Utopia Tech
Healthcare3 min read

Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents

AngMar Management Services, a Mansfield, Texas-based home health and hospice management company, has identified unauthorized access to its information technology systems. The incident was identified on July 20, 2026, and the forensic investigation determined that an unauthorized individual potentially accessed and/or acquired files containing patient information on or around Ju

UT

Utopia Tech

October 2, 2026 · 3 min read

Share

AngMar Management Services, a Mansfield, Texas-based home health and hospice management company, has identified unauthorized access to its information technology systems. The incident was identified on July 20, 2026, and the forensic investigation determined that an unauthorized individual potentially accessed and/or acquired files containing patient information on or around July 18, 2026.

The review of the affected data was completed on September 8, 2026, when it was confirmed that the data compromised in the incident included names, addresses, dates of birth, Social Security numbers, patient IDs, medical record numbers, health insurance information, dates of service, diagnosis/condition information, provider names, prescription information, and/or medical history information.

AngMar Management Services said it has implemented additional security measures to reduce the risk of similar incidents in the future. The affected individuals have been offered complimentary credit monitoring services. The incident appears to have been a ransomware attack by the Interlock ransomware group, which added AngMar Management Services to its dark web data leak site in August 2026.

The group claims to have exfiltrated 710 GB of data in the incident. The total number of affected individuals has yet to be publicly disclosed; however, the Texas Attorney General was informed that the personal and protected health information of 35,916 Texas residents was potentially compromised in the incident. Eskenazi Health Eskenazi Health, an Indianapolis, Indiana-based safety net health system, has announced a cybersecurity incident involving unauthorized access to certain patient data.

A threat actor had gained access to the email account of a trusted business contact and used that account to send thousands of emails to contacts in the address book, including to an Eskenazi Health employee. The email appeared to have been sent by a trusted contact and contained a document notification. The employee clicked the link in the email and entered their contact details as part of the authentication process.

The threat actor captured the credentials and used them to access the employee’s cloud-based work account. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The employee responded to the email on June 3, 2026, and the compromised account was identified by Eskenazi Health on July 27, 2026.

During that time, emails and attachments in the account may have been accessed or acquired. The review of the account determined that it contained patients’ demographic and contact information, health insurance and billing information, internal identifiers such as medical record numbers, medical and treatment information, Social Security numbers, and sensitive health information such as substance use disorder diagnosis and treatment information.

The account has been secured, additional protective measures have been implemented, and employee education about cyber threats is being enhanced to prevent similar incidents in the future. The affected individuals have been notified and offered complimentary credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

Suffolk County House of Correction | Nashua Street Jail Inmates at Suffolk County House of Correction and Nashua Street Jail in Boston, Massachusetts, have been affected by a cybersecurity incident at Computer Systems Integrated Inc. Computer Systems Integrated is a technology company affiliated with Correctional Psychiatric Services, a healthcare provider serving inmates at several correctional facilities in the state.

Computer Systems Integrated runs the electronic health record system used by the correctional facilities. The cybersecurity incident is under investigation, and it is currently unclear how many inmates have been affected or what types of information were involved. The incident appears to be limited to Suffolk County House of Correction and Nashua Street Jail.

The post Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content