35
Matching signals
in the rolling 90-day window
Sector intelligence · rolling 90-day view
Monitor current cyber incidents across healthcare and social care, with evidence-led context for protecting patient services, clinical systems and sensitive health data.
Current 90-day insights
These observations are calculated from signals currently classified in this sector. They describe the available reporting, not the sector's total incident prevalence.
35
in the rolling 90-day window
13
confidence classifications
32
represented in current signals
Explore related intelligence
Based on all published healthcare signals in the rolling 90-day window. Counts describe this reporting set, not overall incident prevalence.
Current signals
Huntsville Hospital Health System informed patients on June 26, 2026, about a data exposure stemming from a 2025 breach on Cerner's (now Oracle Health) legacy systems. The breach, which occurred on January 22, 2025, exposed personal and medical information. Cerner had notified its healthcare clients, including Huntsville Hospital, on August 12, 2025, but patient notification was delayed at the request of law enforcement.
Health Care and Social Assistance
Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts. Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.
Information
Nintendo of America confirmed that internal employee survey data was stolen in a cyberattack targeting TinyPulse, a third-party employee engagement platform owned by WebMD Health Services. Nintendo's own systems were not compromised, and no customer or financial data was accessed. The breach was claimed by the Shadowbyt3$ extortion group, which initially demanded a $2 million ransom from Nintendo on June 12, 2026, but shifted its demand directly to TinyPulse on June 14, 2026, after Nintendo declined to engage. The claimed dataset includes employee names, email addresses, analytics, survey records, bank statement PDFs, and W-9 tax forms.
Information
Zuther+Hautmann GmbH & Co. KG, a German specialist dealer for medical and hospital supplies and a homecare service provider, experienced a data leak. The ransomware group 'Play' is suspected to be responsible. The incident was registered on May 20, 2026, with public reporting and updates on May 28-29, 2026.
Health Care and Social Assistance
May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, Tampa Bay Dental Implants & Prosthetics, Aligned Orthopedic Partners, South Alabama Regional Planning Commission, Pivot Health, LHC Group, Mays Housecall Home Health, and the World Trade Center Health Program. University of Nebraska Medical Center (UNMC) has discovered that a vulnerability in a third-party software application has been exploited by a threat actor, exposing patient information. UNMC learned about the vulnerability in the REDCap software application in February 2026. REDCap software is used by UNMC to support its research studies and public health activities. When UNMC learned about the vulnerability, the software was taken offline, and an investigation was launched to determine if the vulnerability had already been exploited. Assisted by third-party cybersecurity experts, UNMC determined that the vulnerability had been exploited on September 20, 2023, and access remained possible until February 3, 2026. The data review confirmed that the system contained a range of sensitive data, which varied from individual to individual depending on the nature of the research study/public health activities. That information may have included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and information created or collected in connection with a research study. Such information may have included visit dates, diagnoses, medications, laboratory results, imaging or procedure information, questionnaire responses, or other health-related information. A subset of individuals also had their Social Security numbers exposed. In total, 26,937 individuals had data exposed. Individuals whose Social Security numbers were impacted have been offered complimentary credit monitoring services. Singing River Health System, a non-profit health system with three hospitals and more than 50 clinics serving the Mississippi Gulf Coast, has started notifying patients about a hacking incident identified on or around December 21, 2025. The forensic investigation confirmed unauthorized access to its computer network between December 19, 2025, and December 21, 2025, and on February 10, 2026, it was confirmed that files containing patient information were viewed and potentially copied. Immediate Delivery of Checklist Link To Your Email Address Data exposed varied from individual to individual and may have included names in combination with one or more of the following: contact information, Social Security numbers, driver’s license numbers, dates of birth, bank account information, health insurance information, provider names, internal patient identification numbers, dates of service, medication information, and treatment and/or diagnostic information. Singing River Health System said, “We will continue to implement and evaluate enhanced safeguards and security measures to further protect our systems and continue to provide security training to our employees.” The affected individuals have been advised to monitor their accounts and explanation of benefits statements for data misuse. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected. Tampa Bay Dental Implants & Prosthetics, which also does business as Tampa Bay Dental Implants, Periodontics & Oral Surgery, a dental care provider serving the St. Petersburg and Tampa Bay area in Florida, has recently disclosed a data breach affecting 6,400 individuals. Tampa Bay Dental discovered unauthorized access to its network on January 19, 2026, when ransomware was used to encrypt files. The attack affected a legacy server that contained a backup of electronic medical records. The file review confirmed that patient data was exposed, including names, contact information, birth dates, treatment notes, and clinical histories, and for a limited number of individuals, Social Security numbers. Tampa Bay Dental has implemented additional security measures to prevent similar incidents in the future, including enhancing its security logging, strengthening server encryption, and updating access controls. Credit monitoring and identity theft protection services do not appear to have been offered to the affected individuals. The World Trade Center (WTC) Health Program, which provides no-cost healthcare services to individuals harmed by the 9/11 attack on the World Trade Center, has reported a data security incident to the HHS’ Office for Civil Rights affecting 1,071 individuals. Highly sensitive data was compromised in the incident, which occurred at a vendor, Managed Care Advisors/Sedgwick Government Solutions. Hackers accessed a server containing files associated with the WTC Health Program and exfiltrated sensitive data before encrypting files. The TridentLocker ransomware group claimed responsibility for the attack. The attack was detected by Managed Care Advisors/Sedgwick Government Solutions on December 4, 2025, and the forensic investigation confirmed that the server was first breached on November 16, 2025. Data compromised in the incident includes names, addresses, Social Security numbers, dates of birth, and protected health information. TridentLocker proceeded to leak the stolen data on its dark web data site when the ransom was not paid. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. Bethesda, Maryland-based ASC Ortho Management Company, LLC, doing business as Aligned Orthopedic Partners, has discovered unauthorized access to its email environment and the exposure of the protected health information of 7,213 individuals. The forensic investigation determined unauthorized access occurred between November 16, 2025, and December 16, 2025, during which time, emails and files may have been accessed or acquired. The file review determined on February 17, 2026, that the exposed data included names in combination with one or more of the following: date of birth, Social Security number, driver’s license or state identification number, Medicaid or Medicare number, financial account number, date(s) of service, medical provider name, mental or physical condition, medical treatment information, diagnosis or clinical information, prescription information, health insurance information, patient account number, and or medical record number. The affected individuals were notified on April 17, 2026, and complimentary identity protection services have been made available. Aligned Orthopedic Partners said steps have been taken to augment security to prevent similar incidents in the future. During that time, files containing member data were viewed or copied.
Information
Singing River Health System notified patients about a hacking incident where an unauthorized party accessed its computer network between December 19-21, 2025. Files containing patient information, including names, contact info, SSNs, driver's license numbers, dates of birth, bank account info, and health insurance details, were viewed and potentially copied.
Finance and Insurance
A data breach at NYC Health + Hospitals Corporation, the largest public health system in the U.S., may have affected over 1.8 million current and former patients and employees. The Department of Health and Human Services Office for Civil Rights breach portal was updated to reflect the compromise of personal and protected health information. Investigators found attackers had network access for 11 weeks, with the breach originating from a security incident involving one of the organization's vendors. Exposed data includes fingerprints and palm prints.
Health Care and Social Assistance
ViaQuest Psychiatric & Behavioral Solutions, an Ohio-based provider of behavioral and mental health services, disclosed a data breach to the U.S. Department of Health and Human Services (HHS) on May 8, 2026. The cybersecurity incident affected at least 6,420 individuals, compromising both personally identifiable information (PII) and protected health information (PHI). The types of information exposed include names, Social Security Numbers, dates of birth, addresses, government IDs, and medical information. The breach was classified as a hacking/network server incident.
Health Care and Social Assistance
Data breaches have become an all-too-common reality for businesses in 2026. From small startups to huge corporations, these breaches are impacting everyone and understanding the full scope of the problem is the first step to preventing your business from falling victim. Additionally, the consequences of these breaches are nothing if not substantial. Ransomware attacks, phishing schemes, and even weak passwords are wreaking havoc on businesses, forcing some to shutter their doors when these attacks become too much to bare. That’s why we want to spread the word and keep businesses in the know about what kind of companies are being hit with data breaches, so you can understand exactly how big the problem is and how you can keep your business safe in 2026. Types : Data breaches are the result of a number of types of cyber attacks, including phishing schemes, ransomware attacks, malware, and social engineering. Cost : Statistics vary, but most studies put the cost of a data breach between one and ten million dollars. Business size : No matter the size of your business, data breaches are possible, with big names like McDonald’s and Adidas falling victim. Prevention : Businesses can prevent data breaches by training staff and shoring up cybersecurity measures like two-factor authentication. Lansing Community College: Reportedly, the community college was targeted in February 2026, with more than 170,000 people possibly affected. The college claims that it has “no evidence” that stolen information has been “misused.” Xsolis, Inc: The Tennessee-based healthtech company reveals that it was breached in January 2026 by a suspected phishing attack. As many as 1,396,519 individuals were affected, with Social Security numbers and health insurance information thought to have been stolen. Carnival Corporation: The world’s largest leisure travel and cruise company discloses that it has suffered a massive data breach, with almost 6 million customers thought to have been affected. Compromised information included names, addresses, emails, phone numbers, and dates of birth. GitHub: GitHub confirms a data breach that saw the loss of about four thousand developer code repositories. One threat actor that typically targets open source ecosystems for financial gain, TeamPCP, has taken credit. TeamPCP says it is not offering a ransom, but will instead sell the stolen internal source code and organization data. Open Loop Health : The telehealth platform provider gives more details on a data breach that took place in January: 716,000 individuals were compromised in a breach caused by an unauthorized third party that exfiltrated files containing data including names, addresses, email addresses, dates of birth, and medical information. Instructure : Edtech and learning management company Instructure was breached multiple times by the ShinyHunters extortion gang, prompting the company to pay a ransom in order to regain access to its own data. The cause (at least for the initial breach) was a disruption to certain tools relying on API keys, with a preported loss of 3.65 terabytes of data impacted nearly 9,000 schools worldwide. Heritage Bank: The financial services company reveals that it suffered a data breach between March and April 2026. Personal information belonging to 182,793 individuals is potentially compromised, although the nature of the information is still unknown. Texas Tech University Health Sciences Center: The Oregon Department of Justice reveals that the university department suffered a massive cyberattack in September 2024, with over 800,00 individuals potentially affected. illumifin Corporation: The insurance company is subject to a wide-ranging data breach. It is thought that 97,781 individuals may be affected, with the type of breach and nature of the compromised information still unknown. Restaurant Management Company of Wichita, Inc: The hospitality company experiences a data breach thought to impact up to 52,017 people. Compromised information includes names, addresses, Social Security numbers, and more. Ameriprise Financial, Inc: The financial services company discloses to the Oregon Department of Justice that it was breached in March 2026. The type of information compromised is unknown, but it is thought that as many as 47,876 individuals are affected. Impac Mortgage Holdings, Inc: The mortgage broker reveals that it was affected by a massive cyberattack between February and March 2024. It is thought that up to 61,066 individuals have been affected, with the exposed information still unknown. Georgia Heritage Federal Credit Union: Maine Attorney General notifies affected individuals, who could reach up to 43,077, that the credit union was subject to a ransomware attack in January 2025. Innovative Scientific Solutions, LLC: The South Carolina healthcare provider experiences a cyberattack potentially affecting 143,842 individuals. At the time of the writing, both of the origin of the breach and the compromised information are unknown. Iowa Department of Health and Human Services: The state department experiences a massive data breach resulting in the exposure of Medicaid data belonging to more than 6,000 people. Community Psychiatry Management: California-based practitioner announces that it has experienced a wide-ranging cyberattack, with the personal and health information of around 14,000 individuals exposed in the process. Cookeville Regional Medical Center: More than 330,000 people are thought to have been affected by a massive data breach against the healthcare practitioner. The breach took place in July 2025, with its discovery only recently coming to light.
