Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
FMC Services Agrees to $2.15M Settlement to End Data Breach Lawsuit
FMC Services LLC, a Texas-based primary care clinic operator, has agreed to a $2.15 million settlement to resolve a consolidated class action lawsuit stemming from a 2022 cyberattack that exposed protected health information of over 233,000 individuals. The breach compromised sensitive data including Social Security numbers, health records, and personal identifiers, leading to claims of negligence
AIBusiness Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar
Healthcare third-party vendor breaches have surged dramatically, with business associate involvement in breaches rising from 20% (2009-2017) to 43% in early 2026, prompting increased regulatory scrutiny from HHS OCR. Vendors present attractive targets for threat actors due to their access to multiple healthcare clients' data, with 65% of affected individuals in 2025 breaches involving business ass
Labcorp Agrees to $35M Settlement to Resolve AMCA Data Breach Litigation
Labcorp has agreed to a $35 million settlement to resolve class action litigation stemming from a 2018 data breach at its third-party collections vendor, American Medical Collection Agency (AMCA), which exposed protected health information of over 10.2 million Labcorp patients. The breach, which occurred between August 2018 and March 2019, was part of a larger incident affecting more than 25 milli
PHI Compromised in Cyber Incidents at Medenet; United Medical Doctors; Stewart Home & School
Three healthcare-related organizations have disclosed cybersecurity incidents compromising protected health information (PHI). Medenet, a Florida revenue cycle management provider, United Medical Doctors in California, and Kentucky's Stewart Home & School all experienced unauthorized access to their systems, with incidents ranging from December 2025 to March 2026, affecting thousands of individual
Florida Law Firm Data Breach Affects 65,000 Individuals
GrayRobinson, a Florida-based law firm, disclosed a data breach affecting 65,113 individuals after unauthorized network access between March 5-24, 2025, exposed sensitive personal and health information including SSNs, financial data, and medical records. Two additional healthcare-related breaches were reported: C2N Diagnostics in Missouri affecting 2,027 individuals, and Virta Health in Colorado,
Duke University Health System; Derick Dermatology Settle Class Action Pixel Lawsuits
Duke University Health System and Derick Dermatology have settled separate class action lawsuits alleging unauthorized use of website tracking pixels that transmitted patients' personal health information to third parties like Meta. Duke agreed to a $3.7 million settlement fund while Derick Dermatology agreed to pay up to $1 million, with both organizations denying any wrongdoing despite agreeing
Data Breaches Announced by Two Digestive Health Companies
Two digestive health organizations, Gastro Health and Spokane Digestive Disease Center, have disclosed separate data breaches resulting from phishing attacks and unauthorized email account access. Both incidents exposed sensitive patient information including Social Security numbers, medical records, and financial data, affecting thousands of individuals across multiple states. The breaches occurr
Henderson & Walton Women’s Center Settles Class Action Data Breach Lawsuit
Henderson & Walton Women's Center has agreed to settle a class action lawsuit following a 2022 email account breach that exposed personal and protected health information of 34,306 patients. The unauthorized access occurred over a three-day period in February 2022, compromising names, dates of birth, identification numbers, and medical information. While denying wrongdoing, the healthcare provider
Southern Illinois Ob-Gyn Associates Announces Data Breach Affecting 38,700 Individuals
Southern Illinois Ob-Gyn Associates disclosed a data breach affecting 38,700 individuals after unauthorized access to systems was detected in November 2025, compromising sensitive patient information including Social Security numbers and health records. Two additional healthcare-related breaches were reported: Wellpoint Washington experienced an email account compromise affecting 12,020 individual
HSCC Issues Guidance on Cyber Governance Frameworks for Secure AI implementation
The Health Sector Coordinating Council (HSCC) has released comprehensive guidance to help healthcare CISOs establish cybersecurity governance frameworks for secure AI implementation. The 87-page framework addresses AI-specific cyber risks including data poisoning, model drift, and bias, while providing practical tools for managing AI systems throughout their lifecycle from assessment to decommissi
Onsite Women’s Health $2.5M Data Breach Settlement
Onsite Women's Health reached a $2.525 million settlement following a phishing-enabled email breach that exposed protected health information of 357,265 individuals, including Social Security numbers, financial data, and medical records. The consolidated class action lawsuit alleged inadequate security measures failed to prevent or quickly detect the October 2024 breach, though the company denies
Clarinda Regional Health Center Reports Data Breach Affecting 24K Patients
Four healthcare organizations have reported significant data breaches affecting tens of thousands of patients. Clarinda Regional Health Center in Iowa experienced the largest breach, affecting 24,341 individuals through a LockBit5 ransomware attack that exposed comprehensive personal and medical data including Social Security numbers, financial information, and health records. The incidents highli
Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals
Conduent Business Services experienced a massive data breach affecting over 62.2 million individuals after hackers accessed its network for three months between October 2024 and January 2025. The breach, now ranked as the third-largest healthcare data breach in history, compromised protected health information including names, addresses, social security numbers, and medical records. Missouri regul
Singing River Health System: 54K Individuals Affected by December Cyberattack
Singing River Health System disclosed a December 2025 cyberattack affecting 53,888 individuals, where unauthorized access occurred between December 19-21, 2025, exposing comprehensive patient data including SSNs, financial information, and medical records. Additionally, Adams County Memorial Hospital reported a phishing incident affecting 5,305 individuals, and Central Kansas Mental Health Center
$3.3M Settlement Resolves Data Breach Lawsuit Against Mt. Baker Imaging & Northwest Radiologists
Mt. Baker Imaging and Northwest Radiologists have agreed to a $3.3 million settlement following a January 2025 ransomware attack that compromised sensitive data of over 362,000 patients. The breach, which occurred between January 20-25, 2025, exposed names, Social Security numbers, health information, and other personal data, triggering multiple consolidated class action lawsuits alleging inadequa
Parents Sue Minnesota Hospital to Enforce HIPAA Right of Access for Minor Child’s Medical Records
Parents of a 15-year-old with a rare chromosomal condition have sued a Minnesota hospital after being denied full access to their daughter's medical records through the MyChart portal. The hospital's policy, based on state law interpretation, restricts parental access to minors' records after age 12 unless the child consents following a private interview. The lawsuit argues that federal HIPAA law,
Patient Data Exposed in Cyberattacks on Dental Practices
Three dental practices—Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics—have disclosed data breaches affecting over 32,700 patients combined. The incidents involved unauthorized access to email accounts and network environments, exposing protected health information including names, Social Security numbers, medical records, and insurance details. All three organization
Family Medicine Centers Pays $2.15M to Resolve Data Breach Lawsuit
Family Medicine Centers (FMC Services, LLC) has agreed to a $2.15 million settlement to resolve consolidated class action lawsuits stemming from a July 2022 data breach that exposed personal and health information of approximately 234,000-267,000 individuals. The breach involved unauthorized access to network systems containing Social Security numbers, birth dates, addresses, and protected health
Medical Billing Company Data Breach Affects 7 Medical Groups
Las Vegas-based medical billing company La Perouse has disclosed a data breach affecting seven medical group clients, compromising sensitive patient information including Social Security numbers and medical records. The breach, discovered in July 2025, occurred through unauthorized access to a third-party billing platform. Additionally, several other healthcare organizations including Acadia Healt