Last Update: 08/01/2026 at 1:00 PM EST

Sensitive Data Breaches Hit Service Providers

Coverage from Reuters, BleepingComputer, and others

Articles

97

Active Days

705

The Topic

Sensitive Data Breaches Hit Service Providers topic image

Organizations that hold sensitive legal, medical, and diagnostic information are investigating breaches involving compromised credentials, impersonation, third-party storage, and exposed portals. The incidents affect diverse data types, including Social Security numbers, clinical records, financial details, and technical documentation, while several organizations dispute or have not confirmed attackers’ claims about the volume and sensitivity of stolen data. The events also show continuing legal and notification consequences when organizations disclose breaches after delays or when attackers allege access through external systems.

First Article: 08/21/24

Latest Article: 07/26/26

Summary

  • Blank Rome faces proposed class actions after a breach allegedly exposed data belonging to more than 57,000 current, former, and prospective clients.
  • Healthcare incidents include exposures involving One Medical patient records and Southern Illinois Dermatology data, with reported medical identifiers and clinical information at risk.
  • Abbott confirmed limited unauthorized access to legacy Exact Sciences systems but disputed or had not verified threat-actor claims involving large volumes of customer and medical data.
  • Social engineering and credential compromise appear repeatedly, including an attacker impersonating Blank Rome IT and alleged voice-phishing against Abbott employees.
  • External file storage, SaaS applications, and customer portals are recurring access surfaces in the reported incidents.
  • Delayed or incomplete notification and uncertainty over affected records are contributing to privacy litigation and potential regulatory exposure.
  • Threat actors’ data-volume and exfiltration claims remain unverified in several cases, and operational disruption was limited or not reported by the affected organizations.

History

07/23/2026

The story now centers more clearly on a broader set of breach vectors and a more specific mix of disputed claims, with new emphasis on social engineering, compromised accounts, and external systems. It also adds Southern Illinois Dermatology and Amazon as relevant actors, while reinforcing that several attackers’ volume claims remain unverified.

07/21/2026

The story now includes several new named incidents and actors, with the emphasis shifting from a broad healthcare breach pattern to specific investigations, alleged extortion, and lawsuits around disputed breach scope. Abbott and One Medical’s reported incidents, plus Blank Rome’s class actions, make the uncertainty over actual impact and disclosure timing more central.

Full History

Featured

Timeline: 705 Days

2024Jan 1Mar 4May 27Jul 29Oct 21Dec 232025Jan 1Mar 5May 28Jul 30Oct 22Dec 242026Jan 1Mar 5May 28Jul 30Oct 22Dec 24

Additional Articles

⭐⭐⭐⭐⭐

Bloomberg Law07-06-2026
Blank Rome LLP faced two proposed class actions in the Eastern District of Pennsylvania, filed July 6, 2026, alleging a May data incident exposed sensitive personal, financial, and health information for more than 57,000 clients.
The Record / Daryna Antoniuk05-22-2026
Unknown hackers breached Unimed, an external billing provider, leading German university hospitals in Cologne and Baden-Württemberg to report patient data theft in mid-April.
Rocket City Now07-02-2026
Billy Parker filed a class-action in Madison County, Alabama, alleging Huntsville Hospital Health System violated HIPAA duties after a Cerner-linked cyberattack exposed patient medical and financial records.
Lakes Area Radio07-13-2026
Lake Region Healthcare in Fergus Falls, Minnesota notified patients in 2026 after unauthorized access detected in 2025 potentially exposed patient identity and health data.
ClassAction.org / Olivia DeRicco05-13-2026
Alera Group received March 30, 2026 preliminary approval for a $2 million class action settlement resolving claims tied to a 2024 data breach impacting potentially 873,211 employees.
The Philadelphia Inquirer07-07-2026
Two Blank Rome class-action lawsuits in the Eastern District of Pennsylvania allege inadequate safeguards after May 21 third-party impersonation led to Social Security and medical data exposure.
amNewYork / Isabella Gallo06-05-2026
A Manhattan federal class action alleges NYC Health + Hospitals exposed millions to identity theft after a breach exposed Social Security numbers, medical records, and biometric data.
Starlocalmedia06-18-2026
A Potts Law Firm class action in Taylor County, Texas alleges Hendrick Health and Xsolis delayed patient breach notice after a January 2025 phishing attack.
Cyber Updates 365 / Uday Patil07-19-2026
Abbott Laboratories investigated ShinyHunters and ShadowByt3$ claims after alleged single sign-on compromise and LabCentral credential misuse during mid-June.
Beckers Hospital Review / Naomi Diaz06-25-2026
June 19 federal court filing alleges One Medical exposed health records after unauthorized access to third-party archived storage used for Iora Health data.
DistilINFO07-22-2026
Penobscot Valley Hospital in Lincoln, Maine notified patients in mid-2026 after June 4 confirmation that a late-Jan detected healthcare breach involved protected health information.
Paubox / Caitlin Anthoney07-26-2026
Wildwood Surgical Center in Toledo, Ohio reported a 2025 network intrusion on June 26 with public breach notice issued July 13, 2026.
AL.com / Savannah Tryens-Fernandes07-01-2026
A proposed class action filed in 2026 alleges Huntsville Hospital Health System violated HIPAA after a January 2025 Cerner breach exposed patient data with delayed notification.
Class Action U07-15-2026
Wildwood Surgical Center reported unauthorized network access in June 2025, later concluding exposure of personal data and protected health information with notification letters starting in July 2026.
Above the Law / Joe Patrice07-07-2026
Blank Rome faced proposed class actions in Pennsylvania after an impersonation scam allegedly prompted a Google Drive upload of client files, exposing Social Security numbers and other personal data.
PR Newswire07-14-2026
Schubert Jonckheer & Kolbe LLP announced an investigation in response to a May 21, 2026 Blank Rome LLP data breach after late June notification.
The HIPAA Journal / Steve Alder10-13-2025
ALN Medical Management revealed a March 2024 third-party-hosted data breach affecting over one million individuals, leading to consolidated U.S. class actions and a proposed $4 million settlement in Nebraska.
ClassAction.org04-14-2026
Springfield Hospital disclosed an unauthorized email-account access in December 2025 that exposed sensitive identifiers, leading to investigation and possible class action.
McNicholas & McNicholas / Matthew McNicholas07-14-2026
Healthcare data breaches expose medical and financial information, triggering HIPAA security and notification duties and potentially enabling CCPA claims in California.
WOSU Public Media / Jeremiah Fowler09-17-2025
Jeremiah Fowler reported an unprotected database exposing nearly one million Ohio medical patient records.
Class Action U06-04-2026
Sandhills Medical disclosed a May 2025 ransomware attack discovered May 8 that potentially exposed patient identifiers and health data for 169,017 people.
Databreaches06-22-2026
Cherry Health in Michigan issued a preliminary breach notice on June 18, 2026, after suspected unauthorized access and data copying was detected April 19, 2026.
Nashville Banner07-07-2026
Class actions filed in Tennessee allege CareNow tracking disclosures and an XSolis Jan. 20 network breach exposed patient PII and PHI, including Social Security numbers.
Ahdoot & Wolfson / Chris Stiner07-02-2026
Ahdoot & Wolfson explored a potential class action after Boston Orthotics and Prosthetics disclosed a cybersecurity incident that may have exposed sensitive patient and employee data.
BlackFog / Rebecca Harpur04-27-2026
BlackFog says data breach compensation claims can expose US businesses to major civil liability through negligence, regulatory failures, and delayed disclosure after sensitive data incidents.

