BleepingComputer / Bill Toulas07-02-2026Medtronic notified customers in 2026 after investigation found unauthorized access to corporate IT systems during April 13 to April 19, following ShinyHunters extortion claims.
BleepingComputer / Bill Toulas07-27-2026Coca-Cola disclosed on July 16 that ransomware disrupted Fairlife production and enabled data theft, followed by an Anubis extortion leak after July 27.
Morningstar05-06-2026Schubert Jonckheer & Kolbe LLP is investigating a Medtronic data breach after ShinyHunters claimed unauthorized access and Medtronic confirmed the incident in April 2026.
Morningstar05-23-2026Radiology Associates of Richmond notified 266,000 patients after unauthorized access on or around July 25, 2025, exposing health and personal information.
WTAW / Jeanette Muenchow07-26-2026Eyemart Express, LLC reported unauthorized access on February 12, 2026, and notified customers in the United States, including Social Security number exposure.
Top Class Actions06-03-2026Radiology Associates of Richmond notified the Office of the Maine Attorney General on May 21 about unauthorized access to records of 266,183 patients.
ClassAction.org06-18-2026Blue Fish Pediatrics notified 41,485 Texas residents after a July 2025 computer system breach potentially exposed Social Security numbers and health records, with mailed notices starting June 17, 2026.
Dark Reading / Robert Lemos07-10-2026Ransomware attacks and vendor breaches against healthcare providers in the USA and Germany increased in early 2026, leading to large-scale patient data theft and prolonged operational disruptions.
Claim Depot04-16-2026Longevity Health Plan reported a data breach affecting about 15,000 U.S. Medicare plan members after disclosure to HHS on March 4, 2026.
Claim Depot04-18-2026Aligned Orthopedic Partners reported an email system intrusion between Nov. 16 and Dec. 16, 2025, potentially exposing PII and protected health information.
Claim Depot04-29-2026Sandhills Medical Foundation disclosed on April 28, 2026 a ransomware breach that affected 169,017 patients after unauthorized access to company servers and potential exposure of personal health information.
Claim Depot04-29-2026Greater Boston Urology reported a protected health information breach affecting 4,717 people to the U.S. Department of Health and Human Services on Feb. 28, 2026.
Claim Depot05-04-2026Hematology Oncology Consultants reported a ransomware data breach targeting its Michigan network in 2025, exposing medical records and Social Security numbers, with notifications in 2026.
Claim Depot05-12-2026Belmont Aesthetic & Reconstructive Plastic Surgery disclosed a U.S. health-data breach impacting 528 individuals after an Insomnia ransomware dark-web claim on March 3, 2026.
Claim Depot05-13-2026FMRS Health Systems disclosed in 2026 an intrusion from January to February that potentially exposed PII and PHI, after Qilin claimed responsibility.
Claim Depot05-18-2026Lumio Dental disclosed a ransomware-linked breach to HHS on March 29, 2026, involving passport, driver license, and medical record extracts.
Claim Depot05-18-2026Vacation Myrtle Beach disclosed a ransomware-linked breach on June 16-19, 2025, potentially exposing Social Security numbers, financial data, and possible health records for about 10,750 people.
Claim Depot05-19-2026Medi-Rents & Sales Inc. disclosed an email data breach in early 2026 affecting 1,524 U.S. individuals, with potentially exposed insurance and limited health information.
Claim Depot06-08-2026NJ Pain Care Specialists LLC reported to U.S. HHS on May 14, 2026 after unauthorized access between Feb 25 and Feb 28, 2025 potentially exposed PII and protected health information.
Claim Depot07-07-2026Heart of America Eye Care disclosed a likely unauthorized network access event in Kansas City during April 2026, with HHS notification on June 5, 2026 after a CMD Organization dark web claim.
Claim Depot07-08-2026Mid-South Pulmonary & Sleep Specialists P.C. investigated ransomware-linked unauthorized network access in Memphis after Nov. 2, 2025 detection, later notifying patients in June 2026.
Claim Depot07-08-2026United HealthCare Services disclosed a health data breach affecting 34,574 U.S. individuals to HHS on June 5, 2026.
Claim Depot07-08-2026Erick K. Perroud, DDS disclosed a data breach affecting 7,692 individuals in the United States to the U.S. Department of Health and Human Services on June 10, 2026.
Claim Depot07-13-2026PennyMac unit Private National Mortgage Acceptance Company LLC disclosed a Group Health Plan breach affecting 3,972 U.S. individuals after HHS notification on June 9, 2026.
Claim Depot07-15-2026Easypak reported a ransomware-related data breach discovered in January 2026, with possible exposure of sensitive personal data for at least 217 Massachusetts residents.
Claim Depot07-15-2026Entyre Care Massachusetts Inc. disclosed a March 2026 data breach involving publicly accessible files containing Medicaid IDs and medical records, discovered on May 12, 2026.
Claim Depot07-16-2026Hudson Valley Medical Billing & Credentialing LLC reported possible unauthorized access in 2026, with Massachusetts notification and credit monitoring support beginning July 2026.
