Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIData Breaches Announced by Five HIPAA-Regulated Entities
Five HIPAA-regulated entities across the United States have disclosed data breaches affecting over 86,000 individuals combined, with incidents ranging from network intrusions to email account compromises. The breaches exposed sensitive patient and employee information including Social Security numbers, medical records, financial data, and health insurance details. All affected organizations are of
AIData Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have disclosed data breaches affecting patient information, with incidents ranging from ransomware attacks to email account compromises occurring between October 2025 and May 2026. The breaches exposed sensitive patient data including names, Social Security numbers, medical records, and health insurance information, with threat actors Genesis ransomware group an
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, FBI, and international partners have issued a joint advisory warning about the Gunra ransomware-as-a-service operation targeting healthcare organizations and critical infrastructure globally. The group, which transitioned to a RaaS model in 2026, offers affiliates an 80% ransom cut and exploits known vulnerabilities in VPNs and firewalls to gain network access, conducting double extortion at
Data Breaches Reported by Sunshine Health; Health Payment Systems
Two healthcare-related organizations have reported significant data breaches affecting thousands of individuals. Sunshine Health, a Florida Medicaid insurer, fell victim to a vishing attack compromising 41,569 individuals' protected health information, while Health Payment Systems, a Wisconsin billing company, experienced an email security incident affecting 9,380 patients with unauthorized access
Data Breaches Announced by Loma Linda University Health & UCLA Health
Two major California healthcare systems have disclosed separate data breach incidents affecting patient information. Loma Linda University Health experienced a breach when patient data from a research study was inadvertently uploaded to an external AI platform, while UCLA Health reported improper disclosure of patient information to an outside healthcare provider over a 16-month period. Both organ
AIFree HIPAA Security Risk Assessment
HIPAA security risk assessments are mandatory evaluations that help healthcare organizations identify threats to protected health information (PHI), assess their likelihood and impact, and ensure adequate safeguards are in place. The requirements appear in both the HIPAA Security Rule for electronic PHI and the Breach Notification Rule, though organizations may need to conduct additional privacy r
Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks
Health-ISAC has issued a cybersecurity alert warning healthcare organizations about increasing attacks by ShinyHunters, a threat group that uses voice-based social engineering (vishing) to compromise cloud accounts and exfiltrate data from SaaS platforms. Unlike ransomware actors, ShinyHunters targets SSO systems like Okta and Microsoft Entra to gain access to multiple applications, then demands r
AIFree Webinar: Inside 250 HIPAA Investigations – What You Need to Know
Abyde is hosting a webinar featuring insights from over 250 actual OCR HIPAA investigations, led by their Chief Legal Officer and Senior VP of Operations. The session will cover investigation triggers, response protocols, common compliance failures, and real-world examples to help healthcare organizations avoid fines and lengthy investigations in an era of increasing ransomware breaches and patien
Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds
A business email compromise attack on a Children's Healthcare of Atlanta vendor in 2023 resulted in $5.3 million being stolen and redirected to accounts controlled by former CPA Ronald Deabler. Deabler, who conspired with the hacker to launder the funds in exchange for commission, was sentenced to four years in prison and ordered to pay over $682,000 in restitution, though approximately $4 million
INC Ransomware Thrives by Mastering the Basics
INC ransomware group has achieved success by focusing on fundamental attack strategies rather than sophisticated techniques. The group strategically targets sectors like healthcare where operational disruptions create urgent pressure to pay ransoms quickly, maximizing their likelihood of payment.
Clinical Registry Solutions; Jason R Egbert OD PC; VNC Health Announce Data Breaches
Three healthcare-related organizations have announced data breaches affecting patient information in early 2026. Clinical Registry Solutions experienced an Akira ransomware attack compromising patient and employee data, while First Sight Family Vision and VHC Health were impacted by breaches at their third-party vendors RXNT and Xsolis respectively, exposing sensitive patient information including
Clinical Trial Data Stolen in Novo Nordisk Cyberattack
Novo Nordisk, the pharmaceutical company behind Ozempic and Wegovy, disclosed a cyberattack that resulted in the theft of clinical trial data affecting both patients and healthcare providers. While patient data was pseudonymized (using random ID numbers rather than names), the breach exposed limited health information including biomarkers and lifestyle factors. Healthcare provider contact informat
Labcorp Agrees to $35M Settlement to Resolve AMCA Data Breach Litigation
Labcorp has agreed to a $35 million settlement to resolve class action litigation stemming from a 2018 data breach at its third-party collections vendor, American Medical Collection Agency (AMCA), which exposed protected health information of over 10.2 million Labcorp patients. The breach, which occurred between August 2018 and March 2019, was part of a larger incident affecting more than 25 milli
Florida Law Firm Data Breach Affects 65,000 Individuals
GrayRobinson, a Florida-based law firm, disclosed a data breach affecting 65,113 individuals after unauthorized network access between March 5-24, 2025, exposed sensitive personal and health information including SSNs, financial data, and medical records. Two additional healthcare-related breaches were reported: C2N Diagnostics in Missouri affecting 2,027 individuals, and Virta Health in Colorado,
Cybersecurity Incidents Reported by Multiple Dental Practices
Multiple dental practices across the U.S. have reported cybersecurity incidents affecting thousands of patients, with breaches ranging from ransomware attacks to phishing-based email compromises. The incidents exposed sensitive patient data including Social Security numbers, medical records, and insurance information, with Bayside Dental's breach affecting over 10,000 patients and involving a rans
Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach
DentaQuest, a dental benefits administrator serving 32 million Americans, has suffered a significant data breach claimed by the ShinyHunters extortion group. The breach exposed 234 GB of data including 2.6 million unique email addresses along with personal information such as names, addresses, phone numbers, and dates of birth, though Social Security numbers were not compromised. The incident repr
Onsite Women’s Health $2.5M Data Breach Settlement
Onsite Women's Health reached a $2.525 million settlement following a phishing-enabled email breach that exposed protected health information of 357,265 individuals, including Social Security numbers, financial data, and medical records. The consolidated class action lawsuit alleged inadequate security measures failed to prevent or quickly detect the October 2024 breach, though the company denies
Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients
Four healthcare organizations have reported significant data breaches affecting tens of thousands of patients. Clarinda Regional Health Center in Iowa experienced the largest breach, affecting 24,341 individuals through a LockBit5 ransomware attack that exposed comprehensive personal and medical data including Social Security numbers, financial information, and health records. The incidents highli
Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals
Conduent Business Services experienced a massive data breach affecting over 62.2 million individuals after hackers accessed its network for three months between October 2024 and January 2025. The breach, now ranked as the third-largest healthcare data breach in history, compromised protected health information including names, addresses, social security numbers, and medical records. Missouri regul
