NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Bacon County Health Services Investigating Cyber Incident

Data breaches have been announced by Bacon County Health Services in Georgia, Comprehensive Orthopaedics & Musculoskeletal Care in Connecticut, Imagine the Possibilities in Iowa, and Health Plans Inc. in Massachusetts.

Bacon County Health Services

Bacon County Health Services, an Alma, Georgia-based nonprofit healthcare organization, is investigating a data security incident involving unauthorized access to systems containing patient information. Bacon County Health Services provides healthcare services to individuals in and around Alma through Bacon County Hospital, Twin Oaks Convalescent Center, and a rural health clinic.

Suspicious network activity was identified on July 27, 2026, and the forensic investigation determined that an unauthorized third party had access to its computer network between July 10, 2026, and July 27, 2026.  The investigation confirmed that files containing patient information were exfiltrated by the threat actor. The data review is ongoing, and the number of affected individuals and the types of data involved have yet to be determined. Notification letters will be mailed to the affected individuals when the data review is concluded. At the time of announcing the incident, no misuse of the affected data had been identified.

While the incident may not have affected all patients, Bacon County Health Services has warned all patients to remain vigilant against identity theft and fraud. To meet breach reporting requirements, the HHS’ Office for Civil Rights has been informed and provided with an estimate of at least 501 affected individuals. The total will be updated when the data review is concluded.

Comprehensive Orthopaedics & Musculoskeletal Care

Comprehensive Orthopaedics & Musculoskeletal Care, a Connecticut-based orthopedic practice, has recently notified the HHS’ Office for Civil Rights about a breach of the protected health information of 21,897 individuals. According to the practice’s substitute data breach notice, suspicious network activity was identified on February 12, 2026. Immediate action was taken to investigate the activity and secure its network, and it was confirmed that an unauthorized third party potentially accessed sensitive data.

The investigation and data review were completed on June 17, 2026, confirming that the impacted data included names, dates of birth, Social Security numbers, financial account numbers, payment card information, government-issued ID numbers, medical information, and health insurance information. While not described as a ransomware attack, a ransomware group called Crypto24 claimed to have exfiltrated sensitive data, including patients’ protected health information. The group has published the stolen data on its dark web data leak site.

Imagine the Possibilities

Imagine the Possibilities, an Iowa-based nonprofit organization that provides community-based support services for individuals with intellectual difficulties, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 1,693 individuals. The security incident occurred at one of its business associates, the Waterloo, IA-based insurance agency PDCM Insurance. Suspicious activity was identified within the PDCM Insurance network on April 28, 2025, and the forensic investigation confirmed unauthorized access to files and folders between April 27, 2025, and April 28, 2025. The review of the affected data was recently completed.

Data potentially compromised in the incident included names in combination with one or more of the following: date of birth, Social Security number, driver’s license number, state identification number, taxpayer identification number, financial account information, treatment information, diagnosis, treating/referring physician, prescription/medication information, group health insurance/subscriber number, medical policy number, individual health insurance/subscriber number, and/or medical record number. It is currently unclear how many of the company’s clients have been affected. PDCM Insurance said it has reviewed its security policies and procedures and has implemented additional safeguards to prevent similar incidents in the future.

Health Plans Inc.

Health Plans Inc., a Westborough, Massachusetts-based third-party administrator of self-funded employer health and benefit plans, has disclosed a cybersecurity incident involving one of its SaaS vendors. The number of affected individuals has yet to be publicly disclosed.

The incident involved Alegeus, a Waltham, Massachusetts-based provider of a SaaS platform for administering healthcare accounts. The data breach details have yet to be publicly disclosed, other than Social Security numbers being exposed. Alegeus has confirmed that it has taken steps to reduce the risk of similar incidents in the future and is offering the affected individuals two years of complimentary credit monitoring services.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist