Healthcare Vendors Expose Patient DataHealthcare Vendors Expose Patient DataCoverage from Paubox, Rescana, and others
00/00/0000
DailyWeekly
Healthcare technology and service providers are reporting breaches that expose patient health, identity, insurance, and financial information at substantial scale.
Incidents involving CareCloud, MCBS, OpenLoop Health, Hawthorn Medical, and other vendors show how shared platforms, cloud environments, file servers, and business associates can concentrate sensitive records across multiple healthcare organizations. The disclosures also highlight uncertainty about the exact records accessed and the often lengthy interval between intrusion, investigation, and patient notification.
Key Issues
01
Exceptional breach scale
Healthcare-related disclosures continue to affect hundreds of thousands to millions of people. CareCloud, MCBS, OpenLoop Health, and Unlimited Technology Systems show how single incidents can expose patient, identity, insurance, and medical data at population scale.
Drawn from 4 articles
02
Vendor and platform concentration
Business associates, billing systems, practice-management platforms, and shared infrastructure concentrate records from multiple healthcare organizations in relatively few technology environments. A compromise at one provider can therefore propagate across downstream brands and patient populations.
Drawn from 4 articles
03
Long investigation and notification delays
Several incidents were disclosed months after unauthorized access or discovery, including MCBS, Hawthorn, Centers Laboratory, Unlimited Technology Systems, and the Washington Post. The delays prolong uncertainty for affected people and create compliance and accountability concerns.
Drawn from 5 articles
04
Uncertain scope and downstream harm
Public notices frequently describe data as potentially exposed without establishing whether records were downloaded, misused, or linked to confirmed fraud. Monitoring, restoration, and credit services provide mitigation, but do not resolve uncertainty about the exposed data or longer-term medical and identity-fraud risk.
Drawn from 3 articles
Looking Back
588 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Jan '25
Apr '25
Jul '25
Nov '25
Jan '26
May '26
Aug '26
The Story So Far
No material change
The new Monmouth University breach report adds another healthcare-related data exposure but provides no substantiated details that materially change the Topic’s established scope or dynamics.
Previously
Healthcare technology and service providers are reporting breaches that expose patient health, identity, insurance, and financial information at substantial scale. Incidents involving CareCloud, MCBS, OpenLoop Health, Hawthorn Medical, and other vendors show how shared platforms, cloud environments, file servers, and business associates can concentrate sensitive records across multiple healthcare organizations. The disclosures also highlight uncertainty about the exact records accessed and the often lengthy interval between intrusion, investigation, and patient notification.
Unlimited Technology Systems reported in 2026 that a ransomware attack discovered in Ohio in October 2025 exposed healthcare and identity data associated with 3,803,750 people.
8/12/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems disclosed a healthcare data breach affecting potentially 3,803,750 patients after unauthorized access occurred at its Montgomery, Ohio data center in October 2025.
8/9/2026 • Data Breaches & Exposure Events • General
Medical Computer Business Services reported in June 2026 that a September 2025 network intrusion potentially exposed healthcare information for 1,261,464 individuals.
7/30/2026 • Data Breaches & Exposure Events • General
Hawthorn Medical Associates notified potentially affected Massachusetts residents in July after a December 2025 server intrusion may have exposed extensive medical and financial information.
7/30/2026 • Data Breaches & Exposure Events • General
OpenLoop Health confirmed a breach affecting over 716,000 patients across 120 healthcare organizations after an unauthorized session exposed regulated patient records.
7/26/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood investigates a Unlimited Technology Systems, LLC data breach reported to the Vermont Attorney General involving unauthorized access to Vermont residents healthcare and identity data.
7/24/2026 • Data Breaches & Exposure Events • General
Centers Laboratory detected suspicious activity in August 2025 and notified 542,377 affected patients around July 20, 2026, prompting privacy litigation claims.
7/24/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems, LLC discovered unauthorized datacenter activity on October 19, 2025 and began patient notifications around July 20, 2026 after a potential data exposure.
7/20/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems disclosed a 2025 breach involving unauthorized access to patient files, with potential PII and PHI exposure and Iowa Attorney General notification submitted in 2026.
7/20/2026 • Data Breaches & Exposure Events • General
Fundamental Administrative Services reported a data security incident impacting 13,302 people, disclosed in a Texas Attorney General breach report on August 19, 2025.
7/18/2026 • Data Breaches & Exposure Events • General
J. Arthur Trudeau Memorial Center reported suspicious network activity on Jan. 29 that led to unauthorized access to PHI and PII between Jan. 22 and Jan. 28 in Rhode Island.
7/16/2026 • Data Breaches & Exposure Events • General
Firstsource notified individuals in response to a potential programming-error platform incident involving protected health information and standalone Social Security numbers.
7/16/2026 • Data Breaches & Exposure Events • General
J. Arthur Trudeau Memorial Center reported Jan. 22 to Jan. 28 data exfiltration after suspicious activity detection on Jan. 29, exposing PII and protected health information.
7/16/2026 • Data Breaches & Exposure Events • General
WP Company LLC disclosed a July 10, 2025 breach with Vermont and Texas notices filed in July 2026, exposing Social Security, government ID, financial, and health insurance data.
7/15/2026 • Data Breaches & Exposure Events • General
Centers Laboratory disclosed a 2025 breach affecting about 540,000 people in Cedar Knolls, New Jersey, after unauthorized access exposed health and identity records.
7/13/2026 • Data Breaches & Exposure Events • General
X-Copper Professional Corporation reported a June 8, 2026 hack involving compromised credentials and malware in Canada, potentially exposing customers personal data.
7/10/2026 • Data Breaches & Exposure Events • General
Medtronic disclosed an April 2026 corporate IT breach that exposed SSNs and health-related data, with notifications starting in late June 2026 after ShinyHunters extortion claims.
7/5/2026 • Data Breaches & Exposure Events • General
Medtronic disclosed a April 2026 patient-data incident involving unauthorized access to corporate IT systems, reporting impacts across Texas, Massachusetts, and Vermont.
7/1/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood investigates INTEGRIS Health after Cerner detected unauthorized third-party access to legacy electronic health record systems affecting Oklahoma patients.
6/29/2026 • Data Breaches & Exposure Events • General
Cybernews researchers reported a temporarily misconfigured Elasticsearch database publicly exposed 24 billion records with plaintext passwords and login URLs.
6/19/2026 • Data Breaches & Exposure Events • General
In 2024, healthcare breaches in the United States exposed over 289 million individuals, with Change Healthcare's cyberattack driving exposure for many Chicago-area providers.
6/8/2026 • Data Breaches & Exposure Events • General
Edelson Lechtzin LLP offered free consultations in connection with Excelas after Excelas disclosed a 2025-2026 data breach and Massachusetts notification in 2026.
5/18/2026 • Data Breaches & Exposure Events • General
OpenLoop Health disclosed in 2026 that hackers accessed systems between January 7 and 8 and exposed telehealth patient personal data of 716,000 people.
5/13/2026 • Data Breaches & Exposure Events • General
Conduent Business Services notified over 25 million Americans after ransomware operators accessed sensitive benefit and HR records from October 2024 to January 2025.
5/2/2026 • Data Breaches & Exposure Events • General
Security Boulevard reported this week that ten breaches and suspected incidents affected organizations across healthcare, finance, communications, retail, software, and data services worldwide.
8/21/2026 • Data Breaches & Exposure Events • General
Suno suffered a November 2025 cyberattack that exposed data for over 55.3 million people, including partial payment card numbers, without timely user notification.
7/21/2026 • Data Breaches & Exposure Events • General
Craneware notified the FBI and the UK Information Commissioner's Office after a contained network intrusion copied employee and customer partner data in the USA and UK.
7/20/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems LLC disclosed to the Iowa Attorney General on July 1, 2026 that unauthorized activity in an October 2025 datacenter may have exposed PII and limited PHI, and offered Kroll identity monitoring.
