Last Update: 08/01/2026 at 1:00 PM EST

Healthcare Data Breach Wave

Coverage from SecurityWeek, TechCrunch, and others

Articles

138

Active Days

568

The Topic

Healthcare Data Breach Wave topic image

Healthcare organizations continue to disclose breaches that expose patient identifiers, medical records, and sometimes financial data, with ransomware, email compromise, and vendor incidents recurring across hospitals, specialty practices, and medical service providers. Notification letters, credit monitoring, and HIPAA reporting remain the standard response, while some cases involve delayed discovery, litigation, or unclear root cause.

First Article: 01/07/25

Latest Article: 07/28/26

Summary

  • Healthcare breaches remain the dominant pattern, with hospitals, clinics, and medical service providers repeatedly disclosing unauthorized access to patient data.
  • Ransomware and intrusion-linked incidents are common, but several cases also involve third-party vendors or compromised email systems rather than direct attacks on core medical records.
  • Exposed data frequently includes names, Social Security numbers, dates of birth, driver license numbers, health insurance details, and clinical information, creating both identity theft and medical privacy risk.
  • Notification timelines often lag the incident by months, and some disclosures involve delayed discovery or extended review before patient notice is sent.
  • Credit monitoring, identity theft protection, and credit freeze guidance have become routine remediation steps after these breaches.
  • HIPAA reporting and state attorney general filings are recurring regulatory touchpoints, while some incidents also lead to class action litigation.
  • A smaller set of current coverage adds system-level context, suggesting breach volume remains high even as faster detection and segmentation may reduce the number of affected individuals in some periods.

History

07/26/2026

The story has broadened from a few notable healthcare intrusions into a wider pattern of repeated breaches across hospitals, medical groups, and outside vendors, with more emphasis on notification delays and formal compliance reporting. The new version also shifts the focus toward the recurring remediation playbook and the persistence of high breach volume.

07/23/2026

The story broadens to include additional healthcare entities and shifts from isolated breach reports to a wider pattern of compromised accounts, data exfiltration, and extortion activity across healthcare vendors and providers. The updated version also adds more explicit emphasis on vendor-held data concentration and response measures while scope remains unresolved.

Full History

Featured

Timeline: 568 Days

2025Jan 1Mar 5May 28Jul 30Oct 22Dec 242026Jan 1Mar 5May 28Jul 30Oct 22Dec 24

Additional Articles

⭐⭐⭐⭐⭐

TechCrunch / Zack Whittaker07-20-2026
Craneware disclosed an ongoing response to a cyberattack after hackers exfiltrated customer, employee, and partner data, with the investigation continuing in the United Kingdom.
BleepingComputer / Bill Toulas07-28-2026
Medical Computer Business Services reported a PEAR-attributed 2025 network breach impacting 1,261,464 people in Georgia, including exposure of health and identity data.
The Record / Suzanne Smalley07-06-2026
Medtronic notified more than 3.8 million patients after unauthorized access to corporate IT systems, and California released the breach notification letter on June 29.
Yahoo / Zack Whittaker07-20-2026
Craneware disclosed an ongoing cyberattack and data exfiltration incident in the United Kingdom, impacting U.S. healthcare billing customers as investigation continues.
Yahoo / Rebecca Pifer Parduhn07-20-2026
Clover Health disclosed a July 4 employee-account compromise in USA operations, potentially exposing member PII and protected health information while the company investigates scope.
BankInfoSecurity / Pooja Tikekar07-09-2026
Breach and vulnerability updates reported disclosure noncompliance, GitHub agentic exposure via prompt injection, and multiple major personal-data incidents affecting millions in the United States and United Kingdom.
Claim Depot07-28-2026
AcademyHealth disclosed a ransomware-related data breach to the Vermont Attorney General on July 27, 2026 after a SafePay dark web claim in April 2026.
Claim Depot04-17-2026
Texas received a breach filing on April 17, 2026, after ransomware group Payouts King claimed 435 GB of Eyemart Express data including PII and protected health information.
Claim Depot05-05-2026
Western Orthopaedics disclosed a 2025 ransomware data breach affecting Texas and Massachusetts patients after PEAR claimed data access on the dark web.
Claim Depot05-18-2026
NYC Health + Hospitals disclosed a data breach reported to U.S. HHS on March 24, 2026, affecting about 1.8 million people in New York City.
Claim Depot07-01-2026
NLACRC detected suspected ransomware on Nov. 28, 2024 and later reported a Nov. 20-Dec. 1 data breach exposing PII and PHI to multiple state attorneys general.
Claim Depot07-15-2026
Averhealth Holdings notified Vermont and Massachusetts residents after unauthorized access to Averest Inc email systems exposed Social Security numbers and health information in 2025-2026.
Claim Depot07-20-2026
Heart Care Centers of Illinois reported a phishing-enabled employee email breach with exposure of sensitive PII and health information discovered in 2026.
Becker's Payer / Elizabeth Casolo07-20-2026
Clover Health disclosed in a July 17 SEC filing that abnormal logins on July 4 led to social-engineering access of three employee health plan accounts.
Cloud Link Tech07-21-2026
Clover Health disclosed a July 4 social-engineering incident in a U.S. SEC filing after three employee accounts were compromised and PII and protected health information exposure occurred.
OODA Loop07-06-2026
Medtronic notified more than 3.8 million people after ShinyHunters accessed corporate IT systems in April 2026 and stole personal and medical information.
Health Exec / Chad Van Alstin07-13-2026
Greenbaum Rowe Smith & Davis reported a healthcare data breach in New Jersey after compromised credentials exposed patient records in November 2025.
Security Today04-28-2026
Bridewell and US HHS data show over 2,200 US medical center breaches since 2023, with fewer affected individuals in 2025 amid HIPAA segmentation and faster detection.
KVIA / Gabrielle Lopez07-24-2026
Eyemart Express reported an unauthorized access incident in February, with Feb. 12 exposure that may include Social Security numbers and health-plan data for some customers in the United States.
Rescana05-26-2026
Radiology Associates of Richmond disclosed a 266,000-person breach after unauthorized acquisition of PHI and financial data around July 25, 2025, with notifications beginning May 21, 2026.
Healthcare Dive / Rebecca Pifer Parduhn07-20-2026
Clover Health disclosed a July 4 breach after unauthorized access to three employee accounts exposed potential personal and protected health information, pending scope investigation.
Becker's Behavioral Health / Ella Ruder07-23-2026
NAS Recovery Solutions in Lakewood, Colorado discovered May 13, 2026 that unauthorized workforce downloads exposed limited client identifiers, potentially revealing substance use disorder treatment under HIPAA.
Becker's Behavioral Health / Ella Ruder07-24-2026
Behavioral health providers in Colorado, Nebraska, Arizona, and Texas disclosed four data breaches involving unauthorized access and email compromises affecting patients and employees.
The Lyon Firm07-21-2026
Heart Care Centers of Illinois notified affected Chicago-area individuals in July 2026 after unauthorized access to an employee email account from Aug 2024 to Nov 2024.
DistilINFO07-09-2026
AdaptHealth disclosed on July 2 that social engineering enabled contractor-session compromise, leading to exfiltration of patient and insurance billing data from cloud systems.
QPulse07-05-2026
Medtronic reported a ShinyHunters extortion attack discovered April 15, 2026, exposing personal and medical information for 3.8 million individuals.
CyberInsider07-13-2026
Centers Lab NJ disclosed a HIPAA breach affecting 542,377 people after unauthorized system access between August 9 and 14, 2025.
Mallory07-05-2026
Medtronic disclosed an April 2026 unauthorized access incident attributed to ShinyHunters that exposed personal and health information for 3.8 million people.
Security Affairs / Pierluigi Paganini07-05-2026
Medtronic notified 3,834,294 individuals in 2026 after ShinyHunters claimed unauthorized access to corporate IT systems and possible exposure of medical and identity data.
Paubox / Abby Grifno06-10-2026
La Perouse notified the California Attorney General in 2025 of unauthorized access at a third-party billing platform affecting at least seven healthcare providers.
DigitalShield07-18-2026
TrendAI analysis reports ransomware at 36.3% of healthcare-linked underground marketplace activity, using double extortion to steal and sell medical records.
Almeida Law Group04-15-2026
In April 2026, Exitium ransomware claims targeted Gastroenterology & Hepatology of CNY in Syracuse, potentially exposing HIPAA medical records for over 167,000 patients.
Fierce Healthcare / Paige Minemyer07-20-2026
Clover Health disclosed in an SEC filing on July 17 that social engineering enabled unauthorized access to three health plan employee accounts discovered on July 4.
Class Action U07-20-2026
Clover Health reported a July 4, 2026 unauthorized access incident after anomalous employee logins, with social engineering used to reach accounts handling member scheduling and sales data in the USA.
Class Action U07-27-2026
Lifespark Management Services detected suspicious email access in February 2026 and notified individuals in July 2026 of potential exposure of personal and health data.
Schubert Jonckheer & Kolbe / Celina Reynes06-24-2026
On June 13, 2026, One Medical reported a June 8-11 vendor file-storage breach affecting archived former Iora Health Seniors patient data in multiple U.S. cities.
GS Legal07-13-2026
AdaptHealth reported a July 2, 2026 Form 8-K describing a June 15, 2026 threat actor claim and confirmed exfiltration of billing password data and possible PII/PHI from external EHR portals.
Healthcare IT News / Andrea Fox06-24-2026
One Medical Seniors reported unauthorized access to third-party file storage of archived Iora Health patient files discovered June 13, with ShinyHunters extortion claims unverified.
CBS News Texas07-25-2026
Eyemart Express disclosed February 13 that unauthorized access the previous day may have exposed customers' sensitive personal data, including Social Security numbers.
The HIPAA Journal / Steve Alder09-12-2025
In 2025, hospitals report email and vendor driven data breaches exposing protected health information across California, Louisiana, Connecticut, South Dakota, and Tennessee.
The HIPAA Journal / Steve Alder11-03-2025
Two healthcare providers disclosed data breaches in 2025, exposing patient identifiers and health information, prompting breach notifications and identity protection measures.
Security Boulevard07-28-2026
HHS OCR reports 772 large healthcare breaches in 2025 under HITECH rules, while affected individuals fell versus 2024 due to Change Healthcare outlier impact.
Packet3307-28-2026
HHS OCR breach-portal data under the HITECH Act reports 772 large US healthcare breaches in 2025, with hacking and mega-incidents shaping totals.
Compliancy Group / Miranda Satterly07-16-2026
HHS OCR reported 772 large healthcare data breaches in 2025, exposing about 138.5 million records while OCR increased HIPAA Security Rule risk-analysis enforcement.
Paubox / Mara Ellis07-10-2026
Sentara Hospitals in Virginia disclosed a reportable HIPAA violation after misrouted billing mail exposed protected health information without hacking, highlighting persistent physical-mail risk.
Almeida Law Group / Luke Coughlin06-19-2026
INC Ransom claimed mid-June 2026 ransomware access to Horizon Family Medical Group in Orange County, New York, with alleged protected health and financial data exposure.
Class Action U07-24-2026
In the US, healthcare data breaches expose identifiable medical information and are governed by HIPAA and the FTC Health Breach Notification Rule, shaping notice, mitigation, and legal recourse.
Hipaacomplianthosting / Joseph Abear07-05-2026
HHS Office for Civil Rights statistics show 2024 healthcare breaches exposed about 289 million people, largely due to a Change Healthcare ransomware attack.
PrivacyOn / Sarah Chen05-27-2026
In February 2024, ALPHV/BlackCat ransomware disrupted Change Healthcare systems and exposed Social Security numbers and medical records for about 192.7 million people in the United States.
Cory Watson Attorneys / Patrick Nolen07-25-2026
Whitfield Regional Hospital detected unauthorized network access in 2025, later traced it to May 15, 2025, and issued patient notifications in July 2026.
The Lyon Firm / Joseph Lyon05-01-2026
Medtronic disclosed on April 24, 2026 an IT breach tied to ShinyHunters claims of stolen PII and internal data, with investigation and potential notifications under HIPAA and state breach laws.

⭐⭐⭐

BleepingComputer / Bill Toulas07-02-2026
Medtronic notified customers in 2026 after investigation found unauthorized access to corporate IT systems during April 13 to April 19, following ShinyHunters extortion claims.
BleepingComputer / Bill Toulas07-27-2026
Coca-Cola disclosed on July 16 that ransomware disrupted Fairlife production and enabled data theft, followed by an Anubis extortion leak after July 27.
Morningstar05-06-2026
Schubert Jonckheer & Kolbe LLP is investigating a Medtronic data breach after ShinyHunters claimed unauthorized access and Medtronic confirmed the incident in April 2026.
Morningstar05-23-2026
Radiology Associates of Richmond notified 266,000 patients after unauthorized access on or around July 25, 2025, exposing health and personal information.
WTAW / Jeanette Muenchow07-26-2026
Eyemart Express, LLC reported unauthorized access on February 12, 2026, and notified customers in the United States, including Social Security number exposure.
Top Class Actions06-03-2026
Radiology Associates of Richmond notified the Office of the Maine Attorney General on May 21 about unauthorized access to records of 266,183 patients.
ClassAction.org06-18-2026
Blue Fish Pediatrics notified 41,485 Texas residents after a July 2025 computer system breach potentially exposed Social Security numbers and health records, with mailed notices starting June 17, 2026.
Dark Reading / Robert Lemos07-10-2026
Ransomware attacks and vendor breaches against healthcare providers in the USA and Germany increased in early 2026, leading to large-scale patient data theft and prolonged operational disruptions.
Claim Depot04-16-2026
Longevity Health Plan reported a data breach affecting about 15,000 U.S. Medicare plan members after disclosure to HHS on March 4, 2026.
Claim Depot04-18-2026
Aligned Orthopedic Partners reported an email system intrusion between Nov. 16 and Dec. 16, 2025, potentially exposing PII and protected health information.
Claim Depot04-29-2026
Sandhills Medical Foundation disclosed on April 28, 2026 a ransomware breach that affected 169,017 patients after unauthorized access to company servers and potential exposure of personal health information.
Claim Depot04-29-2026
Greater Boston Urology reported a protected health information breach affecting 4,717 people to the U.S. Department of Health and Human Services on Feb. 28, 2026.
Claim Depot05-04-2026
Hematology Oncology Consultants reported a ransomware data breach targeting its Michigan network in 2025, exposing medical records and Social Security numbers, with notifications in 2026.
Claim Depot05-12-2026
Belmont Aesthetic & Reconstructive Plastic Surgery disclosed a U.S. health-data breach impacting 528 individuals after an Insomnia ransomware dark-web claim on March 3, 2026.
Claim Depot05-13-2026
FMRS Health Systems disclosed in 2026 an intrusion from January to February that potentially exposed PII and PHI, after Qilin claimed responsibility.
Claim Depot05-18-2026
Lumio Dental disclosed a ransomware-linked breach to HHS on March 29, 2026, involving passport, driver license, and medical record extracts.
Claim Depot05-18-2026
Vacation Myrtle Beach disclosed a ransomware-linked breach on June 16-19, 2025, potentially exposing Social Security numbers, financial data, and possible health records for about 10,750 people.
Claim Depot05-19-2026
Medi-Rents & Sales Inc. disclosed an email data breach in early 2026 affecting 1,524 U.S. individuals, with potentially exposed insurance and limited health information.
Claim Depot06-08-2026
NJ Pain Care Specialists LLC reported to U.S. HHS on May 14, 2026 after unauthorized access between Feb 25 and Feb 28, 2025 potentially exposed PII and protected health information.
Claim Depot07-07-2026
Heart of America Eye Care disclosed a likely unauthorized network access event in Kansas City during April 2026, with HHS notification on June 5, 2026 after a CMD Organization dark web claim.
Claim Depot07-08-2026
Mid-South Pulmonary & Sleep Specialists P.C. investigated ransomware-linked unauthorized network access in Memphis after Nov. 2, 2025 detection, later notifying patients in June 2026.
Claim Depot07-08-2026
United HealthCare Services disclosed a health data breach affecting 34,574 U.S. individuals to HHS on June 5, 2026.
Claim Depot07-08-2026
Erick K. Perroud, DDS disclosed a data breach affecting 7,692 individuals in the United States to the U.S. Department of Health and Human Services on June 10, 2026.
Claim Depot07-13-2026
PennyMac unit Private National Mortgage Acceptance Company LLC disclosed a Group Health Plan breach affecting 3,972 U.S. individuals after HHS notification on June 9, 2026.
Claim Depot07-15-2026
Easypak reported a ransomware-related data breach discovered in January 2026, with possible exposure of sensitive personal data for at least 217 Massachusetts residents.
Claim Depot07-15-2026
Entyre Care Massachusetts Inc. disclosed a March 2026 data breach involving publicly accessible files containing Medicaid IDs and medical records, discovered on May 12, 2026.
Claim Depot07-16-2026
Hudson Valley Medical Billing & Credentialing LLC reported possible unauthorized access in 2026, with Massachusetts notification and credit monitoring support beginning July 2026.
Claim Depot07-17-2026
Madera Community Hospital reported an undisclosed-data network breach to the California Attorney General on July 14, 2026, after unauthorized third-party access in May 2025.
Claim Depot07-24-2026
Clover Health disclosed a healthcare data breach to the SEC on July 4, 2026, with PII and PHI exposure in the United States.
Claim Depot07-26-2026
Lifespark Management Services Inc. disclosed a 2026 email-environment data breach in St. Louis Park, Minnesota, after suspicious activity led to possible unauthorized access to PII and protected health information.
PR Newswire / Wolf Haldenstein07-24-2026
Wolf Haldenstein Adler Freeman & Herz LLP began investigating a Heart Care Centers of Illinois data breach in Palos Park, Illinois, after breach notifications.
Becker’s Dental Review05-19-2026
Shamis & Gentile investigated a ransomware-linked breach at Tampa Bay Dental Implants & Periodontics in St. Petersburg, Florida, affecting 6,400 people via backed electronic medical records.
Cafferty Clobes Meriwether & Sprengel LLP07-12-2026
Clinical Registry disclosed a data breach affecting 8,545 patients at Dignity Health’s St. Mary’s Medical Center, including medical record identifiers.
Lubbock Avalanche-Journal / Alana Edgin07-24-2026
Eyemart Express disclosed a February 2026 unauthorized-access cybersecurity event involving customer personal data and customer notification on July 24, 2026, from Texas.
DailyHodl / Rhodilee Jean Dolor05-06-2026
Sandhills Medical Foundation discovered a May 2, 2025 ransomware incident on May 8, 2025, potentially exposing personal and medical data of 169,017 patients.
Data Breach Rights07-15-2026
Casper Orthopedics disclosed a ransomware-linked data breach in the US after Anubis claimed responsibility for unauthorized exposure of patient medical records.
Data Breach Rights07-25-2026
RXNT filed a Washington State Attorney General breach notification after possible unauthorized access to healthcare cloud systems holding personal and health-related data.
Cybersecurity Dive07-20-2026
Craneware reported a cyberattack and stolen files from its data environment in the UK, with employee and selected customer and partner records exposed and investigation ongoing.
COE Security07-27-2026
Medical Cost Benefit Services (MCBS) disclosed a data breach affecting about 1.2 million individuals, raising concerns about healthcare cybersecurity across integrated third-party ecosystems.
Paubox / Abby Grifno05-27-2026
Radiology Associates of Richmond reported a healthcare data breach beginning around July 25, 2025, with PHI access discovered and investigated through April 6, 2026.
DataBreachToday07-20-2026
Craneware and Abbott investigated healthcare cyber incidents after alleged exfiltration through vendor systems and Abbott LabCentral portal access claims.
Becker's Dental Review05-18-2026
Lumio Dental reported an HHS Breach Portal submission on March 29 for a ransomware-linked breach affecting 500 people in Jenks, Oklahoma.
Technadu / Lore Apostol07-22-2026
Anubis claimed credit in a Fairlife ransomware incident on the dark web while Coca-Cola reported unauthorized third-party access to production-related systems on July 16.
Hoodline / Cat Ansar06-14-2026
Open Arms Care Corporation notified clients in Tennessee starting June 9, 2026 after an internal review found unauthorized access to certain email accounts in 2025.
KBZK News07-07-2026
Lumexa notified Butte, Montana residents in June about a medical records breach that occurred March 31 to April 9 and affected at least 3,000 people.
Almeida Law Group06-09-2026
Almeida Law Group investigates a June 8, 2026 alleged ransomware breach at Central Arkansas Pediatrics in Conway, Arkansas, while affected data scope remains unconfirmed.
DeXpose07-13-2026
Ransomware group Anubis claimed an attack on Casper Orthopedics in Wyoming on July 12, 2026, involving exposed patients data and medical records.
Class Action U / Class Action U05-11-2026
Alta Orthopaedics reported a March 2026 discovery of unauthorized access to patient data affecting systems during February 3-6, 2026, with remediation and credit monitoring offered.
Class Action U06-18-2026
Blue Fish Pediatrics in Houston, Texas disclosed a 2025 unauthorized access incident, later confirming exposed patient medical data and some Social Security numbers, with notifications starting June 17, 2026.
Strauss Borrelli PLLC06-09-2025
Select Medical began June 6, 2025 notifications after a July 2024 unauthorized third-party access to patient systems potentially exposed personal identifiers and protected health information.
Schubert Jonckheer & Kolbe / Nelida Almeida05-20-2026
Lumexa Imaging reported a vendor network incident on April 9, 2026, with unauthorized access between March 31 and April 9 potentially exposing patient records.
Schubert Jonckheer & Kolbe / Nelida Almeida05-22-2026
Radiology Associates of Richmond faced an alleged 2025 systems intrusion exposing patient PII and protected health information, with notifications mailed starting May 21, 2026, in Richmond, Virginia.
Emery Reddy06-22-2026
Xsolis disclosed a targeted phishing incident around January 22, 2026, involving potential unauthorized access to personal and protected health information, and offered identity monitoring via Kroll.
GS Legal07-24-2026
Unlimited Technology Systems LLC identified suspicious activity on October 19, 2025, after an unauthorized party potentially accessed patient PII and PHI in Montgomery, Ohio.
Federman & Sherwood / Caroline Chesher07-24-2026
Federman & Sherwood is investigating NAS Recovery Solutions after a reported patient-data breach involving electronic medical records and network systems affected about 7,000 people in the USA.
BeyondMachines05-03-2026
Integrated Pain Associates reported a 2026 data breach in Killeen, Texas, exposing patient Social Security numbers and medical records and offering 12 months of credit monitoring.
Xinhua06-09-2026
Hokkaido's National Hospital Organization reported a hard-drive leak to police after a waste disposal vendor improperly destroyed drives containing hospital medical records.
PR Newswire04-15-2026
Vital Imaging Diagnostic Centers reported a 2025 network intrusion in Miami involving unauthorized file removal that may have exposed medical and government identification data and issued notifications in 2026.
PR Newswire / Wolf Haldenstein07-20-2026
Heart Care Centers of Illinois notified individuals after a potential data breach on when and where Palos Park, Illinois exposed identity, payment, and medical information.
Cision PR Newswire05-06-2026
On April 24, 2026, Medtronic confirmed a corporate IT breach after ShinyHunters claimed terabytes of internal data exposure.
JD Supra03-26-2025
OCH Regional Medical Center filed an HHS Office for Civil Rights breach notice on March 11, 2025 and began notifying affected individuals after unauthorized access to sensitive consumer information.
The HIPAA Journal / Steve Alder08-20-2025
Health data breaches at CPAP Medical Services, Health Services LLC, and East Adams Rural Healthcare affect patients in Florida, Maine, and Washington during 2024 and 2025.
The HIPAA Journal / Steve Alder04-28-2025
Frederick Health Medical Group confirmed a ransomware breach affecting 934,326 patients in Maryland in 2025, triggering class action lawsuits alleging cybersecurity and breach-notice failures.
The HIPAA Journal / Steve Alder04-16-2025
Healthcare providers in the United States reported 2024 to 2025 data breaches, with investigations finding unauthorized access to patient identifiers and medical information.
Cbsnews05-28-2025
UChicago Medicine disclosed a July 2024 third-party vendor cybersecurity incident through Nationwide Recovery Services that may have exposed personal data of nearly 40,000 patients.
Top Class Actions09-19-2025
Altos disclosed on June 17 that an unauthorized party accessed an internet exposed internal system containing personal and health data of patients in Southern California.
Claim Depot09-18-2025
Goshen Medical Center in Fayetteville disclosed a ransomware driven data breach affecting 456385 patients on March 4 2025
Health Exec / Chad Van Alstin09-29-2025
Hackers breached Healthcare Interactive between July 8 and July 12, 2025, exposing customer personal and health data in the United States.
NetWitness Platform / John Bosco04-15-2026
Healthcare breaches involving unsecured PHI trigger HIPAA notification duties to individuals and HHS, with ransomware, phishing, and cloud misconfiguration cited as common causes.
MedCity News07-13-2026
Novo Nordisk is linked to a reported cyberattack targeting clinical trial and AI research data, while 2025 healthcare breach reporting indicates large-scale credential-driven exposures.
Gs Legal04-10-2026
IPPC reported an unauthorized network access in September 2025 that potentially exposed PHI and PII for over 133,000 customers across six states.
Healthcare Finance News / Jeff Lagasse01-07-2025
Richmond University Medical Center reported a healthcare data breach in New York involving accessed or removed files around May 6, 2023, with potential exposure of protected health information for 674,000 people.
Class Action U04-14-2026
Springfield Hospital notified individuals starting February 10, 2026, after a December 17, 2025 employee email account compromise potentially exposed personal and health information.
Class Action U07-02-2026
Ransomware intelligence on July 2, 2026 alleged an unverified INCRansom attack on Colorado Rehabilitation & Occupational Medicine, with patient data exposure unconfirmed.
Emery Reddy04-10-2026
DermCare Management notified affected individuals in March 2026 after a February 2025 unauthorized access event potentially impacted patient information.
Emery Reddy07-07-2026
Spokane Digestive Disease Center disclosed May 2026 findings of unauthorized employee email access that exposed patient data, with notifications beginning May 26.
Cory Watson Attorneys / Patrick Nolen06-11-2026
McLeod Health detected unauthorized access to a Dillon Family Medicine server months after Oct 2025 intrusions, with Qilin ransomware blamed and HIPAA timing issues discussed.
Almeida Law Group05-14-2026
Qilin claimed a mid-May 2026 ransomware attack on Spirit Medical Transport, potentially exposing protected health information for patients in Western Ohio and Eastern Indiana.
Emery Reddy / Sarah Onstott05-22-2026
Sterling Seacrest Pritchard notified people about possible unauthorized access to email-environment data between August 12 and 13, 2025, with notifications through April 2026.
GS Legal04-15-2026
DermCare Management found suspicious activity on February 26, 2025 and reported an intrusion between February 14 and February 26 that may have exposed patient PII and PHI.

⭐️⭐️

SecurityWeek / Eduard Kovacs08-22-2025
Hackers accessed CPAP Medical Supplies and Services systems in December 2024, exposing personal and health information for more than 90,000 individuals in the United States.
Top Class Actions10-03-2025
Medical Associates of Brevard in Melbourne, Florida, disclosed a January 2025 data breach affecting about 246,711 individuals.
ClassAction.org08-28-2025
February 13 2025 breach at Vital Imaging affected 260000 patients in Florida, with investigators probing medical and demographic data exposure.
Claim Depot03-13-2026
Delta Medical Systems detected a data breach on July 15 2025 in Wisconsin and notified affected individuals by February 11 2026.