Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Clinical Registry Solutions; Jason R Egbert OD PC; VNC Health Announce Data Breaches
Three healthcare-related organizations have announced data breaches affecting patient information in early 2026. Clinical Registry Solutions experienced an Akira ransomware attack compromising patient and employee data, while First Sight Family Vision and VHC Health were impacted by breaches at their third-party vendors RXNT and Xsolis respectively, exposing sensitive patient information including
Clinical Trial Data Stolen in Novo Nordisk Cyberattack
Novo Nordisk, the pharmaceutical company behind Ozempic and Wegovy, disclosed a cyberattack that resulted in the theft of clinical trial data affecting both patients and healthcare providers. While patient data was pseudonymized (using random ID numbers rather than names), the breach exposed limited health information including biomarkers and lifestyle factors. Healthcare provider contact informat
Labcorp Agrees to $35M Settlement to Resolve AMCA Data Breach Litigation
Labcorp has agreed to a $35 million settlement to resolve class action litigation stemming from a 2018 data breach at its third-party collections vendor, American Medical Collection Agency (AMCA), which exposed protected health information of over 10.2 million Labcorp patients. The breach, which occurred between August 2018 and March 2019, was part of a larger incident affecting more than 25 milli
Florida Law Firm Data Breach Affects 65,000 Individuals
GrayRobinson, a Florida-based law firm, disclosed a data breach affecting 65,113 individuals after unauthorized network access between March 5-24, 2025, exposed sensitive personal and health information including SSNs, financial data, and medical records. Two additional healthcare-related breaches were reported: C2N Diagnostics in Missouri affecting 2,027 individuals, and Virta Health in Colorado,
Cybersecurity Incidents Reported by Multiple Dental Practices
Multiple dental practices across the U.S. have reported cybersecurity incidents affecting thousands of patients, with breaches ranging from ransomware attacks to phishing-based email compromises. The incidents exposed sensitive patient data including Social Security numbers, medical records, and insurance information, with Bayside Dental's breach affecting over 10,000 patients and involving a rans
Hacking Group Claims Responsibility for Multi-Million-Record DentaQuest Data Breach
DentaQuest, a dental benefits administrator serving 32 million Americans, has suffered a significant data breach claimed by the ShinyHunters extortion group. The breach exposed 234 GB of data including 2.6 million unique email addresses along with personal information such as names, addresses, phone numbers, and dates of birth, though Social Security numbers were not compromised. The incident repr
Onsite Women’s Health $2.5M Data Breach Settlement
Onsite Women's Health reached a $2.525 million settlement following a phishing-enabled email breach that exposed protected health information of 357,265 individuals, including Social Security numbers, financial data, and medical records. The consolidated class action lawsuit alleged inadequate security measures failed to prevent or quickly detect the October 2024 breach, though the company denies
Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients
Four healthcare organizations have reported significant data breaches affecting tens of thousands of patients. Clarinda Regional Health Center in Iowa experienced the largest breach, affecting 24,341 individuals through a LockBit5 ransomware attack that exposed comprehensive personal and medical data including Social Security numbers, financial information, and health records. The incidents highli
Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals
Conduent Business Services experienced a massive data breach affecting over 62.2 million individuals after hackers accessed its network for three months between October 2024 and January 2025. The breach, now ranked as the third-largest healthcare data breach in history, compromised protected health information including names, addresses, social security numbers, and medical records. Missouri regul
Singing River Health System: 54K Individuals Affected by December Cyberattack
Singing River Health System disclosed a December 2025 cyberattack affecting 53,888 individuals, where unauthorized access occurred between December 19-21, 2025, exposing comprehensive patient data including SSNs, financial information, and medical records. Additionally, Adams County Memorial Hospital reported a phishing incident affecting 5,305 individuals, and Central Kansas Mental Health Center
Patient Data Exposed in Cyberattacks on Dental Practices
Three dental practices—Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics—have disclosed data breaches affecting over 32,700 patients combined. The incidents involved unauthorized access to email accounts and network environments, exposing protected health information including names, Social Security numbers, medical records, and insurance details. All three organization
Medical Billing Company Data Breach Affects 7 Medical Groups
Las Vegas-based medical billing company La Perouse has disclosed a data breach affecting seven medical group clients, compromising sensitive patient information including Social Security numbers and medical records. The breach, discovered in July 2025, occurred through unauthorized access to a third-party billing platform. Additionally, several other healthcare organizations including Acadia Healt
HIPAA Security Rule Training Requirements
HIPAA Security Rule training requirements mandate that covered entities and business associates provide comprehensive security awareness training to all workforce members, not just those with direct patient record access. The training must cover electronic Protected Health Information (ePHI) protection, security policies, threat recognition, incident reporting, and the distinctions between HIPAA v