Healthcare Security Intelligence
Tracking breaches, regulatory updates, and threats affecting hospitals, clinics, and health technology.
Latest Intelligence
View All →AdaptHealth, LLC - Data Breach
AdaptHealth, LLC experienced a data breach on June 15, 2026, when an unauthorized third party gained access to company systems through a social engineering attack targeting a single user account on June 5, 2026. The compromised data may include patient names, contact information, demographic information, health insurance details, and health information related to durable medical equipment orders and referring healthcare providers. AdaptHealth has secured the services of Kroll to provide identity monitoring for affected individuals and has reported the incident to law enforcement.
Allied Health - Data Breach
On or about December 18, 2025, Aesto, a healthcare data migration and archiving service provider for Allied Health, experienced a network security incident impacting a portion of its Amazon Web Services infrastructure. An investigation confirmed that between December 2, 2025, and December 18, 2025, an unauthorized actor may have accessed and/or acquired a limited amount of personal information pertaining to patient care, including full name and unspecified variable text. Aesto has no evidence of misuse. Allied Health was notified on June 26, 2026, and confirmed the scope of the impact on July 22, 2026. Affected individuals are offered complimentary credit monitoring and identity theft protection services through Cyberscout.
American Addiction Centers - Data Breach
American Addiction Centers (AAC) disclosed a data breach that occurred on May 12, 2026, involving a third-party vendor. The company learned of suspicious activity in its Salesforce environment on June 5, 2026, and an investigation determined that an unauthorized third party acquired certain information from their Salesforce instance on May 12, 2026. The incident did not involve access to AAC's internal systems, network, or electronic health records. The exposed information included the victim's name, contact information, Social Security number, and a brief description of their health, which was obtained during an initial outreach to AAC and not from their EHR application. AAC is implementing additional safeguards and offering a complimentary membership to Privacy Solutions ID through Epiq for identity protection.
Boston Healthcare for the Homeless Program - Data Breach
Boston Health Care for the Homeless Program (BHCHP) experienced a data security incident where certain patient or employee personal information may have been accessed or acquired without authorization. The incident was initially learned of on November 11, 2025, and discovered on June 8, 2026. BHCHP has no evidence of misuse of the impacted information. Affected individuals are being offered 12 months of free credit monitoring and fraud assistance services through Cyberscout, a TransUnion company.
Kaniksu Community Health - Data Breach
Kaniksu Community Health experienced a data incident involving its healthcare data management service provider, Aesto, LLC. The incident occurred on or about December 18, 2025, and Aesto notified Kaniksu on June 26, 2026. Patient data may have been accessed or acquired due to unauthorized access to Aesto's platform. Kaniksu is offering identity monitoring services through Kroll to affected individuals.
Kern Psychiatric Health and Wellness Center, Inc - Data Breach
Kern Psychiatric Health and Wellness Center, Inc. was notified of a data breach that occurred on June 22, 2026, when their management company, Genesis Healthcare Management, discovered unusual activity on their network. An investigation revealed that certain files containing PWC data were accessed without authorization. The potentially impacted information includes patient names along with sensitive details such as Social Security numbers, driver's license numbers, dates of birth, diagnosis and treatment information, prescription details, provider information, dates of service, medical record and patient account numbers, Medicare/Medicaid IDs, lab results, and health insurance information. Genesis Healthcare Management has implemented additional security measures, notified law enforcement, and is reviewing its data protection policies. The company is offering complimentary credit monitoring and identity protection services to affected individuals.
Livara Health Medical Group - dba SpineZone - Data Breach
Aesto, LLC, a healthcare data migration and archiving service provider for Livara Health Medical Group (dba SpineZone), experienced a network security incident impacting a portion of their Amazon Web Services infrastructure. The incident occurred around December 18, 2025, and an investigation confirmed between December 2, 2025, and December 18, 2025, that a limited amount of protected health information, including full names, may have been accessed or acquired by an unauthorized actor. Aesto has no evidence of misuse but is offering complimentary credit monitoring and identity theft protection services from TransUnion.
Murfreesboro Medical Clinic - Data Breach
Murfreesboro Medical Clinic disclosed a data breach on December 2, 2025. The notification letter suggests precautionary measures such as placing fraud alerts and security freezes on credit files, obtaining credit reports, and monitoring financial accounts. The clinic is offering free credit monitoring and identity protection services through Cyberscout, a TransUnion company, for twelve months. Affected individuals are encouraged to enroll within 90 days of the letter's date. The letter also advises reviewing credit reports and account statements for suspicious activity and provides information on fraud alerts.
Nebraska Orthopaedic Center, P.C. - Data Breach
Aesto LLC, a data migration and archiving service provider for Nebraska Orthopaedic Center, P.C., experienced a network security incident on or about December 18, 2025. The incident impacted a limited portion of their Amazon Web Services infrastructure. An unauthorized actor may have accessed and/or acquired sensitive information between December 2, 2025, and December 18, 2025. The potentially impacted data includes full name, medical record number, date of birth, and Social Security number. Aesto has no evidence of misuse of the information and has notified affected Covered Entities. The incident was contained to Aesto's AWS infrastructure and did not affect the systems of the Covered Entities.
Northern Inyo Healthcare District d/b/a Northern Inyo Hospital - Data Breach
Northern Inyo Healthcare District d/b/a Northern Inyo Hospital experienced a data security incident involving its service provider, Aesto, LLC. On or about December 18, 2025, Aesto experienced a network security incident impacting a portion of its Amazon Web Services infrastructure. A forensic investigation confirmed that between December 2, 2025, and December 18, 2025, a limited amount of protected health information, including full name, may have been accessed or acquired by an unauthorized actor. Aesto has no evidence of misuse but is offering complimentary identity protection services.
Quantum Health, Inc. - Data Breach
Quantum Health, Inc. experienced a data security incident where unauthorized access to their IT network occurred after a user responded to a vishing call on May 29, 2026. Between May 29, 2026, and June 1, 2026, an unauthorized party accessed and acquired files containing personal and health information. The company discovered the service outage related to this unauthorized access on June 1, 2026, and launched an investigation. It was determined on July 8, 2026, that some files contained affected individuals' information. Quantum Health is offering identity monitoring services through Kroll.
Silver Summit Medical Corporation - Data Breach
Silver Summit Medical Corporation (SSMC), doing business as Digestive Disease Center and Heart Vascular & Leg Center, disclosed a data breach that occurred due to a third-party vendor's cybersecurity event. Between November 27, 2025, and November 30, 2025, unauthorized access to certain data from the vendor's systems resulted in the acquisition of personal and protected health information. The exposed data includes the individual's name. SSMC is offering 12 months of free credit monitoring and identity restoration services through Cyberscout.
Terry J. Dubrow, MD, A Medical Corporation - Data Breach
Terry J. Dubrow, MD, A Medical Corporation experienced a data security incident where an unauthorized actor gained access to a portion of their network from January 16, 2025. The investigation determined that certain data was acquired. The breach was disclosed on June 21, 2026, with the company learning of the specific impact on July 27, 2026. The exposed data includes patient names, driver's license or state ID numbers, phone numbers, mailing addresses, email addresses, Social Security Numbers, and medical information such as date of birth, prescription details, treatment information, procedure images, and x-rays. The company is offering complimentary identity protection services and has reported the incident to the FBI.
The Health Trust and its subsidiary, FASS - Data Breach
The Health Trust, a non-profit assisting governmental and non-governmental organizations, disclosed a data breach on May 26, 2025. Suspicious activity was first identified on May 26, 2025, leading to network security measures. Further suspicious activity on June 11, 2025, prompted the company to take its systems offline for investigation. The investigation revealed that an unknown actor gained access to certain Health Trust systems prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025, accessing and/or copying information. The affected data, which was processed by their subsidiary FASS, included the recipient's name and other unspecified information. There is no evidence of actual or attempted fraud or identity theft. The Health Trust is offering complimentary credit monitoring services and has reported the event to law enforcement.
Together Women's Health LLC - Aesto - Data Breach
Together Women's Health LLC - Aesto disclosed a data breach on December 2, 2025. The notification letter provides guidance on protecting personal information, including placing fraud alerts and security freezes on credit files, obtaining credit reports, and remaining vigilant in reviewing financial statements. It also suggests steps to protect medical information. A dedicated toll-free response line (833-918-8060) is available for questions, staffed by professionals knowledgeable about the incident. The letter also includes information on obtaining an IP PIN from the IRS to prevent tax-related identity theft and directs individuals to resources from the Fair Credit Reporting Act and the Federal Trade Commission, along with state-specific attorney general contact information for Connecticut, District of Columbia, Iowa, Kentucky, and Massachusetts.
Virta Health Corp. and Virta Medical, PC - Data Breach
Virta Health Corp. and Virta Medical, P.C. experienced a data security incident where unauthorized activity was identified in a separate data repository. The incident occurred between March 19, 2026, and March 22, 2026, and potentially exposed personal information including first and last name along with other unspecified data elements. The company has secured the environment, engaged cybersecurity experts, and notified law enforcement. No indication of data misuse has been found. As a precautionary measure, Virta Health is offering complimentary single bureau credit monitoring and fraud assistance services to affected individuals.
Everside Health - Data Breach
Aesto, LLC, a healthcare data migration and archiving service provider for Everside Health, experienced a network security incident on or about December 18, 2025, impacting a limited portion of its Amazon Web Services infrastructure. An investigation confirmed that between December 2, 2025, and December 18, 2025, an unauthorized actor may have accessed and/or acquired a limited amount of protected health information, including full name and other unspecified elements. Aesto has no evidence of misuse but is offering identity protection services out of an abundance of caution. The incident was disclosed on December 2, 2025, with notification to the healthcare provider on June 26, 2026.
Stanislaus County Health Services Agency - Data Breach
Stanislaus County Health Services Agency was impacted by a data security incident at Aesto, LLC, a healthcare data migration and archiving service provider. On or about December 18, 2025, Aesto experienced a network security incident affecting a portion of its Amazon Web Services infrastructure. An investigation confirmed that between December 2, 2025, and December 18, 2025, a limited amount of protected health information, including full name and other unspecified elements, stored on Aesto's network may have been accessed or acquired by an unauthorized actor. Aesto has no evidence of misuse but is offering complimentary identity protection services.
CareCloud, Inc. - Data Breach
CareCloud, Inc., a healthcare solutions provider, experienced a network disruption in its CareCloud Health division on March 16, 2026, impacting an electronic health record environment. An investigation revealed that between March 10 and March 16, 2026, an unauthorized third party accessed an AWS environment and claimed to have exfiltrated data. The affected data may have included full names and other unspecified protected health information. CareCloud has engaged cybersecurity experts, secured the environment, and is strengthening its systems. They are offering identity theft protection services to affected individuals.
Regional Center of Orange County - Data Breach
On May 27, 2026, a janitorial service contracted by the Regional Center of Orange County (RCOC) mistakenly disposed of documents containing personal information into regular trash instead of secure destruction bins. The documents could not be recovered after the trash was collected. The affected information may include name, address, date of birth, phone number, email address, Unique Client Identifier (UCI) number, and personal health information. No Social Security numbers, financial account numbers, or medical record numbers were involved. RCOC has implemented secure destruction containers, is reviewing procedures and vendor oversight, and is offering a complimentary one-year membership to Experian IdentityWorks services.
Devereux Foundation - Data Breach
On November 9, 2025, Devereux Foundation discovered suspicious activity on its computer network, which was later determined to be unauthorized access from November 6 to November 9, 2025. An investigation revealed that an unauthorized actor copied files without permission. A review completed on June 23, 2026, confirmed that the impacted files contained the recipient's name and other unspecified information. Devereux is offering complimentary credit monitoring through Experian and has notified regulators and law enforcement.
Unlimited Technology Systems, LLC - Data Breach
Unlimited Technology Systems, LLC, a provider of practice management software to healthcare organizations, experienced a data security incident between October 5 and October 10, 2025, which was discovered on October 19, 2025. An unauthorized actor obtained a copy of personal information, potentially including name, health insurance and patient balance information, medical information, scanned documents (like driver's licenses and insurance cards), Social Security number, date of birth, email, address, phone number, and demographic information. The company has hired a cybersecurity firm, notified law enforcement, and is offering two years of identity monitoring services through Kroll.
