Healthcare Data Breaches Hit PatientsHealthcare Data Breaches Hit PatientsCoverage from PMBAUSA, Paubox, and others
00/00/0000
DailyWeekly
Healthcare organizations and service providers are reporting breaches that expose combinations of patient identities, medical histories, insurance details, and financial information.
The incidents range from credential compromise and social engineering to ransomware-linked intrusions and unauthorized access to third-party storage or billing systems, with the largest disclosed case affecting more than 1.26 million people through MCBS. The disclosures also show continuing exposure beyond hospitals, including medical equipment suppliers, law firms, insurers, and business associates, followed by credit-monitoring offers, regulatory reporting, and proposed litigation.
Key Issues
01
Third-party concentration expands the exposure surface
Billing companies, business associates, law firms, software vendors, and external storage platforms concentrate records from multiple healthcare organizations, allowing one compromise to affect patients across providers. HHS-reported data indicates vendor and business-associate exposures represented 28% of email breaches in 2025.
Drawn from 4 articles
02
Long investigation and notification timelines persist
Organizations continue to identify or disclose exposure months after unauthorized access, including an MCBS delay of about eight months, an Averhealth delay of more than five months, and Whitfield Regional Hospital notifications beginning 404 days after detection. These timelines prolong uncertainty about scope and delay mitigation by affected individuals.
Drawn from 4 articles
03
Mega-breach outliers continue to drive potential harm
Healthcare incidents continue to expose identity, medical, insurance, and financial information at very large scale, including 1,261,464 people in the MCBS breach and 3.8 million tied to Medtronic. Aggregate exposure fell from 2024 to 2025 in the cited statistics, but high-impact outliers remain consequential.
Mixed
Drawn from 4 articles
04
Credential and access-control failures remain central entry points
Reported incidents repeatedly involve compromised employee or contractor accounts, social engineering, and email or remote-access weaknesses alongside ransomware-linked intrusions. The cited 2025 statistics attribute more than 80% of large healthcare breaches to hacking or other IT incidents, while recent cases include Clover’s compromised employee accounts and behavioral-health email compromises.
Drawn from 4 articles
Looking Back
599 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Jan '25
Apr '25
Jul '25
Oct '25
Feb '26
May '26
Aug '26
The Story So Far
No material change
The new-member evidence adds another healthcare-related breach disclosure but does not materially change the known pattern of patient-data exposure through providers and service partners.
Previously
Healthcare providers, medical suppliers, billing firms, law practices, and other service partners are reporting unauthorized access to systems and files containing patient identities, insurance details, medical histories, and financial information. Several incidents involve ransomware or extortion claims, while breaches at business associates and third-party storage platforms demonstrate how patient data can be exposed beyond the systems operated directly by care providers. The reported impact ranges from thousands of people to more than 1.26 million in the MCBS incident, with investigations and notifications often occurring months after the underlying access.
History
08/24/2026
The story now emphasizes post-breach consequences and more specific attack methods, including social engineering, credential compromise, credit-monitoring offers, and proposed litigation. PEAR and ShinyHunters claims are further detailed as alleged large-scale publication or exfiltration, though some claims remain unverified.
08/05/2026
The story expands with several newly named incidents and a clearer emphasis on the breadth of affected healthcare-adjacent organizations, not just core providers. It also adds a notable outlier: the Fairlife ransomware case, which is framed as extending the cluster beyond healthcare into operational disruption and alleged theft.
MCBS reported in 2026 that unauthorized network access during September 2025 compromised personal and health information for approximately 1.26 million healthcare patients.
8/15/2026 • Data Breaches & Exposure Events • General
Averhealth Holdings began notifying 9,909 individuals in July 2026 after hackers accessed Avertest's healthcare email environment between December 2025 and January 2026.
8/3/2026 • Data Breaches & Exposure Events • General
Lifespark Management Services detected suspicious email access in February 2026 and notified individuals in July 2026 of potential exposure of personal and health data.
7/27/2026 • Data Breaches & Exposure Events • General
Eyemart Express disclosed February 13 that unauthorized access the previous day may have exposed customers' sensitive personal data, including Social Security numbers.
7/25/2026 • Data Breaches & Exposure Events • General
In the US, healthcare data breaches expose identifiable medical information and are governed by HIPAA and the FTC Health Breach Notification Rule, shaping notice, mitigation, and legal recourse.
7/24/2026 • Data Breaches & Exposure Events • General
Eyemart Express reported an unauthorized access incident in February, with Feb. 12 exposure that may include Social Security numbers and health-plan data for some customers in the United States.
7/24/2026 • Data Breaches & Exposure Events • General
Behavioral health providers in Colorado, Nebraska, Arizona, and Texas disclosed four data breaches involving unauthorized access and email compromises affecting patients and employees.
7/24/2026 • Data Breaches & Exposure Events • General
NAS Recovery Solutions in Lakewood, Colorado discovered May 13, 2026 that unauthorized workforce downloads exposed limited client identifiers, potentially revealing substance use disorder treatment under HIPAA.
7/23/2026 • Data Breaches & Exposure Events • General
Clover Health disclosed a July 4 social-engineering incident in a U.S. SEC filing after three employee accounts were compromised and PII and protected health information exposure occurred.
7/21/2026 • Data Breaches & Exposure Events • General
Heart Care Centers of Illinois notified affected Chicago-area individuals in July 2026 after unauthorized access to an employee email account from Aug 2024 to Nov 2024.
7/21/2026 • Data Breaches & Exposure Events • General
Clover Health disclosed a July 4 breach after unauthorized access to three employee accounts exposed potential personal and protected health information, pending scope investigation.
7/20/2026 • Data Breaches & Exposure Events • General
Clover Health reported a July 4, 2026 unauthorized access incident after anomalous employee logins, with social engineering used to reach accounts handling member scheduling and sales data in the USA.
7/20/2026 • Data Breaches & Exposure Events • General
Clover Health disclosed a July 4 employee-account compromise in USA operations, potentially exposing member PII and protected health information while the company investigates scope.
7/20/2026 • Data Breaches & Exposure Events • General
Craneware disclosed an ongoing cyberattack and data exfiltration incident in the United Kingdom, impacting U.S. healthcare billing customers as investigation continues.
7/20/2026 • Data Breaches & Exposure Events • General
Clover Health disclosed in a July 17 SEC filing that abnormal logins on July 4 led to social-engineering access of three employee health plan accounts.
7/20/2026 • Data Breaches & Exposure Events • General
Clover Health disclosed in an SEC filing on July 17 that social engineering enabled unauthorized access to three health plan employee accounts discovered on July 4.
7/20/2026 • Data Breaches & Exposure Events • General
TrendAI analysis reports ransomware at 36.3% of healthcare-linked underground marketplace activity, using double extortion to steal and sell medical records.
7/18/2026 • Data Breaches & Exposure Events • General
HHS OCR reported 772 large healthcare data breaches in 2025, exposing about 138.5 million records while OCR increased HIPAA Security Rule risk-analysis enforcement.
7/16/2026 • Data Breaches & Exposure Events • General
AdaptHealth reported a July 2, 2026 Form 8-K describing a June 15, 2026 threat actor claim and confirmed exfiltration of billing password data and possible PII/PHI from external EHR portals.
7/13/2026 • Data Breaches & Exposure Events • General
Sentara Hospitals in Virginia disclosed a reportable HIPAA violation after misrouted billing mail exposed protected health information without hacking, highlighting persistent physical-mail risk.
7/10/2026 • Data Breaches & Exposure Events • General
Medtronic notified more than 3.8 million people after ShinyHunters accessed corporate IT systems in April 2026 and stole personal and medical information.
7/6/2026 • Data Breaches & Exposure Events • General
Medtronic notified 3,834,294 individuals in 2026 after ShinyHunters claimed unauthorized access to corporate IT systems and possible exposure of medical and identity data.
7/5/2026 • Data Breaches & Exposure Events • General
HHS Office for Civil Rights statistics show 2024 healthcare breaches exposed about 289 million people, largely due to a Change Healthcare ransomware attack.
7/5/2026 • Data Breaches & Exposure Events • General
Medtronic disclosed an April 2026 unauthorized access incident attributed to ShinyHunters that exposed personal and health information for 3.8 million people.
7/5/2026 • Data Breaches & Exposure Events • General
On June 13, 2026, One Medical reported a June 8-11 vendor file-storage breach affecting archived former Iora Health Seniors patient data in multiple U.S. cities.
6/24/2026 • Data Breaches & Exposure Events • General
One Medical Seniors reported unauthorized access to third-party file storage of archived Iora Health patient files discovered June 13, with ShinyHunters extortion claims unverified.
