NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Data Breaches Announced by Gastroenterology Practice and Hospice Companies

Data breaches have been announced by Gastroenterology & Hepatology of Central New York, Three Oaks Hospice, and Doctor’s Choice Home Care.

Gastroenterology & Hepatology of Central New York

Gastroenterology & Hepatology of Central New York, a medical practice specializing in digestive disorders and liver disease with locations in Liverpool and Syracuse, has started notifying patients about a cybersecurity incident first identified on March 6, 2026. Immediate action was taken to contain the threat, and third-party cybersecurity and digital forensics experts were engaged to investigate the activity. The forensic investigation confirmed unauthorized access to certain systems and the exfiltration of files from its network on or around March 6, 2026.

The stolen files contained full names, addresses, phone numbers, dates of birth, Social Security numbers, and medical record numbers. The affected individuals were notified on September 17, 2026, and complimentary credit monitoring and identity theft protection services have been made available. At the time of issuing the notifications, no misuse of the affected data had been identified. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Three Oaks Hospice / Elevation Hospice

Dallas, Texas-based Three Oaks Hospice, a medical service provider specializing in hospice care, identified unauthorized access to its email environment on August 8, 2025. Assisted by cybersecurity experts, Three Oaks Hospice determined that limited email accounts had been accessed by an unauthorized third party and personal information was exposed.

Three Oaks Hospice, along with its sister companies Agape Hospice Care, Elevation Hospice of Colorado, and Sage Hospice of Arizona, provides hospice and palliative care services in 9 U.S. states. It took more than a year for its affiliated hospices to be notified that they had been affected. The affected hospices were notified on August 17, 2026, and the affected individuals were notified on September 17, 2026.

Data exposed in the incident includes names, dates of birth, Social Security numbers, driver’s license numbers, medical information, and health insurance information. The number of affected individuals has yet to be publicly disclosed. The Texas attorney general was notified that 3,034 Texas residents were affected.

Doctor’s Choice Home Care (WellSky)

Houston, Texas-based Doctor’s Choice Home Care, a home care and hospice provider, has been affected by a data breach at its electronic medical record vendor, WellSky. WellSky identified the incident on July 21, 2026, and its forensic investigation determined that an unauthorized third party gained access to a WellSky clinical user account within the electronic medical record system between June 5, 2026, and July 24, 2026.

Data exposed and potentially stolen included names, addresses, birth dates, Social Security numbers, scheduling information, clinical information, treatment information, and health insurance information. Doctor’s Choice Home Care confirmed that its internal systems were unaffected. The incident is not yet shown on the HHS’ Office for Civil Rights website. The Texas Attorney General was notified that 14,333 Texas residents have been affected.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist