HIPAA Breach News

Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon

Data breaches have recently been announced by Terry J. Dubrow, MD, SunCloud Health, Integer Precision Technologies, Minnesota ENT, and Nipro Medical Corp.

Terry J. Dubrow, MD, California

Terry J. Dubrow, MD, a Beverly Hills, CA-based plastic surgeon, has notified the California Attorney General about a recent security incident involving patient information. The practice was contacted by an individual who claimed to have breached its computer systems and copied sensitive patient information. An investigation was launched to establish whether the claim was legitimate, and it was confirmed that there had been unauthorized access to parts of its network starting on January 16, 2026, and that files had been copied.

The affected data was reviewed, and on July 27, 2026, the practice confirmed that patients’ personal information had been obtained, including names, information collected on patient charts, and referring physician information. That information may have included contact information, Social Security numbers, driver’s license numbers or state ID numbers, birth dates, prescription information, treatment information, procedure images, and X-rays. The practice has implemented additional security measures to reduce the risk of similar incidents in the future, and the affected individuals have been offered complimentary identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

SunCloud Health, Illinois

SunCloud Health, a Northbrook, Illinois-based behavioral health treatment network, has recently disclosed a data security incident involving the protected health information of 2,594 individuals. Unusual activity was identified in certain employee email accounts. Steps were taken to secure its email system, and an investigation was initiated to determine the cause of the activity. The investigation confirmed unauthorized access to certain employee email accounts between April 22, 2026, and May 4, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The affected accounts were reviewed, and on June 16, 2026, SunCloud Health determined that the accounts contained patient names and medical information related to the services provided, including diagnoses, medications, and treatment information. The affected individuals were notified by mail on July 23, 2026; existing security protocols have been enhanced, and IT systems are being monitored, with additional safeguards being evaluated.

Integer Precision Technologies, Massachusetts

Integer Precision Technologies, a Hudson, Massachusetts-based company that makes coatings for medical devices, has recently disclosed a data security incident involving a cloud-based SaaS file sharing application. While it is unclear exactly when the incident was detected or for how long access was possible, the investigation determined that an unauthorized third party accessed the application and copied files.

Assisted by a third-party data review firm, the company determined that the files contained personal information including names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account numbers, and some health-related information. The affected individuals have been offered 24 months of complimentary credit monitoring and identity theft protection services, and steps have been taken to enhance security. The number of affected individuals has yet to be publicly disclosed.

Minnesota ENT

Oakdale Ear, Nose, & Throat PA, doing business as Minnesota ENT, has started notifying individuals affected by a recent email security incident. It is unclear from the substitute breach notice when the security incident was detected, or for how long it lasted. The notice states that six employee email accounts were accessed by an unauthorized third party and, assisted by third-party cybersecurity experts, Minnesota ENT determined on July 15, 2026, that the accounts contained HIPAA-protected data.

Data compromised in the incident included first and last names, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information.  Notification letters started to be mailed to the affected individuals on August 12, 2026. The letters include information on the steps that can be taken to protect against data misuse. The number of affected individuals has yet to be publicly disclosed.

Nipro Medical Corp., New Jersey

Nipro Medical Corp., the U.S. subsidiary of the Japanese company Nipro Corp, has identified a security incident that exposed sensitive information. The New Jersey-based company provides medical supplies to hospitals, including renal care products, vascular and interventional devices, and disposable hospital supplies. Nipro said it identified suspicious activity within its IT systems and determined that an unauthorized third party may have viewed or acquired sensitive information such as credit and debit card information, Social Security numbers, and other government identifiers.  The affected individuals have been offered 24 months of complimentary credit monitoring services. The number of affected individuals has yet to be publicly disclosed.

The post Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon appeared first on The HIPAA Journal.

Vishing Attack Provides Threat Act with Access to Quantum Health Network

Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers.

Quantum Health

Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has disclosed a cybersecurity incident that it identified in May 2026.

The incident started with a vishing attempt. The attacker called a Quantum Health user on May 29, 2026, and tricked them into providing access to the Quantum Health network. Between May 29, 2026, and June 1, 2026, the unauthorized third party had access to its network and acquired files. On June 1, 2026, Quantumn Health experienced a network disruption affecting both internal and external systems. An investigation was launched, which traced the incident back to the vishing call. The threat group behind the incident was not named, and no ransomware group appears to have claimed responsibility for the attack. These tactics are commonly used by the ShinyHunters threat group, which was the subject of a recent Health-ISAC cybersecurity alert.

