Healthcare Breach NoticesHealthcare Breach NoticesCoverage from SecurityWeek, BleepingComputer, and others
00/00/0000
DailyWeekly
This topic centers on healthcare and adjacent organizations disclosing data breaches that exposed personal, financial, and protected health information.
Across the material, notices, investigations, and legal actions focus on how many people were affected, what data was accessed, and whether reporting and notification obligations were met. The pattern matters because these incidents can create identity theft risk, trigger regulatory scrutiny, and lead to litigation or settlement costs.
Looking Back
542 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Jan '25
Apr '25
Jul '25
Sep '25
Dec '25
Mar '26
Jun '26
History
07/05/2026
The story has shifted from healthcare breach reporting to a specific cross-sector campaign against Oracle PeopleSoft, centered on a newly disclosed zero-day exploit and attributed to ShinyHunters. This materially expands the scope and clarifies the mechanism, victim profile, and urgency of the incident.
07/05/2026
The story broadens from Rochester-area provider/vendor breach notices to a wider set of healthcare organizations nationwide, and now emphasizes follow-on class-action litigation. It also shifts from confusion over notices to a stronger pattern of delayed discovery, broader exposure, and legal pressure.
Nissan reported a PeopleSoft zero-day incident in breach notice filings with the California Attorney General, citing potential SSN and financial data exposure across the US, Canada, Mexico, and Brazil.
7/2/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Kubota North America Corporation disclosed June 30 employee notification following month-long unauthorized access involving personal data exposure from March 16 to April 20.
7/1/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
iRhythm Holdings disclosed a June 2026 data breach after ransomware communications and social-engineering access exfiltrated patient health information from third-party hosted applications.
6/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic notified customers in 2026 after investigation found unauthorized access to corporate IT systems during April 13 to April 19, following ShinyHunters extortion claims.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Schubert Jonckheer & Kolbe LLP is investigating a Medtronic data breach after ShinyHunters claimed unauthorized access and Medtronic confirmed the incident in April 2026.
5/6/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Radiology Associates of Richmond notified 266,000 patients after unauthorized access on or around July 25, 2025, exposing health and personal information.
5/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Minnesota Epilepsy Group notified patients in Roseville, Minnesota, after a March 2026 data breach exposed Social Security and health data, with legal investigation underway.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
West Pharmaceutical Services disclosed a May 4 ransomware incident involving data theft and encrypted systems, with recovery ongoing and investigation led by Palo Alto Networks Unit 42.
5/12/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
Nissan Americas disclosed a PeopleSoft-related breach affecting employees in the United States, Canada, Mexico, and Brazil after Oracle notified the company of CVE-2026-35273 exploitation.
6/30/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Nissan disclosed a PeopleSoft-linked employee data breach in the United States, Canada, Mexico, and Brazil after exploitation of CVE-2026-35273 tied to ShinyHunters.
6/30/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Hackers accessed CPAP Medical Supplies and Services systems in December 2024, exposing personal and health information for more than 90,000 individuals in the United States.
8/22/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
iRhythm Holdings reported a third-party hosted application data breach after unauthorized access, followed by confirmation of stolen personal and protected health information for about 8 million device users.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
iRhythm Holdings disclosed June 2026 third-party hosted application cyberattack results including theft of patient protected health information and other personal data, while investigation continued.
6/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Blue Fish Pediatrics notified Texans on a 2025 breach affecting 41,485 people, with exposed records including Social Security numbers and medical information, after a delayed notification.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ASC Ortho Management Company disclosed an email-environment data breach in 2025 that may have exposed personal and protected health information, with notifications mailed starting April 17, 2026 across Washington, D.C., Maryland, and Virginia.
4/24/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Pediatric Products disclosed suspicious network activity in February 2026 and reported unauthorized access exposing customers' medical and personal data across multiple U.S. states.
4/15/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Florida Physician Specialists reported a late-November 2025 data breach, with April 2026 mail notifications and class-action investigation efforts underway in Jacksonville, Florida.
4/27/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
ClassAction.org attorneys are assessing potential class action after Mid-South Pulmonary & Sleep Specialists detected suspicious activity in November 2025 and found exposure of Social Security and medical diagnosis data.
