Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Vishing Attack Provides Threat Act with Access to Quantum Health Network
Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers. Quantum Health Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has dis

Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents
Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company in West Virginia, and Open Door Health Center of Illinois. Boston Healthcare for the Homeless Program, Massachusetts Boston Healthcare for the Homeless Program, a Boston, MA-based nonprofit organization that provides healthcare services
AITexas Hearing Institute Ransomware Attack Affects 30,000 Patients
Texas Hearing Institute suffered a ransomware attack by the Interlock group affecting 29,744 patients, with 540 GB of data stolen including SSNs, diagnosis information, and financial data. Two additional healthcare breaches were reported: Family Partnerships of Central Florida (8,151 affected by MoneyMessage threat group) and SportsMed Physical Therapy in New Jersey (3,400 affected via email compr
AIBoston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents
Three healthcare organizations have reported significant data breaches affecting patient information. Boston Healthcare for the Homeless Program experienced the largest incident with at least 185,000 Massachusetts residents affected after unauthorized network access exposed comprehensive patient data including SSNs, financial information, and health records. Additional breaches were reported at Mo
AIAesto Health Data Security Incident Affects Multiple Healthcare Provider Clients
Aesto Health, a Birmingham-based healthcare technology provider specializing in data migration and EHR exchanges, experienced a data breach affecting its AWS infrastructure between December 2-18, 2025, compromising sensitive patient information including SSNs, medical records, and financial data. The incident impacted over two dozen healthcare provider clients and hundreds of thousands of patients
AIZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
ZOLL Medical Corporation has agreed to a $3.5 million settlement following a January 2023 data breach that exposed personal and health information of over 1 million individuals, primarily LifeVest wearable defibrillator patients. The settlement, which received preliminary court approval, consolidates 15 class action lawsuits alleging HIPAA violations, negligence, and failure to implement adequate
AIData Breaches Announced by Five HIPAA-Regulated Entities
Five HIPAA-regulated entities across the United States have disclosed data breaches affecting over 86,000 individuals combined, with incidents ranging from network intrusions to email account compromises. The breaches exposed sensitive patient and employee information including Social Security numbers, medical records, financial data, and health insurance details. All affected organizations are of
AIOnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits
OnePoint Patient Care and Clay-Platte Family Medicine have reached settlements totaling $3.115 million to resolve class action lawsuits stemming from 2024 data breaches affecting over 1.7 million individuals. The lawsuits alleged negligence in implementing adequate cybersecurity measures, with hackers gaining unauthorized access to protected health information including Social Security numbers and
AIHighland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits
Highland Health Systems and Albany Gastroenterology Consultants have reached preliminary settlements for class action lawsuits stemming from 2023 and 2024 data breaches affecting 83,543 and 57,751 individuals respectively. Highland Health Systems agreed to a $650,000 settlement fund offering affected individuals either up to $5,000 in documented losses or approximately $85 cash payments plus two-y
AIStrict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
Strict data handling protocols have been established for attorneys managing the stolen Change Healthcare dataset in consolidated multidistrict litigation against UnitedHealth Group. The 2024 ransomware attack compromised 6 terabytes of data affecting approximately 192.7 million individuals, triggering over 150 lawsuits from patients and healthcare providers. The court-approved protective order man
AICritical Vulnerabilities Identified in Popular Consumer Fertility Device
Critical security vulnerabilities have been discovered in two consumer health devices: the Mira Hormone Monitor fertility tracker and the Pulsetto Vagus Nerve Stimulator. The Mira device contained 20 vulnerabilities including two critical flaws that could expose sensitive reproductive health data and enable account takeover, while the Pulsetto device has an unpatched vulnerability allowing unautho
AIData Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have disclosed data breaches affecting patient information, with incidents ranging from ransomware attacks to email account compromises occurring between October 2025 and May 2026. The breaches exposed sensitive patient data including names, Social Security numbers, medical records, and health insurance information, with threat actors Genesis ransomware group an
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, FBI, and international partners have issued a joint advisory warning about the Gunra ransomware-as-a-service operation targeting healthcare organizations and critical infrastructure globally. The group, which transitioned to a RaaS model in 2026, offers affiliates an 80% ransom cut and exploits known vulnerabilities in VPNs and firewalls to gain network access, conducting double extortion at
Data Breaches Reported by Sunshine Health; Health Payment Systems
Two healthcare-related organizations have reported significant data breaches affecting thousands of individuals. Sunshine Health, a Florida Medicaid insurer, fell victim to a vishing attack compromising 41,569 individuals' protected health information, while Health Payment Systems, a Wisconsin billing company, experienced an email security incident affecting 9,380 patients with unauthorized access
Data Breaches Announced by Loma Linda University Health & UCLA Health
Two major California healthcare systems have disclosed separate data breach incidents affecting patient information. Loma Linda University Health experienced a breach when patient data from a research study was inadvertently uploaded to an external AI platform, while UCLA Health reported improper disclosure of patient information to an outside healthcare provider over a 16-month period. Both organ
California Child Care Company Discovers 9-Year Employee Data Leak
Child Care Resource Center, a California non-profit, disclosed a nine-year data breach involving an employee forwarding internal files containing personal data to an external email account from October 2016 to October 2025. While the practice was intended to facilitate work duties rather than data theft, the organization lost control of sensitive information and cannot rule out unauthorized access
Health Information Privacy Reform Act Advanced by HELP Committee
The Health Information Privacy Reform Act, which extends HIPAA-like protections to health data collected by non-regulated entities such as fitness trackers and health apps, has been unanimously advanced by the Senate HELP Committee with a 22-0 vote. The legislation addresses significant privacy gaps by requiring HHS to establish privacy, security, and breach notification standards for consumer hea
Five Healthcare Providers Settle Pixel Class Action Lawsuits
Five healthcare providers have recently settled class action lawsuits related to their use of website tracking pixels and analytics tools that allegedly disclosed patient data to third parties without consent. While settlements are common, a recent dismissal of a lawsuit against CRH Healthcare demonstrates that plaintiffs must prove compensable injury rather than speculative damages. Settlement am
Ransom Cartel Mastermind Sentenced to 16 Years in Prison
Maksim Silnikau, a 40-year-old Belarusian cybercriminal and administrator of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison for orchestrating attacks on at least 18 companies worldwide. Operating between 2021 and 2023, Silnikau's operation caused over $6.7 million in losses while attempting to extort $5.2 million from victims through a network of recr
