Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
California Child Care Company Discovers 9-Year Employee Data Leak
Child Care Resource Center, a California non-profit, disclosed a nine-year data breach involving an employee forwarding internal files containing personal data to an external email account from October 2016 to October 2025. While the practice was intended to facilitate work duties rather than data theft, the organization lost control of sensitive information and cannot rule out unauthorized access
Health Information Privacy Reform Act Advanced by HELP Committee
The Health Information Privacy Reform Act, which extends HIPAA-like protections to health data collected by non-regulated entities such as fitness trackers and health apps, has been unanimously advanced by the Senate HELP Committee with a 22-0 vote. The legislation addresses significant privacy gaps by requiring HHS to establish privacy, security, and breach notification standards for consumer hea
Five Healthcare Providers Settle Pixel Class Action Lawsuits
Five healthcare providers have recently settled class action lawsuits related to their use of website tracking pixels and analytics tools that allegedly disclosed patient data to third parties without consent. While settlements are common, a recent dismissal of a lawsuit against CRH Healthcare demonstrates that plaintiffs must prove compensable injury rather than speculative damages. Settlement am
Ransom Cartel Mastermind Sentenced to 16 Years in Prison
Maksim Silnikau, a 40-year-old Belarusian cybercriminal and administrator of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison for orchestrating attacks on at least 18 companies worldwide. Operating between 2021 and 2023, Silnikau's operation caused over $6.7 million in losses while attempting to extort $5.2 million from victims through a network of recr
Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance
Two healthcare organizations, McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts, have reached settlements to resolve class action lawsuits stemming from data breaches in 2025 and 2023 respectively. McKenzie Health's breach affected 58,839 individuals and offers two years of credit monitoring plus up to $4,000 in reimbursement or $50 cash payments, while Aspire Health A
Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations
The HHS Office of Inspector General announced two EMTALA violation settlements: Merit Health Central Hospital in Mississippi will pay $350,000 for failing to provide adequate medical screening and stabilizing treatment to 14 patients between 2013-2015, and NorthShore University Health System in Illinois will pay $105,000 after a patient waited over 9 hours without reassessment before being found i
Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic
Two healthcare organizations, Omni Healthcare Financial Holdings and Western Montana Clinic, have reached settlements in class action lawsuits following data breaches affecting 16,852 and 8,255 individuals respectively. Both breaches exposed sensitive protected health information including Social Security numbers, medical records, and treatment details, with lawsuits alleging failures to implement
Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data
The U.S. Consumer Product Safety Commission (CPSC) is requesting digital patient data from over 100 hospitals through contractor Konza Health to modernize its National Electronic Injury Surveillance System (NEISS), transitioning from manual to automated data collection. The initiative has raised significant privacy concerns as hospitals report being asked to provide identifiable patient informatio
Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals
Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts) experienced a data breach affecting approximately 312,000 individuals when an unauthorized third party accessed a legacy file server between December 15-16, 2025. The compromised data included sensitive information such as names, Social Security numbers, financial account details, and employee personnel records, though the
AIFree HIPAA Security Risk Assessment
HIPAA security risk assessments are mandatory evaluations that help healthcare organizations identify threats to protected health information (PHI), assess their likelihood and impact, and ensure adequate safeguards are in place. The requirements appear in both the HIPAA Security Rule for electronic PHI and the Breach Notification Rule, though organizations may need to conduct additional privacy r
AmGen Announces Cyberattack and Data Breach Involving Patient Data
Biopharmaceutical company Amgen disclosed a material cybersecurity incident involving unauthorized access to third-party cloud storage systems, resulting in the exfiltration of proprietary data, patient protected health information, and other sensitive data. The company detected the breach in July 2026, immediately activated its incident response plan, and filed an 8-K with the SEC, though it does
FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices
The FTC, along with Utah and California, has filed a lawsuit against telehealth company Him & Hers for allegedly sharing sensitive consumer health data with third-party advertising platforms including Meta, Google, TikTok, and others without proper consent, while falsely claiming to maintain privacy. The complaint also alleges deceptive billing practices, including enrolling customers into difficu
CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft
CareCloud, a cloud-based healthcare IT solutions provider, experienced a cyberattack between March 10-16, 2026, affecting one of its six EHR environments hosted on AWS. The breach compromised sensitive data of at least 345,000 patients, including Social Security numbers, financial information, and medical records. CareCloud has contained the incident, engaged third-party cybersecurity experts, and
Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks
Health-ISAC has issued a cybersecurity alert warning healthcare organizations about increasing attacks by ShinyHunters, a threat group that uses voice-based social engineering (vishing) to compromise cloud accounts and exfiltrate data from SaaS platforms. Unlike ransomware actors, ShinyHunters targets SSO systems like Okta and Microsoft Entra to gain access to multiple applications, then demands r
AIFree Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team)
A free webinar scheduled for August 7, 2026, will address how small healthcare practices can achieve HIPAA-compliant email without dedicated IT staff. The session will explain why standard email solutions like Gmail and Microsoft 365 are insufficient for HIPAA compliance and demonstrate practical approaches to closing security gaps while maintaining ease of use for both staff and patients.
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System agreed to pay $552,250 to settle a HIPAA investigation following a 2021 Nephilim ransomware attack that compromised the protected health information of 53,907 patients. The OCR investigation found OSF Healthcare failed to conduct proper risk analysis, made impermissible PHI disclosures, and did not provide timely breach notifications to affected individuals and HHS. The settl
AIFree Webinar: Inside 250 HIPAA Investigations – What You Need to Know
Abyde is hosting a webinar featuring insights from over 250 actual OCR HIPAA investigations, led by their Chief Legal Officer and Senior VP of Operations. The session will cover investigation triggers, response protocols, common compliance failures, and real-world examples to help healthcare organizations avoid fines and lengthy investigations in an era of increasing ransomware breaches and patien
Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds
A business email compromise attack on a Children's Healthcare of Atlanta vendor in 2023 resulted in $5.3 million being stolen and redirected to accounts controlled by former CPA Ronald Deabler. Deabler, who conspired with the hacker to launder the funds in exchange for commission, was sentenced to four years in prison and ordered to pay over $682,000 in restitution, though approximately $4 million
Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits
Banner Health and LifeStance Health Group have agreed to settle class action lawsuits alleging unauthorized disclosure of patient data to Meta and Google through website tracking pixels and analytics tools. Banner Health will compensate approximately 1.028 million affected individuals with $20 payments plus identity protection services, while LifeStance established a $3 million settlement fund for