HIPAA Breach News

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Investments has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident first identified on July 4, 2026. Clover Health Investments is a publicly traded health insurer that provides Medicare Advantage plans, directly contracts with the U.S. government, and manages care for Medicare beneficiaries in 11 states. The company also provides technology and software tools to physicians.

Unusual login activity was identified, and its forensic investigation confirmed that a hacker had accessed three employee email accounts after the employees had been tricked by social engineering into disclosing their credentials. Clover Health activated its incident response plan to contain the incident and believes that unauthorized access has been terminated.

Clover Health said the compromised accounts belonged to non-managerial health plan employees who were responsible for handling member visit scheduling and broker-facing sales work. The accounts did not have permissions to access corporate financial or claims systems, but they could access some personal and protected health information.

The volume of exposed data has yet to be determined, and Clover Health has not publicly confirmed whether sensitive data was exfiltrated from its systems. Clover Health has reported the incident to law enforcement and is working with third-party cybersecurity experts to investigate the incident and review the information that was exposed, viewed, or exfiltrated.

Clover Health said it does not believe that the incident has had a material impact on business operations, its financial condition, or results of operations. Notifications will be mailed to the affected individuals if it is determined that HIPAA-protected data has been exposed or stolen, and Clover Health has confirmed that steps are being taken to strengthen security to prevent similar incidents in the future.

The post Clover Health Assessing Impact of Social Engineering Incident appeared first on The HIPAA Journal.

Major Healthcare Software Vendor Investigating Cyberattack

The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was stolen in the attack, including some employee and customer data.

Craneware is a UK company that heavily targets U.S. healthcare companies. The company makes healthcare accounting and billing software, and partners with 2,000  hospitals and health systems, and around 10,000 pharmacies and clinics, many of which are located in the United States. According to the Craneware website, its software and Trisus cloud platform underpin around 165 million unique patient encounters and impact half a trillion healthcare dollars.

Craneware reports that the company quickly implemented its incident response plan and contained the incident, without any disruption to customer services or the company’s operations. The external investigators assisting with the response have not found any further signs of compromise, which indicates that the hackers have been ejected from its network.

While the review of the impacted data is still in the early stages, the company has confirmed that “a significant volume of file names were viewed and exfiltrated” by the hackers before they were ejected from its systems. “A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” explained the company in its cybersecurity incident notice. “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.” The company has yet to confirm if any patient data was compromised in the incident.

The cyberattack has been reported to the UK’s data watchdog, the Information Commissioner’s Office (ICO), and the U.S. Federal Bureau of Investigation (FBI). The company has not yet disclosed the threat actor or group behind the attack, when access to its environment was gained, when the attack was discovered, or the names of affected customers.

“The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations,” explained the company.

There has been a spate of recent cyberattacks on healthcare vendors including software providers and medical device companies. Vendors often work with large numbers of healthcare clients and store or have access to large volumes of sensitive patient data, so they are attractive targets for hackers. It is currently unclear whether this was a data theft and extortion incident and if a ransom demand has been issued. No hacking group appears to have claimed responsibility for the attack.

The post Major Healthcare Software Vendor Investigating Cyberattack appeared first on The HIPAA Journal.

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy Exact Sciences systems of its cancer diagnostics business, and another involving its LabCentral portal.

Abbott acquired Exact Sciences in late 2025, a company specializing in cancer screening and precision oncology diagnostics. The acquisition allowed the company to enter the fast-growing cancer diagnostics market. Abbott has yet to confirm the extent to which patient data has been compromised but has confirmed unauthorized access to certain legacy cancer diagnostics systems. The intrusion did not impact any other Abbott businesses, and had no impact on its business operations, products, product availability, manufacturing/lab operations, or its ability to serve patients. The impacted Exact Sciences systems are separate from Abbott’s systems. In a July 16, 2026, announcement, Abbott said it does not anticipate the incident having any material impact on the business or its financial results.

The ShinyHunters data theft and extortion group claimed responsibility for the attack and threatened to publish the stolen data if payment was not made. Abbott negotiated with the group, and the publication deadline was extended to July 21, 2026. It is currently unclear if payment has been made, and as of July 20, 2026, the stolen data has not been leaked.

ShinyHunters often compromises victims’ systems through voice phishing (vishing) and appears to have used those tactics in this attack. Bleeping Computer reports that it received communications from a ShinyHunters spokesperson stating vishing attacks were conducted on Abbott employees in mid-June, which allowed the group to compromise a Microsoft Entra single sign-on account that provided access to certain internal systems. The group claims to have exfiltrated 30 million rows of customer data, including names, contact information, dates of birth, and one million Social Security numbers.

An investigation has also been launched into a separate claim from a hacker with the moniker ShadowByt3$. This separate attack, so the hacker claims, involved unauthorized access to the Abbott core business via the LabCentral customer portal. The threat actor claims to have gained access on July 4, 2026, using compromised customer credentials, exfiltrating data over the weekend, although no customer or patient data was compromised. Abbott maintains that the third-party hosted portal does not contain sensitive data, only publicly available, non-sensitive data, such as technical product reference documents including operating manuals, product specifications, and troubleshooting checklists.

Abbott is one of several medtech companies to announce cyberattacks and data breaches in recent months, including Stryker, Medtronic, iRhythm, AdaptHealth, and Intuitive.

The post Abbott Investigating Cyberattack Claims From Two Threat Actors appeared first on The HIPAA Journal.

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a Hanover, New Jersey-based diagnostic testing laboratory that provides medical and diagnostic testing services to healthcare providers, has announced an August 2025 cybersecurity incident affecting more than half a million patients of its healthcare provider clients.

Suspicious activity was identified within its computer systems on August 25, 2025. Systems were isolated to contain the incident, and steps were taken to prevent further unauthorized access. The forensic investigation confirmed that an unauthorized third party gained limited access to certain systems between August 9, 2025, and August 14, 2025. The forensic investigators determined that files containing patient data were exfiltrated from its systems by an unauthorized third party.

Centers Lab engaged third-party data review specialists to perform a detailed review of the impacted data, and after that process was completed, the findings were internally validated. The validation process has recently been completed, and notification letters have been mailed to the affected individuals.  The information compromised in the incident varies from individual to individual and may include names in combination with some or all of the following: date of birth, Social Security number, passport number, driver’s license number/state ID number, medical information, and health insurance information.

Centers Lab said additional data security measures have been implemented to prevent similar incidents in the future, stressing that strong cybersecurity measures had already been implemented prior to the incident. As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring and identity theft protection services for between 12 and 24 months. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 542,377 individuals.

While not disclosed by Centers Lab, the Worldleaks threat group claimed responsibility for the attack and published the stolen data on its dark web data leak site. The affected individuals should therefore take advantage of the free services being offered as a precaution against data misuse.

The post Centers Laboratory Discloses Data Breach Affecting 542K Individuals appeared first on The HIPAA Journal.

All About Women’s Care Data Breach Affects Up to 12,000 Patients

All About Women’s Care in Colorado has notified 12,000 patients that their data has been compromised in a data breach, and Mid-South Pulmonary Sleep Specialists in Tennessee is assessing the impact of a November 2025 ransomware attack.

All About Women’s Care, Colorado

All About Women’s Care, an Englewood, CO-based obstetrics and gynecology practice, has identified unauthorized access to its IT environment. Suspicious activity was identified involving an employee VPN account. Third-party cybersecurity experts were engaged to investigate the activity and confirmed that an unauthorized actor obtained the credentials for the VPN account and used them to access its network environment. Files were copied in the attack, the review of which was completed on June 5, 2026.

The file review confirmed that the impacted data included names, dates of birth, Social Security numbers, driver’s license numbers, other ID numbers, clinical/treatment information, lab results, prescription information, provider information, medical documents, ultrasound images, copies of identification documents (such as passports), and health insurance information.

The practice is working with cybersecurity professionals to enhance security and prevent similar incidents in the future, and policies and procedures related to data privacy and security are being reviewed. The data breach was recently reported to the HHS’ Office for Civil Rights as affecting up to 12,000 patients.

Mid-South Pulmonary Sleep Specialists, Tennessee

Mid-South Pulmonary Sleep Specialists, a Memphis, Tennessee-based pulmonary and sleep medicine practice, has started notifying certain patients about a cybersecurity incident that exposed their personal and protected health information.

