Utopia Tech
Healthcare4 min read

Five Healthcare Providers Report Ransomware-Related Data Breaches

Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks. Alta Orthopaedics Medical Group, California Alta Orthopaedics, a specialty

UT

Utopia Tech

September 3, 2026 · 4 min read

Share

Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks. Alta Orthopaedics Medical Group, California Alta Orthopaedics, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, has recently confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen in a cybersecurity incident earlier this year.

Unusual network activity was identified on March 10, 2026, and the investigation determined that an unauthorized third party had accessed information on its network between February 3, 2026, and February 6, 2026. The review of the affected data was completed on June 24, 2026. Personally identifiable information potentially compromised in the incident included names, contact information, Social Security numbers, driver’s licence numbers/state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth, and login information.

Protected health information compromised in the incident included diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information, and biometric data. Notification letters have been mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been made available for 24 months.

While not mentioned in the notification letters, this appears to have been a ransomware attack. The INC Ransom ransomware group claimed responsibility for the attack and said 26 GB of data was exfiltrated. The data was subsequently leaked.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Cornerstone Behavioral Healthcare, Maine Cornerstone Behavioral Healthcare, a Worcester, Maine-based mental health and substance use disorder treatment provider, has notified patients that some of their protected health information may have been compromised in a May 2026 ransomware attack.

Cornerstone identified the attack on May 26, 2026, the same day that the attackers gained access to its network. The attacker’s access to its network was blocked within an hour of discovery, and computers on the affected parts of the network were powered down rapidly, limiting the extent of file encryption. Cornerstone said it believes that less than 10% of the data on the affected computers and servers was encrypted.

The initial findings of the investigation indicated that the protected health information of approximately 2,830 patients was compromised as a result of the attack, including names, addresses, other contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare information, and Social Security numbers.

Further investigation determined on July 22, 2026, that a log of appointment reminders was also compromised, which included the protected health information of approximately 12,000 patients. The log data included names, birth dates, appointment times, and reminders of documentation due. The investigation has now been completed, and the HHS’ Office for Civil Rights has been informed that, in total, the protected health information of 14,830 patients was potentially compromised in the incident.

Cornerstone explained in its refreshingly detailed breach notification letter that it received a ransom demand but did not pay. All affected computers were wiped, new computers were purchased, and all systems, policies, and procedures have been reviewed. Additional security measures have been implemented on its servers, and special training has been provided to the workforce on ransomware.

Cameron Regional Medical Center, Missouri Cameron Regional Medical Center, a 60-bed acute care hospital in Cameron, Missouri, announced in August 2026 that it recently discovered that it was the victim of a sophisticated ransomware attack. The attack was detected on June 18, 2026, when files on its network were encrypted. In an announcement on August 18, 2026, the hospital explained that the investigation into the attack is ongoing; however, the initial findings indicate that patients’ protected health information was subject to unauthorized access and may have been exfiltrated from its network.

While the specific types of data involved for each patient have yet to be determined, Cameron Regional Medical Center said the information likely compromised includes names plus some or all of the following: home addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient ID numbers, agency-assigned identification numbers, treatment cost information, health insurance information, electronic/digital signatures, and/or employer-assigned identification numbers.

Third-party cybersecurity experts have been engaged to investigate the attack and assist with evaluating and reinforcing its security measures to ensure optimal data security. At the time of issuing the notification, no actual or attempted misuse of patient data had been identified. Individual notification letters will be mailed to the affected individuals when the data review is concluded.

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content