7/20/2026 • Data Breaches & Exposure Events • General
Firstsource disclosed a healthcare platform programming-error data breach affecting potentially exposed Social Security numbers, reported to Massachusetts on July 15, 2026.
7/15/2026 • Data Breaches & Exposure Events • General
Centers Laboratory notified US officials in connection with a late-discovered August 2025 breach affecting 542,377 people, after WorldLeaks posted leak and extortion claims.
7/13/2026 • Data Breaches & Exposure Events • General
Mount Royal University reported a June 17 cyberattack in Calgary involving stolen and deleted H drive data, with exposure uncertainty and response actions including notifications and credit monitoring.
7/8/2026 • Data Breaches & Exposure Events • General
Medtronic notified 3.8 million Indiana-area affected individuals after ShinyHunters accessed corporate IT in April 2026 and obtained personal and medical data.
7/4/2026 • Data Breaches & Exposure Events • General
Medtronic notified customers in 2026 after unauthorized access to corporate IT systems may have exposed Social Security numbers and health-related data, per ShinyHunters extortion claims.
7/2/2026 • Data Breaches & Exposure Events • General
Optalis Management Solutions disclosed unauthorized network access from April 2025, affecting financial and health data, and notified Massachusetts regulators in June 2026.
6/30/2026 • Data Breaches & Exposure Events • General
AgelessRx disclosed help-desk ticket access in April 2026 that exposed patient health and identity data, with consumer notifications starting June 23 and state reporting on June 24.
6/25/2026 • Data Breaches & Exposure Events • General
Colorado Health Network disclosed a data breach to regulators on June 22, 2026 after alleged Tor data posting by threat actor Cephalus on Aug. 28, 2025.
6/22/2026 • Data Breaches & Exposure Events • General
C2N Diagnostics LLC disclosed an April 27, 2026 breach notice after unauthorized access to employee email communications exposed patient PII and protected health information affecting about 2,027 people in the United States.
6/5/2026 • Data Breaches & Exposure Events • General
Excelas disclosed a May 12, 2026 data breach to Massachusetts and New Hampshire after 2025 unauthorized access may have exposed PII and protected health information.
5/15/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems notified potentially affected individuals in July 2026 after an October 2025 unauthorized file access incident involving health and identity data in Ohio.
8/7/2026 • Data Breaches & Exposure Events • General
Middletown, Ohio, notified residents on June 3 after a late-2025 breach exposed Social Security numbers and medical information, with TransUnion providing credit monitoring.
6/4/2026 • Data Breaches & Exposure Events • General
Monmouth University reported a data breach affecting approximately 299 Vermont residents after a notification to the Vermont Attorney General, with potentially exposed identity, financial, and health information.
8/25/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems disclosed a ransomware-related breach affecting approximately 3.8 million patients after hackers accessed its Ohio commercial data center between October 5 and October 10.
8/11/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems disclosed in October 2025 that unauthorized access at an Ohio data center exposed personal and health information affecting 3,803,750 people.
8/8/2026 • Data Breaches & Exposure Events • General
Paidwork suffered a March 29, 2026 data breach that reportedly exposed personal and financial information, with Mozilla Monitor documenting the incident on July 19, 2026.
8/8/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems notified patients on July 1, 2026, after an October 2025 breach potentially exposed personal information belonging to 3,803,750 people across U.S. healthcare providers.
8/7/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems reported in July 2026 that a 2025 network intrusion in Montgomery, Ohio, potentially exposed patient data belonging to 3,803,750 individuals.
8/7/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems notified 3.8 million people in the United States about a healthcare data theft discovered at its data center in October 2025.
8/7/2026 • Data Breaches & Exposure Events • General
Paidwork LLC allegedly exposed 23.3 million users' personal and financial data after an unauthorized actor leaked files in July 2026 from a March 2026 breach.
8/4/2026 • Data Breaches & Exposure Events • General
Edelson Lechtzin LLP began investigating potential claims in 2026 after alleged Paidwork platform data was publicly exposed and users faced possible identity theft risks.