4/30/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Tri-Cities Gastroenterology notified 67,115 individuals in April 2026 after a third-party data breach exposed Social Security numbers and medical record numbers.
5/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ClassAction.org attorneys investigated whether a class action can be filed after Integrated Pain Associates disclosed an unauthorized systems access around February 24, 2026 in Texas.
5/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Western Orthopaedics reported a 2025 unauthorized access incident that potentially exposed identity, financial, and health data, with legal teams seeking class action filings.
5/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ClassAction.org attorneys are investigating a reported DentaQuest data breach after ShinyHunters claimed responsibility on May 23, 2026, and threatened release for May 27.
5/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Minnesota Epilepsy Group began breach notifications on June 5, 2026, after unauthorized access potentially exposed health and identity data between March 19 and April 10.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Attorneys pursued a potential class action after Karl Auto Group disclosed an April 4, 2026 data breach affecting Iowa customers, employees, and affiliated individuals.
6/10/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Blue Fish Pediatrics notified 41,485 Texas residents after a July 2025 computer system breach potentially exposed Social Security numbers and health records, with mailed notices starting June 17, 2026.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Physicians' Primary Care of Southwest Florida, P.L. reached a preliminary settlement on May 18, 2026, in a class action over a September 2024 patient data breach, with final approval set for September 14, 2026.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas received a breach filing on April 17, 2026, after ransomware group Payouts King claimed 435 GB of Eyemart Express data including PII and protected health information.
4/17/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Florida Physician Specialists disclosed an April 2026 investigation finding that late-2025 unauthorized access may have exposed identity, financial, and medical data for affected patients.
4/27/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Western Orthopaedics disclosed a 2025 ransomware data breach affecting Texas and Massachusetts patients after PEAR claimed data access on the dark web.
5/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Ikron Corp. disclosed to the U.S. Department of Health and Human Services on May 4, 2026, that a ransomware attack exposed personal and protected health information for about 11,845 people.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NLACRC detected suspected ransomware on Nov. 28, 2024 and later reported a Nov. 20-Dec. 1 data breach exposing PII and PHI to multiple state attorneys general.
7/1/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Aligned Orthopedic Partners reported an email system intrusion between Nov. 16 and Dec. 16, 2025, potentially exposing PII and protected health information.
4/18/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Skin & Beauty Center Inc. and DermCare Management reported an unauthorized patient-data copy from Feb. 26, 2025, and mailed breach notices after a March 2, 2026 review in California.
4/27/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Sandhills Medical Foundation disclosed on April 28, 2026 a ransomware breach that affected 169,017 patients after unauthorized access to company servers and potential exposure of personal health information.
4/29/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Greater Boston Urology reported a protected health information breach affecting 4,717 people to the U.S. Department of Health and Human Services on Feb. 28, 2026.
4/29/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Community Health Systems Inc. disclosed a suspected data breach in late February 2026 affecting potential PII and protected health information across California clinic locations.
4/30/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Integrated Pain Associates notified patients on April 30, 2026 after investigation found possible unauthorized access to sensitive data around February 24, 2026 in Killeen, Texas.
5/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Hematology Oncology Consultants reported a ransomware data breach targeting its Michigan network in 2025, exposing medical records and Social Security numbers, with notifications in 2026.
5/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Belmont Aesthetic & Reconstructive Plastic Surgery disclosed a U.S. health-data breach impacting 528 individuals after an Insomnia ransomware dark-web claim on March 3, 2026.
5/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Champion Healthcare disclosed a May 8, 2026 consumer notification after a late-January 2026 incident involving unauthorized access to internal systems.
5/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Vacation Myrtle Beach disclosed a ransomware-linked breach on June 16-19, 2025, potentially exposing Social Security numbers, financial data, and possible health records for about 10,750 people.
5/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medi-Rents & Sales Inc. disclosed an email data breach in early 2026 affecting 1,524 U.S. individuals, with potentially exposed insurance and limited health information.
5/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Rochester Philharmonic Orchestra disclosed an Akira ransomware incident in late 2025 that may have exposed personal identifiers and protected health information for about 1,726 people.
5/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
LGBTQ Center OC reported a Dec 25-26, 2025 data breach to the California Attorney General on June 5, 2026, exposing PII, PHI, and biometric identifiers affecting Rhode Island residents.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Lincoln Retirement Services Company LLC disclosed June 2, 2026 unauthorized access exposing Social Security numbers and financial account information, with consumer notification guidance issued May 29, 2026 in the United States.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NJ Pain Care Specialists LLC reported to U.S. HHS on May 14, 2026 after unauthorized access between Feb 25 and Feb 28, 2025 potentially exposed PII and protected health information.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Fresenius Kabi USA LLC disclosed in 2026 a third-party unauthorized access incident on an Ivenix-associated network potentially exposing employee identifiers and medical data affecting 285 Massachusetts residents.
6/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Kubota North America Corp. disclosed in 2026 an HR data breach affecting 2,237 Texas residents and offering Kroll identity monitoring after potential exposure of PII and benefits data.
7/1/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Murphy Law Firm said a Florida Physician Specialists data breach exposed Social Security, financial, and health information, with cybercriminal risks and class-action legal outreach.
4/28/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
A Manhattan federal class action filed in 2026 alleges NYC Health + Hospitals exposed millions of patients and staff, including biometric and medical data.
6/6/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
iRhythm Holdings reported a HIPAA-relevant patient data breach in third-party hosted applications, with potential downstream breach notification duties for referring providers.
6/16/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Billy Parker filed a class-action in Madison County Circuit Court alleging Huntsville Hospital Health System violated HIPAA after a Cerner-linked cyberattack exposed patient medical and personally identifiable information.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
GrayRobinson reported unauthorized access from March 5-24, 2025 that exposed protected health information for 65,113 people, including Maine residents.
6/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Brian Magadan filed a proposed nationwide class action in the Middle District of Louisiana against Grace Design Studios over alleged PII and PHI exposure after a Payouts King ransomware attack.
5/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Radiology Associates of Richmond disclosed a 266,000-person breach after unauthorized acquisition of PHI and financial data around July 25, 2025, with notifications beginning May 21, 2026.
5/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
iRhythm Technologies notified California officials in 2026 of unauthorized access to unencrypted patient information affecting more than 500 residents.
6/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Nissan Americas disclosed a May 27 to June 9, 2026 breach involving Oracle PeopleSoft zero-day SSRF exploitation, exposing sensitive employee data and triggering monitoring and regulator notifications.
6/30/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Nissan and the NAIC confirmed ShinyHunters data theft after Oracle PeopleSoft PeopleTools CVE-2026-35273 exploitation, with suspected impact across the United States, Canada, Mexico, and Brazil.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Kubota North America Corporation notified employees after an HR-related intrusion with possible exposure of Social Security numbers and bank details from March 16 to April 20.
7/2/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Sandhills Medical Foundation discovered a May 2, 2025 ransomware incident on May 8, 2025, potentially exposing personal and medical data of 169,017 patients.
5/6/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Shamis & Gentile investigated a ransomware-linked breach at Tampa Bay Dental Implants & Periodontics in St. Petersburg, Florida, affecting 6,400 people via backed electronic medical records.
5/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Tennessee officials investigated reports from consumers in Minnesota, New York, and Idaho of Medicare and private insurance charges for unreceived medical supplies traced to Memphis DME Supply.
5/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
In India, a wearable health app breach exposed contact details, transaction history, and fitness data after a March 27 intrusion, with notifications on June 2.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federal court approved an $8.7 million class action settlement in Canada for victims of a 2020 Government of Canada platform breach involving CRA My Account and My Service Canada Account.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Kubota North America notified employees in 2026 after unauthorized access to HR systems potentially exposed personal and financial identifiers, and provided Kroll identity monitoring.
7/2/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Nissan and NAIC disclosed PeopleSoft-linked cyber extortion after ShinyHunters exploited CVE-2026-35273, with impact potentially spanning the United States, Canada, Mexico, and Brazil.
6/30/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Bridewell and US HHS data show over 2,200 US medical center breaches since 2023, with fewer affected individuals in 2025 amid HIPAA segmentation and faster detection.
4/28/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Community Bank disclosed a May 7 SEC filing after unauthorized employee use of an external AI tool exposed customer names, birth dates, and Social Security numbers.
5/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
iRhythm Technologies disclosed June 8 unauthorized access to third-party hosted systems and subsequent ransom demands for stolen patient health information to the SEC.
6/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Nissan and NAIC confirmed PeopleSoft cyber extortion in 2026 after ShinyHunters exploited Oracle PeopleTools CVE-2026-35273, warned by Oracle and CISA.
6/30/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Tech Jacks Solutions Security Command Center / Tech Jacks Solutions0
FBI investigators are looking into a Karl Malone Auto Group data breach discovered April 4, 2026, involving exposed customer Social Security, license, financial, and passport data in Iowa.
6/10/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Nissan disclosed a PeopleSoft zero-day breach affecting employee and payroll records between May 27 and June 9, following Oracle and Mandiant notifications tied to ShinyHunters.
6/30/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
KerberRose Wealth Management disclosed a data breach beginning April 29, notifying about 27,000 potentially affected customers in Wisconsin and other states.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
U.S. digital healthcare firm iRhythm disclosed a June 2026 cyberattack on third-party-hosted applications involving stolen patient protected health information and an extortion demand.
6/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
La Perouse notified the California Attorney General in 2025 of unauthorized access at a third-party billing platform affecting at least seven healthcare providers.
6/10/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
iRhythm Holdings disclosed on June 15, 2026 that a social-engineering breach tied to third-party applications posed no identified risk to medical device systems or patient safety.
6/16/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Nissan notified the California Attorney General after ShinyHunters exploited Oracle PeopleSoft PeopleTools using CVE-2026-35273, exposing employee financial and identity data across multiple countries.
6/30/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Community Bank disclosed an AI-linked breach in a May 2026 SEC filing, exposing Social Security numbers and dates of birth for customers in Pennsylvania.
5/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
On June 13, 2026, One Medical reported a June 8-11 vendor file-storage breach affecting archived former Iora Health Seniors patient data in multiple U.S. cities.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Radiology Associates of Richmond reported a healthcare data breach beginning around July 25, 2025, with PHI access discovered and investigated through April 6, 2026.
5/27/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood investigates a Florida Physician Specialists network intrusion reported to the Maine Attorney General, alleging possible exposure of Social Security, financial, and medical data.
4/28/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Federman & Sherwood is investigating an NYC Health + Hospitals data breach reported to U.S. HHS after unauthorized network server access impacted about 5,086 patients.
5/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
In April 2026, Exitium ransomware claims targeted Gastroenterology & Hepatology of CNY in Syracuse, potentially exposing HIPAA medical records for over 167,000 patients.
4/15/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Select Medical began June 6, 2025 notifications after a July 2024 unauthorized third-party access to patient systems potentially exposed personal identifiers and protected health information.
6/9/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
CPAP Medical reported to the California Attorney General a breach discovered June 27, 2025, involving potential access to sensitive data between December 2024.
8/18/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Schubert Jonckheer & Kolbe LLP described investigation of a DermCare Management patient data breach affecting 9,724 Texas residents after file exfiltration in February 2025.
5/1/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Erie Family Health Centers confirmed unauthorized access between December 10, 2025 and January 27, 2026, potentially exposing health and identity data for about 570,000 people in Chicago.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Lumexa Imaging reported a vendor network incident on April 9, 2026, with unauthorized access between March 31 and April 9 potentially exposing patient records.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Radiology Associates of Richmond faced an alleged 2025 systems intrusion exposing patient PII and protected health information, with notifications mailed starting May 21, 2026, in Richmond, Virginia.
5/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
One Medical Seniors reported unauthorized access to third-party file storage of archived Iora Health patient files discovered June 13, with ShinyHunters extortion claims unverified.
6/24/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
KND Complex Litigation urged eligible Canadians to file LastPass breach settlement claims by June 23, 2026 after a 2022 intrusion involving stolen employee credentials.
6/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Columbia Medical Practice in Maryland reported a data breach on November 5, 2025 exposing personal and health information of approximately 3000 patients.
1/22/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Emanuel Medical Center in Georgia detected unauthorized third party access to sensitive information from May 21 to May 24, 2025, with breach notice posted February 17, 2026.