Suspicious activity was identified within its computer network on November 2, 2025. The network was secured, and assisted by third-party cybersecurity experts, the practice confirmed unauthorized network access and the exposure and potential theft of patient data. The data review was completed on May 18, 2026, and revealed that a wide range of data was exposed in the incident. The types varied from individual to individual, and may have included names in combination with one or more of the following: address, date of birth, date of service, driver’s license or state ID number, financial account information, health insurance information, medical diagnosis information, medical history, medical provider name, medical record number, medical treatment information, Medicare/Medicaid number, mental or physical condition, other patient identifier, patient account number, prescription information, and/or Social Security number.

Regulators have been notified, but the incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected. The website breach notice does not state the nature of the attack, or for how long the threat actors had access to its network.

This appears to have been a ransomware attack, as the Anubis ransomware claimed responsibility and added Mid-South Pulmonary Sleep Specialists to its data leak site in late November 2025, along with samples of data allegedly stolen in the attack. Anubis claims that the data stolen includes patient information.

The post All About Women’s Care Data Breach Affects Up to 12,000 Patients appeared first on The HIPAA Journal.

Ohio Living; Erlanger; Heart of America Eye Care Announce Data Breaches

Data breaches have recently been announced by the senior living company Ohio Living, Erlinger Health System in Tennessee, and Heart of America Eye Care in Missouri.

Ohio Living

The Westerville, Ohio-based nonprofit senior living company Ohio Living has identified unauthorized access to its network. Suspicious activity was identified within its computer network on April 17, 2026. Its network was secured, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts.

The forensic investigation confirmed unauthorized network access between April 16, 2026, and April 17, 2026, and the exfiltration of files containing patient information. While the specific types of information involved for each individual have yet to be determined, Ohio Living states that the categories of data likely involved include names, addresses, birth dates, Social Security numbers, medical histories, disability information, diagnostic and treatment information, prescription information, physician information, medical record numbers, health insurance information, and financial account/payment card information.

Ohio Living is reviewing its security policies and procedures and is implementing enhanced cybersecurity safeguards to prevent similar incidents in the future. The data review is ongoing, so the total number of affected individuals has yet to be determined. The HHS’ Office for Civil Rights has been informed that the data breach affected at least 500 individuals. The total will be updated when the data review is concluded.

Erlanger Health System

Erlanger Health System, a Chattanooga, Tennessee-based health system and operator of six hospitals and multiple healthcare facilities, has announced a security incident affecting a limited number of patients. The incident was detected on May 13, 2026, and affected 4,237 Erlanger Western California patients.

The investigation revealed that patient information was inadvertently sent to a billing partner that provides services for its Erlanger Tennessee campuses. The information was disclosed between July 1, 2025, and May 27, 2026, and related to individuals who had received anesthesia care. Those patients of Erlanger Western California received anesthesia care from a different anesthesia group.

The billing partner was a business associate and was therefore aware of its responsibilities with respect to HIPAA; however, it was an impermissible disclosure warranting breach notifications. The data transmitted included names, birth dates, medical record numbers, mailing addresses, email addresses, telephone numbers, internal hospital account numbers, insurance information, guarantor names, guarantor addresses, guarantor telephone numbers, dates of service, and limited medical information associated with surgical care, including operative notes.

Heart of America Eye Care

MVP VIP Holdco, doing business as Heart of America Eye Care, an ophthalmology and optometry services provider at its locations in Overland Park, Prairie Village and Shawnee Mission, KS, and Belton, MO, has notified regulators and patients about a hacking incident that exposed patient data.

The website breach notice does not state when the hacking incident was detected; however, the forensic investigation determined that patient information was viewed or copied from its systems between April 1, 2026, and April 6, 2026. The notice states that the investigation is underway to determine the extent to which protected health information was involved. The HHS’ Office for Civil Rights has been informed that the data breach affected at least 500 individuals. The total will be updated when the data review is concluded.

The post Ohio Living; Erlanger; Heart of America Eye Care Announce Data Breaches appeared first on The HIPAA Journal.

Community Health Center of Buffalo & Greenbaum Rowe Smith & Davis Confirm Data Breaches

Data breaches have been announced by Community Health Center of Buffalo in New York and the New Jersey law firm Greenbaum Rowe Smith & Davis.

Community Health Center of Buffalo, New York

Community Health Center of Buffalo (CHCB) in New York has identified a cybersecurity incident in which sensitive data was potentially accessed or acquired. Suspicious activity was identified within its computer network on April 21, 2026. Assisted by digital forensics experts, unauthorized network access was confirmed between April 20 and April 21, 2026.

The files are currently being reviewed to determine the types of data involved and the affected individuals. That process is ongoing; however, CHCB reports that the types of data likely involved includes names in combination with one or more of the following: address, date of birth, Social Security number, driver’s license, medical information such as diagnoses, treatment information, prescriptions/medications, treatment locations, lab results, medical record numbers, provider names, patient medical histories, and health insurance information

Data privacy and security practices are being reviewed, and steps are being taken to improve security. Credit monitoring and identity theft protection services will be made available. The data breach has been reported to the HHS’ Office for Civil Rights using an interim total of at least 501 affected individuals. The total will be updated when the investigation and file review are concluded.

Greenbaum Rowe Smith & Davis, New Jersey

Greenbaum Rowe Smith & Davis LLP, a New Jersey-based law firm, has started notifying 12,801 individuals about a breach of their protected health information. The practice provides legal services to healthcare practices in the state of New Jersey, which require access to certain patient data. The practice has confirmed that it experienced a cybersecurity incident involving unauthorized access to systems containing the data of patients of Atlantic Health System, Hackensack Meridian Health, and Trinitas Regional Medical Center.

Data exposed in the incident included names, Social Security numbers, medical information, health insurance information, and other personal data. At the time of issuing notifications, the practice was unaware of any public release of the impacted data. The practice is offering the affected individuals complimentary credit monitoring and identity theft protection services and has taken steps to improve security to prevent similar incidents in the future.

The post Community Health Center of Buffalo & Greenbaum Rowe Smith & Davis Confirm Data Breaches appeared first on The HIPAA Journal.

May 2026 Healthcare Data Breach Report

Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting 500 or more individuals were reported in May 2026. May’s current total represents a 27.1% month-over-month increase in data breaches. Over the past 12 months, an average of 64 large healthcare data breaches were reported each month.

Healthcare data breaches in the past 12 months - May 2026

From January 1, 2026, to May 31, 2026, 319 data breaches affecting 500 or more individuals have been reported to OCR. This time last year, the total stood at 342 large data breaches.

HEalthcare data breaches - January 1 - May 31 - 2022-2026

While data breaches increased from April, the number of affected individuals fell by 34.8% to 879,447 individuals. In May, an average of 14,417 individuals were affected by healthcare data breaches, down from an average of 28,116 individuals in April. Over the past 12 months, an average of 10.6 million individuals have been affected by healthcare data breaches each month.

Individuals affected by healthcare data breaches in the past 12 months - May 2026

Data breaches are down slightly year-over-year, but there has been a massive reduction in the number of affected individuals. Very large data breaches have not been reported to OCR in the numbers seen in previous years. From January 1, 2026, to May 31, 2026, across the 319 data breaches, at least 21,085,405 individuals have been affected. The OCR breach portal shows that from January 2025 to May 2025, 33,116,809 individuals were affected by data breaches.

Individuals affected by healthcare data breaches - jan 1 - May 31, 2022-2026

Biggest Healthcare Data Breaches of May 2026

In May 2026, 17 data breaches affecting 10,000 or more individuals were reported to OCR, all of which were hacking incidents. The biggest data breach of the month was reported by Radiology Associates of Richmond, affecting more than 266,000 individuals, followed by a hacking incident at Western Orthopaedics which affected more than 113,000 individuals.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
Radiology Associates of Richmond VA Healthcare Provider 266,183 Hacking incident
Western Orthopaedics, P.C. CO Healthcare Provider 113,330 Hacking incident
ERMI LLC GA Healthcare Provider 74,074 Hacking incident
Singing River Health System MS Healthcare Provider 53,888 Hacking incident
Southern Illinois Ob-Gyn Associates, S.C. IL Healthcare Provider 38,700 Hacking incident
Gastro Health FL Healthcare Provider 35,632 Unauthorized access to email accounts
Eyemart Express, LLC TX Healthcare Provider 25,000 Hacking incident
Connecticut Department of Social Services CT Health Plan 22,500 Unauthorized access to provider portal website
Bridle Trails Family Dentistry WA Healthcare Provider 20,976 Unauthorized access to email account
Community Connections DC Healthcare Provider 18,943 Ransomware attack (INCRansom)
Virta Medical PC CO Healthcare Provider 14,636 Hacking incident (Lapsus$)
Saurabh N. Patel, M.D – Florida Retina Center LA Healthcare Provider 13,652 Hacking incident
Greenbaum Rowe Smith & Davis LLP NJ Business Associate 12,801 Hacking incident
Wellpoint Washington, Inc. IN Health Plan 12,020 Unauthorized access to email account
Defense Health Agency (TriWest) VA Health Plan 11,848 Hacking incident
IKRON Corporation OH Healthcare Provider 11,845 Hacking incident
Elara Caring TX Healthcare Provider 10,490 Hacking incident at third-party vendor