8/4/2026 • Data Breaches & Exposure Events • General
Paidwork LLC suffered a data breach involving 23.3 million records after an unauthorized actor leaked exfiltrated files in California on July 18, 2026.
8/3/2026 • Data Breaches & Exposure Events • General
CareCloud disclosed in 2026 that unauthorized actors accessed an AWS-hosted electronic health record data store in the United States, potentially affecting 345,000 people.
8/2/2026 • Data Breaches & Exposure Events • General
CareCloud disclosed in California filings that hackers accessed an AWS-hosted data environment in March 2026, potentially exposing medical and financial information belonging to nearly 350,000 people.
8/2/2026 • Data Breaches & Exposure Events • General
CareCloud notified at least 345,000 people in the United States after unauthorized access to a New Jersey company electronic health record database exposed medical, identity, and financial information in March 2026.
8/1/2026 • Data Breaches & Exposure Events • General
CareCloud notified at least 350,000 people on June 24, 2026, after hackers accessed an AWS electronic health record environment in the CareCloud Health division between March 10 and March 16.
8/1/2026 • Data Breaches & Exposure Events • General
CareCloud reported in United States regulatory notifications that a March cyberattack accessed a cloud repository and may have exposed medical, identity, and financial records of at least 345,000 people.
7/31/2026 • Data Breaches & Exposure Events • General
Jeffrey David Reuben, MD notified Texas authorities of a data breach affecting approximately 14,172 Texas residents in Houston and potentially additional individuals nationwide.
7/29/2026 • Data Breaches & Exposure Events • General
Edelson Lechtzin LLP investigated potential class action claims tied to a January 28, 2026 Penobscot Valley Hospital network intrusion in Lincoln, Maine.
7/28/2026 • Data Breaches & Exposure Events • General
Bridgeway Benefit Technologies LLC investigated unauthorized access from March to May 2026 after a May 18 potential employee email compromise affecting personal information.
7/28/2026 • Data Breaches & Exposure Events • General
AcademyHealth reported a data breach to the Vermont Attorney General on July 27, 2026, involving Social Security and financial account information for at least one Vermont resident.
7/27/2026 • Data Breaches & Exposure Events • General
Centers Laboratory in New Jersey detected unauthorized access in August 2025 and reportedly began patient notification around July 20, 2026 after data exfiltration.
7/24/2026 • Data Breaches & Exposure Events • General
Ohio consumers can receive breach notifications and take protective actions after unauthorized access to personal information triggers notice requirements.
7/20/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood investigates an Averhealth Holdings data breach affecting about 858 Vermont residents after unauthorized access to protected health information was reported to the Vermont Attorney General.
7/15/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed a June 19, 2026 breach at Inter-Con Security Systems in Pasadena, California, alleging 2.7 million records stolen and delayed notification through July 13.
7/13/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed a June 2026 breach of Inter-Con Security Systems in Pasadena, California, allegedly exposing 2.7 million records with unconfirmed notification status.
7/13/2026 • Data Breaches & Exposure Events • General
Medtronic confirmed a breach discovered on April 15, 2026, after unauthorized access to corporate IT systems potentially exposed sensitive health and identity data.
7/12/2026 • Data Breaches & Exposure Events • General
Check Point Research reported 22 June 2026 privacy-relevant breaches affecting a Texas licensing vendor, iRhythm health data, and Salesforce-connected OAuth tokens.
6/22/2026 • Cybersecurity (Privacy-Relevant) • General
Kentucky Management Services Organization reported a CRS medical records vendor breach affecting about 500 Kentucky Bariatric Institute patients, with exposure limited to names, medical record numbers, and service dates.
6/13/2026 • Data Breaches & Exposure Events • General
On May 20, 2026, Kroll notified The Oncology Institute about vendor-detected unauthorized access tied to patient data after a November 2025 breach disclosure.
5/26/2026 • Data Breaches & Exposure Events • General
Patients and health care providers affected by a data breach at TriZetto Provider Solutions between November 2024 and October 2 2025 in the United States.