2/18/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Beverly Hills Cancer Center reported unauthorized network access between February 7 and February 11, 2025 in California, potentially exposing personal data and protected health information.
11/3/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Integrated Pain Associates reported a 2026 data breach in Killeen, Texas, exposing patient Social Security numbers and medical records and offering 12 months of credit monitoring.
5/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Verber Dental Group notified patients and state regulators on May 7, 2026, after unauthorized access potentially exposed sensitive personal and protected health information in January.
5/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
iRhythm Holdings disclosed June 8-10, 2026 unauthorized access to third-party-hosted business applications after social engineering and later ransomware extortion.
6/16/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
NCH Corporation disclosed an unauthorized access incident reported to the Maine Attorney General, potentially exposing Social Security numbers and health data between January and February 2026.
5/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood is investigating the Pathfinder LL&D Insurance Group data breach after Texas Attorney General reporting, affecting about 7,382 residents.
5/7/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood is investigating Nacogdoches Memorial Hospital after HHS OCR received a breach notification describing a hacking incident affecting about 2,507,073 people.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood began investigating a Verber Dental Group PC network-server data breach reported June 2, 2026, affecting about 8,598 people in Pennsylvania.
6/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood is investigating the Waveny LifeCare Network data breach reported to Maine on June 3, 2026 after unauthorized access was found on or about May 28, 2025.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood began investigating the Pivot Health data breach on June 19, 2026 after reporting of unauthorized access to sensitive health information in the USA.
6/19/2026 • Cybersecurity Tech (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
Almeida Law Group investigates a June 8, 2026 alleged ransomware breach at Central Arkansas Pediatrics in Conway, Arkansas, while affected data scope remains unconfirmed.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Women’s Center for Radiology in Orlando reported a late-April unauthorized-access incident in legacy systems after detecting suspicious activity on April 29.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Alta Orthopaedics reported a March 2026 discovery of unauthorized access to patient data affecting systems during February 3-6, 2026, with remediation and credit monitoring offered.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Blue Fish Pediatrics in Houston, Texas disclosed a 2025 unauthorized access incident, later confirming exposed patient medical data and some Social Security numbers, with notifications starting June 17, 2026.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Open Arms Care Corporation notified clients in Tennessee starting June 9, 2026 after an internal review found unauthorized access to certain email accounts in 2025.
6/14/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Verber Dental Group reported a Jan 27 data breach in Pennsylvania with potential access to medical and identity information, followed by a May 11 class action investigation.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Hokkaido's National Hospital Organization reported a hard-drive leak to police after a waste disposal vendor improperly destroyed drives containing hospital medical records.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Americans affected by a 2022 LastPass data breach seek compensation under an $8.2 million class action settlement, including cryptocurrency-loss claims reviewed by a Special Master.
6/25/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
McShane & Brady, LLC announced a Tennessee data breach involving unauthorized email access that exposed PII and protected health information for 3,171 individuals in December 2025.
4/14/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Xsolis disclosed a targeted phishing incident around January 22, 2026, involving potential unauthorized access to personal and protected health information, and offered identity monitoring via Kroll.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DentaQuest confirmed a June 2, 2026 unauthorized access breach potentially affecting up to 2.6 million account records, prompting Edelson Lechtzin LLP to review class action claims.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Evanston Township High School reported a June 7 ransomware attack that disrupted district systems and internet services while incident response and data exposure assessment continued.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Rochester Regional Health notified patients in Rochester, New York after a January phishing attack involving a third-party vendor system, offering 12-month identity monitoring despite an incorrect hospital name on letters.
6/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Florida investigators charged former Department of Juvenile Justice probation officer Crystal Lawson in 2026 for alleged retained-access leaks from a state criminal case database.
Vital Imaging Diagnostic Centers reported a 2025 network intrusion in Miami involving unauthorized file removal that may have exposed medical and government identification data and issued notifications in 2026.
4/15/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Edelson Lechtzin LLP is investigating potential class action privacy claims after New York Life confirmed April 8, 2026 that an agent email account compromise exposed clients personal information.
5/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Schubert Jonckheer & Kolbe LLP investigated a Community Health Systems patient data breach disclosed around April 29, 2026 after access around February 28, 2026 in California.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
OCH Regional Medical Center filed an HHS Office for Civil Rights breach notice on March 11, 2025 and began notifying affected individuals after unauthorized access to sensitive consumer information.
3/26/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Dental Group of Amarillo and Heart South Cardiovascular Group settled 2023–2024 patient data breach lawsuits with monetary funds and credit monitoring for affected patients in Texas and Alabama.
8/5/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
In 2025, hospitals report email and vendor driven data breaches exposing protected health information across California, Louisiana, Connecticut, South Dakota, and Tennessee.
9/12/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Two healthcare providers disclosed data breaches in 2025, exposing patient identifiers and health information, prompting breach notifications and identity protection measures.
11/3/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Health data breaches at CPAP Medical Services, Health Services LLC, and East Adams Rural Healthcare affect patients in Florida, Maine, and Washington during 2024 and 2025.
8/20/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Frederick Health Medical Group confirmed a ransomware breach affecting 934,326 patients in Maryland in 2025, triggering class action lawsuits alleging cybersecurity and breach-notice failures.
4/28/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Healthcare providers in the United States reported 2024 to 2025 data breaches, with investigations finding unauthorized access to patient identifiers and medical information.
4/16/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
UChicago Medicine disclosed a July 2024 third-party vendor cybersecurity incident through Nationwide Recovery Services that may have exposed personal data of nearly 40,000 patients.
5/28/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Rocky Mountain Associated Physicians reported on February 2, 2026 that an unauthorized systems access may have exposed patient and financial data for 50,640 people in Salt Lake City.
4/13/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Acadia Healthcare reported a social-engineering incident accessing email and SharePoint from March 21-25, 2026, with patient notifications starting May 22, 2026.
5/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Altos disclosed on June 17 that an unauthorized party accessed an internet exposed internal system containing personal and health data of patients in Southern California.
9/19/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Fort Wayne Medical Education Program data breach affects 29,485 individuals in Indiana; unauthorized access occurred December 12-17, 2024; notices mailed October 2, 2025.
10/6/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Attorneys sought individuals affected by a January 2025 Sierra Vista Hospital & Clinics breach in Truth or Consequences, New Mexico, to assess a possible class action.
1/29/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
BMC Health System identified unauthorized access to Workday-linked user accounts on March 9, 2025, and attorneys sought breach-notified individuals for a potential class action.
4/28/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Stockton Cardiology disclosed a breach in California between December 2025 and February 2026, exposing patient identifiers and billing records and triggering class-action intake for affected individuals.
3/23/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
ClassAction.org attorneys investigated a potential class action after Bank3 reported unauthorized access from July 25 to August 7, 2025 that may exposed identity, financial, and health data.
4/16/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Secure Health Plans of Georgia confirmed a 2026 data breach in Georgia after alleged unauthorized access to medical and insurance files emerged by Feb 3-12, 2026.
4/17/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Florida Physician Specialists notified potentially affected individuals starting April 24, 2026 after unauthorized access in late 2025 may have compromised SSNs, payment data, and medical records.
4/27/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
On April 16, 2026, threat-actor claims linked to New York-based Empower Group led to attorney outreach for potential class action over alleged Social Security number exposure.
5/28/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
On June 10, 2026, Vermont received a report from Miami accounting firm Palacio, Palacio & Zimmerman stating Social Security numbers may have been compromised.
6/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Orthopaedic Specialists of Massachusetts disclosed a January 2026 data breach in Massachusetts, reporting potential exposure of patient and employee medical records.
6/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Attorneys working on a potential class action sought Colorado Health Network breach victims after a cybersecurity incident exposed sensitive personal and health data and notices began June 18, 2026.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Nissan North America reported an Oracle PeopleSoft breach in which sensitive employee data may have been accessed, with attorneys seeking class-action claim input.
6/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
attorneys with classaction.org seek affected patients for potential class action over gaylord specialty healthcare data breach disclosed in 2024 in wallingford connecticut
9/25/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Legend Senior Living LLC disclosed a March 2026 data breach discovered after unauthorized access between July 2025 and August 2025, with April 10, 2026 notices to Texas and other state attorneys general.
