian Health Plan of Illinois, and Little Flower Children and Family Services.

Unlimited Technology Systems

Unlimited Technology Systems LLC (UTS), a Montgomery, Ohio-based revenue cycle management company and practice management software provider, has identified unauthorized activity within a commercial data center that contained the personal and protected health information of patients of its healthcare provider clients.

According to its data breach notification letter, unauthorized activity was identified on October 19, 2025. Assisted by a third-party cybersecurity and digital forensics company, UTS determined that an unauthorized third party may have obtained a copy of files from that environment between October 5 and October 10, 2025.

The data review has recently been completed, and UTS has confirmed that the following types of information may have been involved: name, address, email address, phone number, date of birth, health insurance information, patient balance information, Social Security number, medical information including diagnosis, and scanned documents such as driver’s license or other government ID documents. UTS said full medical records, medical images, and financial information were not involved.

As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring services for 24 months, and UTS has implemented enhanced security measures to prevent similar incidents in the future.  The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Meridian Health Plan of Illinois

Meridian Health Plan of Illinois, a government-sponsored managed care service provider, has announced a data breach affecting 21,027 individuals. The incident was detected on April 28, 2026, when unauthorized access to the Meridian provider portal was identified. The provider portal is used by healthcare providers to manage patient information and process claims.

The unauthorized access was blocked, and an investigation was launched to determine the nature and scope of the breach. Meridian Health Plan has confirmed that personally identifiable information such as member names, contact information, and dates of birth had been exposed, along with protected health information such as Member ID numbers, health plan names, eligibility and claims information, and provider information. At the time of issuing notification letters, no misuse of the exposed information had been identified. Credit monitoring and identity theft protection services do not appear to have been made available.

Little Flower Children and Family Services

Little Flower Children and Family Services, a New York-based provider of support services to individuals with developmental disabilities and their families, has recently issued notification letters to individuals informing them that some of their information was exposed in a recent security incident.

Unusual network activity was identified on March 20, 2026, and the forensic investigation confirmed unauthorized access to its network between March 12, 2026, and March 20, 2026. While the review of the affected data is ongoing to determine the specific information exposed, Little Flower Children and Family Services said the types of data likely compromised in the incident include the following:

Name, address, phone number, email address, date of birth, Social Security number, driver’s license number, state ID number, taxpayer ID number, passport number, financial account information, payment card information, digital signature, biometric data, diagnosis and treatment information, prescription information, Medicare/Medicaid number, health insurance information, and treatment cost information. The affected individuals are being offered complementary credit monitoring and identity theft protection services, and steps have been taken to improve security to prevent similar incidents in the future.

The post Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company appeared first on The HIPAA Journal.

TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries

Data breaches have been announced by TriWest Healthcare Alliance, Texas Medicaid and Healthcare Partnership, the Minnesota Health Insurance Network, and Secure Health Plans of Georgia.

TriWest Healthcare Alliance

TriWest Healthcare Alliance, a contractor that manages care for active duty, retired, and National Guard and Reserve military personnel and their family members under the United States Department of Veterans Affairs VAPCCC program, has shared information on a data breach reported to the HHS’ Office for Civil Rights on May 21, 2026. According to the OCR breach report, the protected health information of 11,848 individuals was potentially compromised in the incident.

The security incident was first identified on April 16, 2026. The forensic investigation confirmed that an unauthorized third party gained limited access to parts of its network and downloaded files containing protected health information. Data compromised in the incident includes names, Department of Defense Benefits Numbers, beneficiaries’ ZIP codes, and health-related information. Only 5 individuals had their addresses, dates of birth, and Social Security numbers stolen.

At the time of issuing notification letters, some of which were sent on July 2, 2026, no misuse of the impacted information had been identified; however, as a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring services for 24 months. Security controls have been enhanced, system monitoring tools have been strengthened, and additional security awareness training has been provided to its workforce.

Texas Medicaid and Healthcare Partnership

Texas Medicaid and Healthcare Partnership (TMHP), a state Medicaid contractor, has recently reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 2,045 individuals.  According to the TMHP substitute data breach notice, this was a fraud-related incident that involved unauthorized access to certain internal systems between February 5, 2026, and March 26, 2026.

When the unauthorized access was detected, immediate action was taken to contain the incident and secure its network, and additional security measures have been implemented to harden security. The forensic investigation determined on April 20, 2026, that personal and protected health information of 1,828 Medicaid clients and 217 healthcare providers had been exposed.

For Medicaid clients, the data compromised in the incident included full names, addresses, dates of birth, Social Security numbers, Medicaid numbers, Medicaid benefits information, Medicaid card information, and health information. Healthcare provider information included full names, addresses, emails, medical license information, financial information, driver’s license numbers, Social Security numbers, tax identification numbers, and other provider enrollment management system information.

Notification letters were mailed to the affected individuals on June 18, 2026, who have been offered complimentary identity theft protection and identity recovery services. TMHP said that at the time of issuing notifications, no information had been found to indicate any actual or attempted misuse of the impacted information.

Minnesota Health Insurance Network

Minnesota Health Insurance Network, a Burnsville, MN-based health insurance brokerage, has started notifying individuals about a recent security incident that exposed personal and protected health information. The security incident was identified on March 17, 2026, and its forensic investigation determined that there had been unauthorized access to parts of its network between March 16 and March 17, 2026, during which time files were exfiltrated from its network.

The affected data has been reviewed and found to include names, dates of birth, Social Security numbers, driver’s license/state ID numbers, other government-issued ID numbers, financial account numbers, credit/debit card information, diagnosis and treatment information, and health insurance information. Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While regulators have been notified, the incident is not currently listed on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.

Secure Health Plans of Georgia

Secure Health Plans of Georgia (Secure Health), a provider of administrative services, care management, and healthy lifestyle programs to employers with self-funded health benefit plans, is reviewing files that were exposed in a recent cybersecurity incident. The incident was identified on February 12, 2026, and the forensic investigation confirmed unauthorized access to its systems on or before February 3, 2026, until February 12, 2026. During that time, files containing individuals’ protected health information may have been viewed or copied. Secure Health has not yet confirmed the exact types of information exposed in the incident, although protected health information was exposed.

The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 individuals. The total will be updated when the data review is concluded, and notification letters will be mailed stating the types of data involved. Secure Health has taken steps to strengthen security to prevent similar incidents in the future.

The post TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries appeared first on The HIPAA Journal.

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Investments has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident first identified on July 4, 2026. Clover Health Investments is a publicly traded health insurer that provides Medicare Advantage plans, directly contracts with the U.S. government, and manages care for Medicare beneficiaries in 11 states. The company also provides technology and software tools to physicians.

Unusual login activity was identified, and its forensic investigation confirmed that a hacker had accessed three employee email accounts after the employees had been tricked by social engineering into disclosing their credentials. Clover Health activated its incident response plan to contain the incident and believes that unauthorized access has been terminated.

Clover Health said the compromised accounts belonged to non-managerial health plan employees who were responsible for handling member visit scheduling and broker-facing sales work. The accounts did not have permissions to access corporate financial or claims systems, but they could access some personal and protected health information.

The volume of exposed data has yet to be determined, and Clover Health has not publicly confirmed whether sensitive data was exfiltrated from its systems. Clover Health has reported the incident to law enforcement and is working with third-party cybersecurity experts to investigate the incident and review the information that was exposed, viewed, or exfiltrated.

Clover Health said it does not believe that the incident has had a material impact on business operations, its financial condition, or results of operations. Notifications will be mailed to the affected individuals if it is determined that HIPAA-protected data has been exposed or stolen, and Clover Health has confirmed that steps are being taken to strengthen security to prevent similar incidents in the future.

The post Clover Health Assessing Impact of Social Engineering Incident appeared first on The HIPAA Journal.

Major Healthcare Software Vendor Investigating Cyberattack

The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was stolen in the attack, including some employee and customer data.

Craneware is a UK company that heavily targets U.S. healthcare companies. The company makes healthcare accounting and billing software, and partners with 2,000  hospitals and health systems, and around 10,000 pharmacies and clinics, many of which are located in the United States. According to the Craneware website, its software and Trisus cloud platform underpin around 165 million unique patient encounters and impact half a trillion healthcare dollars.

Craneware reports that the company quickly implemented its incident response plan and contained the incident, without any disruption to customer services or the company’s operations. The external investigators assisting with the response have not found any further signs of compromise, which indicates that the hackers have been ejected from its network.

While the review of the impacted data is still in the early stages, the company has confirmed that “a significant volume of file names were viewed and exfiltrated” by the hackers before they were ejected from its systems. “A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” explained the company in its cybersecurity incident notice. “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.” The company has yet to confirm if any patient data was compromised in the incident.

The cyberattack has been reported to the UK’s data watchdog, the Information Commissioner’s Office (ICO), and the U.S. Federal Bureau of Investigation (FBI). The company has not yet disclosed the threat actor or group behind the attack, when access to its environment was gained, when the attack was discovered, or the names of affected customers.

“The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations,” explained the company.

There has been a spate of recent cyberattacks on healthcare vendors including software providers and medical device companies. Vendors often work with large numbers of healthcare clients and store or have access to large volumes of sensitive patient data, so they are attractive targets for hackers. It is currently unclear whether this was a data theft and extortion incident and if a ransom demand has been issued. No hacking group appears to have claimed responsibility for the attack.

The post Major Healthcare Software Vendor Investigating Cyberattack appeared first on The HIPAA Journal.

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy Exact Sciences systems of its cancer diagnostics business, and another involving its LabCentral portal.

Abbott acquired Exact Sciences in late 2025, a company specializing in cancer screening and precision oncology diagnostics. The acquisition allowed the company to enter the fast-growing cancer diagnostics market. Abbott has yet to confirm the extent to which patient data has been compromised but has confirmed unauthorized access to certain legacy cancer diagnostics systems. The intrusion did not impact any other Abbott businesses, and had no impact on its business operations, products, product availability, manufacturing/lab operations, or its ability to serve patients. The impacted Exact Sciences systems are separate from Abbott’s systems. In a July 16, 2026, announcement, Abbott said it does not anticipate the incident having any material impact on the business or its financial results.

The ShinyHunters data theft and extortion group claimed responsibility for the attack and threatened to publish the stolen data if payment was not made. Abbott negotiated with the group, and the publication deadline was extended to July 21, 2026. It is currently unclear if payment has been made, and as of July 20, 2026, the stolen data has not been leaked.

ShinyHunters often compromises victims’ systems through voice phishing (vishing) and appears to have used those tactics in this attack. Bleeping Computer reports that it received communications from a ShinyHunters spokesperson stating vishing attacks were conducted on Abbott employees in mid-June, which allowed the group to compromise a Microsoft Entra single sign-on account that provided access to certain internal systems. The group claims to have exfiltrated 30 million rows of customer data, including names, contact information, dates of birth, and one million Social Security numbers.

An investigation has also been launched into a separate claim from a hacker with the moniker ShadowByt3$. This separate attack, so the hacker claims, involved unauthorized access to the Abbott core business via the LabCentral customer portal. The threat actor claims to have gained access on July 4, 2026, using compromised customer credentials, exfiltrating data over the weekend, although no customer or patient data was compromised. Abbott maintains that the third-party hosted portal does not contain sensitive data, only publicly available, non-sensitive data, such as technical product reference documents including operating manuals, product specifications, and troubleshooting checklists.

Abbott is one of several medtech companies to announce cyberattacks and data breaches in recent months, including Stryker, Medtronic, iRhythm, AdaptHealth, and Intuitive.

The post Abbott Investigating Cyberattack Claims From Two Threat Actors appeared first on The HIPAA Journal.

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a Hanover, New Jersey-based diagnostic testing laboratory that provides medical and diagnostic testing services to healthcare providers, has announced an August 2025 cybersecurity incident affecting more than half a million patients of its healthcare provider clients.

Suspicious activity was identified within its computer systems on August 25, 2025. Systems were isolated to contain the incident, and steps were taken to prevent further unauthorized access. The forensic investigation confirmed that an unauthorized third party gained limited access to certain systems between August 9, 2025, and August 14, 2025. The forensic investigators determined that files containing patient data were exfiltrated from its systems by an unauthorized third party.

Centers Lab engaged third-party data review specialists to perform a detailed review of the impacted data, and after that process was completed, the findings were internally validated. The validation process has recently been completed, and notification letters have been mailed to the affected individuals.  The information compromised in the incident varies from individual to individual and may include names in combination with some or all of the following: date of birth, Social Security number, passport number, driver’s license number/state ID number, medical information, and health insurance information.

Centers Lab said additional data security measures have been implemented to prevent similar incidents in the future, stressing that strong cybersecurity measures had already been implemented prior to the incident. As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring and identity theft protection services for between 12 and 24 months. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 542,377 individuals.

While not disclosed by Centers Lab, the Worldleaks threat group claimed responsibility for the attack and published the stolen data on its dark web data leak site. The affected individuals should therefore take advantage of the free services being offered as a precaution against data misuse.

The post Centers Laboratory Discloses Data Breach Affecting 542K Individuals appeared first on The HIPAA Journal.

All About Women’s Care Data Breach Affects Up to 12,000 Patients

All About Women’s Care in Colorado has notified 12,000 patients that their data has been compromised in a data breach, and Mid-South Pulmonary Sleep Specialists in Tennessee is assessing the impact of a November 2025 ransomware attack.

All About Women’s Care, Colorado

All About Women’s Care, an Englewood, CO-based obstetrics and gynecology practice, has identified unauthorized access to its IT environment. Suspicious activity was identified involving an employee VPN account. Third-party cybersecurity experts were engaged to investigate the activity and confirmed that an unauthorized actor obtained the credentials for the VPN account and used them to access its network environment. Files were copied in the attack, the review of which was completed on June 5, 2026.

The file review confirmed that the impacted data included names, dates of birth, Social Security numbers, driver’s license numbers, other ID numbers, clinical/treatment information, lab results, prescription information, provider information, medical documents, ultrasound images, copies of identification documents (such as passports), and health insurance information.

The practice is working with cybersecurity professionals to enhance security and prevent similar incidents in the future, and policies and procedures related to data privacy and security are being reviewed. The data breach was recently reported to the HHS’ Office for Civil Rights as affecting up to 12,000 patients.

Mid-South Pulmonary Sleep Specialists, Tennessee

Mid-South Pulmonary Sleep Specialists, a Memphis, Tennessee-based pulmonary and sleep medicine practice, has started notifying certain patients about a cybersecurity incident that exposed their personal and protected health information.

Suspicious activity was identified within its computer network on November 2, 2025. The network was secured, and assisted by third-party cybersecurity experts, the practice confirmed unauthorized network access and the exposure and potential theft of patient data. The data review was completed on May 18, 2026, and revealed that a wide range of data was exposed in the incident. The types varied from individual to individual, and may have included names in combination with one or more of the following: address, date of birth, date of service, driver’s license or state ID number, financial account information, health insurance information, medical diagnosis information, medical history, medical provider name, medical record number, medical treatment information, Medicare/Medicaid number, mental or physical condition, other patient identifier, patient account number, prescription information, and/or Social Security number.

Regulators have been notified, but the incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected. The website breach notice does not state the nature of the attack, or for how long the threat actors had access to its network.

This appears to have been a ransomware attack, as the Anubis ransomware claimed responsibility and added Mid-South Pulmonary Sleep Specialists to its data leak site in late November 2025, along with samples of data allegedly stolen in the attack. Anubis claims that the data stolen includes patient information.

The post All About Women’s Care Data Breach Affects Up to 12,000 Patients appeared first on The HIPAA Journal.