⭐⭐⭐

Morningstar04-24-2026
Schubert Jonckheer & Kolbe LLP investigates an alleged Southern Illinois Dermatology data breach after November 28, 2025 access and April 2, 2026 notification in Illinois.
Morningstar06-24-2026
One Medical reported a June 2026 vendor file storage breach affecting One Medical Seniors archived patient health records, with ShinyHunters claiming responsibility.
JDJournal07-07-2026
Blank Rome faces a proposed class action after a May 2026 security incident allegedly exposed Social Security numbers and increased identity theft risk.
Yahoo06-26-2026
Northeast Professional Caregivers reported an email account breach discovered April 23 in Jackson Township, Ohio, potentially exposing personal health information and personal identifiers.
Cision PR Newswire06-24-2026
One Medical identified June 8 to June 11, 2026 unauthorized access to a third-party file storage system for One Medical Seniors patient records, as ShinyHunters claimed 8.8 TB exfiltration on June 13, 2026.
ClassAction.org04-20-2026
Elmwood Healthcare reported an unauthorized access incident from January 24 to February 13, 2026, potentially exposing medical and identity data for patients in Rhode Island and Massachusetts.
ClassAction.org05-13-2026
Attorneys sought affected individuals after Elara Caring disclosed a third-party vendor system breach that may have exposed Social Security numbers and medical records.
Arizona Daily Sun07-14-2026
Cyber threat reports on June 2, 2026 describe a ransomware attack claim against Cambridge Mobile Telematics, with threatened disclosure of driving and GPS data in Cambridge, Massachusetts.
Claim Depot06-15-2026
Legal Services of Long Island disclosed a data breach to the Vermont Attorney General on June 12, 2026, exposing Social Security, financial, health, and biometric data.
Claim Depot06-20-2026
On June 13, 2026, One Medical Seniors disclosed unauthorized access to a third-party archived-file storage system, affecting patients at multiple US clinic locations.
Claim Depot07-01-2026
Shamis & Gentile P.A. investigates a PLAY ransomware-claimed EMA Engineering & Consulting breach first disclosed to the Texas Attorney General on July 1, 2026.
Claim Depot07-21-2026
SportsMed Physical Therapy disclosed a July 7, 2026 breach in Glen Rock, New Jersey, after a compromised employee email account potentially exposed patient and health insurance information.
Benzinga05-03-2026
Edelson Lechtzin LLP announced a class action investigation of alleged NCH Corporation data breach exposure between January 21, 2026 and February 25, 2026 in Irving, Texas.
Benzinga05-19-2026
Edelson Lechtzin LLP investigates a potential class action after Elara Caring reported a vendor breach affecting thousands of patients in 2026.
CyberTechnology Insights05-04-2026
Edelson Lechtzin LLP is investigating a May 8, 2025 ransomware breach at Sandhills Medical in North Carolina that exposed patient health information for about 169,017 people.
Houston06-20-2026
In Houston, a developing investigation into an alleged One Medical data breach examines patient information exposure and potential legal claims for affected individuals.
LawFuel07-08-2026
Blank Rome faced proposed federal class actions after a social-engineering cyberattack exposed sensitive client data for more than 57,000 individuals.
WHNT / Logan Sparkman07-01-2026
A class-action lawsuit filed in Huntsville, Alabama alleges Huntsville Hospital Health System delayed notifying patients after a Cerner-related data breach exposed names, Social Security numbers, and medical records.
Fierce Healthcare06-17-2026
On June 13, One Medical learned of unauthorized access to a third-party file storage system used for archived One Medical Senior Health records, affecting a limited number of patients.
MLive / Ron Fonger06-19-2026
Cherry Health reported a computer network breach after suspicious activity on April 19 in Grand Rapids, Michigan, with potential exposure of patient and staff identifiers.
Class Action U07-18-2026
Fox Rothschild LLP reported a May 21, 2026 data breach to the California Attorney General on July 16, 2026 under California breach-notification law.
Strauss Borrelli PLLC02-19-2026
North East Medical Services detected unauthorized access to patient data on October 19 2025 in California via United Layer network.
Strauss Borrelli PLLC09-11-2025
Huron Regional Medical Center in South Dakota reported a May 31 2025 data breach exposing PII and PHI.
Abajournal / John O'Brien07-07-2026
Two proposed class action lawsuits filed in Pennsylvania allege Blank Rome suffered a May breach exposing sensitive client data for over 57,000 people.
Schubert Jonckheer & Kolbe / Matt Foti07-13-2026
On June 2, 2026, CoinbaseCartel ransomware claimed a Cambridge Mobile Telematics attack, and CMT had not notified individuals as of July 13, 2026.
The Repository06-26-2026
Northeast Professional Caregivers disclosed an April 23 email account breach potentially affecting personal health information and personal identifiers.
Federman & Sherwood / Caroline Chesher04-21-2026
Federman & Sherwood investigates a hacking-related network server data breach at Hospital Caribbean Medical Center in Puerto Rico after HHS notification affecting about 92,000 people.
Federman & Sherwood / Caroline Chesher05-20-2026
Federman & Sherwood is investigating a Rhode Island nonprofit data breach reported to HHS after unauthorized network server access allegedly exposed patient information for about 5,630 people.
Federman & Sherwood / Caroline Chesher05-29-2026
Federman & Sherwood investigates the Elara Caring data breach after a network server intrusion exposed sensitive patient information reported to HHS in 2026.
Federman & Sherwood / Caroline Chesher07-06-2026
Federman & Sherwood is investigating a Women’s Center for Radiology data breach reported to the Nebraska Attorney General after April 2026 unauthorized network access.
Federman & Sherwood / Caroline Chesher07-06-2026
Federman & Sherwood is investigating the Midland Care Connections data breach, involving potential unauthorized access to sensitive personal data reported to the Nebraska Attorney General in 2026.
Federman & Sherwood / Caroline Chesher07-20-2026
Redwood Caregiver Resource Center notified caregivers on June 30, 2026 of unintended disclosure of personal identifiers via a misdirected email.
The National Law Review04-19-2026
Edelson Lechtzin LLP is investigating alleged P3 Global Intel data theft reported in mid-March 2026, including millions of law-enforcement tips.
The National Law Review05-18-2026
Elara Caring disclosed a third-party vendor breach involving home health document access in November 2025, leading to patient notifications mailed May 12, 2026.
Westlaw Today06-12-2026
Between June 9 and June 10, proposed class actions in U.S. federal courts alleged healthcare, financial, real estate, and hospitality companies failed to protect sensitive personal data from phishing and ransomware.
PR Newswire06-18-2026
Potts Law Firm filed a Taylor County class action alleging Xsolis phishing caused a delayed June 2026 breach notice for potentially exposed patient data at Hendrick Health.
Cision PR Newswire05-03-2026
Edelson Lechtzin LLP is investigating potential class action claims after Sandhills Medical reported a ransomware attack exposing patient health data in McBee, South Carolina.
Top Class Actions05-22-2026
Alera Group Inc. agreed to a $2 million class action settlement for an August 2024 breach, with claims due June 29, 2026, affecting thousands in the United States.
ClassAction.org09-18-2025
Goshen Medical Center reported a data security incident in March 2025 in North Carolina, potentially affecting 456,385 individuals, with ClassAction.org seeking affected persons for a possible class action.
ClassAction.org02-23-2026
Alert Medical Alarms disclosed a June 17 2025 data breach in Pennsylvania, prompting potential class action litigation over exposed personal and health data.
ClassAction.org02-20-2025
On October 2, 2024, Charleston Area Medical Center detected phishing-driven email compromise affecting 67,413 people, potentially exposing health and identity data and prompting class action discussions.
ClassAction.org10-08-2024
CF Medical disclosed in 2024 that a February vendor breach at FBCS potentially exposed personal information for 626,396 people, prompting class action evaluation.
ClassAction.org05-30-2025
Shore Medical Center notified patients in New Jersey after a Nationwide Recovery Services vendor breach exposed potentially sensitive medical and identity data, with class action discussions beginning in 2025.
ClassAction.org04-06-2026
Attorneys working with ClassAction.org are investigating a potential class action after DocketWise disclosed an October 2025 third-party repository breach affecting 116,666 people.
ClassAction.org06-15-2026
ClassAction.org attorneys investigated a potential class action for alleged South Texas Spinal Clinic breach exposure after a June 15, 2026 dark web claim by The Gentlemen.
ClassAction.org07-01-2026
Texas Hearing Institute confirmed unauthorized access in a data breach in 2026, exposing Social Security, financial, and medical information after a Massachusetts regulator report.
Benzinga04-06-2026
In October 2025, DocketWise reported potential unauthorized credential access to a partner-managed repository, prompting Edelson Lechtzin LLP to investigate class action privacy claims.
Class Action Defense02-05-2026
Duane Morris partners say data breach and privacy class actions escalated across the United States in 2025 due to ransomware and broader data exposures.
McNicholas & McNicholas / Patrick McNicholas06-08-2026
California medical data breaches can compromise protected records and trigger HIPAA breach notification duties under federal rules and state confidentiality protections.
KRTV NEWS Great Falls12-12-2025
Wakefield and Associates data breach affects Benefis Health System patients in central Montana in January 2025
Stratix Systems07-22-2026
Identity Theft Resource Center reported 1,862 data breaches in 2021, as Wawa lawsuits and healthcare breach cost estimates highlight persistent data-security failures.
Federman & Sherwood / Caroline Chesher06-29-2026
Federman & Sherwood investigated NewYork-Presbyterian Hospital after a paper-records breach affecting about 6,909 patients was reported to U.S. HHS.
Delaware Public Media / Abigail Lee09-22-2025
Rhysida hacking group accessed Bayhealth patient data in Delaware in August; settlement awaiting court approval in October to resolve unauthorized access and data exposure.
Cole & Van Note04-06-2026
On February 27, 2026, Boston Mountain Rural Health Center began notifying about a data security incident affecting about 4,800 individuals, prompting class action investigation.
Westlaw Today04-10-2026
Between April 2 and April 6, 2026, U.S. federal courts saw class actions against health care and tech firms over alleged 2025 data breaches exposing sensitive identifiers and patient records.
Cole & Van Note06-29-2026
Operation PAR began breach notifications on June 25, 2026 for at least 375 Florida clients after unauthorized access to medical and identity data.
Cision PR Newswire02-25-2026
Schubert Jonckheer & Kolbe LLP investigate a December 2025 data breach at QualDerm Partners affecting Texas residents.
Federman & Sherwood / Caroline Chesher05-13-2026
Federman & Sherwood began investigating the Waterford Surgical Center data breach in Waterford, Michigan, reported to U.S. HHS on May 13, 2026.
Federman & Sherwood / Caroline Chesher07-07-2026
Federman & Sherwood investigates the Cottage Hospital data breach affecting about 932 Vermont residents after a cybersecurity incident reported to the Vermont Attorney General.
Federman & Sherwood / Caroline Chesher07-21-2026
Federman & Sherwood began investigating Fox Rothschild LLP after a Texas-reported data breach exposed names and Social Security numbers for about 422 residents, with U.S. mail notice.