4/13/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Aligned Orthopedic Partners identified unusual activity in its email system on December 8, 2025, reporting potential exposure of personal and health information after unauthorized access in late 2025.
4/18/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Claim Depot’s class action settlements database lists privacy-related breach, biometric, and health-data cases with instructions for claim submission across the 2020s.
5/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
U.S. consumers receive settlement and refund claim options through 2026 for Comcast Xfinity exposure, Google Assistant audio recordings, and Sprouts FACTA receipt printing.
5/25/2026 • Regulation, Law & Enforcement • Fines & Settlements
Healthcare breaches involving unsecured PHI trigger HIPAA notification duties to individuals and HHS, with ransomware, phishing, and cloud misconfiguration cited as common causes.
4/15/2026 • Cybersecurity (Privacy-Relevant) • Data Breaches & Mass Exposures
Richmond University Medical Center reported a healthcare data breach in New York involving accessed or removed files around May 6, 2023, with potential exposure of protected health information for 674,000 people.
1/7/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
INC Ransom claimed mid-June 2026 ransomware access to Horizon Family Medical Group in Orange County, New York, with alleged protected health and financial data exposure.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis, Inc. disclosed on June 5, 2026 that a phishing attack in January 2026 led to acquisition of sensitive personal information and protected health information.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Unauthorized access occurred December 13-21, 2024 on CPAP Medical Supplies and Services, Inc.'s Florida network, affecting 90,133 patients and clients.
8/18/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Ransomware intelligence on July 2, 2026 alleged an unverified INCRansom attack on Colorado Rehabilitation & Occupational Medicine, with patient data exposure unconfirmed.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Springfield Hospital notified individuals starting February 10, 2026, after a December 17, 2025 employee email account compromise potentially exposed personal and health information.
4/14/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Kubota North America Corporation notified employees on June 30, 2026 about a March 16, 2026 breach affecting Social Security numbers, medical records, and payment data in Grapevine, Texas.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
McShane & Brady, LLC is investigating a Doctor Alliance vendor breach that potentially exposed health records of 724 Duncan Regional Hospital patients in Oklahoma between Oct. 31 and Nov. 17, 2025.
4/30/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
DermCare Management notified of a healthcare data breach in 2025, exposing Social Security, financial, and medical records across Florida, Texas, Virginia, and California.
4/30/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
DermCare Management notified affected individuals in March 2026 after a February 2025 unauthorized access event potentially impacted patient information.
4/10/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
On June 29, 2026, dark web monitoring sites reported Rocky Mountain Care as a data breach victim, with suspected Social Security number and address exposure.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ID Care discovered suspicious network activity on November 5, 2025, leading to unauthorized access to Social Security numbers and medical records and HHS notification.
3/18/2026 • Cybersecurity (Privacy-Relevant) • Data Breaches & Mass Exposures
In February 2024, ALPHV/BlackCat ransomware disrupted Change Healthcare systems and exposed Social Security numbers and medical records for about 192.7 million people in the United States.
5/27/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic disclosed on April 24, 2026 an IT breach tied to ShinyHunters claims of stolen PII and internal data, with investigation and potential notifications under HIPAA and state breach laws.
5/1/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
McLeod Health detected unauthorized access to a Dillon Family Medicine server months after Oct 2025 intrusions, with Qilin ransomware blamed and HIPAA timing issues discussed.
6/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DermCare Management found suspicious activity on February 26, 2025 and reported an intrusion between February 14 and February 26 that may have exposed patient PII and PHI.
4/15/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Federman & Sherwood is investigating a Providence St. Joseph Orange healthcare data breach reported in 2026 after unauthorized network-server access exposed patient information to about 11,329 people.
5/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Qilin claimed a mid-May 2026 ransomware attack on Spirit Medical Transport, potentially exposing protected health information for patients in Western Ohio and Eastern Indiana.
5/14/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Southern California University of Health Sciences disclosed unauthorized access on or about March 24, 2026, with personal information exposed in accessed files.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Sterling Seacrest Pritchard notified people about possible unauthorized access to email-environment data between August 12 and 13, 2025, with notifications through April 2026.
5/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
KerberRose Wealth Management investigated an April 29, 2026 employee email-account compromise and notified individuals in May 2026 after potential PII exposure.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches