Sandhills Medical Foundation Ransomware Attack Affects 169,000 Patients
Sandhills Medical Foundation in South Carolina and Laurel Eye Clinic in Pennsylvania have experienced security incidents that exposed patient data. The ransomware attack on Sandhills Medical Foundation affected more than 169,000 individuals. Sandhills Medical Foundation, South Carolina Sandhills Medical Foundation, Inc., a federally qualified community health center (FQHC) that provides primary care, behavioral health, and immunization services to residents of Chesterfield, Kershaw, Lancaster, and Sumter Counties in South Carolina, has notified 169,017 individuals that some of their personal and health information was stolen by a ransomware group that compromised its network in May 2025. The ransomware attack was detected on May 8, 2025, when files were encrypted. Digital forensics experts were engaged to investigate the incident, who determined that the ransomware group had access to its network from May 2, 2025, to May 8, 2025. During that time, files were exfiltrated from its network. The exposed and stolen files have been reviewed and were found to contain names, dates of...
Vendor Data Breaches Announced by Six HIPAA-Regulated Entities
There have been several announcements about data breaches at business associates of HIPAA-regulated entities recently, including Providence St. Joseph Orange and Skin & Beauty Center in California, Management-ILA Managed Health Care Trust Fund in New York, and Ideal Home Care, Duncan Regional Home Care, and Chisholm Trail Hospice in Oklahoma. Providence St. Joseph Orange, California Providence St. Joseph Orange, a catholic general hospital in Orange, California, has been affected by a data security incident at its vendor, Pinnacle Holdings, LTD, a health care consulting company. Pinnacle experienced a network disruption in November 2024, and the forensic investigation confirmed unauthorized access to its network between November 11, 2024, and November 25, 2024, during which time files containing protected health information may have been exfiltrated from Pinnacle’s network. Data potentially compromised in the incident included patients’ first and last name, address, email address, date of birth, encounter ID number, health insurance claim number, health insurance policy number,...
Southern Illinois Healthcare Enterprises Pixel Settlement Approved
A settlement has been agreed to resolve litigation against defendants Southern Illinois Healthcare Enterprises, Southern Illinois Hospital Services, and Southern Illinois Medical Services over their use of website tracking technologies without website users’ knowledge or consent. Southern Illinois Healthcare Enterprises Pixel Settlement A class action lawsuit over the use of website tracking technologies has been settled. The lawsuit was filed by John Doe, individually and on behalf of similarly situated individuals, against the defendants Southern Illinois Healthcare Enterprises, Southern Illinois Hospital Services, and Southern Illinois Medical Services over an alleged impermissible disclosure of the plaintiff’s and class members’ private information to third parties. The lawsuit – Doe v. Southern Illinois Healthcare Enterprises, Inc. – was filed in Williamson County Circuit Court, Illinois, and alleged that personally identifiable information was disclosed to Meta (Facebook) via third-party tools on the defendants’ websites without the knowledge or permission of...
Settlements Agreed to Resolve Two Class Action Healthcare Data Breach Lawsuits
Settlements have received preliminary approval from the courts to resolve class action data breach lawsuits against Dove Healthcare Management Services and Blackstone Valley Community Health Care over the exposure of plaintiffs’ private information in 2023 and 2024 hacking incidents. Dove Healthcare Management Services Data Breach Settlement Dove Healthcare Management Services, a provider of nursing and rehabilitation care, assisted living, and palliative care services, has agreed to a settlement to resolve litigation over a July 2024 cyberattack that exposed the private information of patients and employees. Cybercriminals breached its information systems on or around July 6, 2024, exposing names, dates of birth, Social Security numbers, driver’s license numbers, full face photographs, health information, and health insurance information. The affected individuals began receiving notifications about the incident on March 18, 2025. The first class action lawsuit was filed on March 26, 2025, followed by several similar lawsuits. The complaints were consolidated into a single action...
AI Analysis Identifies 38 Flaws in OpenEMR Platform
An automated, AI-driven analysis of the most widely used electronic medical records platform uncovered 38 previously unknown vulnerabilities, including two critical flaws with maximum CVSS severity scores of 10.0. The vulnerabilities were identified as part of a collaboration between AISLE, an autonomous, AI-native application security platform, and OpenEMR, an open source and U.S. government-certified platform, the purpose of which was to identify and remediate critical vulnerabilities in the platform before they could be exploited by malicious actors. OpenEMR is used by more than 100,000 healthcare providers worldwide, and the platform serves more than 200 million patients globally. OpenEMR is free open source software with no licensing fees and relatively low operating costs, making it a popular choice for under-resourced healthcare providers. The platform is widely used in the United States. The analysis by AISLE resulted in 39 GitHub Security Advisory (GHSA) vulnerabilities in Q1, 2026, including critical, high, and moderate severity vulnerabilities, with 38 of the 39...



