Texas Gastroenterology Clinic Falls Victim to Interlock Ransomware Attack
Ransomware groups have attacked three healthcare providers: Gastroenterology Consultants of South Texas, Infinite Services in New York, and High Point Treatment Center in Massachusetts. Gastroenterology Consultants of South Texas (Texas Digestive Specialists) Gastroenterology Consultants of South Texas, which does business as Texas Digestive Specialists, has recently disclosed a May 2025 cybersecurity incident and data breach. According to the substitute data breach notice, an unauthorized third party gained access to its network in late May 2025 and may have obtained files containing personally identifiable information (PII) and protected health information (PHI). The Texas Attorney General was informed that the exposed information may have included names, addresses, dates of birth, medical records, and health insurance information. The breach notification does not state when the attack was detected or for how long the hackers had access to the network. Third-party cybersecurity experts assisted with the investigation, and the lessons learned will be used to enhance the security...
Bone & Joint Clinic Settles Ransomware Class Action Lawsuit for $575,000
Bone & Joint Clinic S.C. has agreed to pay $575,000 to settle a class action lawsuit stemming from a January 2023 security incident that affected 105,094 current and former patients and employees. Bone & Joint is an orthopedic and pain management clinical practice in Northcentral Wisconsin. On January 16, 2025, a security incident was identified that caused network disruption. An unauthorized third party accessed its network, used ransomware to encrypt files, and may have obtained protected health information such as names, contact information, dates of birth, Social Security numbers, health insurance information, diagnoses, treatment information, and other sensitive data. Lawsuits were filed by four Bone & Joint Clinic patients, which were consolidated into a single complaint – Keith Tesky, et al. vs. Bone & Joint Clinic, S.C., – in the U.S. District Court for the Western District of Wisconsin. The lawsuits claimed that the practice failed to implement reasonable and appropriate safeguards to protect sensitive employee and patient data. The consolidated...
HHS-OIG Audit Finds Security Gaps at Large Northeastern Hospital
An audit of a large northeastern hospital by the Department of Health and Human Services Office of Inspector General (HHS-OIG) has identified cybersecurity gaps and weaknesses that are likely to be present in similarly sized hospitals across the country. Cyberattacks on healthcare organizations have increased sharply in recent years. Between 2018 and 2022, there was a 93% increase in large data breaches reported to the HHS’ Office for Civil Rights (OCR) and a 278% increase in large data breaches involving ransomware. In 2022 alone, OCR received 64,592 reports of healthcare data breaches, across which the protected health information of 42 million individuals may have been exposed or stolen. The HHS plays an important role in guiding and supporting the adoption of cybersecurity measures to protect patients and healthcare delivery from cyberattacks. The large number of successful cyberattacks raises questions about whether the HHS, including the Centers for Medicare and Medicaid Services (CMS) and OCR, could do more with its cybersecurity guidance, oversight, and outreach to help...
Lake Charles Memorial Health Agrees to $2 Million Data Breach Settlement
A $2 million settlement has received preliminary approval from the court to resolve a class action lawsuit against Southwest Louisiana Hospital Association, which does business as Lake Charles Memorial Health, that stemmed from a 2022 data breach that affected 269,752 patients. The Louisiana health system identified suspicious activity within its computer network on October 21, 2022, and it was later confirmed that an unauthorized third party had access to its network between October 20, 2022, and October 21, 2022. During that time, files were exfiltrated from the network, including names, addresses, dates of birth, medical record numbers, patient identification numbers, health insurance information, payment information, limited clinical information, and in some cases, Social Security numbers. The affected individuals were notified on December 23, 2025. The first lawsuit stemming from the data breach was filed on January 5, 2023, in the Calcasieu Parish District Court in Louisiana. Further lawsuits were filed, which were consolidated into a single complaint as they were materially...
McKenzie Memorial Hospital Announces Data Breach Affecting Almost 59,000 Patients
McKenzie Memorial Hospital in Michigan has reported a hacking incident affecting almost 59,000 patients. Arbor Associates in Massachusetts has reported a 17K-record data breach, and data breaches have been confirmed by Blue Shield of California and Human Development Services of Westchester. McKenzie Memorial Hospital, Michigan McKenzie Memorial Hospital in Sandusky, Michigan, has recently disclosed a cybersecurity incident that was detected on or around April 15, 2025, when suspicious activity was identified within its network. McKenzie Memorial did not state whether ransomware was used, only that the forensic investigation confirmed that its network was accessed by an unauthorized third party between April 14, 2025, and April 15, 2025. During that time, files containing patients’ protected health information may have been accessed. The investigation and file review were completed on June 19, 2025, and confirmed that the potentially compromised information included names, Social Security numbers, and financial account information. The data breach was recently reported to the Maine...



