Utopia Tech
Healthcare3 min read

Vishing Attack Provides Threat Act with Access to Quantum Health Network

Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers. Quantum Health Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has dis

UT

Utopia Tech

August 17, 2026 · 3 min read

Share

Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers. Quantum Health Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has disclosed a cybersecurity incident that it identified in May 2026.

The incident started with a vishing attempt. The attacker called a Quantum Health user on May 29, 2026, and tricked them into providing access to the Quantum Health network. Between May 29, 2026, and June 1, 2026, the unauthorized third party had access to its network and acquired files.

On June 1, 2026, Quantumn Health experienced a network disruption affecting both internal and external systems. An investigation was launched, which traced the incident back to the vishing call. The threat group behind the incident was not named, and no ransomware group appears to have claimed responsibility for the attack.

These tactics are commonly used by the ShinyHunters threat group, which was the subject of a recent Health-ISAC cybersecurity alert. On June 8, 2026, Quantum Health confirmed that the exfiltrated data included personal and protected health information, including names, addresses, email addresses, phone numbers, dates of birth, demographic information, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, dates of service, insurance information, and claims or benefits information.

The affected individuals are being offered complimentary credit monitoring and identity theft protection services. It is unclear how any companies have been affected by the incident, and the number of affected individuals has yet to be publicly disclosed. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.

Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Heart of America Medical Center Heart of America Medical Center, a faith-based nonprofit hospital and medical facility in Rugby, North Dakota, has experienced a cybersecurity incident that exposed patient data.

Suspicious network activity was identified on or around June 12, 2025, and the investigation determined on September 15, 2025, that an unauthorized third party accessed its network and exfiltrated files, some of which contained patient information, including names, Social Security numbers, medical records, and other medical information. A third-party vendor was engaged to review the affected data, and that process concluded on May 12, 2026.

The findings were reviewed, and that process was completed on June 9, 2026. Contact information was verified, and on July 9, 2026, Heart of America Medical Center obtained a final list of individuals to notify. Notification letters have now been sent to the affected individuals, who have been offered complimentary single-bureau credit score, credit report, and credit monitoring services.

Heart of America Medical Center has implemented additional technical and administrative safeguards to enhance data privacy and security. The Embargo ransomware group claimed responsibility for the incident and claimed to have exfiltrated around 800 GB of data in the attack. The incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.

Precision Imaging Centers The Medical Imaging Partnership, doing business as Precision Imaging Centers in Florida, has announced a hacking incident that exposed patient information. Suspicious activity was identified within its computer network on May 7, 2026. The investigation determined that its network was accessed by an unauthorized third party, who copied files from its systems.

The investigation and data review are ongoing, so the exact data types involved and the names of the affected individuals have yet to be determined. As such, the incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of 501 individuals. The total will be updated when the file review is concluded.

Precision Imaging Centers has advised current and former patients to remain vigilant against identity theft and fraud by monitoring their free credit reports, accounts, and explanation of benefits statements for signs of data misuse. Notification letters will be mailed to the affected individuals as soon as possible after the data review is concluded. The post Vishing Attack Provides Threat Act with Access to Quantum Health Network appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content