2/17/2026 • Data Breaches & Exposure Events • General
HHS OCR listings show nearly 57 million individuals affected by healthcare data breaches in 2025, with major vendor and ransomware incidents reported across the United States.
1/2/2026 • Data Breaches & Exposure Events • General
Healthcare providers in Virginia, Massachusetts, California, New York, and Ohio reported protected health information exposure from ransomware and unauthorized access incidents during 2023 to 2024.
1/15/2025 • Data Breaches & Exposure Events • General
Unlimited Technology Systems notified more than 3.8 million people in the United States after hackers stole personal and health information from company systems in October 2025.
8/7/2026 • Data Breaches & Exposure Events • General
Unlimited Technology Systems notified U.S. authorities and patients in July 2026 about a 2025 breach exposing sensitive information of 3,803,750 people.
8/7/2026 • Data Breaches & Exposure Events • General
CareCloud notified at least 350,000 people on June 24, 2026, after hackers accessed and likely exfiltrated sensitive information from an AWS environment supporting healthcare records.
7/31/2026 • Data Breaches & Exposure Events • General
CareCloud notified at least 350,000 people in June 2026 that hackers accessed a Massachusetts-reported AWS environment and likely stole personal, financial, and medical information.
7/31/2026 • Data Breaches & Exposure Events • General
CareCloud disclosed that hackers accessed health record storage in the United States from March 10 through March 16, affecting at least 345,000 people.
7/30/2026 • Data Breaches & Exposure Events • General
Maximus US Services Inc. disclosed in 2026 that a breach of Nebraska's Provider Data Management System may have exposed provider names, birth dates, and Social Security numbers.
7/30/2026 • Data Breaches & Exposure Events • General
Jeffrey David Reuben MD disclosed in July 2026 that a Bellaire, Texas, data breach exposed personal and health information belonging to 14,172 Texas residents.
7/29/2026 • Data Breaches & Exposure Events • General
From July 17-23, 2026, multiple organizations disclosed data breaches involving third-party access, privilege escalation, legacy systems, credential-stuffing, and exposed customer and employee data.
7/24/2026 • Data Breaches & Exposure Events • General
Oak Hill confirmed May 13, 2026 that an October 6, 2025 security incident involved unauthorized access to files containing PII and protected health information, with notifications mailed June 30, 2026 in Connecticut.
7/20/2026 • Data Breaches & Exposure Events • General
Yorozu Automotive Tennessee Inc. reported a Oct. 9, 2024 data breach affecting 20,627 U.S. individuals, including exposure of PII and protected health information, with notifications starting June 2, 2026.
7/2/2026 • Data Breaches & Exposure Events • General
Novo Nordisk, Kodak, Fortinet, Infinite Campus, and Texas government systems disclosed breaches that exposed sensitive personal data and credentials amid ransom demands.
6/19/2026 • Data Breaches & Exposure Events • General
SafePay claimed responsibility in a months-long ransomware intrusion against Conduent Business Services, allegedly exposing Tennessee residents medical and identity data and prompting class actions.
5/21/2026 • Data Breaches & Exposure Events • General
CareCloud reported that an unauthorized third party accessed a health-record AWS environment from March 10 to March 16, 2026, potentially affecting 3,756,469 people in the United States.
8/21/2026 • Data Breaches & Exposure Events • General
ColorTokens threat advisory reports ransomware and healthcare data exposures tied to stolen credentials, identity vulnerabilities, and third-party application access in the 2020s.
7/1/2026 • Data Breaches & Exposure Events • General
Paidwork users faced a reported data breach in which personal and financial data were exposed for more than 23 million users, with an impact-check process provided in the associated report.
7/22/2026 • Data Breaches & Exposure Events • General
David Ludlow of NCC Group discusses cybersecurity measures and patient steps after a data breach at a major Australian healthcare provider affects patient information.
7/20/2026 • Data Breaches & Exposure Events • General
Mount Royal University in Calgary reported a June 17, 2026 data breach after attackers copied shared-drive files, deleted originals, and CMD Organization posted sample data.
