Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US). Midwest Spine and Brain Institute (3C Care Systems) Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems.
According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation.
The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C Care Systems. The investigation concluded on June 18, 2026, revealing that personally identifiable information and protected health information was potentially involved, including first and last names in combination with one or more of the following: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service, and health insurance claim and/or policy information.
MSBI is mailing notification letters to the affected individuals and has offered complimentary identity monitoring and protection services to individuals whose Social Security numbers were involved. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many MSBI patients have been affected. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.
Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy No information was provided as to the nature of the data breach, but this appears to have been a ransomware attack by the now-disbanded RansomHub ransomware operation on or around November 21, 2024.
RansomHub claimed it had exfiltrated 100 GB of data from 3C Care Systems, although no separate breach announcement appears to have been made by the IT company, and those claims remain unverified. It is unclear if clients other than MSBI had data compromised in the incident. Brookhaven ENT Allergy and Facial Surgery Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, has notified 30,403 individuals that some of their personal and protected health information was compromised in a recent cybersecurity incident.
The incident involved a third-party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. The CareCloud breach listing on the OCR data breach portal indicates that 3. 75 million individuals were affected.
The incident occurred between March 10, 2026, and March 16, 2026, and the file review determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information had potentially been compromised. You can read more about the CareCloud data breach in this post .
At the time of issuing notifications, no actual or attempted misuse of the impacted data had been identified. Silver Summit Medical Corporation (Digestive Disease Center and Heart Vascular & Leg Center), California Silver Summit Medical Corporation, doing business as the Digestive Disease Center and Heart Vascular & Leg Center, has notified certain patients about a cybersecurity incident at a third-party vendor that exposed some of their protected health information.
The Bakersfield, California-based ambulatory surgical center learned about the incident on or around July 20, 2026. The investigation determined that an unauthorized third party accessed the unnamed vendor’s systems from November 27, 2025, to November 30, 2025, and exfiltrated files containing personal and protected health information. The data review determined that the exfiltrated files contained names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, taxpayer identification numbers, passport numbers, and/or other government identifiers.
Protected health information included diagnoses, treatment information, prescription information, and health insurance information. The affected individuals were notified on August 19, 2026, and complimentary credit monitoring and identity theft protection services have been made available. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so the number of affected individuals is not yet known.
Premier Medical Group of the Hudson Valley, New York Premier Medical Group of the Hudson Valley, a Poughkeepsie, New York-based multispecialty practice, has started notifying patients impacted by a cybersecurity incident this summer. The incident disrupted certain IT systems, and the forensic investigation determined that there was unauthorized access to files containing patient information on June 14, 2026.
The substitute data breach notice on the practice’s website does not state when the incident was detected.
Originally published at hipaajournal.com


