HIPAA Breach News

Boston Scientific Cyberattack Impacting Operations

The Massachusetts-based biotechnology and biomedical engineering firm Boston Scientific has disclosed a major cyber incident that is affecting certain information technology systems. The incident has caused a network outage, prevented access to certain business applications, and is disrupting company operations.

Boston Scientific is a medical device company that operates in 127 countries, employs around 59,000 individuals globally, and has annual revenues of around $20.1 billion. The company manufactures devices for interventional cardiology such as pacemakers and cardiac ablation systems, and a range of devices and products for neuromodulation, neurological surgery, urology and pelvic health, endoscopy, pulmonology, interventional radiology, and vascular surgery. The company’s products are used to treat more than 48 million patients a year.

According to the August 26, 2026, announcement, the company identified the incident on August 25, 2026. The company also filed a Form 8-K report with the U.S. Securities and Exchange Commission (SEC) to alert shareholders. At the time of the filing, Boston Scientific had yet to determine if the incident is reasonably likely to have a material impact on the company.

Boston Scientific immediately implemented its incident response procedures and engaged a third-party cybersecurity company to assist with assessment, containment, and to determine the nature and scope of the unauthorized activity. Boston Scientific said the incident has prevented access to certain operating systems and business applications, and is affecting the company’s ability to process and ship customer orders. The disruption is global, with employees in its manufacturing facilities in Cork, Ireland, sent home as they are unable to work. Work is ongoing to safely and securely restore the affected functions and systems, and investigate the incident to determine the extent, if any, of data theft. Boston Scientific is currently unable to provide a timeline of when systems will be fully restored and normal business operations will resume.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Boston Scientific has not publicly disclosed information about the exact nature of the attack, such as whether ransomware was involved, how access to its systems occurred, if a ransom demand was received, and if the company is aware of any data theft claims. The threat actor behind the attack does not appear to have claimed responsibility, which, given that the attack occurred only two days ago, is not unusual.

The Boston Scientific cyberattack is the latest in a string of attacks on medical technology and biotechnology firms. Previous attacks include the recently disclosed ShinyHunters attack on Baxter International, and cyberattacks on Medtronic, Stryker, Abbott Laboratories, iRhythm, and AdaptHealth.  Several threat groups were behind those attacks, including financially motivated data theft and extortion operations, ransomware groups, and, in the case of Stryker, an Iran-linked threat group.

Cyberattacks on medtech companies typically involve data theft and extortion, but as this incident shows, they can cause major disruption to business operations, which can impact patients. “A cardiac device that misses its ship date can mean a cancelled surgery. That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for,” said Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs.

“Medical devices also aren’t something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them,” Krell said. “Disrupt order processing and shipping, and the consequences show up in hospitals pretty quickly. The harder problem is getting manufacturing back online. These aren’t ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another.”

The post Boston Scientific Cyberattack Impacting Operations appeared first on The HIPAA Journal.

ShinyHunters Leaks 7.1 Million Baxter International Records

The ShinyHunters data theft and extortion group recently claimed responsibility for an intrusion at the medical device manufacturer Baxter International (Baxter). Baxter was added to its dark web data leak site a day after Baxter issued a statement about a cybersecurity incident. ShinyHunters proceeded to leak around 7.1 million records allegedly stolen in the incident. The data leak suggests that Baxter refused to negotiate payment or that negotiations broke down.

Baxter is a Deerfield, Illinois-based manufacturer of medical devices for renal care, IV solutions & infusion pumps, surgical products, inhaled anesthetics, and a range of patient monitoring devices and digital health tools. According to an August 13, 2026, statement from Baxter, unauthorized activity was detected within certain third-party applications. The company immediately activated its cybersecurity response procedures and launched an investigation, with assistance provided by third-party cybersecurity and digital forensics experts. The investigation is ongoing to determine the types and amount of information that may have been accessed or acquired.

Baxter said the incident did not have any impact on patient services or business continuity, and the company continues to operate normally. The incident has not had any impact on its products, connected solutions, or technologies used by customers to deliver patient care. Baxter said it does not anticipate the incident having a material impact on financials or the results of operations. The name of the threat group behind the incident was not publicly disclosed.