6/24/2026 • Data Breaches & Exposure Events • General
INC Ransom claimed mid-June 2026 ransomware access to Horizon Family Medical Group in Orange County, New York, with alleged protected health and financial data exposure.
6/19/2026 • Data Breaches & Exposure Events • General
La Perouse notified the California Attorney General in 2025 of unauthorized access at a third-party billing platform affecting at least seven healthcare providers.
6/10/2026 • Data Breaches & Exposure Events • General
In February 2024, ALPHV/BlackCat ransomware disrupted Change Healthcare systems and exposed Social Security numbers and medical records for about 192.7 million people in the United States.
5/27/2026 • Data Breaches & Exposure Events • General
Radiology Associates of Richmond disclosed a 266,000-person breach after unauthorized acquisition of PHI and financial data around July 25, 2025, with notifications beginning May 21, 2026.
5/26/2026 • Data Breaches & Exposure Events • General
Medtronic disclosed on April 24, 2026 an IT breach tied to ShinyHunters claims of stolen PII and internal data, with investigation and potential notifications under HIPAA and state breach laws.
5/1/2026 • Data Breaches & Exposure Events • General
Bridewell and US HHS data show over 2,200 US medical center breaches since 2023, with fewer affected individuals in 2025 amid HIPAA segmentation and faster detection.
4/28/2026 • Data Breaches & Exposure Events • General
In April 2026, Exitium ransomware claims targeted Gastroenterology & Hepatology of CNY in Syracuse, potentially exposing HIPAA medical records for over 167,000 patients.
4/15/2026 • Data Breaches & Exposure Events • General
HHS OCR reports 772 large healthcare breaches in 2025 under HITECH rules, while affected individuals fell versus 2024 due to Change Healthcare outlier impact.
7/28/2026 • Data Breaches & Exposure Events • General
AcademyHealth disclosed a ransomware-related data breach to the Vermont Attorney General on July 27, 2026 after a SafePay dark web claim in April 2026.
7/28/2026 • Data Breaches & Exposure Events • General
Medical Computer Business Services reported a PEAR-attributed 2025 network breach impacting 1,261,464 people in Georgia, including exposure of health and identity data.
7/28/2026 • Data Breaches & Exposure Events • General
MCBS reported a PEAR-attributed ransomware breach affecting 1,261,464 people in late September 2025, exposing Social Security numbers and medical information.
7/27/2026 • Data Breaches & Exposure Events • General
Clover Health Investments disclosed a July 4 breach after a social engineering attack compromised three employee accounts accessing personal and protected health information in the U.S.
7/21/2026 • Data Breaches & Exposure Events • General
Craneware disclosed an ongoing response to a cyberattack after hackers exfiltrated customer, employee, and partner data, with the investigation continuing in the United Kingdom.
7/20/2026 • Data Breaches & Exposure Events • General
Heart Care Centers of Illinois reported a phishing-enabled employee email breach with exposure of sensitive PII and health information discovered in 2026.
7/20/2026 • Data Breaches & Exposure Events • General
Averhealth Holdings notified Vermont and Massachusetts residents after unauthorized access to Averest Inc email systems exposed Social Security numbers and health information in 2025-2026.
7/15/2026 • Data Breaches & Exposure Events • General
NLACRC detected suspected ransomware on Nov. 28, 2024 and later reported a Nov. 20-Dec. 1 data breach exposing PII and PHI to multiple state attorneys general.
7/1/2026 • Data Breaches & Exposure Events • General
Western Orthopaedics disclosed a 2025 ransomware data breach affecting Texas and Massachusetts patients after PEAR claimed data access on the dark web.
5/5/2026 • Data Breaches & Exposure Events • General
Texas received a breach filing on April 17, 2026, after ransomware group Payouts King claimed 435 GB of Eyemart Express data including PII and protected health information.
4/17/2026 • Data Breaches & Exposure Events • General
Eyemart Express, LLC reported unauthorized access to customer information in July 2026 through notifications filed with attorneys general in Vermont and Washington.
8/28/2026 • Data Breaches & Exposure Events • General
Clover Health faces four proposed class-action lawsuits filed from July 22 through July 24 in Tennessee after a social-engineering breach exposed employee-account personal and health information.
8/8/2026 • Data Breaches & Exposure Events • General
Whitfield Regional Hospital notified potentially affected individuals beginning July 17, 2026, after a 2025 unauthorized network access incident potentially exposed personal, financial, and health information.
8/5/2026 • Data Breaches & Exposure Events • General
Madera Community Hospital reported in July 2026 that a May 2025 network intrusion potentially exposed personal, financial, medical, and biometric information of 150,810 individuals in California.
8/4/2026 • Data Breaches & Exposure Events • General
Medical Computer Business Services disclosed on July 30, 2026, that a September 2025 ransomware incident in Augusta, Georgia, affected 1,261,464 people across multiple states.
7/31/2026 • Data Breaches & Exposure Events • General
Eyemart Express, LLC reported unauthorized access on February 12, 2026, and notified customers in the United States, including Social Security number exposure.
7/26/2026 • Data Breaches & Exposure Events • General
RXNT filed a Washington State Attorney General breach notification after possible unauthorized access to healthcare cloud systems holding personal and health-related data.
7/25/2026 • Data Breaches & Exposure Events • General
Eyemart Express disclosed a February 2026 unauthorized-access cybersecurity event involving customer personal data and customer notification on July 24, 2026, from Texas.
7/24/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems LLC identified suspicious activity on October 19, 2025, after an unauthorized party potentially accessed patient PII and PHI in Montgomery, Ohio.
7/24/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood is investigating NAS Recovery Solutions after a reported patient-data breach involving electronic medical records and network systems affected about 7,000 people in the USA.
7/24/2026 • Data Breaches & Exposure Events • General
Heart Care Centers of Illinois notified individuals after a potential data breach on when and where Palos Park, Illinois exposed identity, payment, and medical information.
7/20/2026 • Data Breaches & Exposure Events • General
Casper Orthopedics disclosed a ransomware-linked data breach in the US after Anubis claimed responsibility for unauthorized exposure of patient medical records.
7/15/2026 • Data Breaches & Exposure Events • General
Clinical Registry disclosed a data breach affecting 8,545 patients at Dignity Health’s St. Mary’s Medical Center, including medical record identifiers.
7/12/2026 • Data Breaches & Exposure Events • General
AdaptHealth disclosed on July 2 that social engineering enabled contractor-session compromise, leading to exfiltration of patient and insurance billing data from cloud systems.
7/9/2026 • Cybersecurity (Privacy-Relevant) • General
Breach and vulnerability updates reported disclosure noncompliance, GitHub agentic exposure via prompt injection, and multiple major personal-data incidents affecting millions in the United States and United Kingdom.
7/9/2026 • Data Breaches & Exposure Events • General
Healthcare breaches involving unsecured PHI trigger HIPAA notification duties to individuals and HHS, with ransomware, phishing, and cloud misconfiguration cited as common causes.
4/15/2026 • Cybersecurity (Privacy-Relevant) • General
Two healthcare providers disclosed data breaches in 2025, exposing patient identifiers and health information, prompting breach notifications and identity protection measures.
11/3/2025 • Data Breaches & Exposure Events • General
In 2025, hospitals report email and vendor driven data breaches exposing protected health information across California, Louisiana, Connecticut, South Dakota, and Tennessee.
9/12/2025 • Data Breaches & Exposure Events • General
Frederick Health Medical Group confirmed a ransomware breach affecting 934,326 patients in Maryland in 2025, triggering class action lawsuits alleging cybersecurity and breach-notice failures.
4/28/2025 • Data Breaches & Exposure Events • General
Healthcare providers in the United States reported 2024 to 2025 data breaches, with investigations finding unauthorized access to patient identifiers and medical information.
4/16/2025 • Data Breaches & Exposure Events • General
Richmond University Medical Center reported a healthcare data breach in New York involving accessed or removed files around May 6, 2023, with potential exposure of protected health information for 674,000 people.
1/7/2025 • Data Breaches & Exposure Events • General
AdaptHealth, LLC notified the Texas Attorney General of a data breach affecting approximately 143,454 Texas residents and potentially exposing sensitive health information nationwide.
8/17/2026 • Data Breaches & Exposure Events • General
AdaptHealth Corp. confirmed in June 2025 that a threat actor accessed cloud systems through compromised contractor credentials and exfiltrated potentially sensitive patient data in the United States.
