Vishing Attack on Quantum Health Network Exposed Patient Data
Data breaches have recently been announced by the healthcare navigation and care coordination company Quantum Health, Heart of America Medical Center, and Precision Imaging Centers. Quantum Health Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company that helps self-insured employers manage employee benefits and lower healthcare costs, has disclosed a cybersecurity incident that it identified in May 2026. The incident started with a vishing attempt. The attacker called a Quantum Health user on May 29, 2026, and tricked them into providing access to the Quantum Health network. Between May 29, 2026, and June 1, 2026, the unauthorized third party had access to its network and acquired files. On June 1, 2026, Quantumn Health experienced a network disruption affecting both internal and external systems. An investigation was launched, which traced the incident back to the vishing call. The threat group behind the incident was not named, and no ransomware group appears to have claimed responsibility for the attack. These tactics are commonly used by the...
Boston Healthcare for the Homeless Program Breach Affects 201,000 Individuals
Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company in West Virginia, and Open Door Health Center of Illinois. Boston Healthcare for the Homeless Program, Massachusetts Boston Healthcare for the Homeless Program, a Boston, MA-based nonprofit organization that provides healthcare services for the homeless population, has notified state attorneys general about a network security incident first identified on November 11, 2025. The incident was detected when it experienced a network disruption. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party accessed its network and potentially viewed or obtained files containing sensitive patient information. The review of the affected data was completed on June 8, 2026, when it was learned that names, Social Security numbers, credit/debit card information, government identification numbers, financial account codes, medical information, health records, and health insurance...
Texas Hearing Institute Ransomware Attack Affects 30,000 Patients
Texas Hearing Institute has announced a cybersecurity incident involving the protected health information of almost 30,000 patients. Data breaches have also recently been announced by Family Partnerships of Central Florida and SportsMed Physical Therapy. Texas Hearing Institute The Center for Hearing and Speech, doing business as Texas Hearing Institute, a provider of pediatric audiology services, has notified 29,744 current and former patients about a security incident identified on March 20, 2026. Suspicious network activity was identified, and immediate action was taken to lock down and secure its environment. Assisted by third-party cybersecurity specialists, Texas Hearing Institute determined on or around April 22, 2026, that certain parts of its network were accessed by an unauthorized third party, including files containing patient information. The list of the affected individuals was finalized on June 19, 2026, and notification letters were mailed on June 26, 2026. Information potentially compromised in the incident includes names, personal identifiers, Social Security...
ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
A $3,500,000 settlement has received preliminary approval from the court to resolve class action data breach litigation against ZOLL Medical Corporation. The litigation relates to a January 2023 data breach that affected more than 1 million individuals. Zoll Medical is a Chelmsford, Massachusetts-based global medical device and software company that makes products for resuscitation, cardiac monitoring, and critical cardiopulmonary conditions. Unauthorized network access was identified on January 28, 2023, and the investigation confirmed that personally identifiable information (PII) and protected health information (PHI) were exposed in the incident, mainly relating to individuals who received or were considered for use of the ZOLL LifeVest wearable cardioverter defibrillator. According to the breach notice submitted to the HHS’ Office for Civil Rights, the electronic protected health information (ePHI) of 997,097 individuals was involved, including names, addresses, dates of birth, and Social Security numbers. Those individuals started to be notified about the data breach in March...
Data Breaches Announced by Five HIPAA-Regulated Entities
Data breaches have recently been announced by the Women’s Center for Radiology in Florida, Optalis Management Solutions in Michigan, the Association for Neurologically Impaired Brain Injured in New York, the Cardiovascular Institute of New England in Rhode Island, and the Kubota Tractor Corporation in Texas. Women’s Center for Radiology, Florida Women’s Center for Radiology, a Florida-based women’s radiology practice with two centers in Orlando, has notified 66,422 patients about a data security incident identified on April 29, 2026. Assisted by third-party cybersecurity specialists, the Women’s Center for Radiology determined that an unauthorized third party had access to its network between April 26, 2026, and April 28, 2026, and accessed or downloaded files containing patient information. After securing its network, the files were reviewed and found to contain patient information such as names, addresses, dates of birth, contact information, diagnosis/condition information, lab test results, treating/referring physician names, medical record numbers, driver’s license numbers,...



