Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

Boston Children’s Hospital named in North Korean hacking operation

By: Dissent
7 August 2026 at 13:37
Naomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device. Mr. Stykas, chief technology officer at...

Source

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients

By: Dissent
7 August 2026 at 09:38
HIPAA Journal reports an update to the Unlimited Technology Systems breach that occurred between October 10 – 15, 2025, and was discovered on October 19, 2025: On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based provider of revenue cycle management services. At the time, the...

Source

AU: Updoc patients notified of security breach where personal information may have been stolen

By: Dissent
5 August 2026 at 09:38
Emma Kirk reports: Updoc patients have been notified their personal information may have been accessed in a security breach. The website is used for 24/7 telehealth services across Australia. Customers were advised there was a “brief period of unauthorised access to a third party system” where hackers had access to names, email and postal addresses...

Source

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

By: Dissent
1 August 2026 at 10:30
Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and...

Source

CareCloud Data Breach Impacts Over 350,000

By: Dissent
1 August 2026 at 10:25
Ionut Arghire reports: Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between...

Source

AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked

By: Dissent
1 August 2026 at 10:16
Will Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April after a phishing attack. It wasn’t until almost three months later...

Source

Mon General Hospital notifies patients of phishing attack and breach

By: Dissent
1 August 2026 at 10:14
WDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, when they identified that a phishing attack had targeted a small number...

Source

AMGEN reports breach to SEC

By: Dissent
31 July 2026 at 21:45
From Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged...

Source

Family says woman violated HIPAA, ‘weaponized’ info

By: Dissent
30 July 2026 at 12:48
Chris Dickerson reports: A medical administrator spent years secretly accessing a family’s medical records and “weaponizing” their private health information for a family dispute, according to a newly filed civil lawsuit. The plaintiffs, identified only by their initials, filed the complaint July 23 in Kanawha Circuit Court against Sarah Gross, West Virginia University Medical Corporation...

Source

Accountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors say (1)

By: Dissent
27 July 2026 at 07:15
Dan Raby reports: A former accountant has been sentenced to years in federal prison after he was convicted for taking part in a scheme to laundering more than $5.3 million stolen from Children’s Healthcare of Atlanta. Ronald Deabler, a 66-year-old Atlanta business owner and former Certified Public Accountant, was found guilty by a jury earlier...

Source

Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open

By: Dissent
26 July 2026 at 10:10
Media outlets are reporting that all AnMed  hospital locations are experiencing a phone and internet outage, but patients are being seen in the emergency rooms. AnMed is an independent, not-for-profit health system serving Upstate South Carolina and northeast Georgia with four hospitals: AnMed Medical Center, AnMed Cannon,  AnMed Rehabilitation Hospital, and  Regency Hospital – Upstate....

Source

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

By: Dissent
25 July 2026 at 10:24
Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information without authorisation. Detectives launched an investigation under Strike Force Civic and, after inquiries, searched a home in Frenchs Forest...

Source

Medical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breaches

By: Dissent
19 July 2026 at 09:26
Anna Zhadan reports: American healthcare giant Abbott Laboratories is investigating two cyber incidents that appear to be unrelated: one involving its Cancer Diagnostics business and another affecting its LabCentral portal. Although unrelated, the two disclosures came within days of each other. On July 16th, Abbott said it was investigating an incident involving unauthorized access to a limited...

Source

NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data

By: Dissent
18 July 2026 at 08:13
There’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws.  New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general today secured $18 million from genetic testing company 23andMe for failing to...

Source

AU: Partnered Health Data Breach Exposes Patient Records at Family Clinics

By: Dissent
15 July 2026 at 07:48
Trevor Long reports: A large health care chain that owns family medical clinics across Australia has been the victim of a cyber breach which has exposed the data of their patients, including potentially treatment information. Partnered Health runs a large number of clinics across Australia, with sixteen of them listed as directly affected, and a...

Source

Finland issues wanted notice for hacker behind massive psychotherapy data breach

By: Dissent
14 July 2026 at 17:12
I was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison?  Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted notice for convicted hacker Aleksanteri...

Source

Patients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal Information

By: Dissent
8 July 2026 at 11:31
Mikeie Honda Reiland reports: A suite of recent class action lawsuits in state and federal courts seeks to hold large healthcare corporations accountable for exposing or leaking patients’ personally identifiable information (PII) and protected health information (PHI). On June 11 in Davidson County Circuit Court, three Jane Does filed suit against CareNow, which operates more...

Source

AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data

By: Dissent
4 July 2026 at 08:01
Connor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SEC) on Thursday, noting that attackers accessed internal patient management systems, document storage platforms, and external electronic health record system...

Source

NZ pharmacy scrambles to scrub internet of patients’ private messages

By: Dissent
28 June 2026 at 09:40
Mary Argue reports: A Wellington pharmacy at the centre of a data leak says sensitive patient information has now been scrubbed from the internet. Unichem Petone said it was contacting 29 patients affected by what it described as an error on the website that saw patients’ private messages to the pharmacy via its ‘contact us’...

Source

First Circuit Affirms Dismissal of Data Breach Class Action for Lack of Traceable Injury

By: Dissent
26 June 2026 at 15:00
Melanie Conroy of Pierce Atwood LLP writes: The First Circuit recently affirmed dismissal of a putative data breach class action against Bayamón Medical Center (BMC), holding that the plaintiff failed to plausibly allege that her injuries were traceable to the healthcare provider’s 2019 ransomware attack. In Santos-Pagán v. Bayamón Medical Center, the court concluded that allegations...

Source

❌
❌