Claim Depot07-17-2026Madera Community Hospital reported an undisclosed-data network breach to the California Attorney General on July 14, 2026, after unauthorized third-party access in May 2025.
Claim Depot07-24-2026Clover Health disclosed a healthcare data breach to the SEC on July 4, 2026, with PII and PHI exposure in the United States.
Claim Depot07-26-2026Lifespark Management Services Inc. disclosed a 2026 email-environment data breach in St. Louis Park, Minnesota, after suspicious activity led to possible unauthorized access to PII and protected health information.
PR Newswire / Wolf Haldenstein07-24-2026Wolf Haldenstein Adler Freeman & Herz LLP began investigating a Heart Care Centers of Illinois data breach in Palos Park, Illinois, after breach notifications.
Becker’s Dental Review05-19-2026Shamis & Gentile investigated a ransomware-linked breach at Tampa Bay Dental Implants & Periodontics in St. Petersburg, Florida, affecting 6,400 people via backed electronic medical records.
Cafferty Clobes Meriwether & Sprengel LLP07-12-2026Clinical Registry disclosed a data breach affecting 8,545 patients at Dignity Health’s St. Mary’s Medical Center, including medical record identifiers.
Lubbock Avalanche-Journal / Alana Edgin07-24-2026Eyemart Express disclosed a February 2026 unauthorized-access cybersecurity event involving customer personal data and customer notification on July 24, 2026, from Texas.
DailyHodl / Rhodilee Jean Dolor05-06-2026Sandhills Medical Foundation discovered a May 2, 2025 ransomware incident on May 8, 2025, potentially exposing personal and medical data of 169,017 patients.
Data Breach Rights07-15-2026Casper Orthopedics disclosed a ransomware-linked data breach in the US after Anubis claimed responsibility for unauthorized exposure of patient medical records.
Data Breach Rights07-25-2026RXNT filed a Washington State Attorney General breach notification after possible unauthorized access to healthcare cloud systems holding personal and health-related data.
Cybersecurity Dive07-20-2026Craneware reported a cyberattack and stolen files from its data environment in the UK, with employee and selected customer and partner records exposed and investigation ongoing.
COE Security07-27-2026Medical Cost Benefit Services (MCBS) disclosed a data breach affecting about 1.2 million individuals, raising concerns about healthcare cybersecurity across integrated third-party ecosystems.
Paubox / Abby Grifno05-27-2026Radiology Associates of Richmond reported a healthcare data breach beginning around July 25, 2025, with PHI access discovered and investigated through April 6, 2026.
DataBreachToday07-20-2026Craneware and Abbott investigated healthcare cyber incidents after alleged exfiltration through vendor systems and Abbott LabCentral portal access claims.
Becker's Dental Review05-18-2026Lumio Dental reported an HHS Breach Portal submission on March 29 for a ransomware-linked breach affecting 500 people in Jenks, Oklahoma.
Technadu / Lore Apostol07-22-2026Anubis claimed credit in a Fairlife ransomware incident on the dark web while Coca-Cola reported unauthorized third-party access to production-related systems on July 16.
Hoodline / Cat Ansar06-14-2026Open Arms Care Corporation notified clients in Tennessee starting June 9, 2026 after an internal review found unauthorized access to certain email accounts in 2025.
KBZK News07-07-2026Lumexa notified Butte, Montana residents in June about a medical records breach that occurred March 31 to April 9 and affected at least 3,000 people.
Almeida Law Group06-09-2026Almeida Law Group investigates a June 8, 2026 alleged ransomware breach at Central Arkansas Pediatrics in Conway, Arkansas, while affected data scope remains unconfirmed.
DeXpose07-13-2026Ransomware group Anubis claimed an attack on Casper Orthopedics in Wyoming on July 12, 2026, involving exposed patients data and medical records.
Class Action U / Class Action U05-11-2026Alta Orthopaedics reported a March 2026 discovery of unauthorized access to patient data affecting systems during February 3-6, 2026, with remediation and credit monitoring offered.
Class Action U06-18-2026Blue Fish Pediatrics in Houston, Texas disclosed a 2025 unauthorized access incident, later confirming exposed patient medical data and some Social Security numbers, with notifications starting June 17, 2026.
Strauss Borrelli PLLC06-09-2025Select Medical began June 6, 2025 notifications after a July 2024 unauthorized third-party access to patient systems potentially exposed personal identifiers and protected health information.
Schubert Jonckheer & Kolbe / Nelida Almeida05-20-2026Lumexa Imaging reported a vendor network incident on April 9, 2026, with unauthorized access between March 31 and April 9 potentially exposing patient records.
Schubert Jonckheer & Kolbe / Nelida Almeida05-22-2026Radiology Associates of Richmond faced an alleged 2025 systems intrusion exposing patient PII and protected health information, with notifications mailed starting May 21, 2026, in Richmond, Virginia.
Emery Reddy06-22-2026Xsolis disclosed a targeted phishing incident around January 22, 2026, involving potential unauthorized access to personal and protected health information, and offered identity monitoring via Kroll.