On June 8, 2026, Quantum Health confirmed that the exfiltrated data included personal and protected health information, including names, addresses, email addresses, phone numbers, dates of birth, demographic information, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, dates of service, insurance information, and claims or benefits information. The affected individuals are being offered complimentary credit monitoring and identity theft protection services. It is unclear how any companies have been affected by the incident, and the number of affected individuals has yet to be publicly disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Heart of America Medical Center

Heart of America Medical Center, a faith-based nonprofit hospital and medical facility in Rugby, North Dakota, has experienced a cybersecurity incident that exposed patient data. Suspicious network activity was identified on or around June 12, 2025, and the investigation determined on September 15, 2025, that an unauthorized third party accessed its network and exfiltrated files, some of which contained patient information, including names, Social Security numbers, medical records, and other medical information.

A third-party vendor was engaged to review the affected data, and that process concluded on May 12, 2026. The findings were reviewed, and that process was completed on June 9, 2026. Contact information was verified, and on July 9, 2026, Heart of America Medical Center obtained a final list of individuals to notify. Notification letters have now been sent to the affected individuals, who have been offered complimentary single-bureau credit score, credit report, and credit monitoring services. Heart of America Medical Center has implemented additional technical and administrative safeguards to enhance data privacy and security.

The Embargo ransomware group claimed responsibility for the incident and claimed to have exfiltrated around 800 GB of data in the attack. The incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.

Precision Imaging Centers

The Medical Imaging Partnership, doing business as Precision Imaging Centers in Florida, has announced a hacking incident that exposed patient information. Suspicious activity was identified within its computer network on May 7, 2026. The investigation determined that its network was accessed by an unauthorized third party, who copied files from its systems. The investigation and data review are ongoing, so the exact data types involved and the names of the affected individuals have yet to be determined. As such, the incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of 501 individuals. The total will be updated when the file review is concluded.

Precision Imaging Centers has advised current and former patients to remain vigilant against identity theft and fraud by monitoring their free credit reports, accounts, and explanation of benefits statements for signs of data misuse. Notification letters will be mailed to the affected individuals as soon as possible after the data review is concluded.

The post Vishing Attack Provides Threat Act with Access to Quantum Health Network appeared first on The HIPAA Journal.

Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents

Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company in West Virginia, and Open Door Health Center of Illinois.

Boston Healthcare for the Homeless Program, Massachusetts

Boston Healthcare for the Homeless Program, a Boston, MA-based nonprofit organization that provides healthcare services for the homeless population, has notified state attorneys general about a network security incident first identified on November 11, 2025.

The incident was detected when it experienced a network disruption. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party accessed its network and potentially viewed or obtained files containing sensitive patient information.

The review of the affected data was completed on June 8, 2026, when it was learned that names, Social Security numbers, credit/debit card information, government identification numbers, financial account codes, medical information, health records, and health insurance information were involved. The affected individuals have been offered single-bureau credit score, credit report, and credit monitoring services for 12 months. While the total number of affected individuals is unclear, at least 184,914 Massachusetts residents have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Monongalia County General Hospital Company, West Virginia

Monongalia County General Hospital Company, aka Mon General, has recently confirmed a data breach that exposed the personal and medical information of certain patients. Suspicious activity was identified within its email system on May 6, 2026. Assisted by a digital forensics company, Mon General determined that a small number of employee email accounts had been accessed by an unauthorized third party. Employees had responded to phishing emails and disclosed their credentials.

The forensic investigation confirmed that the incident was limited to the email accounts; however, they did contain patient information such as first and last names, birth dates, email addresses, phone numbers, Social Security numbers, health information, and health insurance information. Notifications have been issued, and the affected patients have been offered two years of complimentary credit monitoring and identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

Open Door Health Center of Illinois

Open Door Health Center of Illinois, a primary care and sexual health care clinic in Chicago, Illinois, has fallen victim to a cyberattack that appears to have involved the theft of patient data. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 affected individuals. There is currently no substitute breach notice on the Open Door Health Center of Illinois website, so the types of data involved are not yet known. This appears to have been a ransomware attack by the Inc Ransom ransomware group, which added Open Door Health Center of Illinois to its dark web data leak site on May 21, 2026. Inc Ransom is a ransomware group that engages in data theft and extortion. The group claims to have exfiltrated sensitive data.

The post Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents appeared first on The HIPAA Journal.

Texas Hearing Institute Ransomware Attack Affects 30,000 Patients

Texas Hearing Institute has announced a cybersecurity incident involving the protected health information of almost 30,000 patients. Data breaches have also recently been announced by Family Partnerships of Central Florida and SportsMed Physical Therapy.

Texas Hearing Institute

The Center for Hearing and Speech, doing business as Texas Hearing Institute, a provider of pediatric audiology services, has notified 29,744 current and former patients about a security incident identified on March 20, 2026. Suspicious network activity was identified, and immediate action was taken to lock down and secure its environment. Assisted by third-party cybersecurity specialists, Texas Hearing Institute determined on or around April 22, 2026, that certain parts of its network were accessed by an unauthorized third party, including files containing patient information.

The list of the affected individuals was finalized on June 19, 2026, and notification letters were mailed on June 26, 2026. Information potentially compromised in the incident includes names, personal identifiers, Social Security numbers, diagnosis and treatment information, and financial account information. The affected individuals have been offered complimentary single-bureau credit score, credit record, and credit monitoring services.

While not mentioned in the breach notification letters, this appears to have been a ransomware attack. The Interlock ransomware group claimed responsibility and states on its data leak site that 540 GB of data was copied in the attack. Interlock is a ransomware-as-a-service group that steals data and encrypts files, demanding payment for the decryption keys and to prevent the publication of stolen data. The group proceeded to leak the stolen data, indicating the ransom was not paid. As such, the affected individuals are strongly advised to take advantage of the credit monitoring services being offered.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Family Partnerships of Central Florida

Community Based Care of Brevard, doing business as Family Partnerships of Central Florida, a community-based care lead agency contracted by the Florida Department of Children and Families, has notified 8,151 individuals that some of their protected health information has been leaked online. The MoneyMessage threat group claimed responsibility for the attack.

Family Partnerships of Central Florida launched an investigation when it learned about the data leak to determine the nature and scope of the incident. The investigation confirmed that a threat actor had access to its network between December 4, 2025, and January 2, 2026, and exfiltrated files containing names, birth dates, Social Security numbers, driver’s license numbers, state IDs, financial account information, and personal health information.

Since data has been leaked online, the affected individuals have been advised to remain vigilant against identity theft and fraud. The notification letters include information on how they can protect against data misuse. The substitute breach notice does not mention complimentary credit monitoring or identity theft protection services. Family Partnerships of Central Florida said it is reviewing its policies, procedures, and processes related to the storage and access of sensitive information to reduce the risk of similar incidents in the future.

SportsMed PT, New Jersey

SportsMed Physical Therapy in Glen Rock, New Jersey, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on May 8, 2026. The investigation confirmed that the breach was limited to a single email account, which has now been secured. The account was reviewed, and while the investigation into the incident is ongoing, SportsMed Physical Therapy said the exposed data included names in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information.

No actual or attempted misuse of the exposed data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. The breach was recently reported to the HHS’ Office for Civil Rights as affecting 3,400 individuals.

The post Texas Hearing Institute Ransomware Attack Affects 30,000 Patients appeared first on The HIPAA Journal.

Aesto Health Data Breach Affects 9.5 Million Patients

On August 14, 2026, we reported on a data breach at the Birmingham, Alabama-based healthcare technology company Aesto Health. While it was clear when we reported on the incident that it was a major breach, the number of individuals affected was unclear.  We now know that at least 30 of the company’s healthcare provider clients were affected, as detailed in the list at the bottom of this page.

The data breach has now been reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 9,540,683 individuals, which makes it the second-largest confirmed healthcare data breach of the year to date, behind the 15 million record data breach at DentaQuest.

August 14, 2026: Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients

A data breach at Aesto Health, a Birmingham, Alabama-based healthcare technology company, has affected several of its healthcare provider clients. Aesto Health provides secure data migration, legacy data archiving, and electronic health record (EHR) exchanges for medical practices and healthcare enterprises. According to its announcement, a security incident was identified on or around December 18, 2025, involving part of its Amazon Web Services (AWS) infrastructure. Third-party cybersecurity experts were engaged to investigate the incident and confirmed that its AWS environment was accessed by an unauthorized third party between December 2 and December 18, 2025.

