Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Clinical Registry Solutions; Jason R Egbert OD PC; VNC Health Announce Data Breaches
Three healthcare-related organizations have announced data breaches affecting patient information in early 2026. Clinical Registry Solutions experienced an Akira ransomware attack compromising patient and employee data, while First Sight Family Vision and VHC Health were impacted by breaches at their third-party vendors RXNT and Xsolis respectively, exposing sensitive patient information including
Clinical Trial Data Stolen in Novo Nordisk Cyberattack
Novo Nordisk, the pharmaceutical company behind Ozempic and Wegovy, disclosed a cyberattack that resulted in the theft of clinical trial data affecting both patients and healthcare providers. While patient data was pseudonymized (using random ID numbers rather than names), the breach exposed limited health information including biomarkers and lifestyle factors. Healthcare provider contact informat
AIShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
The ShinyHunters hacking group exploited a zero-day vulnerability in Oracle's ERP software to conduct widespread attacks primarily targeting American universities. The vulnerability enabled attackers to exfiltrate significant volumes of sensitive data from higher education institutions running the affected Oracle systems.
Labcorp Agrees to $35M Settlement to Resolve AMCA Data Breach Litigation
Labcorp has agreed to a $35 million settlement to resolve class action litigation stemming from a 2018 data breach at its third-party collections vendor, American Medical Collection Agency (AMCA), which exposed protected health information of over 10.2 million Labcorp patients. The breach, which occurred between August 2018 and March 2019, was part of a larger incident affecting more than 25 milli
AIShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The ShinyHunters cybercrime group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft between May 27 and June 9 to breach enterprise systems, primarily targeting universities. The attacks involved data theft and extortion demands, with Oracle not releasing a security advisory until June 10, after the exploitation window had closed.
Florida Law Firm Data Breach Affects 65,000 Individuals
GrayRobinson, a Florida-based law firm, disclosed a data breach affecting 65,113 individuals after unauthorized network access between March 5-24, 2025, exposed sensitive personal and health information including SSNs, financial data, and medical records. Two additional healthcare-related breaches were reported: C2N Diagnostics in Missouri affecting 2,027 individuals, and Virta Health in Colorado,
Cybersecurity Incidents Reported by Multiple Dental Practices
Multiple dental practices across the U.S. have reported cybersecurity incidents affecting thousands of patients, with breaches ranging from ransomware attacks to phishing-based email compromises. The incidents exposed sensitive patient data including Social Security numbers, medical records, and insurance information, with Bayside Dental's breach affecting over 10,000 patients and involving a rans
Senator Seeks Answers from NYC Health & Hospitals About 1.8M Record Breach
Senate HELP Committee Chair Senator Bill Cassidy is demanding answers from NYC Health + Hospitals regarding a data breach affecting 1.8 million individuals, where unauthorized access persisted for nearly three months through a third-party vendor compromise. The breach, discovered in February 2026, exposed sensitive patient data including Social Security numbers, medical records, and geolocation in
Henderson & Walton Women’s Center Settles Class Action Data Breach Lawsuit
Henderson & Walton Women's Center has agreed to settle a class action lawsuit following a 2022 email account breach that exposed personal and protected health information of 34,306 patients. The unauthorized access occurred over a three-day period in February 2022, compromising names, dates of birth, identification numbers, and medical information. While denying wrongdoing, the healthcare provider
Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach
DentaQuest, a dental benefits administrator serving 32 million Americans, has suffered a significant data breach claimed by the ShinyHunters extortion group. The breach exposed 234 GB of data including 2.6 million unique email addresses along with personal information such as names, addresses, phone numbers, and dates of birth, though Social Security numbers were not compromised. The incident repr
Onsite Women’s Health $2.5M Data Breach Settlement
Onsite Women's Health reached a $2.525 million settlement following a phishing-enabled email breach that exposed protected health information of 357,265 individuals, including Social Security numbers, financial data, and medical records. The consolidated class action lawsuit alleged inadequate security measures failed to prevent or quickly detect the October 2024 breach, though the company denies
Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients
Four healthcare organizations have reported significant data breaches affecting tens of thousands of patients. Clarinda Regional Health Center in Iowa experienced the largest breach, affecting 24,341 individuals through a LockBit5 ransomware attack that exposed comprehensive personal and medical data including Social Security numbers, financial information, and health records. The incidents highli
Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals
Conduent Business Services experienced a massive data breach affecting over 62.2 million individuals after hackers accessed its network for three months between October 2024 and January 2025. The breach, now ranked as the third-largest healthcare data breach in history, compromised protected health information including names, addresses, social security numbers, and medical records. Missouri regul
Singing River Health System: 54K Individuals Affected by December Cyberattack
Singing River Health System disclosed a December 2025 cyberattack affecting 53,888 individuals, where unauthorized access occurred between December 19-21, 2025, exposing comprehensive patient data including SSNs, financial information, and medical records. Additionally, Adams County Memorial Hospital reported a phishing incident affecting 5,305 individuals, and Central Kansas Mental Health Center
Patient Data Exposed in Cyberattacks on Dental Practices
Three dental practices—Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics—have disclosed data breaches affecting over 32,700 patients combined. The incidents involved unauthorized access to email accounts and network environments, exposing protected health information including names, Social Security numbers, medical records, and insurance details. All three organization
Family Medicine Centers Pays $2.15M to Resolve Data Breach Lawsuit
Family Medicine Centers (FMC Services, LLC) has agreed to a $2.15 million settlement to resolve consolidated class action lawsuits stemming from a July 2022 data breach that exposed personal and health information of approximately 234,000-267,000 individuals. The breach involved unauthorized access to network systems containing Social Security numbers, birth dates, addresses, and protected health
AIDashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
Password manager Dashlane disclosed a security incident where fewer than 20 personal subscription users had their encrypted vaults downloaded after a brute-force attack targeted their two-factor authentication. The attack, which occurred on May 31, 2026, was launched by an unknown external threat actor attempting to compromise user accounts.
Medical Billing Company Data Breach Affects 7 Medical Groups
Las Vegas-based medical billing company La Perouse has disclosed a data breach affecting seven medical group clients, compromising sensitive patient information including Social Security numbers and medical records. The breach, discovered in July 2025, occurred through unauthorized access to a third-party billing platform. Additionally, several other healthcare organizations including Acadia Healt
California AG Files Lawsuit Over 23andMe Data Breach
California Attorney General Rob Bonta has filed a lawsuit against 23andMe over a 2023 data breach that compromised the personal and genetic information of 6.9 million individuals, including over 855,000 California residents. The breach, which occurred through credential stuffing attacks over five months, exposed vulnerabilities in 23andMe's security practices and was allegedly mishandled by the co