Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “hipaa” · 59 entries

CareCloud breach: 3.7 million records exposed in hacking incident

CareCloud, Inc., a business associate based in New Jersey, reported a hacking/IT incident to HHS OCR on July 24, 2026. The breach affected 3,756,469 individuals, with data compromised on a network server. Because CareCloud is a business associate, any healthcare providers, health plans, or other covered entities that use its services may need to verify if their patient data was included in this incident. Organizations should review their contracts and communications from CareCloud to determine exposure. This filing date is when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered.

Saint Pete MRI reports hacking incident affecting 138,209 patients

A Florida-based healthcare provider, MRI Associates of St. Pete, Inc. d/b/a Saint Pete MRI, filed a breach report with HHS OCR on August 19, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 138,209 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

One Medical Group reports hacking incident affecting 153,174 patients

One Medical Group, Inc., a healthcare provider in California, filed a breach report with HHS OCR on July 17, 2026. The filing describes a hacking/IT incident that compromised the protected health information of 153,174 individuals. The breached data was located on a network server. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own vendor contracts and security protocols, as large-scale provider breaches often signal broader industry threats. While this specific incident involves One Medical Group, the scale highlights the ongoing risk of network server vulnerabilities in healthcare IT infrastructure.

Delta Dental of Virginia reports hacking incident affecting 126,953 individuals

A health plan, Delta Dental of Virginia, filed a breach notification with HHS OCR on November 21, 2025. The filing reports a hacking/IT incident that compromised the protected health information of 126,953 individuals. The breached data was located in email systems. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred or was discovered. As a covered entity, the health plan is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected individuals.

Persante Health Care reports hacking incident affecting 111,815 individuals

Persante Health Care, a business associate operating in New Jersey, filed a breach notification with HHS OCR on November 26, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 111,815 individuals. Because Persante is a business associate, this incident likely impacts the covered entities—such as hospitals, clinics, or health plans—that rely on its services. Healthcare administrators should check whether their organization uses Persante’s services and review any communications from the vendor regarding next steps for affected patients. The submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered.

Wound Technology Network reports hacking incident affecting 139,830 patients

A Florida healthcare provider, Wound Technology Network, Inc., filed a breach report with HHS OCR on January 28, 2026. The filing details a hacking/IT incident that compromised the protected health information of 139,830 individuals. The unauthorized access occurred on a network server. As a covered entity, the provider is required to report breaches affecting 500 or more individuals within 60 days of discovery. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape, particularly for providers managing sensitive wound care data. No further details on the specific nature of the data accessed or the timeline of the incident are provided in this summary.

Acadian Ambulance Service reports massive data breach — 2.9 million records affected

Acadian Ambulance Service, Inc., a healthcare provider in Louisiana, filed a report with HHS OCR on August 20, 2024, disclosing a hacking/IT incident. The breach exposed the protected health information of 2,896,985 individuals. The compromised data was stored on a network server. This filing date reflects when the report was submitted to the government, not necessarily when the incident occurred or was discovered. Healthcare administrators should note the scale of this incident as a reminder of the risks associated with network security. While this specific event involves an ambulance service, the underlying vulnerability type is relevant to any organization managing electronic health records.

HealthEquity breach affects 4.3 million — Business Associate filing

HealthEquity, Inc., a Business Associate based in Utah, filed a report with HHS OCR on August 9, 2024, disclosing a hacking/IT incident. The breach impacted the protected health information of 4.3 million individuals. The compromised data was located on a network server. Because HealthEquity is a Business Associate, your organization may be affected if you use its services for health savings accounts or related benefits administration. Review your contracts and incident response plans to understand your obligations when a vendor experiences a security incident. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred.

Delta Health System reports hacking incident affecting 216,532 individuals

Delta Health System, a healthcare provider in Mississippi, filed a breach notification with HHS OCR on March 29, 2024. The filing reports a hacking/IT incident that compromised the protected health information of 216,532 individuals. The unauthorized access occurred on a network server. This submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should note this incident as a reminder of the risks associated with network infrastructure vulnerabilities. While this specific event involves a provider in Mississippi, the scale of the breach highlights the importance of monitoring IT security across all covered entities and business associates.