On August 14, 2026, ShinyHunters added an entry to its dark web data leak site claiming responsibility for the attack. ShinyHunters gave Baxter an August 17, 2026, deadline to negotiate payment, and threatened to leak the stolen data if payment was not made. On August 19, 2026, ShinyHunters released the stolen data for download.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Baxter has not confirmed the nature of the stolen data, only stating that the attack involved certain third-party applications. ShinyHunters claims that 7.1 million Salesforce records were exfiltrated in the attack, some of which contained personally identifiable information. While the group claims to have obtained 7.1 million records, that does not necessarily mean that 7.1 million patients have been affected. Baxter said it will provide updates as appropriate as additional information is confirmed.

ShinyHunters is one of the most active data theft and extortion groups. The group targets large organizations and has claimed several healthcare victims. In June 2026, ShinyHunters claimed to have exfiltrated 8.8 terabytes of data from Amazon-owned OneMedical, including the protected health information of 153,000 patients. Also in June, the group claimed to have exfiltrated 234 GB of data from DentaQuest, including the protected health information of approximately 2.6 million individuals. ShinyHunters was also behind an incident at another medical device manufacturer earlier this year. In July, Medtronic confirmed that the protected health information of 3.8 million patients was stolen in the attack. Other healthcare victims include iRhythm, AdaptHealth, and Him & Hers.

ShinyHunters has targeted companies across a range of different sectors, and while the group’s attacks appear to be opportunistic, the list of victims includes many healthcare organizations. The increasing number of attacks on healthcare organizations prompted Health-ISAC to issue an alert to the healthcare and public health sector in July about the ShinyHunters group.

The post ShinyHunters Leaks 7.1 Million Baxter International Records appeared first on The HIPAA Journal.

Baylor Genetics: ePHI of 2.8M Patients Exposed in Cybersecurity Incident

On August 19, 2026, we reported on a cybersecurity incident at the clinical genomics company Baylor Genetics. At the time, it was clear that this was a significant breach, based on reports submitted to state attorneys general; however, the scale of the breach was unknown.

The Baylor Genetics data breach has recently been added to the HHS’ Office for Civil Rights website, which shows that the electronic protected health information (ePHI) of 2,810,878 individuals was exposed or stolen in the incident.

August 19, 2026: Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident

Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.

Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston.  The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity.  The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.

Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.

Baylor Genetics said the incident did not impact its laboratory operations, which continued without interruption throughout the investigation, and there was no impact on the company’s ability to provide genetic testing services. Baylor Genetics has enhanced its security and monitoring controls, strengthened identity and access management, and has implemented additional security controls to prevent similar incidents in the future.  Complimentary credit monitoring and identity theft protection services have been offered to at least some patients.

The data breach has been reported to regulators; however, it is currently unclear how many patients and employees had data compromised in the incident. What is known is that almost 250,000 Texas residents, around 57,000 Massachusetts residents, and 2,630 Vermont residents have been affected, bringing the total to around 310,000 patients. Other states, such as California, have been notified that some state residents have been affected, so the final victim count is likely to be considerably higher.

The post Baylor Genetics: ePHI of 2.8M Patients Exposed in Cybersecurity Incident appeared first on The HIPAA Journal.

American Addiction Centers & Oculus Pathology Disclose Hacking Incidents

Hacking incidents have been announced by American Addiction Centers in Tennessee and Oculus Pathology in Texas. Regional Center of Orange County in California has discovered the improper disposal of paper records.

American Addiction Centers, Tennessee

American Addiction Centers, a Brentwood, Tennessee-based provider of addiction treatment services at more than 30 facilities across the United States, has notified the California Attorney General about a recent security incident involving a third-party vendor. According to the notice, suspicious activity was identified within its Salesforce environment on June 5, 2026.

The forensic investigation determined on June 12, 2026, that there had been unauthorized access to its Salesforce instance on May 12, 2026, and data was exfiltrated from that system. The forensic investigation confirmed that the incident did not affect any other systems. The data review confirmed that names, contact information, Social Security numbers, and health insurance information were acquired, along with brief descriptions that patients provided related to their health. The affected data related to initial outreach to American Addiction Centers.

American Addiction Centers said that security measures had been implemented prior to the breach and that it will continue to review its security measures to further protect and monitor its Salesforce environment, and complimentary credit monitoring and identity theft protection services have been made available. At present, it is unclear how many individuals have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Oculus Pathology, Texas

Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology group that provides services in several U.S. states, has announced an email security incident that has exposed patient information. Suspicious activity was identified within an employee’s email account on April 1, 2026. An investigation was launched to determine the nature and scope of the activity, and it was determined that a small number of employee email accounts had been accessed by an unauthorized third party between March 31, 2026, and April 2, 2026.

Data review specialists were engaged to investigate the incident. Data exposed in the incident includes personally identifiable information such as names, birth dates, Social Security numbers, driver’s license numbers/state ID numbers, and individual tax identification numbers. Some financial account numbers and payment card numbers were exposed, in some cases with access information.

In addition, protected health information was exposed, including clinical information, health insurance information, diagnoses, treatment and procedure information, treatment locations, medical record numbers, Medicare numbers, prescription information, and patient IDs. The data review is ongoing. Oculus Pathology has yet to announce how many individuals have been affected in total.

Regional Center of Orange County, California

Regional Center of Orange County, a Santa Ana, California-based nonprofit organization that provides services to approximately 29,000 Orange County residents with autism, epilepsy, cerebral palsy, and intellectual and cognitive disabilities, has announced a data security incident that has exposed sensitive data. The incident involved paper records that were mistakenly disposed of by a Janitorial service contracted to clean its Cypress office. The incident occurred on May 27, 2026, and was discovered on May 28, 2026. Documents had been disposed of in regular trash bins rather than being sent for secure destruction. Attempts were made to retrieve the documents; however, the trash had already been collected.

It was not possible to determine the exact patients involved or the specific types of information, so notification letters have been sent to all individuals who received services at the Cypress office.  Data likely exposed included names, addresses, birth dates, phone numbers, email addresses, unique client identifiers, and personal health information. Regional Center of Orange County said it is reviewing and strengthening internal procedures, staff training, and vendor oversight to prevent similar incidents in the future, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

The post American Addiction Centers & Oculus Pathology Disclose Hacking Incidents appeared first on The HIPAA Journal.

Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon

Data breaches have recently been announced by Terry J. Dubrow, MD, SunCloud Health, Integer Precision Technologies, Minnesota ENT, and Nipro Medical Corp.

Terry J. Dubrow, MD, California

Terry J. Dubrow, MD, a Beverly Hills, CA-based plastic surgeon, has notified the California Attorney General about a recent security incident involving patient information. The practice was contacted by an individual who claimed to have breached its computer systems and copied sensitive patient information. An investigation was launched to establish whether the claim was legitimate, and it was confirmed that there had been unauthorized access to parts of its network starting on January 16, 2026, and that files had been copied.

The affected data was reviewed, and on July 27, 2026, the practice confirmed that patients’ personal information had been obtained, including names, information collected on patient charts, and referring physician information. That information may have included contact information, Social Security numbers, driver’s license numbers or state ID numbers, birth dates, prescription information, treatment information, procedure images, and X-rays. The practice has implemented additional security measures to reduce the risk of similar incidents in the future, and the affected individuals have been offered complimentary identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

SunCloud Health, Illinois

SunCloud Health, a Northbrook, Illinois-based behavioral health treatment network, has recently disclosed a data security incident involving the protected health information of 2,594 individuals. Unusual activity was identified in certain employee email accounts. Steps were taken to secure its email system, and an investigation was initiated to determine the cause of the activity. The investigation confirmed unauthorized access to certain employee email accounts between April 22, 2026, and May 4, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The affected accounts were reviewed, and on June 16, 2026, SunCloud Health determined that the accounts contained patient names and medical information related to the services provided, including diagnoses, medications, and treatment information. The affected individuals were notified by mail on July 23, 2026; existing security protocols have been enhanced, and IT systems are being monitored, with additional safeguards being evaluated.

Integer Precision Technologies, Massachusetts

Integer Precision Technologies, a Hudson, Massachusetts-based company that makes coatings for medical devices, has recently disclosed a data security incident involving a cloud-based SaaS file sharing application. While it is unclear exactly when the incident was detected or for how long access was possible, the investigation determined that an unauthorized third party accessed the application and copied files.

Assisted by a third-party data review firm, the company determined that the files contained personal information including names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account numbers, and some health-related information. The affected individuals have been offered 24 months of complimentary credit monitoring and identity theft protection services, and steps have been taken to enhance security. The number of affected individuals has yet to be publicly disclosed.

Minnesota ENT

Oakdale Ear, Nose, & Throat PA, doing business as Minnesota ENT, has started notifying individuals affected by a recent email security incident. It is unclear from the substitute breach notice when the security incident was detected, or for how long it lasted. The notice states that six employee email accounts were accessed by an unauthorized third party and, assisted by third-party cybersecurity experts, Minnesota ENT determined on July 15, 2026, that the accounts contained HIPAA-protected data.