Information
Acadia Healthcare Company, Inc. (“Acadia”) experienced a data security incident that involved patient information. This notice explains the incident, measures that have been taken, and some steps patients can take in response. On March 25, 2026, unusual activity was detected in a user’s email account. The email account was secured, and an investigation was launched with the assistance of a third-party forensic investigation firm. Through our investigation, we determined that an unauthorized party gained access to one email account and an associated SharePoint account through social engineering. Between March 21, 2026 and March 25, 2026, the unauthorized party accessed and acquired certain emails and SharePoint files. The investigation confirmed that this incident was limited to the one email account and associated SharePoint account and did not involve our electronic health record systems. Importantly, this incident did not disrupt our operations or our ability to care for patients. A review was initiated to determine the contents of those emails and files involved in the incident. Through this ongoing review, files containing patient information have been identified, including names, addresses, dates of birth, treatment information, dates of treatment, type of treatment, and health insurance information. For some individuals, the files also contained their Medicare Health Insurance Claim Number (HICN), which may include their Social Security number. Beginning on May 22, 2026, notification is being provided to patients whose information was involved in the incident. A dedicated, toll-free incident response line has been established to answer any questions you may have about the incident. If you have any questions, please call 888.500.5708, Monday–Friday, 9:00 am – 9:00 pm Eastern Time, excluding major U.S. holidays. For patients whose information was involved, we recommend that you review any statements you receive from your healthcare providers and health insurance plans. If you see any services that were not received, please contact the provider or health plan immediately. We are committed to protecting the confidentiality and security of the information we maintain. We regret any inconvenience or concern this incident may cause and take this matter seriously. To help prevent something like this from happening again, we have implemented, and will continue to adopt, additional safeguards and technical security measures to further protect and monitor our systems. Data Breaches Announced by Florida Retina Center; Acadia Healthcare Company Florida Retina Center has identified unauthorized access to systems containing the protected health information of more than 13,600 patients. Acadia Healthcare Company has experienced a breach affecting 1,800 patients. Bonita Springs-based Florida Retina Center has announced a cybersecurity incident that was first identified on January 30, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity. On May 19, 2026, Florida Retina Center confirmed unauthorized access to parts of its network containing patient data. The file review confirmed that the data of 13,652 patients was exposed and potentially acquired in the incident. The exposed data included names, dates of birth, Social Security numbers, driver’s license numbers, and medical information. Notification letters have been mailed to the affected individuals, and 12 months of complimentary credit monitoring and identity theft protection services have been made available. At the time of issuing notification letters, no misuse of the affected data had been identified. Franklin, Tennessee-based Acadia Healthcare Company, Inc., a provider of psychiatric and chemical dependency services, has announced a data breach affecting 1,807 individuals. Unusual activity was identified within an employee’s email account on March 25, 2026. The account was secured, and an investigation was launched, which confirmed unauthorized access to a single employee’s email account and associated SharePoint files between March 21, 2026, and March 25, 2026. There was no unauthorized access to any other email accounts, other systems, or the electronic medical record system. Immediate Delivery of Checklist Link To Your Email Address The types of data involved varied from individual to individual, and for the majority of affected individuals, involved one or more of the following data elements in addition to their names: address, date of birth, treatment information, dates of treatment, type of treatment, and health insurance information. Certain individuals also had their Medicare Health Insurance Claim Number (HICN) exposed, which may include their Social Security number. Notification letters were mailed to the affected individuals on May 22, 2026, and additional safeguards have been implemented to prevent similar incidents in the future.
Finance and Insurance
The Medusa ransomware gang claimed responsibility for an attack on the University of Mississippi Medical Center (UMMC), posting the organization to its dark web leak site on March 12, 2026. The attack, which began on February 19, forced the closure of 35 clinics, suspended elective surgeries, and disrupted access to the Epic EHR system. Medusa claimed to have stolen over 1TB of patient health information and employee records and demanded an $800,000 ransom.
Health Care and Social Assistance
A ransomware attack crippled the University of Mississippi Medical Center's (UMMC) IT systems, including its electronic health records, on February 20, 2026. This incident forced statewide clinic closures, cancellation of surgeries and appointments, and reliance on manual processes for patient care.