7/9/2026 • Data Breaches & Exposure Events • General
A roundup reports breach concealment pressure, a GitHub AI agent flaw enabling private repository leaks, and major U.S. consumer data exposure events in 2025.
7/9/2026 • Data Breaches & Exposure Events • General
Operation PAR, Boley Centers, and Eleos notified individuals in 2026 after discovering a June 2025 unauthorized network intrusion that may have involved patient and employee personal information.
7/2/2026 • Data Breaches & Exposure Events • General
In April 2026, Medtronic reported a breach exposing Social Security numbers and medical data, triggering identity theft concerns and legal investigation by Murphy Law Firm.
6/30/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood investigated the AgelessRx data breach reported to the Vermont Attorney General after potential health-record exposure for about five Vermont residents.
6/25/2026 • Data Breaches & Exposure Events • General
Stanley Pearlman Enterprises reported a February 2026 network intrusion that exposed names and driver license numbers, with June 2026 notifications to affected individuals in Nebraska.
6/25/2026 • Data Breaches & Exposure Events • General
Colorado Health Network, Inc. disclosed an unauthorized-access cybersecurity incident and began breach notifications on June 18, 2026, after exposure of patients medical and financial data.
6/19/2026 • Data Breaches & Exposure Events • General
ShinyHunters issued an extortion threat against One Medical in 2023, while One Medical confirmed a limited third-party storage access affecting archived Iora Health records.
6/18/2026 • Data Breaches & Exposure Events • General
UBEO Midco LLC disclosed a June 2025 unauthorized-access incident discovered May 13, 2026 in San Antonio, Texas, affecting 3,845 individuals with Social Security and medical data.
6/18/2026 • Data Breaches & Exposure Events • General
Open Arms Care Corporation notified potentially affected individuals starting June 9, 2026 after unauthorized access to its Tennessee email environment occurred between June and August 2025.
6/17/2026 • Data Breaches & Exposure Events • General
HHS OCR reported that 2026 healthcare breach reports have impacted more than 19 million individuals, with hacking/IT incidents the leading breach type as of June 9, 2026.
6/16/2026 • Data Breaches & Exposure Events • General
University of Nottingham and Novo Nordisk reported privacy-impacting breaches in mid-June as attackers exploited vulnerabilities including CVE-2026-35273 and CVE-2026-50751.
6/15/2026 • Data Breaches & Exposure Events • General
In Rhode Island, a community services center began June 2026 notices after a late-December 2025 incident left files potentially containing health and identity information.
6/8/2026 • Data Breaches & Exposure Events • General
MasTec, Inc. disclosed unauthorized third-party access to part of its network lasting several days in August 2025, with individual notifications starting May 2026.
6/8/2026 • Data Breaches & Exposure Events • General
ViaQuest disclosed in Ohio a network server hacking incident in which 6,420 patients and staff had PII and PHI exposed, with HIPAA risk and a 2026 lawsuit investigation.
6/4/2026 • Data Breaches & Exposure Events • General
RXNT reported unauthorized access to personal data between March 1 and March 3, 2026, and started customer notifications in May 2026 while offering credit monitoring services.
6/4/2026 • Data Breaches & Exposure Events • General
American Lending Center notified U.S. residents in multiple states after ransomware activity raised concerns about unauthorized access to personal information, with a review completed April 8, 2026.
5/12/2026 • Data Breaches & Exposure Events • General
Charlie Condon Law Firm, LLC disclosed unauthorized access between October 4 and October 6, 2025, potentially exposing data for about 2,975 people and notifying affected individuals starting May 8, 2026.
5/11/2026 • Data Breaches & Exposure Events • General
Medtronic confirmed a corporate IT breach in April 2026 after ShinyHunters claimed data compromise affecting nine million affiliated individuals, raising privacy and notification concerns.
5/7/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood is investigating a Precipio, Inc. data breach reported to affect 4,952 Texas residents after a Texas Attorney General notification on April 28, 2026.
4/28/2026 • Data Breaches & Exposure Events • General
IPPC Inc. reported a September 18 to 19 network intrusion that potentially exposed medical and Social Security data for up to 133,862 people across New Jersey and neighboring states.