ZenPatient, Inc. - Data Breach
ZenPatient, Inc. experienced a data breach between December 5, 2025, and February 12, 2026, where an unauthorized actor accessed or copied certain patient data. The breach was identified on or around February 27, 2026, and the company completed its investigation and data review by July 1, 2026. The exposed data includes the affected individual's name and other unspecified data elements labeled as '[Extra1]'. ZenPatient is offering 12 months of free credit monitoring and identity theft protection services through Experian and has notified federal law enforcement.
BAYADA Home Health Care, Inc. - Data Breach
BAYADA Home Health Care, Inc. disclosed a data privacy event on March 2, 2026, where an unauthorized actor gained access to certain BAYADA systems and copied data between February 18 and March 2, 2026. The investigation, completed on July 1, 2026, identified that the exposed data included individuals' names and other unspecified information. BAYADA has initiated incident response protocols, engaged third-party specialists, reviewed safeguards, and reported the event to governmental agencies. Affected individuals are encouraged to monitor their accounts and credit reports and are offered credit monitoring services.
DentaQuest LLC - Data Breach
DentaQuest LLC experienced a data security incident where unauthorized individuals accessed personal identification and dental or vision health information on their computer network. The incident began on May 17, 2026, and ended by May 20, 2026. The accessed information, including names, health details, provider names, diagnoses, treatments, and billing information, was subsequently posted on the internet. DentaQuest is offering affected individuals 24 months of identity monitoring services through Kroll.
Madera Community Hospital - Data Breach
Madera Community Hospital detected suspicious activity on its network on May 29, 2025. A subsequent investigation revealed that an unauthorized third party gained access to the network for two days in late May 2025. While no files were initially identified as taken, later developments led the hospital to believe that files containing personal and/or protected health information may have been acquired. The hospital has not found definitive proof of data exfiltration or public release. The investigation and data review were completed in April 2026, leading to this notification. Affected individuals are being offered free identity-theft-protection services.
North Coast Opportunities, Inc. / Redwood Caregiver Resource Center - Data Breach
North Coast Opportunities, Inc. / Redwood Caregiver Resource Center disclosed a data breach on June 30, 2026, where an email sent to caregivers contained incorrect personal information, including names and email addresses. The company advised recipients to delete the email immediately and take steps to prevent further dissemination. The exact number of affected records was not specified.
Alta Orthopaedics Medical Group, Inc. - Data Breach
Alta Orthopaedics Medical Group, Inc. discovered unusual network activity on March 10, 2026, leading to an investigation that determined unauthorized access to certain information occurred between February 3, 2026, and February 6, 2026. The potentially exposed data may include patient names along with addresses, phone numbers, email addresses, Social Security numbers, driver's license numbers, dates of birth, billing codes, dates of service, reasons for visit, treatment costs, provider names, medical diagnoses, clinical information, treatment locations, medical record numbers, patient account numbers, and health insurance information. The company has reset passwords, notified law enforcement, reviewed policies, and is offering credit monitoring and identity protection services to affected individuals.
TriWest Healthcare Alliance - Data Breach
TriWest Healthcare Alliance discovered unauthorized activity on its network on April 16, 2026, where an unauthorized person accessed and downloaded some TriWest information. The exposed data may include name, Department of Defense Benefits Number, ZIP code, and type of authorization request. TriWest has implemented increased security controls, monitoring, and employee training, and is offering 24 months of free identity monitoring services through Experian IdentityWorks.
Glucobit Inc. - Data Breach
Glucobit Inc., operating as Reframe, experienced a data breach where a single system was accessed without authorization. Personal information uploaded to Reframe was downloaded without authorization on or around May 1, 2026. The breach did not involve passwords, home/mailing addresses, payment card or account information, financial information, Social Security numbers, driver's license numbers, or other government identifiers. Reframe is offering 12 months of complimentary credit monitoring and dark web monitoring services through TransUnion and has enhanced its security measures.