Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIHighland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits
Highland Health Systems and Albany Gastroenterology Consultants have reached preliminary settlements for class action lawsuits stemming from 2023 and 2024 data breaches affecting 83,543 and 57,751 individuals respectively. Highland Health Systems agreed to a $650,000 settlement fund offering affected individuals either up to $5,000 in documented losses or approximately $85 cash payments plus two-y
AIStrict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
Strict data handling protocols have been established for attorneys managing the stolen Change Healthcare dataset in consolidated multidistrict litigation against UnitedHealth Group. The 2024 ransomware attack compromised 6 terabytes of data affecting approximately 192.7 million individuals, triggering over 150 lawsuits from patients and healthcare providers. The court-approved protective order man
Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals
Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts) experienced a data breach affecting approximately 312,000 individuals when an unauthorized third party accessed a legacy file server between December 15-16, 2025. The compromised data included sensitive information such as names, Social Security numbers, financial account details, and employee personnel records, though the
CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft
CareCloud, a cloud-based healthcare IT solutions provider, experienced a cyberattack between March 10-16, 2026, affecting one of its six EHR environments hosted on AWS. The breach compromised sensitive data of at least 345,000 patients, including Social Security numbers, financial information, and medical records. CareCloud has contained the incident, engaged third-party cybersecurity experts, and
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System agreed to pay $552,250 to settle a HIPAA investigation following a 2021 Nephilim ransomware attack that compromised the protected health information of 53,907 patients. The OCR investigation found OSF Healthcare failed to conduct proper risk analysis, made impermissible PHI disclosures, and did not provide timely breach notifications to affected individuals and HHS. The settl
Soniva Dental Care Data Breach Affects At Least 30,000 Patients
Four healthcare service providers have disclosed significant data breaches affecting tens of thousands of patients. Soniva Dental Care experienced the largest incident with 30,000 affected individuals after a ransomware attack by TheGentlemen group targeted their remote desktop infrastructure, while Optalis Management Solutions, CareCloud, and Hudson Valley Medical Billing reported breaches affect
Florida SUD Treatment Provider Announces 145,700-record Data Breach
Four healthcare and service providers have disclosed significant data breaches affecting over 180,000 individuals combined. Operation PAR, a Florida addiction treatment provider, suffered the largest breach impacting 145,714 individuals with exposed PHI including SSNs and financial data, while Eyemart Express, Vanderbilt Health, and Averhealth Holdings also reported incidents involving unauthorize
Data Breaches Announced by Open Arms Care; Elmwood Home Care
Two healthcare providers, Open Arms Care Corporation in Tennessee and Elmwood Home Care in Rhode Island/Massachusetts, have disclosed significant data breaches compromising patient information. Open Arms Care experienced unauthorized email account access from June to August 2025, while Elmwood Home Care suffered a suspected LockBit5 ransomware attack between January and February 2026. Both inciden
Data Breaches Announced by Two Digestive Health Companies
Two digestive health organizations, Gastro Health and Spokane Digestive Disease Center, have disclosed separate data breaches resulting from phishing attacks and unauthorized email account access. Both incidents exposed sensitive patient information including Social Security numbers, medical records, and financial data, affecting thousands of individuals across multiple states. The breaches occurr
Southern Illinois Ob-Gyn Associates Announces Data Breach Affecting 38,700 Individuals
Southern Illinois Ob-Gyn Associates disclosed a data breach affecting 38,700 individuals after unauthorized access to systems was detected in November 2025, compromising sensitive patient information including Social Security numbers and health records. Two additional healthcare-related breaches were reported: Wellpoint Washington experienced an email account compromise affecting 12,020 individual
$3.3M Settlement Resolves Data Breach Lawsuit Against Mt. Baker Imaging & Northwest Radiologists
Mt. Baker Imaging and Northwest Radiologists have agreed to a $3.3 million settlement following a January 2025 ransomware attack that compromised sensitive data of over 362,000 patients. The breach, which occurred between January 20-25, 2025, exposed names, Social Security numbers, health information, and other personal data, triggering multiple consolidated class action lawsuits alleging inadequa
Mission Community Hospital Pays $1.55M to Settle Data Breach Lawsuit
Mission Community Hospital, operated by Deanco Healthcare, has agreed to pay $1.55 million to settle a class action lawsuit following a May 2023 ransomware attack by the Ransomhouse group that compromised data of 269,547 patients. The breach exposed sensitive information including Social Security numbers, financial account data, and personal identifiers, with attackers claiming to have exfiltrated
Atrium Health & Interim HealthCare Affected by Business Associate Data Breaches
Atrium Health Navicent and Interim HealthCare facilities have disclosed data breaches stemming from third-party vendor compromises. Atrium Health was impacted by the January 2025 Oracle Health breach affecting legacy Cerner servers, with notification delayed until March 2026 due to complex data review processes. Interim HealthCare locations in Texas were affected by unauthorized access to the Doct
Verber Dental Group Notifies Patients About January Hacking Incident
Five healthcare organizations across the United States have disclosed data breaches affecting thousands of patients, with incidents ranging from email account compromises to unauthorized network access. The breaches, occurring between July 2025 and March 2026, exposed sensitive patient information including Social Security numbers, medical records, and health insurance details. All affected organi