Data compromised in the incident included first and last names, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information.  Notification letters started to be mailed to the affected individuals on August 12, 2026. The letters include information on the steps that can be taken to protect against data misuse. The number of affected individuals has yet to be publicly disclosed.

Nipro Medical Corp., New Jersey

Nipro Medical Corp., the U.S. subsidiary of the Japanese company Nipro Corp, has identified a security incident that exposed sensitive information. The New Jersey-based company provides medical supplies to hospitals, including renal care products, vascular and interventional devices, and disposable hospital supplies. Nipro said it identified suspicious activity within its IT systems and determined that an unauthorized third party may have viewed or acquired sensitive information such as credit and debit card information, Social Security numbers, and other government identifiers.  The affected individuals have been offered 24 months of complimentary credit monitoring services. The number of affected individuals has yet to be publicly disclosed.

The post Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon appeared first on The HIPAA Journal.

Vishing Attack Provides Threat Act with Access to Quantum Health Network

Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers.

Quantum Health

Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has disclosed a cybersecurity incident that it identified in May 2026.

The incident started with a vishing attempt. The attacker called a Quantum Health user on May 29, 2026, and tricked them into providing access to the Quantum Health network. Between May 29, 2026, and June 1, 2026, the unauthorized third party had access to its network and acquired files. On June 1, 2026, Quantumn Health experienced a network disruption affecting both internal and external systems. An investigation was launched, which traced the incident back to the vishing call. The threat group behind the incident was not named, and no ransomware group appears to have claimed responsibility for the attack. These tactics are commonly used by the ShinyHunters threat group, which was the subject of a recent Health-ISAC cybersecurity alert.

On June 8, 2026, Quantum Health confirmed that the exfiltrated data included personal and protected health information, including names, addresses, email addresses, phone numbers, dates of birth, demographic information, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, dates of service, insurance information, and claims or benefits information. The affected individuals are being offered complimentary credit monitoring and identity theft protection services. It is unclear how any companies have been affected by the incident, and the number of affected individuals has yet to be publicly disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Heart of America Medical Center

Heart of America Medical Center, a faith-based nonprofit hospital and medical facility in Rugby, North Dakota, has experienced a cybersecurity incident that exposed patient data. Suspicious network activity was identified on or around June 12, 2025, and the investigation determined on September 15, 2025, that an unauthorized third party accessed its network and exfiltrated files, some of which contained patient information, including names, Social Security numbers, medical records, and other medical information.

A third-party vendor was engaged to review the affected data, and that process concluded on May 12, 2026. The findings were reviewed, and that process was completed on June 9, 2026. Contact information was verified, and on July 9, 2026, Heart of America Medical Center obtained a final list of individuals to notify. Notification letters have now been sent to the affected individuals, who have been offered complimentary single-bureau credit score, credit report, and credit monitoring services. Heart of America Medical Center has implemented additional technical and administrative safeguards to enhance data privacy and security.

The Embargo ransomware group claimed responsibility for the incident and claimed to have exfiltrated around 800 GB of data in the attack. The incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.

Precision Imaging Centers

The Medical Imaging Partnership, doing business as Precision Imaging Centers in Florida, has announced a hacking incident that exposed patient information. Suspicious activity was identified within its computer network on May 7, 2026. The investigation determined that its network was accessed by an unauthorized third party, who copied files from its systems. The investigation and data review are ongoing, so the exact data types involved and the names of the affected individuals have yet to be determined. As such, the incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of 501 individuals. The total will be updated when the file review is concluded.

Precision Imaging Centers has advised current and former patients to remain vigilant against identity theft and fraud by monitoring their free credit reports, accounts, and explanation of benefits statements for signs of data misuse. Notification letters will be mailed to the affected individuals as soon as possible after the data review is concluded.

The post Vishing Attack Provides Threat Act with Access to Quantum Health Network appeared first on The HIPAA Journal.

Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents

Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company in West Virginia, and Open Door Health Center of Illinois.

Boston Healthcare for the Homeless Program, Massachusetts

Boston Healthcare for the Homeless Program, a Boston, MA-based nonprofit organization that provides healthcare services for the homeless population, has notified state attorneys general about a network security incident first identified on November 11, 2025.

The incident was detected when it experienced a network disruption. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party accessed its network and potentially viewed or obtained files containing sensitive patient information.

The review of the affected data was completed on June 8, 2026, when it was learned that names, Social Security numbers, credit/debit card information, government identification numbers, financial account codes, medical information, health records, and health insurance information were involved. The affected individuals have been offered single-bureau credit score, credit report, and credit monitoring services for 12 months. While the total number of affected individuals is unclear, at least 184,914 Massachusetts residents have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Monongalia County General Hospital Company, West Virginia

Monongalia County General Hospital Company, aka Mon General, has recently confirmed a data breach that exposed the personal and medical information of certain patients. Suspicious activity was identified within its email system on May 6, 2026. Assisted by a digital forensics company, Mon General determined that a small number of employee email accounts had been accessed by an unauthorized third party. Employees had responded to phishing emails and disclosed their credentials.

The forensic investigation confirmed that the incident was limited to the email accounts; however, they did contain patient information such as first and last names, birth dates, email addresses, phone numbers, Social Security numbers, health information, and health insurance information. Notifications have been issued, and the affected patients have been offered two years of complimentary credit monitoring and identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

Open Door Health Center of Illinois

Open Door Health Center of Illinois, a primary care and sexual health care clinic in Chicago, Illinois, has fallen victim to a cyberattack that appears to have involved the theft of patient data. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 affected individuals. There is currently no substitute breach notice on the Open Door Health Center of Illinois website, so the types of data involved are not yet known. This appears to have been a ransomware attack by the Inc Ransom ransomware group, which added Open Door Health Center of Illinois to its dark web data leak site on May 21, 2026. Inc Ransom is a ransomware group that engages in data theft and extortion. The group claims to have exfiltrated sensitive data.

The post Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents appeared first on The HIPAA Journal.

Texas Hearing Institute Ransomware Attack Affects 30,000 Patients

Texas Hearing Institute has announced a cybersecurity incident involving the protected health information of almost 30,000 patients. Data breaches have also recently been announced by Family Partnerships of Central Florida and SportsMed Physical Therapy.

Texas Hearing Institute

The Center for Hearing and Speech, doing business as Texas Hearing Institute, a provider of pediatric audiology services, has notified 29,744 current and former patients about a security incident identified on March 20, 2026. Suspicious network activity was identified, and immediate action was taken to lock down and secure its environment. Assisted by third-party cybersecurity specialists, Texas Hearing Institute determined on or around April 22, 2026, that certain parts of its network were accessed by an unauthorized third party, including files containing patient information.

The list of the affected individuals was finalized on June 19, 2026, and notification letters were mailed on June 26, 2026. Information potentially compromised in the incident includes names, personal identifiers, Social Security numbers, diagnosis and treatment information, and financial account information. The affected individuals have been offered complimentary single-bureau credit score, credit record, and credit monitoring services.

While not mentioned in the breach notification letters, this appears to have been a ransomware attack. The Interlock ransomware group claimed responsibility and states on its data leak site that 540 GB of data was copied in the attack. Interlock is a ransomware-as-a-service group that steals data and encrypts files, demanding payment for the decryption keys and to prevent the publication of stolen data. The group proceeded to leak the stolen data, indicating the ransom was not paid. As such, the affected individuals are strongly advised to take advantage of the credit monitoring services being offered.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Family Partnerships of Central Florida

Community Based Care of Brevard, doing business as Family Partnerships of Central Florida, a community-based care lead agency contracted by the Florida Department of Children and Families, has notified 8,151 individuals that some of their protected health information has been leaked online. The MoneyMessage threat group claimed responsibility for the attack.

Family Partnerships of Central Florida launched an investigation when it learned about the data leak to determine the nature and scope of the incident. The investigation confirmed that a threat actor had access to its network between December 4, 2025, and January 2, 2026, and exfiltrated files containing names, birth dates, Social Security numbers, driver’s license numbers, state IDs, financial account information, and personal health information.

Since data has been leaked online, the affected individuals have been advised to remain vigilant against identity theft and fraud. The notification letters include information on how they can protect against data misuse. The substitute breach notice does not mention complimentary credit monitoring or identity theft protection services. Family Partnerships of Central Florida said it is reviewing its policies, procedures, and processes related to the storage and access of sensitive information to reduce the risk of similar incidents in the future.

SportsMed PT, New Jersey

SportsMed Physical Therapy in Glen Rock, New Jersey, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on May 8, 2026. The investigation confirmed that the breach was limited to a single email account, which has now been secured. The account was reviewed, and while the investigation into the incident is ongoing, SportsMed Physical Therapy said the exposed data included names in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information.

No actual or attempted misuse of the exposed data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. The breach was recently reported to the HHS’ Office for Civil Rights as affecting 3,400 individuals.

The post Texas Hearing Institute Ransomware Attack Affects 30,000 Patients appeared first on The HIPAA Journal.

Aesto Health Data Breach Affects 9.5 Million Patients

On August 14, 2026, we reported on a data breach at the Birmingham, Alabama-based healthcare technology company Aesto Health. While it was clear when we reported on the incident that it was a major breach, the number of individuals affected was unclear.  We now know that at least 30 of the company’s healthcare provider clients were affected, as detailed in the list at the bottom of this page.

The data breach has now been reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 9,540,683 individuals, which makes it the second-largest confirmed healthcare data breach of the year to date, behind the 15 million record data breach at DentaQuest.

August 14, 2026: Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients

A data breach at Aesto Health, a Birmingham, Alabama-based healthcare technology company, has affected several of its healthcare provider clients. Aesto Health provides secure data migration, legacy data archiving, and electronic health record (EHR) exchanges for medical practices and healthcare enterprises. According to its announcement, a security incident was identified on or around December 18, 2025, involving part of its Amazon Web Services (AWS) infrastructure. Third-party cybersecurity experts were engaged to investigate the incident and confirmed that its AWS environment was accessed by an unauthorized third party between December 2 and December 18, 2025.

The affected parts of its infrastructure were reviewed and confirmed to contain personally identifiable information and protected health information, including full names, Social Security numbers, partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. Aesto Health said it had taken many precautions to safeguard the sensitive data in its possession and continually evaluates and modifies its security practices. Credit monitoring and identity theft protection services have been made available.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The incident is known to have affected more than two dozen of its healthcare provider clients. They started to be notified on June 26, 2026. Whenever there is a data breach at a business associate of a HIPAA-covered entity, the affected covered entity is ultimately responsible for ensuring that the requirements of the HIPAA Breach Notification Rule are met. The covered entity may delegate the responsibility for issuing notification letters to the breached business associate, or it may choose to issue notification letters itself. As a result, it is often difficult to determine how many individuals have been affected by a business associate data breach, although in this case the breach has certainly affected hundreds of thousands of patients.

Based on state Attorney General breach listings, at least 80,622 South Carolina residents, 37,253 Washington residents, 731 Oregon residents, and 91 Vermont residents have been affected; however, many of the affected clients have chosen to report the breach themselves. In some cases, clients report that tens of thousands of their patients have been affected. For instance, Village Practice Management has confirmed that more than 25,000 of its patients have been affected, and Everside Health informed the Washington Attorney General that approximately 22,000 individuals have been affected in Washington alone.

The healthcare providers known to have been affected are detailed in the table below, although others may also have been affected.

  • Edwards County Medical Center
  • Effingham Obstetrics & Gynecology Associates, PLLC
  • Ellenville Regional Hospital
  • Everside Health
  • Gila Health Resources, LLC
  • Graham County Hospital
  • Greenwood County Hospital
  • Henry County Hospital
  • Little River Memorial Hospital
  • Lone Star Community Health Center
  • Main Street Medical Services, PLLC
  • Marana Health
  • Mid-South OB-GYN, PLLC
  • Midtown Community Health Center
  • Missoula Community Health Services Inc., dba Mineral Community Hospital
  • Monroe Health Center
  • Murfreesboro Medical Clinic
  • My Doctor, LLC
  • Nebraska Orthopedic Center, P.C
  • Park West Health Systems, Inc.
  • Quincy Valley Medical Center
  • Rural Health Resources of Jackson County Inc. d/b/a Holton Community Hospital
  • Shenandoah Valley Medical System Inc.
  • Stanislaus County Health Services Agency
  • Sterling Health Solutions
  • Texas Spine Consultants, LLP
  • Together Women’s Health Medical Group of Alabama, PC
  • Together Women’s Health Medical Group, PC
  • Village Practice Management (VillageMD; Village Medical)
  • Women’s Health Associates, Inc.

The post Aesto Health Data Breach Affects 9.5 Million Patients appeared first on The HIPAA Journal.