Data Breaches Announced by Open Arms Care; Elmwood Home Care
Data breaches have been announced by the Tennessee-based disability care provider Open Arms Care Corporation and the Rhode Island and Massachusetts home healthcare provider, Elmwood Home Care. Open Arms Care, Tennessee Open Arms Care Corporation, a Brentwood, TN-based nonprofit provider of residential and therapeutic care services to individuals with disabilities, has recently disclosed a breach of its email tenant. Suspicious activity was identified in August 2025, indicative of unauthorized access to an email account. The forensic investigation confirmed that the account had been accessed by an unauthorized third party between June 2025 and August 2025. The account was reviewed to determine the individuals affected and the types of data involved, and that process was completed on April 30, 2026. Up-to-date contact information was obtained, and notification letters were mailed to the affected individuals on June 9, 2026. The types of data involved varied from individual to individual and may have included names in combination with one or more of the following: Medical diagnosis,...
FMC Services Agrees to $2.15M Settlement to End Data Breach Lawsuit
FMC Services LLC, the operator of a network of primary care clinics in Amarillo and Canyon, Texas, experienced a cyberattack and data breach in 2022. The class action lawsuit that followed has recently been settled for $2.15 million. The cyberattack was detected on July 26, 2022, and the forensic investigation confirmed that files had been exposed containing names, addresses, dates of birth, Social Security numbers, and health information. The FMC Services data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 233,948 individuals. Notification letters were mailed to 266,540 individuals. Four individuals filed class action lawsuits in response to the exposure of their personal and protected health information. The lawsuits made similar claims and were consolidated into a single action – Sharber, et al. v. FMC Services, LLC – in the District Court of Potter County, Texas. The consolidated lawsuit claimed that FMC Services had a duty to maintain reasonable and appropriate cybersecurity measures and breached that duty,...
Clinical Registry Solutions; Jason R Egbert OD PC; VNC Health Announce Data Breaches
Data breaches have been announced by Clinical Registry Solutions in New York, First Sight Family Vision in Washington, and VHC Health in Virginia. Clinical Registry Solutions, New York Clinical Registry Solutions, a Brooklyn, New York-based provider of clinical data abstraction and registry support services to healthcare providers, is notifying patients of Dignity Health’s St. Mary’s Medical Center that some of their protected health information has potentially been compromised in an April 2026 cybersecurity incident. Suspicious activity was identified within its computer network on April 9, 2026. The forensic investigation identified unauthorized access to its computer network, and evidence was found indicating that files containing patient data were copied by the attackers. The data review determined that patient names, procedure dates, and medical record numbers were involved; however, Social Security numbers and diagnosis and treatment information were not involved. Company data was also stolen in the attack. Clinical Registry Solutions has not identified any misuse of the...
Clinical Trial Data Stolen in Novo Nordisk Cyberattack
Novo Nordisk, the Danish pharmaceutical firm behind the GLP-1 weight loss drugs Ozempic and Wegovy, has experienced a cyberattack that exposed the data of healthcare providers and patients enrolled in clinical trials. According to the company’s June 11, 2026, breach notice, a threat actor gained access to a limited number of its internal systems, and certain personal data stored on those systems was exfiltrated by the attackers. It is currently unclear when the intrusion was detected or for how long hackers had access to its systems, and the threat group behind the attack has yet to publicly claim responsibility. The exposed data related to certain patients who took part in its clinical trials; however, the risk to those patients is limited, as the exfiltrated data was deidentified. Patient names were not exposed; only the ID numbers used to identify specific patients participating in clinical trials. The ID numbers consist of random alphanumeric strings. Other compromised information was limited to sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle...
Business Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar
The healthcare industry has the highest rate of third-party data breaches out of any sector, according to the Verizon Data Breach Investigations Report (DBIR), and third-party data breaches are increasing. The HHS’ Office for Civil Rights (OCR) publishes information on data breaches impacting 500 or more individuals on its data breach portal. Currently, the breach portal shows that in the 9 years from 2009 to 2017, an average of 20% of healthcare data breaches had business associate involvement. For the following 9 years, from 2018 to 2026, an average of 34% data breaches had business associate involvement. In the first 6 months of 2026, that percentage rose to 43%. Modern healthcare relies heavily on third-party vendors to perform a huge range of functions. Vendors are used for revenue cycle management, transcription, medical supplies, telemedicine, IT services, cybersecurity, and provide a huge range of software solutions, SaaS platforms, AI tools, and electronic medical records. A typical U.S. health system could have anywhere from 500 to 2,000 active vendors and a massive...