⭐️⭐️

Law36002-19-2026
A Connecticut medical practice faces three lawsuits after ransomware breach exposing patient and employee data and breach notification concerns.
ClassAction.org02-13-2026
MCA/SGS data breach on November 16, 2025 in the United States exposed personal data.
ClassAction.org09-16-2025
Attorneys with ClassAction.org investigate Hampton Regional Medical Center data breach after notices to affected individuals.
ClassAction.org02-19-2026
North East Medical Services reports a data breach discovered in October 2025 in San Francisco involving a third party vendor UnitedLayer.
ClassAction.org09-10-2025
Huron Regional Medical Center disclosed a data breach on May 31 2025 in South Dakota affecting patient information.
ClassAction.org11-21-2025
Unknown third party accessed Liberty Resources networks in July 2024, exposing personal data and triggering potential class action.
ClassAction.org09-25-2025
California residents affected by the Outcomes data breach may pursue a class action now in California to recover privacy damages.
ClassAction.org11-03-2025
Sedgebrook OpCo SL VII LLC experienced a data breach on May 4-5 2025 in Lincolnshire Illinois, potentially leading to a class action.
The Harvard Law School Forum on Corporate Governance / David Malmstrom08-21-2024
Record US data breaches and rising ransomware in 2023 triggered investor class actions and settlement activity involving Alphabet, Zoom, and Okta while regulators in the US, EU, and Australia tighten disclosure rules.