Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “cybersecurity” · 19 entries

University of Iowa Health Care reports hacking incident affecting 101,875 individuals

University of Iowa Health Care, a healthcare provider in Iowa, filed a breach notification with HHS OCR on August 29, 2025. The filing reports a hacking/IT incident involving data stored on a network server. The breach potentially affected 101,875 individuals. This submission date marks when the report was sent to the regulator, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor such filings to understand the scale of recent cyber threats facing large provider systems. While this specific incident involves a university health system, it highlights the ongoing risk of server-based attacks that can expose large volumes of patient records. No further details on the specific data types or remediation steps are provided in this summary record.

Brightstar Global Solutions reports massive data breach affecting over 100,000 individuals

Brightstar Global Solutions Corporation, a health plan based in Rhode Island, filed a report with HHS OCR on October 3, 2025, regarding a hacking/IT incident. The breach compromised the protected health information of 103,879 individuals. The unauthorized access occurred on a network server. As a covered entity, Brightstar is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor this case to understand how large-scale cyber incidents are handled by health plans. This filing confirms the breach was reported to regulators; it does not indicate when the incident originally occurred or was discovered.

Florida Physician Specialists reports massive data breach affecting nearly 276,500 patients

A Florida-based healthcare provider named Florida Physician Specialists has filed a report with HHS OCR regarding a significant data breach. The incident, classified as a hacking/IT incident, compromised information stored on a network server. The filing indicates that 276,498 individuals were affected by this security failure. The report was submitted on April 24, 2026. Healthcare administrators should note the scale of this breach, which underscores the risks associated with network server vulnerabilities. While this specific event involves a provider group, the implications for data security practices are relevant to all entities handling protected health information. Monitor your own network defenses and review incident response protocols to ensure preparedness against similar threats.

Philadelphia Corporation for Aging reports massive data breach affecting over 400,000 individuals

A significant security incident has been reported by Philadelphia Corporation for Aging (PCA), a Business Associate operating in Pennsylvania. The organization filed a report with HHS OCR on September 23, 2025, disclosing a hacking/IT incident that compromised data stored on a network server. This breach affects a substantial number of individuals, with 410,491 people impacted. Because PCA is a Business Associate, this incident likely involves the health data of patients from various covered entities, such as clinics or health plans, that contract with them. Healthcare administrators should review their vendor contracts and security protocols to ensure their own Business Associates are maintaining adequate safeguards against cyber threats.

Radiology Associates of Richmond reports massive data breach affecting 266,183 patients

A Virginia-based radiology group, Radiology Associates of Richmond, has filed a report with HHS OCR regarding a significant security incident. The filing, submitted on May 21, 2026, indicates that a hacking/IT incident compromised data stored on a network server. This breach affects a substantial number of individuals, with 266,183 people impacted. As a healthcare provider, the entity is a Covered Entity under HIPAA rules. Administrators should note that this submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered. Given the scale of the incident, this serves as a reminder of the risks associated with network server vulnerabilities in medical imaging and diagnostic settings.

Rocky Mountain Gastroenterology Associates reports massive data breach

A Colorado-based gastroenterology practice has filed a report with HHS OCR regarding a significant data security incident. The filing, submitted on November 13, 2024, indicates that a hacking or IT incident compromised information stored on a network server. This breach affects approximately 366,491 individuals. As a healthcare provider, the entity is required to notify affected patients and report the incident to the government. Healthcare administrators should note the scale of this exposure, which highlights the risks associated with network server vulnerabilities. While this specific event involves a specialty practice, the underlying threat vector is relevant to any organization managing electronic health records.

Centers Lab NJ reports massive data breach affecting over 540,000 patients

A major healthcare provider, Centers Lab NJ LLC, has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking/IT incident targeting a network server, compromising the records of 542,377 individuals. The breach was officially filed on June 18, 2026. Hospital administrators should monitor this case closely as a reminder of the risks associated with network security vulnerabilities. While this specific report does not detail immediate operational changes for other facilities, it underscores the critical need for robust cybersecurity measures to protect patient data from unauthorized access.

Mainline Health Systems reports major data breach affecting over 100,000 patients

Mainline Health Systems Inc in Arkansas has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking or IT incident that compromised information stored on a network server. A total of 101,104 individuals were affected by this security failure. The breach was officially reported on June 23, 2025. Hospital administrators should monitor their own network security protocols and ensure incident response plans are up to date. While this specific event affects Mainline Health Systems, it serves as a reminder of the risks associated with server vulnerabilities. No further details were provided in the initial filing.

Major Data Breach at ATSG, Inc. — Nearly 1 Million Records Compromised

A significant data breach has been reported involving ATSG, Inc., a business associate operating in New York. This incident, classified as a hacking/IT event, compromised the protected health information of 909,469 individuals. The breach occurred on a network server and was reported to the HHS Office for Civil Rights on October 4, 2024. Hospital administrators should review their own business associate agreements to ensure vendors have robust cybersecurity measures. While this specific incident affects ATSG, it serves as a stark reminder of the risks associated with third-party data handling. Monitor your own systems for unusual activity and verify that your partners are compliant with security standards.

VectraRx Mail Pharmacy Breach — 109,383 Affected, Hacking Incident

VectraRx Mail Pharmacy Services, LLC, a Healthcare Provider based in Arizona, reported a hacking/IT incident affecting 109,383 individuals. The breach involved data stored on a network server. The report was submitted to HHS OCR on February 6, 2025. This filing is relevant to healthcare administrators and vendors who interact with mail-order pharmacies or share data with similar entities. Because VectraRx is classified as a Covered Entity, this incident highlights risks for providers managing their own patient data systems. Administrators should review their own vendor management protocols to ensure partners maintain robust cybersecurity measures, particularly for systems handling large volumes of patient data. The primary source record does not confirm whether patient notifications have been sent or if credit monitoring was offered, nor does it indicate the incident is resolved.

#data-breach#hacking#mail-pharmacy#covered-entity#cybersecurity

Central Kentucky Radiology reports hacking incident affecting 166,953 individuals

Central Kentucky Radiology, a physician-owned radiology group in Kentucky, filed a breach notification with HHS OCR on June 13, 2025. The filing reports a hacking/IT incident that compromised a network server, exposing the protected health information of 166,953 individuals. While the submission date is June 2025, secondary sources indicate the underlying incident occurred in October 2024. Healthcare administrators, particularly those running imaging practices, diagnostic labs, or provider networks, should note this risk profile. This event highlights the vulnerability of network servers to unauthorized access. Review your own incident response plans and ensure your IT teams are monitoring for similar vulnerabilities. Verify that your security protocols align with current best practices for protecting patient data in digital health environments.

Primary source: HHS OCR Breach Portal

Coastal Carolina Health Care reports major data breach affecting over 110,000 patients

Coastal Carolina Health Care, PA in North Carolina has reported a significant data breach to the Department of Health and Human Services. The incident involved a hacking or IT incident targeting a network server. This breach affects 110,304 individuals, exposing their protected health information. The report was submitted on March 24, 2026. Hospital administrators should review their own cybersecurity protocols to ensure similar vulnerabilities are not present in their systems. While this specific incident is contained to Coastal Carolina Health Care, it serves as a reminder of the ongoing risks posed by cyber threats to healthcare networks. Ensure your IT teams are monitoring for unusual activity and that incident response plans are up to date.

Frederick Health reports massive data breach affecting nearly 1 million patients

Frederick Health in Maryland has reported a significant cybersecurity incident to the Department of Health and Human Services. The breach involved a hacking or IT incident targeting a network server, exposing the protected health information of 934,326 individuals. This filing was submitted on March 28, 2025. Hospital administrators should monitor this case closely as a benchmark for large-scale incident response. While this specific event is reported, it serves as a reminder to review your own network security protocols and ensure your incident response plans are current and tested.

Primary source: HHS OCR Breach Portal

Laurel Eye Clinic reports massive data breach affecting over 145,000 patients

Laurel Eye Clinic in Pennsylvania has reported a significant cybersecurity incident to the HHS Office for Civil Rights. The breach involved a hacking or IT incident targeting the clinic's network server. This event potentially exposed the protected health information of 145,221 individuals. The report was submitted on April 22, 2026. Hospital administrators should review their own network security protocols to ensure similar vulnerabilities are addressed. While this specific incident is contained to one provider, it highlights the ongoing risk of server-based attacks in healthcare settings. Ensure your IT teams are monitoring for unauthorized access and that incident response plans are up to date.

Richmond Behavioral Health Authority reports major data breach — 113,232 records compromised

Richmond Behavioral Health Authority in Virginia has reported a significant data breach affecting 113,232 individuals. The incident, classified as a hacking or IT incident, involved unauthorized access to a network server. The report was submitted to HHS OCR on November 28, 2025. Hospital administrators should monitor this case to understand how large-scale server breaches are being handled and reported. While this specific event affects a behavioral health provider, the scale highlights the ongoing risk to network infrastructure across all healthcare sectors. Ensure your own IT security protocols are robust and that your breach response plan is current.

Dameron Hospital reports major data breach affecting over 210,000 patients

Dameron Hospital in California has reported a significant data breach to HHS OCR. The incident involved a hacking or IT incident that compromised information stored on a network server. This breach affects 210,706 individuals, making it a large-scale event that hospital administrators should monitor for potential industry-wide trends. The filing was submitted on April 2, 2025. While this specific report does not detail the exact data types exposed, the scale suggests a serious security failure. Administrators should review their own server security protocols and ensure incident response plans are current. This is a confirmed breach, not a proposal, and highlights the ongoing risk of cyberattacks on healthcare infrastructure.

Major Data Breach at Specialty Networks — Over 411,000 Records Compromised

A significant hacking/IT incident has been reported involving Specialty Networks, Inc., a business associate located in Tennessee. The breach affected the personal health information of 411,037 individuals. The compromised data was stored on a network server. This incident was reported to the HHS Office for Civil Rights on August 15, 2024. Hospital administrators should review their contracts with business associates to ensure robust cybersecurity measures are in place. If your facility uses Specialty Networks, verify their security protocols and confirm that any shared data was protected. This is a confirmed breach, not a proposal, highlighting the ongoing risks of digital health records.

Massive Data Breach at Conduent Business Services — 62 Million Records Compromised

A major breach has been reported involving Conduent Business Services LLC, a business associate operating in New Jersey. This incident, classified as a hacking/IT incident, compromised the data of approximately 62.2 million individuals. The unauthorized access occurred on a network server. Hospital administrators should verify if their organization uses Conduent for services such as billing, claims processing, or other administrative support. If you do, contact your vendor management team immediately to assess potential risks to your patient data. Even if you are not a direct client, the scale of this breach highlights the critical need to review your own cybersecurity protocols and ensure all business associates have robust security measures in place to protect sensitive health information.

New federal AI-security order: free cyber-defense tools may be coming to hospitals

A second AI executive order (EO 14409, signed June 2, 2026 — separate from the December order about overriding state laws) focuses on AI and cybersecurity. The part that matters for hospitals: the federal cyber agency CISA was given 30 days to expand AI-powered defensive tools and make them easier to access for critical infrastructure operators — which includes healthcare. Treasury is also standing up a clearinghouse for coordinating vulnerability detection and fixes. Nothing here requires you to do anything; it's a potential resource. Worth having your IT/security lead watch CISA's announcements over the coming weeks for new tools or programs your organization can enroll in. The order does not add licensing requirements for AI, and it says nothing about healthcare regulation or state-law preemption.

← Back to AI Health Regulator News