GS Legal07-24-2026Unlimited Technology Systems LLC identified suspicious activity on October 19, 2025, after an unauthorized party potentially accessed patient PII and PHI in Montgomery, Ohio.
Federman & Sherwood / Caroline Chesher07-24-2026Federman & Sherwood is investigating NAS Recovery Solutions after a reported patient-data breach involving electronic medical records and network systems affected about 7,000 people in the USA.
BeyondMachines05-03-2026Integrated Pain Associates reported a 2026 data breach in Killeen, Texas, exposing patient Social Security numbers and medical records and offering 12 months of credit monitoring.
Xinhua06-09-2026Hokkaido's National Hospital Organization reported a hard-drive leak to police after a waste disposal vendor improperly destroyed drives containing hospital medical records.
PR Newswire04-15-2026Vital Imaging Diagnostic Centers reported a 2025 network intrusion in Miami involving unauthorized file removal that may have exposed medical and government identification data and issued notifications in 2026.
PR Newswire / Wolf Haldenstein07-20-2026Heart Care Centers of Illinois notified individuals after a potential data breach on when and where Palos Park, Illinois exposed identity, payment, and medical information.
Cision PR Newswire05-06-2026On April 24, 2026, Medtronic confirmed a corporate IT breach after ShinyHunters claimed terabytes of internal data exposure.
JD Supra03-26-2025OCH Regional Medical Center filed an HHS Office for Civil Rights breach notice on March 11, 2025 and began notifying affected individuals after unauthorized access to sensitive consumer information.
The HIPAA Journal / Steve Alder08-20-2025Health data breaches at CPAP Medical Services, Health Services LLC, and East Adams Rural Healthcare affect patients in Florida, Maine, and Washington during 2024 and 2025.
The HIPAA Journal / Steve Alder04-28-2025Frederick Health Medical Group confirmed a ransomware breach affecting 934,326 patients in Maryland in 2025, triggering class action lawsuits alleging cybersecurity and breach-notice failures.
The HIPAA Journal / Steve Alder04-16-2025Healthcare providers in the United States reported 2024 to 2025 data breaches, with investigations finding unauthorized access to patient identifiers and medical information.
Cbsnews05-28-2025UChicago Medicine disclosed a July 2024 third-party vendor cybersecurity incident through Nationwide Recovery Services that may have exposed personal data of nearly 40,000 patients.
Top Class Actions09-19-2025Altos disclosed on June 17 that an unauthorized party accessed an internet exposed internal system containing personal and health data of patients in Southern California.
Claim Depot09-18-2025Goshen Medical Center in Fayetteville disclosed a ransomware driven data breach affecting 456385 patients on March 4 2025
Health Exec / Chad Van Alstin09-29-2025Hackers breached Healthcare Interactive between July 8 and July 12, 2025, exposing customer personal and health data in the United States.
NetWitness Platform / John Bosco04-15-2026Healthcare breaches involving unsecured PHI trigger HIPAA notification duties to individuals and HHS, with ransomware, phishing, and cloud misconfiguration cited as common causes.
MedCity News07-13-2026Novo Nordisk is linked to a reported cyberattack targeting clinical trial and AI research data, while 2025 healthcare breach reporting indicates large-scale credential-driven exposures.
Gs Legal04-10-2026IPPC reported an unauthorized network access in September 2025 that potentially exposed PHI and PII for over 133,000 customers across six states.
Healthcare Finance News / Jeff Lagasse01-07-2025Richmond University Medical Center reported a healthcare data breach in New York involving accessed or removed files around May 6, 2023, with potential exposure of protected health information for 674,000 people.
Class Action U04-14-2026Springfield Hospital notified individuals starting February 10, 2026, after a December 17, 2025 employee email account compromise potentially exposed personal and health information.
Class Action U07-02-2026Ransomware intelligence on July 2, 2026 alleged an unverified INCRansom attack on Colorado Rehabilitation & Occupational Medicine, with patient data exposure unconfirmed.
Emery Reddy04-10-2026DermCare Management notified affected individuals in March 2026 after a February 2025 unauthorized access event potentially impacted patient information.
Emery Reddy07-07-2026Spokane Digestive Disease Center disclosed May 2026 findings of unauthorized employee email access that exposed patient data, with notifications beginning May 26.
Cory Watson Attorneys / Patrick Nolen06-11-2026McLeod Health detected unauthorized access to a Dillon Family Medicine server months after Oct 2025 intrusions, with Qilin ransomware blamed and HIPAA timing issues discussed.
Almeida Law Group05-14-2026Qilin claimed a mid-May 2026 ransomware attack on Spirit Medical Transport, potentially exposing protected health information for patients in Western Ohio and Eastern Indiana.
Emery Reddy / Sarah Onstott05-22-2026Sterling Seacrest Pritchard notified people about possible unauthorized access to email-environment data between August 12 and 13, 2025, with notifications through April 2026.
GS Legal04-15-2026DermCare Management found suspicious activity on February 26, 2025 and reported an intrusion between February 14 and February 26 that may have exposed patient PII and PHI.