8/15/2026 • Data Breaches & Exposure Events • General
AdaptHealth disclosed on July 2, 2026, in the United States, that attackers using compromised contractor credentials accessed systems containing patient personal and health information.
8/14/2026 • Data Breaches & Exposure Events • General
Madera Community Hospital notified 150,810 people in mid-July 2026 after a May 2025 network intrusion potentially exposed medical, financial, and identity information in Madera, California.
8/4/2026 • Data Breaches & Exposure Events • General
Lifespark Management Services Inc. disclosed a 2026 email-environment data breach in St. Louis Park, Minnesota, after suspicious activity led to possible unauthorized access to PII and protected health information.
7/26/2026 • Data Breaches & Exposure Events • General
Hudson Valley Medical Billing & Credentialing LLC reported possible unauthorized access in 2026, with Massachusetts notification and credit monitoring support beginning July 2026.
7/16/2026 • Data Breaches & Exposure Events • General
Easypak reported a ransomware-related data breach discovered in January 2026, with possible exposure of sensitive personal data for at least 217 Massachusetts residents.
7/15/2026 • Data Breaches & Exposure Events • General
Entyre Care Massachusetts Inc. disclosed a March 2026 data breach involving publicly accessible files containing Medicaid IDs and medical records, discovered on May 12, 2026.
7/15/2026 • Data Breaches & Exposure Events • General
PennyMac unit Private National Mortgage Acceptance Company LLC disclosed a Group Health Plan breach affecting 3,972 U.S. individuals after HHS notification on June 9, 2026.
7/13/2026 • Data Breaches & Exposure Events • General
Medtronic notified more than 3.8 million patients after unauthorized access to corporate IT systems, and California released the breach notification letter on June 29.
7/6/2026 • Cybersecurity Tech (Privacy-Relevant) • General
Blue Fish Pediatrics notified 41,485 Texas residents after a July 2025 computer system breach potentially exposed Social Security numbers and health records, with mailed notices starting June 17, 2026.
6/18/2026 • Data Breaches & Exposure Events • General
Sandhills Medical Foundation disclosed on April 28, 2026 a ransomware breach that affected 169,017 patients after unauthorized access to company servers and potential exposure of personal health information.
4/29/2026 • Data Breaches & Exposure Events • General
Whitfield Regional Hospital detected unauthorized network access in 2025, later traced it to May 15, 2025, and issued patient notifications in July 2026.
7/25/2026 • Data Breaches & Exposure Events • General
Medical Cost Benefit Services (MCBS) disclosed a data breach affecting about 1.2 million individuals, raising concerns about healthcare cybersecurity across integrated third-party ecosystems.
7/27/2026 • Data Breaches & Exposure Events • General
Wolf Haldenstein Adler Freeman & Herz LLP began investigating a Heart Care Centers of Illinois data breach in Palos Park, Illinois, after breach notifications.
7/24/2026 • Data Breaches & Exposure Events • General
Anubis claimed credit in a Fairlife ransomware incident on the dark web while Coca-Cola reported unauthorized third-party access to production-related systems on July 16.
7/22/2026 • Data Breaches & Exposure Events • General
Craneware reported a cyberattack and stolen files from its data environment in the UK, with employee and selected customer and partner records exposed and investigation ongoing.
7/20/2026 • Data Breaches & Exposure Events • General
Spokane Digestive Disease Center disclosed May 2026 findings of unauthorized employee email access that exposed patient data, with notifications beginning May 26.
7/7/2026 • Data Breaches & Exposure Events • General
Ransomware intelligence on July 2, 2026 alleged an unverified INCRansom attack on Colorado Rehabilitation & Occupational Medicine, with patient data exposure unconfirmed.
7/2/2026 • Data Breaches & Exposure Events • General
Xsolis disclosed a targeted phishing incident around January 22, 2026, involving potential unauthorized access to personal and protected health information, and offered identity monitoring via Kroll.
6/22/2026 • Data Breaches & Exposure Events • General
Blue Fish Pediatrics in Houston, Texas disclosed a 2025 unauthorized access incident, later confirming exposed patient medical data and some Social Security numbers, with notifications starting June 17, 2026.
6/18/2026 • Data Breaches & Exposure Events • General
Open Arms Care Corporation notified clients in Tennessee starting June 9, 2026 after an internal review found unauthorized access to certain email accounts in 2025.