Health Care and Social Assistance
Written by UNMC strategic communications In February 2026, the University of Nebraska Medical Center (“UNMC”) learned that REDCap, a software application UNMC uses to support research studies, quality improvement projects, and public health activities, had a vulnerability that could allow an unauthorized person to gain remote access to the application. Upon learning of the vulnerability, UNMC immediately took REDCap offline and initiated an investigation with the support of third-party cybersecurity consultants. On February 18, 2026, UNMC’s investigation determined that its instance of REDCap was subject to unauthorized access between September 20, 2023 and February 3, 2026. The investigation was unable to determine whether any personal information housed in REDCap was actually accessed, though the vulnerability made such access possible. The information housed in REDCap varied by project and by individual, but could include name; identifiers such as date of birth, address, phone number, email address, and/or medical record number; and information created or collected in connection with a research study, such as clinical information, visit dates, diagnoses, medications, laboratory results, imaging or procedure information, questionnaire responses, or other health-related information. For a limited number of projects, Social Security numbers may have been collected and maintained in REDCap. In an abundance of caution, UNMC is notifying individuals whose personal information is identified in REDCap. Please note that UNMC’s review of the REDCap projects is ongoing, and UNMC will provide notice to additionally-identified individuals upon completion of the review. While UNMC does not have evidence that information was actually accessed, it is always a good idea to review statements received from healthcare providers and report any unfamiliar services or charges to the issuing entity. In addition, complimentary credit monitoring is being offered to individuals whose Social Security numbers are identified in REDCap. To help prevent an incident like this from happening again, UNMC migrated to an updated version of REDCap that was released to address the vulnerability. This new version has enhanced logging and security controls enabled. Please note, we have no indication that any other UNMC application or system was impacted; Nebraska Medicine’s clinical systems operate independently from the REDCap application and were also unaffected by this incident. For questions about this incident, UNMC encourages individuals to contact the dedicated call center at (844) 403-4589 between 8:00 a.m. and 5:30 p.m. Central Time, Monday through Friday, excluding US holidays.
Information
On December 5, 2025, multiple law firms announced investigations into a data breach at Healthcare Interactive, Inc. (HCIactive). HCIactive detected unusual network activity on or about July 22, 2025, and an investigation revealed that an unauthorized third party accessed and acquired certain files between July 8 and July 12, 2025. The compromised files potentially included names, birth dates, email and phone contacts, mailing addresses, Social Security numbers, blood test results, biometric information, health insurance registration, medical records, and insurance claims, affecting approximately 87,565 individuals. HCIactive began notifying affected individuals on December 3, 2025.
Finance and Insurance
On October 12, 2025, Heywood Healthcare, encompassing Heywood Hospital and Athol Hospital, experienced a network outage due to a cyberattack. The incident disrupted critical services including radiology, lab services, and email, leading to a 'Code Black' and the diversion of ambulances. The Sinobi ransomware group later claimed responsibility for the attack, threatening to publish 550GB of stolen data. Potentially exposed information includes names, dates of birth, Social Security numbers, driver's license or state ID numbers, medical records, health insurance details, and contact information.
Finance and Insurance
Harbor, a non-profit organization providing behavioral health services, discovered suspicious activity on its computer network on August 1, 2025. An investigation confirmed that an unauthorized actor accessed and removed certain files from its network between July 25, 2025, and August 1, 2025. The compromised information may have included full name, Social Security number, date of birth, address, driver's license number, medical information, health insurance information, and financial information. Harbor began issuing public notifications on September 30, 2025.
Finance and Insurance
Massive Data Breach at Healthcare Interactive Affects Over 3 Million, Including 103,000 SC Residents Healthcare Interactive, Inc. (HCIactive), an Ellicott City, Maryland -based provider of AI-powered software solutions for insurance enrollment and benefits administration, has experienced one of the largest healthcare data breaches of 2025. The breach has compromised the personal and protected health information of over 3 million individuals nationwide, including 103,000 residents of South Carolina . As required by law, HCIactive has notified the South Carolina Department of Consumer Affairs and has begun sending notification letters to affected residents. HCIactive first identified suspicious activity on its computer network on or around July 22, 2025 . According to the company's notice of security incident, an investigation determined that an unauthorized actor had access to their network and copied certain files between July 8, 2025 , and July 12, 2025 . However, information provided to the Oregon Attorney General suggests the unauthorized access may have spanned a longer period, from June 17, 2025 , to July 22, 2025 . HCIactive initially reported the breach to the HHS' Office for Civil Rights on September 22, 2025 , using a placeholder figure while the review of affected data was ongoing. As the investigation progressed, the staggering scope of the breach became clear. By January 2026 , it was confirmed that 3,056,950 individuals were affected, making it the 5th largest healthcare data breach of 2025. The type of data compromised varies by individual but is extensive and highly sensitive. Exposed information may include: Health plan/policy numbers and health insurance provider names Member/group IDs and health insurance claim numbers Explanation of benefitsMedical data, including diagnoses, treatment information, prescriptions, lab results, medical images, care information, doctors' names, and medical record numbers. While HCIactive states they are not aware of any actual or attempted misuse of the stolen information, the sheer volume and sensitive nature of the data present a significant risk for identity theft and medical fraud. The threat actor behind the attack remains unknown. In response to the breach, HCIactive states they have worked quickly to secure their systems. They have implemented additional technical security measures and are reviewing and enhancing their existing policies and procedures to prevent future incidents. In a December 2025 press release, the company announced structural changes to support their "AI First and AI Everywhere" mission, which includes expanded leadership oversight around AI security, zero trust enforcement, AI-driven anomaly detection, modernization of encryption, and stricter compliance oversight. As an added precaution, HCIactive is offering complimentary credit monitoring services through Cyberscout , a TransUnion company, to affected individuals. Due to privacy restrictions, individuals cannot be automatically enrolled and must sign up for the service using the unique code provided in their notification letter. If you received a notification letter from HCIactive, it is crucial to take immediate steps to protect yourself: Enroll in the Complimentary Credit Monitoring: Follow the instructions in your letter to enroll in the free credit monitoring services offered through Cyberscout . You must enroll within 90 days of the date on your letter. Monitor Your Accounts Closely: Remain vigilant by regularly reviewing your free credit reports, account statements, and explanation of benefits forms for any suspicious activity or errors. Request Free Credit Reports: You are entitled to one free credit report annually from each of the three major credit bureaus (Equifax, Experian, and TransUnion ). Visit www.annualcreditreport.com or call 1-877-322-8228 to request yours. Consider a Fraud Alert or Credit Freeze: You have the right to place a free initial or extended "fraud alert" on your credit file. Alternatively, you can place a "credit freeze" on your report, which prohibits credit bureaus from releasing information without your express authorization. Contact the major credit reporting bureaus to set these up. Report Suspicious Activity: Any suspected identity theft or fraud should be promptly reported to the applicable institution, law enforcement, your state Attorney General, and the Federal Trade Commission (FTC). The FTC can provide further resources on identity theft protection and can be reached at www.identitytheft.gov or 1-877-ID-THEFT. Feeling lost in the digital world? Dr. Tom is here to help! Gov. Braun signs bipartisan Medicaid Reform bill into law Wellmark still worries over temporary tax hike How can more Americans achieve financial independence?
Information
Your Private Writing & Media Protection Space Safeguard Your Sensitive Information in an AI-Driven World Global Privacy Infrastructure with Secure Data Centers in US, Canada, UK, France, Netherlands, Germany, Australia, Japan, and Singapore. Software made in USA, Taiwan, France & India. Since 2017 Write, Add Media, and One-Click Encryption + Backup BSafes is an end-to-end encrypted platform for writing, record keeping, and secure storage of visual-rich media and any files. No one else can see your data, including BSafes staff and server machines. Your Private Story Deserves Absolute Protection 🛁 Rest assured that your information is fully encrypted and secure. From your health to your relationships, family, business and finance, all of your data is protected end-to-end. You can trust that your privacy is our top priority. 📝 📺 📷 Consolidate all relevant text, videos, images, and files on the same page for streamlined access and efficient organization. AI-powered tools learn from your data, but can also pose a risk to sensitive information. BSafes encrypts your data on your device before sending it to the server, making it extremely difficult, if not impossible, for anyone else to learn from obscured data. Privacy & Security by Design & by Default. BSafes encrypts your data with a secret key known only to you, and then sends it to the server. No one, not even BSafes, can access your data because only you have the key. This follows the Zero-Trust & Zero-Knowledge principles. BSafes is compliant with global data privacy and security regulations such as GDPR, CCPA, HIPAA, PCI, and HITECH, thanks to its end-to-end encryption. To secure sensitive content, create a page. You can write, add videos, photos, and any files. Everything is encrypted and backed up by your device. With just one click, your device automatically encrypts and backs up your data to the server. The server then receives the obscured data, encrypted with a key that only you know, ensuring complete security. Drag-and-Drop Videos, Photos and any Files Uploading visual content is very simple. All media is encrypted before being uploaded to the server. There are virtually no limits on file size; it is only bound by your device's storage. You can easily view the video later on any device without the need for a full download. More productive than a secure storage solution With BSafes, you can create and store content in a single, streamlined process. You don't need to use a separate word processor, encrypt the document, and then upload it to cloud storage. With BSafes, you can create content that includes visual-rich media, with the added security of encryption and backup to a secure cloud storage - all with just one click. Updating your writing is much quicker with BSafes, as you don't have to download, edit, and then upload again. 📋 📔 🗓️ 📁 🗃️ Add new pages, notebooks, or diaries in boxes or folders to efficiently search for items. A clean workspace improves productivity. 20GB $2.99 PER MONTH 30-day free trial More Storage We started the BSafes project after a confidential record was made searchable on Google due to a misconfiguration in a cloud service. Resolving the issue and removing the leaked information online took a lot of effort. Then, we searched for a cloud service that could provide convenience and strong security controls to protect our confidential records, such as videos, photos, documents, and other files. After extensive research, we discovered that end-to-end encrypted cloud storage options, such as Tresorit and Mega, were the most suitable solutions for our needs. End-to-end encrypted cloud storage is secure because the users' devices encrypt a file before sending it to the server. The server receives obscured data, which no one can access. However, updating a single piece of information in a record was previously a time-consuming process that required users to download the file, edit it using a separate word processor, save the work, and then upload it to the server in different steps. This process was even more challenging to do on a mobile device.
Information
Public, private, specialist and teaching hospitals.
Regional and national networks coordinating healthcare delivery.
Outpatient, diagnostic and ambulatory care providers.
Primary care, dental and specialist practices.
Nursing, rehabilitation and long-term care organizations.
Community and social-assistance service providers.
Technology and service providers supporting clinical care.
Questions answered
Healthcare organizations need to watch ransomware, data theft, credential abuse, exposed services and incidents originating at critical technology providers.
The rolling incident view shows which threats are being reported across hospitals, clinics and care networks. Teams can compare each case with their own exposed systems, identities, clinical dependencies and suppliers, then turn a relevant signal into a focused control check.
Patient records combine identity, health and sometimes financial information, creating serious privacy and fraud consequences when the data is exposed.
The impact depends on which records were accessed and what an attacker can do with them. Privacy and security teams should assess identity abuse, clinical confidentiality, notification obligations and whether exposed information can be combined with data from other breaches.
A cyber incident can delay appointments, diagnostics, medication, referrals or emergency workflows when essential digital services become unavailable or untrusted.
Clinical impact may occur even when medical equipment is not directly compromised. Response plans should connect technical recovery priorities to safe care, downtime procedures, patient transfers, communications and the evidence leaders need to decide when a service can return.
Hospitals should test identity containment, network isolation, resilient backups, clinical downtime procedures and a recovery order based on patient-safety dependencies.
A technical recovery plan is insufficient unless clinical teams can work safely while systems are unavailable. Peer ransomware incidents provide realistic scenarios for testing decision rights, manual procedures, supplier coordination, data-loss assessment and consistent patient communication.
Healthcare delivery depends on laboratories, cloud platforms, billing services and clinical software, so one supplier incident can interrupt many providers.
Teams should map suppliers to the patient services, data and privileged access they support. Current incidents can then trigger checks of notification routes, fallback procedures, concentration risk, remote connectivity and whether an alternative can be activated within a safe timeframe.
Healthcare responders need to protect safe service delivery while preserving reliable evidence for privacy, security and sector-specific reporting duties.
Requirements vary by jurisdiction, but the operational disciplines remain similar: determine patient and data impact, preserve evidence, escalate decisions, coordinate suppliers and communicate consistently. Legal and clinical leaders should map each incident to the obligations that actually apply.
Related current signals
Use relevant peer incidents as triggers for targeted control tests, supplier reviews, threat hunting and clinical resilience exercises with accountable owners.
For each signal, ask whether the organization uses similar technology, exposes the same service, depends on the same supplier type or holds comparable data. Recording the answer, evidence, owner and follow-up turns external reporting into a practical risk decision.