Normal view

There are new articles available, click to refresh the page.
Today — 26 June 2026DataBreaches.Net

Colorado Health Network Notifies Patients of Last Year’s Breach—But Key Details Remain Undisclosed

By: Dissent
25 June 2026 at 12:23
In August 2025, DataBreaches added the Colorado Health Network (CHN) to our non-public worksheets after threat actors called Cephalus added the provider to its’ dark web leak site with a claim that they had acquired 900 GB of data. Cephalus disappeared from public view days later, and never leaked the data on any server that...

Source

Before yesterdayDataBreaches.Net

HHS’ Office for Civil Rights Settles Ransomware Investigation with Spencer Gifts Health Plan for $450k, Corrective Action Plan

By: Dissent
18 June 2026 at 20:56
The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the Plan), the employer-sponsored group health plan of Spencer Gifts LLC, a national retail company, over potential violations of the Health Insurance Portability and Accountability Act of...

Source

Radiology Associates of Richmond discloses second data breach; 266k people affected

By: Dissent
22 May 2026 at 12:46
On July 1, 2025,  Radiology Associates of Richmond (“RAR”) reported a breach to HHS that had occurred in April 2024 and affected more than 1.4 million patients. By the end of July 2025, the well-known radiology practice had experienced a second breach. The second breach, recently reported to the Maine Attorney General’s Office on May...

Source

Maryland pharmacist indicted on unauthorized computer access related to U. Maryland Medical Center

By: Dissent
2 May 2026 at 08:15
From the U.S. Attorney’s Office, District of Maryland: A Maryland man is facing federal indictment stemming from an unauthorized computer access scheme involving a Maryland medical system. Matthew Bathula, 41, of Clarksville, is charged with two counts of unauthorized access to a protected computer, and one count of aggravated identity theft while working as a...

Source

Almost one year after discovery, Sandhills Medical Foundation notifies 169,017 people affected by a cyberattack

By: Dissent
29 April 2026 at 11:58
On April 28, Sandhills Medical Foundation in South Carolina notified the Maine Attorney General’s Office of a data breach that affected a total of 169,017 people, only 8 of whom are Maine residents. Their notification to the state and those affected comes almost a year to the day since they first experienced the breach. According...

Source

OCR Announces Settlements of Four Ransomware Investigations that Affected Over 427,000 Individuals

By: Dissent
24 April 2026 at 07:59
Yesterday, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced settlements with four regulated entities following separate ransomware investigations under HIPAA’S Security Rule. For those keeping count: the resolutions announced mark 19 completed investigations from ransomware breaches and 13 completed investigations in OCR’s Risk Analysis Initiative. The settlements follow...

Source

Outside FDA, Inside the Crosshairs: Cybersecurity Risks for General Wellness and Fitness Products

By: Dissent
22 April 2026 at 13:03
Troutman Pepper Locke writes: In Part One of this series, we discussed how wellness products sit at the intersection of Food and Drug Administration (FDA), Health Insurance Portability and Accountability Act (HIPAA), Federal Trade Commission (FTC), and state privacy/breach laws. In Part Two, we analyzed FDA’s 2026 General Wellness guidance and what it means for device-level cybersecurity expectations....

Source

OCR Releases Risk Management Video

By: Dissent
8 April 2026 at 20:19
From HHS OCR: This video presentation is intended to raise awareness and provide practical education to HIPAA covered entities and business associates of the HIPAA Security Rule’s Risk Management requirement. Like risk analysis, effective risk management is an essential component of both HIPAA Security Rule compliance and broader cybersecurity preparedness. Risk management is a critical step not only for...

Source

❌
❌