6/14/2026 • Data Breaches & Exposure Events • General
Hokkaido's National Hospital Organization reported a hard-drive leak to police after a waste disposal vendor improperly destroyed drives containing hospital medical records.
6/9/2026 • Data Breaches & Exposure Events • General
Almeida Law Group investigates a June 8, 2026 alleged ransomware breach at Central Arkansas Pediatrics in Conway, Arkansas, while affected data scope remains unconfirmed.
6/9/2026 • Data Breaches & Exposure Events • General
Radiology Associates of Richmond reported a healthcare data breach beginning around July 25, 2025, with PHI access discovered and investigated through April 6, 2026.
5/27/2026 • Data Breaches & Exposure Events • General
Sterling Seacrest Pritchard notified people about possible unauthorized access to email-environment data between August 12 and 13, 2025, with notifications through April 2026.
5/22/2026 • Data Breaches & Exposure Events • General
Radiology Associates of Richmond faced an alleged 2025 systems intrusion exposing patient PII and protected health information, with notifications mailed starting May 21, 2026, in Richmond, Virginia.
5/22/2026 • Data Breaches & Exposure Events • General
Lumexa Imaging reported a vendor network incident on April 9, 2026, with unauthorized access between March 31 and April 9 potentially exposing patient records.
5/20/2026 • Data Breaches & Exposure Events • General
Shamis & Gentile investigated a ransomware-linked breach at Tampa Bay Dental Implants & Periodontics in St. Petersburg, Florida, affecting 6,400 people via backed electronic medical records.
5/19/2026 • Data Breaches & Exposure Events • General
Qilin claimed a mid-May 2026 ransomware attack on Spirit Medical Transport, potentially exposing protected health information for patients in Western Ohio and Eastern Indiana.
5/14/2026 • Data Breaches & Exposure Events • General
Alta Orthopaedics reported a March 2026 discovery of unauthorized access to patient data affecting systems during February 3-6, 2026, with remediation and credit monitoring offered.
5/11/2026 • Data Breaches & Exposure Events • General
Sandhills Medical Foundation discovered a May 2, 2025 ransomware incident on May 8, 2025, potentially exposing personal and medical data of 169,017 patients.
5/6/2026 • Data Breaches & Exposure Events • General
Integrated Pain Associates reported a 2026 data breach in Killeen, Texas, exposing patient Social Security numbers and medical records and offering 12 months of credit monitoring.
5/3/2026 • Data Breaches & Exposure Events • General
DermCare Management found suspicious activity on February 26, 2025 and reported an intrusion between February 14 and February 26 that may have exposed patient PII and PHI.
4/15/2026 • Data Breaches & Exposure Events • General
Vital Imaging Diagnostic Centers reported a 2025 network intrusion in Miami involving unauthorized file removal that may have exposed medical and government identification data and issued notifications in 2026.
4/15/2026 • Data Breaches & Exposure Events • General
Springfield Hospital notified individuals starting February 10, 2026, after a December 17, 2025 employee email account compromise potentially exposed personal and health information.
4/14/2026 • Data Breaches & Exposure Events • General
DermCare Management notified affected individuals in March 2026 after a February 2025 unauthorized access event potentially impacted patient information.
4/10/2026 • Data Breaches & Exposure Events • General
Health data breaches at CPAP Medical Services, Health Services LLC, and East Adams Rural Healthcare affect patients in Florida, Maine, and Washington during 2024 and 2025.
8/20/2025 • Data Breaches & Exposure Events • General
UChicago Medicine disclosed a July 2024 third-party vendor cybersecurity incident through Nationwide Recovery Services that may have exposed personal data of nearly 40,000 patients.
5/28/2025 • Data Breaches & Exposure Events • General
Madera Community Hospital reported an undisclosed-data network breach to the California Attorney General on July 14, 2026, after unauthorized third-party access in May 2025.
7/17/2026 • Data Breaches & Exposure Events • General
Erick K. Perroud, DDS disclosed a data breach affecting 7,692 individuals in the United States to the U.S. Department of Health and Human Services on June 10, 2026.
7/8/2026 • Data Breaches & Exposure Events • General
Mid-South Pulmonary & Sleep Specialists P.C. investigated ransomware-linked unauthorized network access in Memphis after Nov. 2, 2025 detection, later notifying patients in June 2026.
