Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAesto Health Data Security Incident Affects Multiple Healthcare Provider Clients
Aesto Health, a Birmingham-based healthcare technology provider specializing in data migration and EHR exchanges, experienced a data breach affecting its AWS infrastructure between December 2-18, 2025, compromising sensitive patient information including SSNs, medical records, and financial data. The incident impacted over two dozen healthcare provider clients and hundreds of thousands of patients
AIZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
ZOLL Medical Corporation has agreed to a $3.5 million settlement following a January 2023 data breach that exposed personal and health information of over 1 million individuals, primarily LifeVest wearable defibrillator patients. The settlement, which received preliminary court approval, consolidates 15 class action lawsuits alleging HIPAA violations, negligence, and failure to implement adequate
AIOnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits
OnePoint Patient Care and Clay-Platte Family Medicine have reached settlements totaling $3.115 million to resolve class action lawsuits stemming from 2024 data breaches affecting over 1.7 million individuals. The lawsuits alleged negligence in implementing adequate cybersecurity measures, with hackers gaining unauthorized access to protected health information including Social Security numbers and
AIHighland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits
Highland Health Systems and Albany Gastroenterology Consultants have reached preliminary settlements for class action lawsuits stemming from 2023 and 2024 data breaches affecting 83,543 and 57,751 individuals respectively. Highland Health Systems agreed to a $650,000 settlement fund offering affected individuals either up to $5,000 in documented losses or approximately $85 cash payments plus two-y
AIStrict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
Strict data handling protocols have been established for attorneys managing the stolen Change Healthcare dataset in consolidated multidistrict litigation against UnitedHealth Group. The 2024 ransomware attack compromised 6 terabytes of data affecting approximately 192.7 million individuals, triggering over 150 lawsuits from patients and healthcare providers. The court-approved protective order man
AICritical Vulnerabilities Identified in Popular Consumer Fertility Device
Critical security vulnerabilities have been discovered in two consumer health devices: the Mira Hormone Monitor fertility tracker and the Pulsetto Vagus Nerve Stimulator. The Mira device contained 20 vulnerabilities including two critical flaws that could expose sensitive reproductive health data and enable account takeover, while the Pulsetto device has an unpatched vulnerability allowing unautho
AIData Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have disclosed data breaches affecting patient information, with incidents ranging from ransomware attacks to email account compromises occurring between October 2025 and May 2026. The breaches exposed sensitive patient data including names, Social Security numbers, medical records, and health insurance information, with threat actors Genesis ransomware group an
Data Breaches Announced by Loma Linda University Health & UCLA Health
Two major California healthcare systems have disclosed separate data breach incidents affecting patient information. Loma Linda University Health experienced a breach when patient data from a research study was inadvertently uploaded to an external AI platform, while UCLA Health reported improper disclosure of patient information to an outside healthcare provider over a 16-month period. Both organ
Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance
Two healthcare organizations, McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts, have reached settlements to resolve class action lawsuits stemming from data breaches in 2025 and 2023 respectively. McKenzie Health's breach affected 58,839 individuals and offers two years of credit monitoring plus up to $4,000 in reimbursement or $50 cash payments, while Aspire Health A
Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic
Two healthcare organizations, Omni Healthcare Financial Holdings and Western Montana Clinic, have reached settlements in class action lawsuits following data breaches affecting 16,852 and 8,255 individuals respectively. Both breaches exposed sensitive protected health information including Social Security numbers, medical records, and treatment details, with lawsuits alleging failures to implement
Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals
Brown Health Medical Group-MA (Lifespan Physicians Group of Massachusetts) experienced a data breach affecting approximately 312,000 individuals when an unauthorized third party accessed a legacy file server between December 15-16, 2025. The compromised data included sensitive information such as names, Social Security numbers, financial account details, and employee personnel records, though the
AIFree HIPAA Security Risk Assessment
HIPAA security risk assessments are mandatory evaluations that help healthcare organizations identify threats to protected health information (PHI), assess their likelihood and impact, and ensure adequate safeguards are in place. The requirements appear in both the HIPAA Security Rule for electronic PHI and the Breach Notification Rule, though organizations may need to conduct additional privacy r
CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft
CareCloud, a cloud-based healthcare IT solutions provider, experienced a cyberattack between March 10-16, 2026, affecting one of its six EHR environments hosted on AWS. The breach compromised sensitive data of at least 345,000 patients, including Social Security numbers, financial information, and medical records. CareCloud has contained the incident, engaged third-party cybersecurity experts, and
AIFree Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team)
A free webinar scheduled for August 7, 2026, will address how small healthcare practices can achieve HIPAA-compliant email without dedicated IT staff. The session will explain why standard email solutions like Gmail and Microsoft 365 are insufficient for HIPAA compliance and demonstrate practical approaches to closing security gaps while maintaining ease of use for both staff and patients.
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System agreed to pay $552,250 to settle a HIPAA investigation following a 2021 Nephilim ransomware attack that compromised the protected health information of 53,907 patients. The OCR investigation found OSF Healthcare failed to conduct proper risk analysis, made impermissible PHI disclosures, and did not provide timely breach notifications to affected individuals and HHS. The settl
AIFree Webinar: Inside 250 HIPAA Investigations – What You Need to Know
Abyde is hosting a webinar featuring insights from over 250 actual OCR HIPAA investigations, led by their Chief Legal Officer and Senior VP of Operations. The session will cover investigation triggers, response protocols, common compliance failures, and real-world examples to help healthcare organizations avoid fines and lengthy investigations in an era of increasing ransomware breaches and patien
Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits
Banner Health and LifeStance Health Group have agreed to settle class action lawsuits alleging unauthorized disclosure of patient data to Meta and Google through website tracking pixels and analytics tools. Banner Health will compensate approximately 1.028 million affected individuals with $20 payments plus identity protection services, while LifeStance established a $3 million settlement fund for
Soniva Dental Care Data Breach Affects At Least 30,000 Patients
Four healthcare service providers have disclosed significant data breaches affecting tens of thousands of patients. Soniva Dental Care experienced the largest incident with 30,000 affected individuals after a ransomware attack by TheGentlemen group targeted their remote desktop infrastructure, while Optalis Management Solutions, CareCloud, and Hudson Valley Medical Billing reported breaches affect
AIHow to Become HIPAA Compliant
This article outlines a practical framework for achieving HIPAA compliance based on HHS's Seven Fundamental Elements of an Effective Compliance Program, updated for 2026 relevance. The approach emphasizes developing comprehensive policies, designating compliance officers, implementing effective training, establishing communication channels, monitoring practices, enforcing sanctions fairly, and res
