Vishing Attack Provides Threat Act with Access to Quantum Health Network
Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers.
Quantum Health
Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has disclosed a cybersecurity incident that it identified in May 2026.
The incident started with a vishing attempt. The attacker called a Quantum Health user on May 29, 2026, and tricked them into providing access to the Quantum Health network. Between May 29, 2026, and June 1, 2026, the unauthorized third party had access to its network and acquired files. On June 1, 2026, Quantumn Health experienced a network disruption affecting both internal and external systems. An investigation was launched, which traced the incident back to the vishing call. The threat group behind the incident was not named, and no ransomware group appears to have claimed responsibility for the attack. These tactics are commonly used by the ShinyHunters threat group, which was the subject of a recent Health-ISAC cybersecurity alert.
On June 8, 2026, Quantum Health confirmed that the exfiltrated data included personal and protected health information, including names, addresses, email addresses, phone numbers, dates of birth, demographic information, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, dates of service, insurance information, and claims or benefits information. The affected individuals are being offered complimentary credit monitoring and identity theft protection services. It is unclear how any companies have been affected by the incident, and the number of affected individuals has yet to be publicly disclosed.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Heart of America Medical Center
Heart of America Medical Center, a faith-based nonprofit hospital and medical facility in Rugby, North Dakota, has experienced a cybersecurity incident that exposed patient data. Suspicious network activity was identified on or around June 12, 2025, and the investigation determined on September 15, 2025, that an unauthorized third party accessed its network and exfiltrated files, some of which contained patient information, including names, Social Security numbers, medical records, and other medical information.
A third-party vendor was engaged to review the affected data, and that process concluded on May 12, 2026. The findings were reviewed, and that process was completed on June 9, 2026. Contact information was verified, and on July 9, 2026, Heart of America Medical Center obtained a final list of individuals to notify. Notification letters have now been sent to the affected individuals, who have been offered complimentary single-bureau credit score, credit report, and credit monitoring services. Heart of America Medical Center has implemented additional technical and administrative safeguards to enhance data privacy and security.
The Embargo ransomware group claimed responsibility for the incident and claimed to have exfiltrated around 800 GB of data in the attack. The incident is not yet shown on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.
Precision Imaging Centers
The Medical Imaging Partnership, doing business as Precision Imaging Centers in Florida, has announced a hacking incident that exposed patient information. Suspicious activity was identified within its computer network on May 7, 2026. The investigation determined that its network was accessed by an unauthorized third party, who copied files from its systems. The investigation and data review are ongoing, so the exact data types involved and the names of the affected individuals have yet to be determined. As such, the incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of 501 individuals. The total will be updated when the file review is concluded.
Precision Imaging Centers has advised current and former patients to remain vigilant against identity theft and fraud by monitoring their free credit reports, accounts, and explanation of benefits statements for signs of data misuse. Notification letters will be mailed to the affected individuals as soon as possible after the data review is concluded.