7/8/2026 • Data Breaches & Exposure Events • General
Heart of America Eye Care disclosed a likely unauthorized network access event in Kansas City during April 2026, with HHS notification on June 5, 2026 after a CMD Organization dark web claim.
7/7/2026 • Data Breaches & Exposure Events • General
Medtronic notified customers in 2026 after investigation found unauthorized access to corporate IT systems during April 13 to April 19, following ShinyHunters extortion claims.
7/2/2026 • Data Breaches & Exposure Events • General
NJ Pain Care Specialists LLC reported to U.S. HHS on May 14, 2026 after unauthorized access between Feb 25 and Feb 28, 2025 potentially exposed PII and protected health information.
6/8/2026 • Data Breaches & Exposure Events • General
Radiology Associates of Richmond notified 266,000 patients after unauthorized access on or around July 25, 2025, exposing health and personal information.
5/23/2026 • Data Breaches & Exposure Events • General
Medi-Rents & Sales Inc. disclosed an email data breach in early 2026 affecting 1,524 U.S. individuals, with potentially exposed insurance and limited health information.
5/19/2026 • Data Breaches & Exposure Events • General
Vacation Myrtle Beach disclosed a ransomware-linked breach on June 16-19, 2025, potentially exposing Social Security numbers, financial data, and possible health records for about 10,750 people.
5/18/2026 • Data Breaches & Exposure Events • General
Belmont Aesthetic & Reconstructive Plastic Surgery disclosed a U.S. health-data breach impacting 528 individuals after an Insomnia ransomware dark-web claim on March 3, 2026.
5/12/2026 • Data Breaches & Exposure Events • General
Schubert Jonckheer & Kolbe LLP is investigating a Medtronic data breach after ShinyHunters claimed unauthorized access and Medtronic confirmed the incident in April 2026.
5/6/2026 • Data Breaches & Exposure Events • General
Hematology Oncology Consultants reported a ransomware data breach targeting its Michigan network in 2025, exposing medical records and Social Security numbers, with notifications in 2026.
5/4/2026 • Data Breaches & Exposure Events • General
Greater Boston Urology reported a protected health information breach affecting 4,717 people to the U.S. Department of Health and Human Services on Feb. 28, 2026.
4/29/2026 • Data Breaches & Exposure Events • General
Aligned Orthopedic Partners reported an email system intrusion between Nov. 16 and Dec. 16, 2025, potentially exposing PII and protected health information.
4/18/2026 • Data Breaches & Exposure Events • General
Altos disclosed on June 17 that an unauthorized party accessed an internet exposed internal system containing personal and health data of patients in Southern California.
9/19/2025 • Data Breaches & Exposure Events • General
Select Medical began June 6, 2025 notifications after a July 2024 unauthorized third-party access to patient systems potentially exposed personal identifiers and protected health information.
6/9/2025 • Data Breaches & Exposure Events • General
OCH Regional Medical Center filed an HHS Office for Civil Rights breach notice on March 11, 2025 and began notifying affected individuals after unauthorized access to sensitive consumer information.
3/26/2025 • Data Breaches & Exposure Events • General
McLeod Health detected unauthorized access to a Dillon Family Medicine server months after Oct 2025 intrusions, with Qilin ransomware blamed and HIPAA timing issues discussed.
6/11/2026 • Data Breaches & Exposure Events • General
Ransomware attacks and vendor breaches against healthcare providers in the USA and Germany increased in early 2026, leading to large-scale patient data theft and prolonged operational disruptions.
7/10/2026 • Cybersecurity (Privacy-Relevant) • General
Craneware and Abbott investigated healthcare cyber incidents after alleged exfiltration through vendor systems and Abbott LabCentral portal access claims.
7/20/2026 • Data Breaches & Exposure Events • General
Novo Nordisk is linked to a reported cyberattack targeting clinical trial and AI research data, while 2025 healthcare breach reporting indicates large-scale credential-driven exposures.
7/13/2026 • Cybersecurity (Privacy-Relevant) • General
Coca-Cola disclosed on July 16 that ransomware disrupted Fairlife production and enabled data theft, followed by an Anubis extortion leak after July 27.
7/27/2026 • Data Breaches & Exposure Events • General
Hackers accessed CPAP Medical Supplies and Services systems in December 2024, exposing personal and health information for more than 90,000 individuals in the United States.
8/22/2025 • Data Breaches & Exposure Events • General