HHS OCR filing: 1.06 million records affected at Connecticut community health center

A Community Health Center, Inc. in Connecticut filed a breach notification with HHS OCR on January 30, 2025. The filing reports that a hacking/IT incident compromised the protected health information of 1,060,936 individuals. The unauthorized access involved data stored on an electronic medical record system and a network server. This submission date marks when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor this case to understand the scale of recent incidents affecting community health providers in the region.

Western Orthopaedics reports hacking incident affecting 113,330 patients

Western Orthopaedics, P.C., a healthcare provider in Colorado, filed a breach notification with HHS OCR on May 1, 2026. The filing reports a hacking/IT incident that compromised the protected health information of 113,330 individuals. The unauthorized access occurred on the organization's network server. This submission date marks when the report was sent to the regulator, not necessarily when the breach occurred or was discovered. As a covered entity, Western Orthopaedics is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should monitor for similar IT incidents and ensure their own incident response plans are current.

VITAS Hospice reports massive data breach affecting 319,177 individuals

A major hacking/IT incident at VITAS Hospice Services, LLC, a healthcare provider in Florida, has been reported to HHS OCR. The filing, submitted on November 24, 2025, indicates that the personal information of 319,177 individuals was compromised. The breach originated from a network server. As a covered entity, VITAS is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for further details regarding the specific data types exposed, as this large-scale incident highlights the ongoing risks to provider networks.

Brown Health Medical Group-MA reports massive hacking incident affecting 311,760 patients

A healthcare provider in Massachusetts has filed a report with HHS OCR regarding a hacking/IT incident. The entity, operating as Brown Health Medical Group-MA, states that the breach impacted 311,760 individuals. The unauthorized access occurred on a network server. This filing was submitted to the government on July 16, 2026. Healthcare administrators should note that this is a covered entity report, distinct from a business associate filing. While the specific data elements are not detailed here, the scale suggests significant patient data exposure. Monitor for further disclosures from the provider regarding notification timelines and remediation steps.

Texas Tech El Paso reports hacking incident affecting 815,000 records

A healthcare provider, Texas Tech University Health Sciences Center El Paso, filed a breach report with HHS OCR on November 25, 2024. The filing details a hacking/IT incident involving data stored on a network server. The breach potentially affected 815,000 individuals. As a covered entity, the university health sciences center is required to report such incidents. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered. Healthcare administrators should note the scale of this incident as a benchmark for risk assessment in their own operations.

Alabama Ophthalmology Associates reports hacking incident affecting 131,576 patients

A healthcare provider in Alabama has filed a breach notification with HHS OCR. Alabama Ophthalmology Associates reported that a hacking/IT incident compromised the protected health information of 131,576 individuals. The unauthorized access occurred on a desktop computer and a network server. This filing was submitted on April 8, 2025, which is the date the report was received by the regulator, not necessarily the date the breach occurred. As a covered entity, the provider is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar incidents involving network servers and ensure their own incident response plans are current.

Mid America Physician Services reports hacking incident affecting 104,513 individuals

A healthcare provider in Kansas, Mid America Physician Services, filed a breach notification with HHS OCR on January 13, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 104,513 individuals. As a covered entity, the provider is required to report breaches affecting 500 or more people within 60 days of discovery. This submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape for cybersecurity risks targeting provider networks.

Southern Illinois Dermatology reports hacking incident affecting 160,312 patients

A healthcare provider in Illinois has reported a significant data breach to HHS OCR. Southern Illinois Dermatology filed a notice on April 2, 2026, stating that a hacking/IT incident compromised the personal information of 160,312 individuals. The unauthorized access occurred on a network server. This filing date represents when the report was submitted to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own systems for similar vulnerabilities and ensure their incident response plans are current, as large-scale provider breaches often signal broader industry threats.

Anne Arundel Dermatology reports massive data breach — 1.9 million records affected

A healthcare provider in Maryland has reported a significant security incident to HHS OCR. Anne Arundel Dermatology filed a breach notification on July 11, 2025, stating that a hacking/IT incident compromised data on a network server. The filing indicates that 1,905,000 individuals were affected. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. As a covered entity, the dermatology group is required to report breaches affecting 500 or more individuals within 60 days of discovery. Healthcare administrators should note the scale of this incident for risk assessment purposes.

Expert MRI reports hacking incident affecting 209,560 patients

A California radiology group, Expert MRI, filed a breach report with HHS OCR on October 31, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, affecting 209,560 individuals. As a healthcare provider, Expert MRI is a covered entity under HIPAA. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected patients.

Florida business associate reports massive hacking breach affecting 279,275 individuals

A Florida-based business associate, Zumpano Patricios, P.A., filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 279,275 individuals, with unauthorized access occurring on a network server. The filing was submitted on July 3, 2025. As a business associate, this entity is bound by HIPAA obligations through its contracts with covered entities. Healthcare administrators should review their vendor contracts to ensure business associates have adequate security measures and breach notification protocols in place. This filing highlights the scale of potential exposure when network servers are compromised.

IPPC Inc. reports hacking incident affecting 133,862 patients

IPPC Inc., IPPC of New York LLC, and Innovative Pharmacy LLC (collectively IPPC) filed a breach report with HHS OCR on February 27, 2026. The New Jersey-based healthcare provider reported a hacking/IT incident involving its network server. The filing indicates that 133,862 individuals were affected by the unauthorized access. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor their own vendor relationships and security protocols, as large-scale provider breaches often signal broader industry threats.

Long Beach City breach: 258,191 records exposed in hacking incident

A healthcare provider operating under the City of Long Beach, CA, reported a hacking/IT incident to HHS OCR on April 14, 2025. The breach affected 258,191 individuals, with data compromised on a network server. This filing date reflects when the report was submitted to regulators, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor this case to understand how large-scale municipal provider breaches are handled. While this specific incident involves a city-run entity, the scale highlights the ongoing risk of server-based attacks. Review your own incident response plans to ensure they can handle mass notification requirements if a similar event impacts your organization.

Retina Group of Florida reports hacking incident affecting 152,691 patients

A healthcare provider, Retina Group of Florida, filed a breach report with HHS OCR on September 3, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server. The breach affected 152,691 individuals. This submission date is when the report was filed with the regulator, not necessarily when the incident occurred or was discovered. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators at other organizations should note the scale of this incident involving a specialist group. Review your own incident response plans to ensure they address server-level compromises. Monitor for further details from the provider regarding the specific types of data exposed.

Modernizing Medicine reports hacking incident affecting nearly 200,000 patients

Business Associate Modernizing Medicine, Inc. filed a breach report with HHS OCR on October 17, 2025, describing a hacking/IT incident involving data on a network server. The filing covers 198,795 individuals. As a Business Associate, Modernizing Medicine provides services to covered entities; if your organisation uses their software, you should verify whether your patient data was among those affected. The submission date is when the report was filed with HHS, not necessarily when the breach occurred or was discovered. This is a reportable event under HIPAA breach notification rules.

Madera Community Hospital reports hacking incident affecting over 150,000 patients

Madera Community Hospital, a healthcare provider in California, filed a breach report with HHS OCR on July 13, 2026. The filing describes a hacking/IT incident involving a network server. The breach potentially exposed the protected health information of 150,810 individuals. This submission date marks when the report was sent to regulators, not when the incident occurred. Healthcare administrators should note the scale of this exposure as a reminder of the risks associated with network server vulnerabilities. While this specific event affects a single provider, it highlights the ongoing threat of cyberattacks in the healthcare sector. Monitor your own systems for similar indicators of compromise.

Alera Group reports hacking incident affecting 155,567 records

Alera Group, Inc., a business associate in Illinois, reported a hacking/IT incident to HHS OCR on July 29, 2025. The breach involved unauthorized access to a network server, exposing the protected health information of 155,567 individuals. As a business associate, Alera Group is required to notify its covered entity clients, who in turn must notify affected patients. Healthcare administrators should verify if their organization contracts with Alera Group and review any notifications received. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered. Monitor communications from vendors to ensure compliance with notification timelines.

North Texas Behavioral Health Authority reports hacking incident affecting 285,086 individuals

A healthcare provider, North Texas Behavioral Health Authority, filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on March 6, 2026, indicates that 285,086 individuals were affected. The breach occurred on a network server. As a covered entity, the authority is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

SimonMed Imaging reports massive data breach affecting 1.2 million patients

SimonMed Imaging, a healthcare provider in Arizona, filed a report with HHS OCR on March 27, 2025, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,275,669 individuals. The unauthorized access occurred on a network server. As a covered entity, SimonMed is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

Chord Specialty Dental Partners reports hacking incident affecting 173,430 patients

A dental service organization, Chord Specialty Dental Partners (operated by CDHA Management, LLC and Spark DSO, LLC), filed a breach report with HHS OCR on March 14, 2025. The filing covers a hacking/IT incident involving email systems that exposed the protected health information of 173,430 individuals. As a healthcare provider in Tennessee, the entity is a Covered Entity under HIPAA. Administrators should note that this submission date reflects when the report was filed with the regulator, not necessarily when the breach occurred or was discovered. This incident highlights the ongoing risks associated with email security in dental and specialty care settings.

United of Omaha Life Insurance reports hacking breach affecting 107,894 individuals

United of Omaha Life Insurance Company, a health plan based in Nebraska, filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 107,894 individuals. According to the filing, the compromised information was located in email. The report was submitted to HHS OCR on July 26, 2024. As a covered entity, the health plan is required to report breaches of unsecured protected health information affecting 500 or more individuals. This filing confirms the incident met that threshold. Healthcare administrators should note that email remains a common vector for data exposure. While this specific breach involves a health plan, the incident highlights the ongoing risks associated with email security across the healthcare ecosystem.

Cierant Corporation reports major data breach affecting 232,506 individuals

Cierant Corporation, a Business Associate based in Connecticut, filed a breach report with HHS OCR on July 3, 2025. The filing describes a hacking/IT incident involving a network server that exposed the protected health information of 232,506 individuals. Because Cierant is a Business Associate, this incident likely impacts the healthcare providers and health plans that contract with them. Your organisation should check whether you have a business relationship with Cierant Corporation. If you do, contact their compliance team immediately to understand the specific data involved and any required next steps for your own breach notification obligations.

Medex Ambulance reports hacking incident affecting 121,190 patients

Medical Express Ambulance Inc., operating as Medex Ambulance in Illinois, filed a breach report with HHS OCR on May 2, 2024. The filing describes a hacking/IT incident where unauthorized access occurred on a network server. The breach potentially exposed the protected health information of 121,190 individuals. As a healthcare provider, Medex is a covered entity under HIPAA. This submission date reflects when the report was sent to regulators, not necessarily when the incident occurred or was discovered. Healthcare administrators should review their own vendor contracts and security protocols to ensure similar network vulnerabilities are addressed.

PIH Health reports massive data breach affecting nearly 3 million patients

Healthcare administrators should note that PIH Health, Inc., a healthcare provider in California, filed a report with HHS OCR for a significant data breach. The filing, submitted on January 31, 2025, indicates that a hacking/IT incident compromised the personal information of 2,947,264 individuals. The unauthorized access occurred on a network server. While this specific filing details the scope of the incident at PIH Health, it serves as a reminder for all covered entities to review their own cybersecurity protocols. This report reflects the submission date to the regulator, not necessarily the date the breach was discovered or announced to patients.

TriZetto Provider Solutions reports massive data breach affecting 3.4 million records

TriZetto Provider Solutions, a business associate serving healthcare providers, reported a hacking/IT incident to HHS OCR. The filing, submitted on February 6, 2026, states that 3,433,965 individuals were affected. The breach occurred on a network server. Because TriZetto is a business associate, your organization may be impacted if you use their services for claims processing or other administrative functions. Review your contracts and contact your vendor management team to confirm whether your entity is among those affected and to understand any required next steps.

University Diagnostic Medical Imaging reports hacking breach affecting 138,080 patients

A New York radiology group, University Diagnostic Medical Imaging, PC, filed a report with HHS OCR on January 21, 2025, disclosing a hacking/IT incident. The breach involved unauthorized access to a network server, exposing the protected health information of 138,080 individuals. As a healthcare provider, the entity is directly responsible for this disclosure. Administrators at imaging centers and hospitals should note the scale of this incident as a benchmark for risk assessment. While the filing date is January 21, 2025, this does not indicate when the breach occurred or was discovered. Monitor for further details on the nature of the data exposed.

Bell Ambulance reports hacking incident affecting 237,830 individuals

Wisconsin-based ambulance provider Bell Ambulance, Inc. filed a breach report with HHS OCR on April 14, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, potentially affecting 237,830 individuals. As a healthcare provider, Bell Ambulance is a covered entity under HIPAA. This submission date reflects when the report was filed, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data types involved and any required notifications to affected individuals.

Insightin Health reports massive data breach affecting nearly 2 million records

Insightin Health, Inc., a business associate based in Maryland, filed a report with HHS OCR on January 16, 2026, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,949,534 individuals. The unauthorized access occurred on a network server. Because Insightin Health is a business associate, your organization may be impacted if you contract with them for services such as claims processing or data analytics. Review your vendor contracts and assess whether you receive data from this entity. If so, contact your legal and compliance teams to determine if you need to notify your own patients or take additional risk mitigation steps.

Summit Pathology reports massive hacking incident affecting 1.8 million patients

Summit Pathology and Summit Pathology Laboratories, Inc., a healthcare provider in Colorado, filed a breach report with HHS OCR on October 18, 2024. The filing covers a hacking/IT incident involving a network server that exposed the protected health information of 1,813,538 individuals. This submission date is when the report was filed with the government, not necessarily when the breach occurred. As a covered entity, Summit Pathology is responsible for notifying affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for notification letters if their patients or staff received pathology services from this organization, as the scale of this incident suggests widespread exposure of sensitive medical data.

Washington radiology group reports massive data breach — 362,713 individuals affected

A Washington-based healthcare provider, Northwest Radiologists, Inc./Mount Baker Imaging, filed a report with HHS OCR regarding a hacking/IT incident. The submission, dated October 28, 2025, indicates that 362,713 individuals were affected. The breach involved unauthorized access to a network server. As a covered entity, this radiology group is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar incidents involving healthcare providers and review their own cybersecurity protocols, though no specific remediation steps are detailed in this filing.

CMS reports hacking incident affecting over 100,000 records

Centers for Medicare & Medicaid Services (CMS) filed a report with HHS OCR on June 30, 2025, disclosing a hacking/IT incident that compromised the data of 107,154 individuals. The breach occurred on a network server. CMS is classified as a Health Plan under HIPAA. Healthcare administrators should note the scale of this federal breach as a benchmark for potential risks to their own systems.

Florida imaging group reports hacking incident affecting 171,862 patients

Doctors Imaging Group, a healthcare provider in Florida, filed a breach report with HHS OCR on September 24, 2025. The filing covers a hacking/IT incident that compromised the personal health information of 171,862 individuals. The unauthorized access occurred on a network server. While this specific incident involves an imaging group, administrators at hospitals, clinics, and health plans should review their own vendor contracts and security monitoring protocols. The submission date marks when the report was filed, not necessarily when the breach occurred or was discovered. Organizations should verify if they share data with this entity or similar providers to assess potential downstream risks.

Pennsylvania eye care group reports hacking incident affecting 200,000 patients

A Pennsylvania-based eye care provider, Tri Century Eye Care PC, filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on October 31, 2025, indicates that the personal information of 200,000 individuals was compromised. The breach originated from a network server. As a healthcare provider, this entity is a covered entity under HIPAA. Administrators should note this as a significant data security event in the ophthalmology sector. The submission date marks when the report was filed with the government, not necessarily when the incident occurred or was discovered. No further details on the specific data types or remediation steps are provided in this initial filing.

University of Iowa Community Home Care reports hacking incident affecting 109,029 individuals

University of Iowa Community Home Care, a healthcare provider, filed a breach report with HHS OCR on August 29, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 109,029 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. This submission date marks when the report was filed, not necessarily when the breach occurred. Healthcare administrators should monitor for similar IT security risks within their own networks and ensure their incident response plans are current.

Fieldtex Products breach filing: 104,071 individuals affected

Fieldtex Products, Inc., a Business Associate, filed an HHS OCR breach report on December 12, 2025, citing 104,071 individuals affected by a hacking/IT incident on a network server. This entry reflects the single OCR filing cited below; additional related filings have been reported elsewhere but are not covered by this record. If your organization uses Fieldtex services, review your contracts to understand notification obligations and monitor the OCR portal for further filings.

Hacking incident at South Carolina healthcare provider affects 143,842 individuals

A healthcare provider in South Carolina, Innovative Scientific Solutions, LLC, reported a hacking/IT incident to HHS OCR on April 17, 2026. The breach affected 143,842 individuals after unauthorized access to a network server. This filing date reflects when the report was submitted, not necessarily when the incident occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data compromised and any required notifications to affected patients or partners.

Highlands Oncology Group reports hacking breach affecting 111,766 patients

Highlands Oncology Group PA, an oncology practice in Arkansas, filed a breach report with HHS OCR on August 1, 2025. The filing covers a hacking/IT incident involving data stored on a network server. The breach potentially affected 111,766 individuals. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators should note the scale of this incident for risk assessment purposes. The submission date is when the report was filed, not necessarily when the breach occurred or was discovered. No further details were provided in the initial filing.

Nacogdoches Memorial Hospital breach: 2.5M affected per federal record

Nacogdoches Memorial Hospital, a healthcare provider in Texas, filed a breach report with HHS OCR on March 30, 2026, regarding a hacking/IT incident. The OCR portal lists 2,507,073 individuals affected. While some secondary sources cite a lower figure of 257,073, the federal record stands at 2.5 million with no documented correction. The breach involved data stored on a network server. As a covered entity, the hospital is responsible for notifying affected individuals. Healthcare administrators should monitor official notifications from the hospital to understand the specific scope of exposure for their own patients or partners, as the federal filing does not detail the specific types of data compromised.

Florida Physician Specialists reports massive data breach affecting nearly 276,500 patients

A Florida-based healthcare provider named Florida Physician Specialists has filed a report with HHS OCR regarding a significant data breach. The incident, classified as a hacking/IT incident, compromised information stored on a network server. The filing indicates that 276,498 individuals were affected by this security failure. The report was submitted on April 24, 2026. Healthcare administrators should note the scale of this breach, which underscores the risks associated with network server vulnerabilities. While this specific event involves a provider group, the implications for data security practices are relevant to all entities handling protected health information. Monitor your own network defenses and review incident response protocols to ensure preparedness against similar threats.

Rocky Mountain Gastroenterology Associates reports massive data breach

A Colorado-based gastroenterology practice has filed a report with HHS OCR regarding a significant data security incident. The filing, submitted on November 13, 2024, indicates that a hacking or IT incident compromised information stored on a network server. This breach affects approximately 366,491 individuals. As a healthcare provider, the entity is required to notify affected patients and report the incident to the government. Healthcare administrators should note the scale of this exposure, which highlights the risks associated with network server vulnerabilities. While this specific event involves a specialty practice, the underlying threat vector is relevant to any organization managing electronic health records.

Mainline Health Systems reports major data breach affecting over 100,000 patients

Mainline Health Systems Inc in Arkansas has reported a significant data breach to the HHS Office for Civil Rights. The incident involved a hacking or IT incident that compromised information stored on a network server. A total of 101,104 individuals were affected by this security failure. The breach was officially reported on June 23, 2025. Hospital administrators should monitor their own network security protocols and ensure incident response plans are up to date. While this specific event affects Mainline Health Systems, it serves as a reminder of the risks associated with server vulnerabilities. No further details were provided in the initial filing.

Central Kentucky Radiology reports hacking incident affecting 166,953 individuals

Central Kentucky Radiology, a physician-owned radiology group in Kentucky, filed a breach notification with HHS OCR on June 13, 2025. The filing reports a hacking/IT incident that compromised a network server, exposing the protected health information of 166,953 individuals. While the submission date is June 2025, secondary sources indicate the underlying incident occurred in October 2024. Healthcare administrators, particularly those running imaging practices, diagnostic labs, or provider networks, should note this risk profile. This event highlights the vulnerability of network servers to unauthorized access. Review your own incident response plans and ensure your IT teams are monitoring for similar vulnerabilities. Verify that your security protocols align with current best practices for protecting patient data in digital health environments.

Primary source: HHS OCR Breach Portal

Frederick Health reports massive data breach affecting nearly 1 million patients

Frederick Health in Maryland has reported a significant cybersecurity incident to the Department of Health and Human Services. The breach involved a hacking or IT incident targeting a network server, exposing the protected health information of 934,326 individuals. This filing was submitted on March 28, 2025. Hospital administrators should monitor this case closely as a benchmark for large-scale incident response. While this specific event is reported, it serves as a reminder to review your own network security protocols and ensure your incident response plans are current and tested.

Primary source: HHS OCR Breach Portal

Liberty Resources reports hacking incident affecting 103,711 individuals

Liberty Resources, Inc., a healthcare provider in New York, submitted a breach report to HHS OCR on March 4, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server, affecting 103,711 individuals. As a covered entity, Liberty Resources must notify affected individuals and HHS OCR. This incident highlights the risk of server-based attacks for any organization handling protected health information. Healthcare administrators should review their own cybersecurity protocols to ensure network servers are secure against similar attacks.

Primary source: HHS OCR Breach Portal

Radiology group reports 1.4M-record breach; second incident status unclear

Radiology Associates of Richmond, Inc., a Virginia-based healthcare provider, filed a breach notification with HHS OCR on July 1, 2025, reporting a hacking/IT incident affecting 1,419,091 individuals. The data was accessed from a network server. This entity has since disclosed a second, separate breach involving 266,183 individuals, stemming from an incident on or about July 25, 2025. This subsequent disclosure was reported to the Maine Attorney General on May 21, 2026. However, claims that this second breach has appeared on HHS OCR's public breach portal are unsupported by primary sources and contradicted by contemporaneous reporting stating it had not yet appeared. The HHS OCR record for the initial filing indicates no business associate was involved. Administrators should monitor the OCR portal for updates on both incidents.

Richmond Behavioral Health Authority reports major data breach — 113,232 records compromised

Richmond Behavioral Health Authority in Virginia has reported a significant data breach affecting 113,232 individuals. The incident, classified as a hacking or IT incident, involved unauthorized access to a network server. The report was submitted to HHS OCR on November 28, 2025. Hospital administrators should monitor this case to understand how large-scale server breaches are being handled and reported. While this specific event affects a behavioral health provider, the scale highlights the ongoing risk to network infrastructure across all healthcare sectors. Ensure your own IT security protocols are robust and that your breach response plan is current.

Major Data Breach at Specialty Networks — Over 411,000 Records Compromised

A significant hacking/IT incident has been reported involving Specialty Networks, Inc., a business associate located in Tennessee. The breach affected the personal health information of 411,037 individuals. The compromised data was stored on a network server. This incident was reported to the HHS Office for Civil Rights on August 15, 2024. Hospital administrators should review their contracts with business associates to ensure robust cybersecurity measures are in place. If your facility uses Specialty Networks, verify their security protocols and confirm that any shared data was protected. This is a confirmed breach, not a proposal, highlighting the ongoing risks of digital health records.

Massive Data Breach at Conduent Business Services — 62 Million Records Compromised

A major breach has been reported involving Conduent Business Services LLC, a business associate operating in New Jersey. This incident, classified as a hacking/IT incident, compromised the data of approximately 62.2 million individuals. The unauthorized access occurred on a network server. Hospital administrators should verify if their organization uses Conduent for services such as billing, claims processing, or other administrative support. If you do, contact your vendor management team immediately to assess potential risks to your patient data. Even if you are not a direct client, the scale of this breach highlights the critical need to review your own cybersecurity protocols and ensure all business associates have robust security measures in place to protect sensitive health information.

Hacking incident at NC healthcare provider affects 106,194 individuals

A hacking/IT incident at Hillcrest Convalescent Center, Inc., a healthcare provider in North Carolina, has been reported to HHS OCR. The filing, submitted on March 4, 2025, indicates that data stored on a network server was compromised. This breach affects 106,194 individuals. Because the source record provides no web description, the specific types of data involved are not detailed here. Healthcare administrators should note this incident as a reminder to verify their own incident response plans and server security protocols. This is a confirmed report from a covered entity classified as a healthcare provider.

Primary source: HHS OCR Breach Portal

No, HIPAA does not yet require encryption everywhere — that's still just a proposal

You may have heard that HIPAA now requires encrypting all patient data. It doesn't — not yet. Federal regulators proposed making encryption mandatory (it's currently just "recommended"), but that proposal has not been finalized into law as of this writing. There's no deadline to comply with yet. Once it is finalized, organizations would get 60 days before it takes effect and 240 days after that to actually comply — so there will be advance warning. Worth watching, not worth panicking about yet.

← Back to AI Health Regulator News