The affected parts of its infrastructure were reviewed and confirmed to contain personally identifiable information and protected health information, including full names, Social Security numbers, partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. Aesto Health said it had taken many precautions to safeguard the sensitive data in its possession and continually evaluates and modifies its security practices. Credit monitoring and identity theft protection services have been made available.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The incident is known to have affected more than two dozen of its healthcare provider clients. They started to be notified on June 26, 2026. Whenever there is a data breach at a business associate of a HIPAA-covered entity, the affected covered entity is ultimately responsible for ensuring that the requirements of the HIPAA Breach Notification Rule are met. The covered entity may delegate the responsibility for issuing notification letters to the breached business associate, or it may choose to issue notification letters itself. As a result, it is often difficult to determine how many individuals have been affected by a business associate data breach, although in this case the breach has certainly affected hundreds of thousands of patients.

Based on state Attorney General breach listings, at least 80,622 South Carolina residents, 37,253 Washington residents, 731 Oregon residents, and 91 Vermont residents have been affected; however, many of the affected clients have chosen to report the breach themselves. In some cases, clients report that tens of thousands of their patients have been affected. For instance, Village Practice Management has confirmed that more than 25,000 of its patients have been affected, and Everside Health informed the Washington Attorney General that approximately 22,000 individuals have been affected in Washington alone.

The healthcare providers known to have been affected are detailed in the table below, although others may also have been affected.

  • Edwards County Medical Center
  • Effingham Obstetrics & Gynecology Associates, PLLC
  • Ellenville Regional Hospital
  • Everside Health
  • Gila Health Resources, LLC
  • Graham County Hospital
  • Greenwood County Hospital
  • Henry County Hospital
  • Little River Memorial Hospital
  • Lone Star Community Health Center
  • Main Street Medical Services, PLLC
  • Marana Health
  • Mid-South OB-GYN, PLLC
  • Midtown Community Health Center
  • Missoula Community Health Services Inc., dba Mineral Community Hospital
  • Monroe Health Center
  • Murfreesboro Medical Clinic
  • My Doctor, LLC
  • Nebraska Orthopedic Center, P.C
  • Park West Health Systems, Inc.
  • Quincy Valley Medical Center
  • Rural Health Resources of Jackson County Inc. d/b/a Holton Community Hospital
  • Shenandoah Valley Medical System Inc.
  • Stanislaus County Health Services Agency
  • Sterling Health Solutions
  • Texas Spine Consultants, LLP
  • Together Women’s Health Medical Group of Alabama, PC
  • Together Women’s Health Medical Group, PC
  • Village Practice Management (VillageMD; Village Medical)
  • Women’s Health Associates, Inc.

The post Aesto Health Data Breach Affects 9.5 Million Patients appeared first on The HIPAA Journal.

Data Breaches Announced by Five HIPAA-Regulated Entities

Data breaches have recently been announced by the Women’s Center for Radiology in Florida, Optalis Management Solutions in Michigan, the Association for Neurologically Impaired Brain Injured in New York, the Cardiovascular Institute of New England in Rhode Island, and the Kubota Tractor Corporation in Texas.

Women’s Center for Radiology, Florida

Women’s Center for Radiology, a Florida-based women’s radiology practice with two centers in Orlando, has notified 66,422 patients about a data security incident identified on April 29, 2026. Assisted by third-party cybersecurity specialists, the Women’s Center for Radiology determined that an unauthorized third party had access to its network between April 26, 2026, and April 28, 2026, and accessed or downloaded files containing patient information.

After securing its network, the files were reviewed and found to contain patient information such as names, addresses, dates of birth, contact information, diagnosis/condition information, lab test results, treating/referring physician names, medical record numbers, driver’s license numbers, and health insurance information. Data privacy and security policies, procedures, and processes are being reviewed to reduce the likelihood of similar incidents in the future. While data misuse has not been identified, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

Optalis Management Solutions, Michigan

Optalis Management Solutions, a Michigan-based management company that operates Optalis Health & Rehabilitation’s skilled nursing, rehabilitation, assisted living, and independent living facilities, has notified 13,723 individuals about a breach of some of their protected health information. Suspicious activity was identified within its computer network, and the investigation confirmed unauthorized access occurred between April 14, 2025, and April 19, 2025. After a breach was confirmed by third-party cybersecurity specialists, a document review was initiated to determine the individuals and data types involved. That process concluded on June 10, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Data potentially viewed or obtained in the incident included full names in combination with one or more of the following: Social Security number, driver’s license number/state ID number, credit/debit card information, financial account information, diagnosis and treatment information, and/or health insurance policy number. Notifications were mailed to the affected individuals on June 29, 2026, and individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services.

Kubota Tractor Corporation, Texas

Kubota Tractor Corporation, a Japanese company that makes agricultural and construction equipment, has recently confirmed that hackers gained access to certain parts of its network earlier this year. The forensic investigation determined that its network was first compromised on March 16, 2026, and the hackers maintained access for more than a month. The unauthorized access was detected and blocked on April 20, 2026. The company, which has its U.S. HQ in Grapevine, Texas, determined that this was a reportable breach under HIPAA, as the incident involved unauthorized access to the protected health information of beneficiaries of its Employee Welfare Benefit Plan.

Employee data potentially compromised in the incident includes names in combination with one or more of the following: Social Security number, date of birth, taxpayer identification number, driver’s license or other government-issued identification number, financial account information for direct deposit, payment card information for corporate cards, benefit enrollment information, and limited claims information. For dependents of employees, the exposed data may have included names in combination with one or more of the following: Social Security number, date of birth, benefit enrollment information, and limited claims information. Notification letters were mailed to the 5,891 affected individuals on June 30, 2026, and complimentary identity monitoring services have been offered.

Cardiovascular Institute of New England, Rhode Island

The Cardiovascular Institute of New England, a heart care practice with seven locations in Rhode Island, started mailing notification letters to patients on July 28, 2026, about a data security incident identified on or around February 12, 2026. Suspicious activity was identified within its email environment, and the investigation confirmed unauthorized email access, which may have resulted in patient data being viewed or acquired.

The review of the affected email accounts was completed on or around July 14, 2026, when the practice learned that names, phone numbers, dates of birth, financial account numbers, medical information, medical diagnoses, treatment information, treatment locations, clinical information, prescription information, and medical insurance provider information had been exposed. No evidence has been found to suggest that any patient data has been misused.

Email security policies, procedures, and security measures are being reviewed, and steps are being taken to reduce the risk of similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

The Association for Neurologically Impaired Brain Injured, New York

The Association for Neurologically Impaired Brain Injured (ANIBIC), a New York-based not-for-profit agency that provides services to individuals with developmental and neurological disabilities, has recently informed the HHS’ Office for Civil Rights about a breach of the protected health information of 1,918 individuals. According to its substitute breach notice, suspicious activity was identified within its computer network on or around March 8, 2026. The investigation determined that an unauthorized third party accessed files containing program member information between March 7, 2026, and March 8, 2026.

The compromised information included names, contact information, Social Security numbers, dates of birth, health insurance information, and service details such as diagnoses, treatment information, and prescriptions. Notification letters were mailed to the affected individuals on July 17, 2026, and complimentary identity monitoring services have been offered to individuals whose Social Security numbers were involved.

The post Data Breaches Announced by Five HIPAA-Regulated Entities appeared first on The HIPAA Journal.

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times.

The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time.

This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class action lawsuits filed by patients who had their data stolen and healthcare providers seeking compensation for the financial and operational disruptions they experienced. On June 7, 2024, the Judicial Panel on Multidistrict Litigation consolidated an initial 49 lawsuits, including 19 consumer complaints and 30 healthcare provider complaints, although the number of lawsuits included in the action has grown to more than 150. The consolidated lawsuit – In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation – was centralized in the U.S. District Court for the District of Minnesota.

The stolen data files are designated discovery material, and due to the sensitive nature of the data and the volume of records, heightened security practices are required to protect against unauthorized access and data theft. The rules concerning the stolen dataset were approved by the plaintiffs’ attorneys and were verified by a cybersecurity expert as being sufficient to ensure the security of the data before being sent to the judge for approval. The stipulated protective order has recently been approved by Magistrate Judge Dulce Foster.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UHG will provide a single copy of the data on an encrypted hard drive built to a federal security standard, and must provide the key to decrypt the data separately, to ensure that in the event of loss or theft of the drive, the data cannot be accessed. The plaintiffs’ attorneys are required to encrypt the data again once they have received the hard drive, using industry-standard encryption. No copies may be made of the data, and the data cannot be saved to the shared file library used by all individuals involved in the case. The plaintiffs’ attorneys are prohibited from using the dataset to identify or locate potential class members.

The hard drive must only be used on computers that are air-gapped – disconnected from the Internet and all networks, with no Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated prior to use, and when the computers are used, no cables, phones, or storage devices are permitted nearby.  When data access is required, only small samples may be accessed, and no more than 25 people are permitted access at any one time. All samples must be encrypted with strong encryption and a complex password set of at least 16 characters.

An audit trail must be maintained, including a detailed chain of custody of the drive and data, and the log must be provided to UHG on request. When the case ends, or if the plaintiffs’ claims are thrown out, the data must be securely destroyed within 30 days, using a government-approved data wiping method – NIST SP 800-88 – or the hard drive must be physically destroyed, and a detailed certificate of destruction obtained under penalty of perjury.

In the event of a security incident or unauthorized data access or data sharing, UHG must be notified within 48 hours. Should it turn out to be a genuine security incident, both sides are required to engage an external digital forensic firm, and if the plaintiffs are found to be at fault, they must pay the full investigation costs.

The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal.

Data Breaches Announced by Five Small Healthcare Organizations

Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of Raleigh; Arkansas Oral & Maxillofacial Surgeons; Alpine Agency of the Midlands; Princeton Family Eye Care; and James C. Standring, DDS.

Family Medical Associates of Raleigh, North Carolina

Family Medical Associates of Raleigh, a multi-provider family medical practice in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, and activated its incident response protocol. Steps were immediately taken to investigate, contain, and remediate the incident; law enforcement was notified, and third-party cybersecurity professionals were engaged. The investigation and data review are ongoing; however, it has been confirmed that certain systems were intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026, who potentially downloaded internal data, including files containing patients’ protected health information.

The data review has not yet been completed, but the types of data exposed in the incident include names, demographic information, contact information, medical and treatment information, health insurance information, financial/payment-related information, government-issued ID numbers, and other data related to the medical services provided. Family Medical Associates of Raleigh said it is unaware of any actual or attempted misuse of patient data as a result of the incident; however, patients have been advised to remain vigilant against identity theft and fraud by monitoring their accounts, free credit reports, and explanation of benefits statements.

Since the investigation has yet to conclude, the number of affected individuals is currently unknown. While the name of the threat actor behind the attack was not disclosed, the Genesis ransomware group claimed responsibility for the attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Arkansas Oral & Maxillofacial Surgeons, Arkansas

Arkansas Oral & Maxillofacial Surgeons, a Hot Springs, Arkansas-based provider of oral surgery, dental implants, and other dental and cosmetic dentistry services, has announced a data security incident that was first identified on April 7, 2026.

An investigation was initiated, and on June 2, 2026, it was confirmed that an unauthorized third party had accessed its network and exfiltrated files containing patient information. The files have been reviewed and were found to contain information such as names, contact information, birth dates, medical record numbers, government identification numbers (including Social Security numbers), diagnoses, treatment records, health insurance information, prescription histories, and payment information.

The affected individuals have been notified by mail and provided with recommendations on how to protect themselves against data misuse. Based on the substitute breach notice on the Arkansas Oral & Maxillofacial Surgeons website, credit monitoring and identity theft protection services do not appear to have been offered. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many patients have been affected.

This appears to have been a data theft and extortion attempt. The PEAR threat group claimed responsibility. PEAR does not encrypt files, as the group engages in data theft and extortion, threatening to publish stolen data if the ransom is not paid.

Alpine Agency of the Midlands, South Carolina

Alpine Agency of the Midlands, LLC, a small, independent health and benefits insurance company based in Columbia, South Carolina, has recently disclosed a security incident involving unauthorized access to its email system. Alpine provides services to insurance carriers, employers, and health plans, and is provided with certain health data by its clients in connection with the services it provides.

Unusual activity was identified within an employee email account in November 2025. The account was secured, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that the incident affected a single email account, which was first accessed by an unauthorized third party on October 28, 2026. Emails and associated attachments may have been copied by the attacker.

The account was reviewed and found to contain first and last names, addresses, dates of birth, health insurance information, and limited Social Security numbers. Notifications will be mailed to the affected individuals when the review is completed. In the meantime, the breach has been reported to the HHS’ Office for Civil Rights as affecting at least 500 individuals. The total will be updated when the file review is concluded.

Princeton Family Eye Care, Texas

Princeton Family Eye Care, a small optometry practice in Princeton, Texas, has notified certain patients about a recent data breach. On May 4, 2026, suspicious activity was identified within its email environment. Assisted by third-party cybersecurity experts, the practice secured its email systems, investigated the activity, and confirmed that a company email account had been accessed by an unauthorized third party.

A data review firm was engaged to determine the types of data involved and the individuals affected, and that process has recently been completed. The data exposed in the incident varied from individual to individual and may have included names in combination with one or more of the following: date of birth, contact information, government identification numbers (such as a driver’s license, passport, or Social Security number), and limited medical information (such as treatment details, health insurance records, or a medical record number).

No misuse of the affected information has been identified; however, the affected patients have been advised to remain vigilant against misuse of their information. The breach was reported to the Texas Attorney General as involving the data of 933 Texas residents.

James C. Standring, DDS, California

James C. Standring, DDS, a dental practice in Crescent City, California, has notified 6,658 patients about a data security incident involving unauthorized access to its computer systems. While the data breach was reported to the HHS’ Office for Civil Rights on July 17, 2026, this appears to have been a historical data breach.

According to the breach explanation on the dental practice website, unauthorized access to certain computer systems was first identified on September 2, 2024. Assisted by third-party cybersecurity specialists, the practice determined that the incident resulted in the exposure of the data of current and former patients, including names, addresses, email addresses, Social Security numbers, driver’s license/state ID numbers, medical information, health insurance information, financial account/payment card information, and other personal information maintained by the practice.

No misuse of the affected data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. No explanation was provided about why it took 22 months from the date of discovery to issue notification letters.

The post Data Breaches Announced by Five Small Healthcare Organizations appeared first on The HIPAA Journal.

Data Breaches Reported by Sunshine Health; Health Payment Systems

A vishing attack on Sunshine Health, a Florida-based Medicaid and health insurance agency, involved the theft of the PHI of more than 41,000 individuals. Health Payment Systems, a Wisconsin healthcare billing company, has experienced an email security incident affecting more than 8,000 patients.

Sunshine Health

Sunshine Health, a Broward County, Florida-based Medicaid and health insurance agency, has recently discovered a vishing incident involving the impermissible disclosure of the protected health information of 41,569 individuals.

Vishing, or voice phishing, takes place over the phone and involves tricking an individual into providing the attacker with access to their device or sensitive information. In this case, an employee was tricked into sharing a limited number of health plan files by a caller pretending to be a trusted individual. The incident occurred on May 6, 2026, and was identified the same day. An investigation was launched, and the shared files were reviewed and were found to include names, dates of birth, medical information/histories, and health plan coverage information.

Sunshine Health said it has not found any evidence to suggest that the disclosed information has been misused at this time; however, to protect against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. Additional training has been provided to the workforce to raise awareness of the techniques that threat actors may use to gain access to internal systems and sensitive data.

Health Payment Systems

Health Payment Systems, Inc., a Wisconsin-based healthcare technology and billing software company, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,380 individuals.

On or around June 27, 2025, the company identified suspicious activity within its email environment. Immediate action was taken to secure the accounts and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident. Assisted by third-party cybersecurity specialists, Health Payment Systems confirmed that certain employee email accounts had been accessed by an unauthorized third party between June 24, 2025, and June 27, 2025, and certain emails were copied.

It has taken more than a year to investigate the incident and review the affected data. The HHS’ Office for Civil Rights was informed about the data breach on July 10, 2026, and notification letters are now being mailed to the affected individuals. Data exposed in the incident included names, addresses, birth dates, IDs, subscription IDs, and subscriber person IDs. For certain individuals, medical information, health insurance information, and Social Security numbers were also involved.

The affected individuals have been offered complimentary credit monitoring and identity theft protection services, and have been advised to monitor their explanation of benefits statements and account statements for signs of data misuse. Health Payment Systems said it has strengthened its security policies and has implemented additional cybersecurity measures to prevent similar incidents in the future.

The post Data Breaches Reported by Sunshine Health; Health Payment Systems appeared first on The HIPAA Journal.