May’s total number of affected individuals may increase considerably over the coming weeks and months, as healthcare organizations complete their data breach investigations. HIPAA-regulated entities have 60 days from the date of discovery of a data breach to issue notifications to the HHS’ Office for Civil Rights and the affected individuals. HIPAA requires OCR to be notified even if the total number of individuals has yet to be determined by the 60-day deadline. In such cases, an estimate should be provided. Many regulated entities use a placeholder estimate of 500 or 501 individuals in such cases, and in May, 7 regulated entities appear to have used these placeholder figures.

Regulated Entity State Covered Entity Type Individuals Affected Cause of Breach
United Medical Doctors CA Healthcare Provider 501 Hacking/IT Incident
NJ Pain Care Specialists, LLC NJ Healthcare Provider 501 Hacking/IT Incident
Palomar Health Medical Group CA Healthcare Provider 501 Hacking/IT Incident
Aroostook Mental Health Center ME Healthcare Provider 501 Hacking/IT Incident
Campbell University NC Healthcare Provider 500 Hacking/IT Incident
BAYADA Home Health Care, Inc. NJ Healthcare Provider 500 Hacking/IT Incident
Integrated Pain Associates TX Healthcare Provider 500 Hacking/IT Incident

Causes of May 2026 Healthcare Data Breaches

Hacking and other IT incidents dominated the breach reports in May, as has been the case each month for several years. Out of the month’s 61 large healthcare data breaches, 54 were classed as hacking/IT incidents – 88.5% of the month’s data breaches. Across those incidents, the protected health information of 853,532 individuals was compromised- 88.5% of the month’s total affected individuals. On average, hacking/IT incidents affected 15,806 individuals in May, with a median breach size of 3,619 individuals.

Causes of May 2026 healthcare data breaches

There were 7 data breaches classed as unauthorized access/disclosure incidents, representing 11.5% of the month’s breaches. Across those incidents, the protected health information of 25,915 individuals was unlawfully accessed or disclosed. On average, 3,702 individuals were affected by each incident in May. The median breach size was 3,086 individuals. There were no reported theft, loss, or improper disposal incidents in May.

Given the large number of hacking incidents, it is no surprise that the most common location of breached protected health information was network servers. Email incidents were also reported in high numbers.

Location of breached PHI in May 2026 healthcare data breaches

States Affected by May 2026 Healthcare Data Breaches

Large healthcare data breaches were reported by HIPAA-regulated entities in 26 U.S. states and the District of Columbia. California was the worst affected state with 6 breaches.

State Breaches
California 6
Florida, New Jersey, New York, North Carolina, Ohio, Texas & Virginia 4
Colorado 3
Indiana, Maine, Michigan, Pennsylvania, South Carolina & the District of Columbia 2
Arizona, Connecticut, Georgia, Illinois, Iowa, Louisiana, Massachusetts, Mississippi, Oregon, Tennessee, Washington & Wisconsin 1

In terms of affected individuals, Virginia topped the list with almost 300,000 state residents affected.

State Individuals Affected State Individuals Affected
Virginia 290,254 Louisiana 13,652
Colorado 128,661 Pennsylvania 7,095
Georgia 74,074 South Carolina 6,946
Mississippi 53,888 Iowa 6,666
Florida 44,649 Michigan 6,456
Texas 40,045 California 5,303
Illinois 38,700 North Carolina 4,949
Ohio 28,540 Massachusetts 3,086
Connecticut 22,500 Maine 3,024
Washington 20,976 Oregon 2,856
District of Columbia 20,014 Arizona 2,316
New York 19,674 Tennessee 1,807
Indiana 17,325 Wisconsin 1,080
New Jersey 14,911

Data Breaches at HIPAA -Regulated Entities

In May 2026, 42 data breaches were reported by healthcare providers, 9 breaches were reported by health plans, and 10 data breaches were reported by business associates. When a breach occurs at a business associate, the affected covered entities must be informed. Each covered entity may delegate the breach notification responsibilities to the business associate, but it is ultimately the responsibility of each covered entity to ensure that breach notifications are issued. In many cases, a breach at a business associate is reported by the covered entity.

The pie charts below show where the data breach occurred, rather than the reporting entity, which shows that 22 of the 61 breaches (rather than 10) occurred at business associates in May.

May 2026 data breaches at HIPAA-regulated entities

Individuasl affected by data breaches at HIPAA-regulated entities in May 2026

HIPAA Enforcement Activity in May 2026

No enforcement actions were announced by OCR or state attorneys general in May.

The post May 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.

California Gay & Lesbian Services Center Data Breach Affects 75,500 Individuals

Gay & Lesbian Community Services Center of Orange County, California, a provider of mental health, HIV testing, education and outreach, has identified unauthorized access to its network and the exposure of the personal and protected health information of up to 75,532 individuals.

Suspicious network activity was identified on or around December 26, 2025, and third-party cybersecurity experts were engaged to investigate the incident. They confirmed that there had been unauthorized access to the network from December 25 to December 26, 2025, and files containing sensitive information may have been viewed or acquired.

The review of the impacted data was completed on May 6, 2026, when it was confirmed that the following types of information were stored on the compromised parts of the network: full names, dates of birth, Social Security numbers, diagnosis information, prescription information, medical histories and treatment information, medical record numbers, health insurance information, driver’s license numbers, government identification numbers, state identification numbers, passport numbers, taxpayer identification numbers, financial account information, biometric identifiers, financial account information, and payment card information. The types of information involved varied from individual to individual.

Gay & Lesbian Community Services Center of Orange County said it is committed to maintaining the privacy of personal information in its possession and continually evaluates and modifies its security practices to enhance data privacy and security. The affected individuals have been advised to remain vigilant and monitor their account statements and free credit reports for suspicious activity. The website breach notice makes no mention of free credit monitoring or identity theft protection services.

Alta Orthopaedics

Alta Orthopaedics, a Santa Barbara, CA-based orthopedics practice with six locations in Santa Barbara, Santa Maria, Solvang, and Oxnard, has started mailing notification letters to patients affected by a recent security incident.

On March 10, 2026, the practice identified suspicious activity within its computer network. The forensic investigation determined that there had been unauthorized access to certain information on its network between February 3, 2026, and February 6, 2026. The review of the exposed files confirmed that they contained personal and protected health information such as names, addresses, phone numbers, Social Security numbers, driver’s license/state ID numbers, birth dates, billing codes, dates of service, reasons for visits, treatment costs, provider names, diagnoses, treatment information, clinical information, treatment location, medical record numbers, patient account numbers, and health insurance information.

The incident was reported to law enforcement, policies and procedures related to data privacy and security have been reviewed, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services. Regulators have been notified; however, the number of affected individuals has yet to be publicly disclosed.

Lake Region Healthcare

Lake Region Healthcare, a nonprofit rural health system based in Fergus Falls, Minnesota, has notified individuals affected by a recent cybersecurity incident. Unauthorized access to its network was first identified on May 19, 2025. Law enforcement was notified, and an investigation was launched to determine the nature and scope of the unauthorized activity.

No evidence was found to indicate any unauthorized access to electronic medical records; however, files containing patient information may have been viewed or acquired on or around May 19, 2025. It has taken more than a year to review the affected data. That process was completed on June 5, 2026, when it was confirmed that names were exposed, along with one or more of the following: date of birth, Social Security number, medical record number, patient account number, health insurance information, contact information, medical and/or treatment information, government-issued identification, and/or financial information.

Lake Region Healthcare said it is unaware of any actual or attempted misuse of that data; however, as a precaution, the affected individuals have been offered complimentary identity theft protection services. The scale of the breach has yet to be publicly disclosed, although according to notifications to state attorneys general, 294 Texas residents and 20 Massachusetts residents are among the affected individuals.

The post California Gay & Lesbian Services Center Data Breach Affects 75,500 Individuals appeared first on The HIPAA Journal.