4/17/2026 • Data Breaches & Exposure Events • General
Gaylord Specialty Healthcare and Gainwell Technologies report data breaches in December 2024 and July 2025 affecting patients in Connecticut and Medicaid recipients in Georgia due to unauthorized network access.
9/29/2025 • Data Breaches & Exposure Events • General
Craneware disclosed a 2026 cybersecurity incident potentially compromising customer and employee data in the United Kingdom, amid rising healthcare breaches targeting billing platforms.
7/28/2026 • Data Breaches & Exposure Events • General
Schubert Jonckheer & Kolbe LLP is investigating an alleged ShinyHunters breach of Inter-Con in Pasadena, California, affecting about 2.7 million records.
7/13/2026 • Data Breaches & Exposure Events • General
Cross Resource Group disclosed to Massachusetts officials on June 26, 2026 a May 19, 2026 employee data breach involving Social Security numbers and payroll data.
6/30/2026 • Data Breaches & Exposure Events • General
MCBS LLC reported a privacy incident involving unauthorized network access between Sept. 22 and Sept. 26, 2025, to the California Attorney General on June 26, 2026.
6/29/2026 • Data Breaches & Exposure Events • General
London Hydro investigated in London, Ontario a suspected breach that may have exposed customer personal and account data, while reporting no payment information impact.
6/20/2026 • Data Breaches & Exposure Events • General
One Medical Seniors disclosed a June 13, 2026 ransomware breach of a third-party file-storage archive, after unauthorized access lasting about three days.
6/20/2026 • Data Breaches & Exposure Events • General
Lifepoint Health disclosed a 2026 vendor-related data breach after compromised account access exposed U.S. vendor employees' personally identifiable information.
6/17/2026 • Data Breaches & Exposure Events • General
Liberty Solutions Inc. reported a PHI-related data breach affecting 7,329 U.S. individuals, with HHS filing details but no public specifics on exposed data types or attack dates.
6/11/2026 • Data Breaches & Exposure Events • General
DTG Consulting Solutions Inc. disclosed May 2026 breach notice to Massachusetts regulators and Vermont Attorney General and notified affected people May 29, 2026.
6/8/2026 • Data Breaches & Exposure Events • General
MasTec notified Maine and South Carolina authorities on June 5, 2026 about a breach affecting 25,220 US residents linked to an August 2025 network intrusion.
6/8/2026 • Data Breaches & Exposure Events • General
CenterWell disclosed a U.S. data breach in notifications to Massachusetts and Texas attorneys general and HHS, affecting 9,651 people including 4,618 Texans.
6/8/2026 • Data Breaches & Exposure Events • General
ViaQuest Psychiatric & Behavioral Solutions disclosed to HHS on May 8, 2026 a data breach affecting at least 6,420 people with exposure of PII and protected health information.
6/2/2026 • Data Breaches & Exposure Events • General
University of Dallas disclosed a data breach on undisclosed date affecting Texas and Vermont residents, potentially exposing sensitive identity, financial, and health information.
5/29/2026 • Data Breaches & Exposure Events • General
Nursa disclosed unauthorized access to clinician profiles on its Murray, Utah platform, exposing names and full dates of birth for 13,168 Washington residents.
5/29/2026 • Data Breaches & Exposure Events • General
Aimbridge Hospitality disclosed a hotel systems data breach to Maine and Vermont authorities after unauthorized access may have occurred in November 2025.
5/27/2026 • Data Breaches & Exposure Events • General
United Medical Systems disclosed a data breach impacting 485 people, including Massachusetts and Maine residents, with notifications beginning May 20, 2026.
5/27/2026 • Data Breaches & Exposure Events • General
Interstate Management Company, LLC disclosed unauthorized hotel-system access from Nov. 19 to Nov. 22, 2025, potentially affecting 22,743 U.S. people, with notices sent May 26, 2026.
5/27/2026 • Data Breaches & Exposure Events • General
Pivot Health disclosed a March 2026 AWS data breach affecting 1,172 people in Texas and 27 in Nebraska after unauthorized access between Feb. 26 and March 13.
5/15/2026 • Data Breaches & Exposure Events • General
American Lending Center reported that a July 2025 ransomware attack exposed names, birthdates, and Social Security information for 123,158 people, with notifications sent April 28, 2026.
5/12/2026 • Data Breaches & Exposure Events • General
Healthcare In Action reported a January 2026 credential compromise that exposed PII and protected health information for 1,143 people, with breach notification to HHS in March 2026.
5/11/2026 • Data Breaches & Exposure Events • General
LexisNexis disclosed a data breach affecting over 364,000 consumers after an unknown hacker obtained sensitive personal data via a third-party software development platform.
5/28/2025 • Data Breaches & Exposure Events • General
CareCloud disclosed in 2026 that unauthorized access to an Amazon Web Services environment affected 3,756,469 people through potentially exposed medical, identity, and financial information.
8/21/2026 • Data Breaches & Exposure Events • General
CareCloud disclosed on March 27 that unauthorized access to an AWS environment supporting electronic health records exposed information affecting 3,756,469 individuals.
8/20/2026 • Data Breaches & Exposure Events • General
CareCloud disclosed in March 2026 that hackers stole personal information and medical records affecting more than 3.75 million people in the United States.
8/20/2026 • Data Breaches & Exposure Events • General
CareCloud reported in June that a March unauthorized intrusion into an AWS environment exposed health and financial information affecting about 3.8 million people in the United States.
8/19/2026 • Data Breaches & Exposure Events • General
CareCloud reported in 2020s that an unauthorized third party accessed a healthcare AWS environment, potentially exposing 3,756,469 patients' personal information.
8/19/2026 • Data Breaches & Exposure Events • General
CareCloud notified nearly 3.8 million people in the United States after unauthorized access to an AWS environment potentially exposed health, identity, and financial records in March 2026.
8/19/2026 • Data Breaches & Exposure Events • General
On July 25, 2026, CareCloud began notifying individuals across the United States that unauthorized access to an AWS environment in March affected 3,756,469 people.
8/19/2026 • Data Breaches & Exposure Events • General
CareCloud disclosed in federal filings that a hacker accessed its AWS and electronic health record environments in March, exposing sensitive information belonging to 3,756,469 people.
8/19/2026 • Data Breaches & Exposure Events • General
CareCloud reported that attackers accessed an AWS environment in mid-March, exposing sensitive healthcare and identity data belonging to 3,756,469 individuals.
8/19/2026 • Data Breaches & Exposure Events • General
CareCloud confirmed in a Monday HHS filing that hackers stole medical, identity, and financial data from more than 3.75 million people in a March cloud breach.
8/19/2026 • Data Breaches & Exposure Events • General
Conduent disclosed in 2026 that a breach dating back to late 2024 exposed personal and medical data of more than 25 million individuals across Texas and Oregon.
2/23/2026 • Data Breaches & Exposure Events • General
Monmouth University notified individuals starting June 30, 2026, after a forensic review found unauthorized access to PII beginning around February 5, 2026.
7/7/2026 • Data Breaches & Exposure Events • General
Malwarebytes reported in February 2026 expanded scope of an October 2025 Conduent data breach affecting an estimated 25 million people in the United States.
7/12/2026 • Data Breaches & Exposure Events • General
Medtronic notified potentially affected people more than two months after disclosure of an unauthorized cyberattack disclosed earlier, offering credit and dark-web monitoring while reporting no evidence of public internet exposure.
7/2/2026 • Data Breaches & Exposure Events • General
Signature Healthcare disclosed a nationwide data breach to the U.S. Department of Health and Human Services on June 5, 2026, while exposed data types remained undisclosed as of June 30, 2026.
7/9/2026 • Data Breaches & Exposure Events • General
Capital One, NPD, Jerico Pictures, MGM Resorts, and Moody's illustrate that data breach harm can last years through litigation, contracting losses, credit impacts, and sustained regulatory oversight.
4/27/2026 • Cybersecurity (Privacy-Relevant) • General