Ransomware Attack on Arkansas Oncology Group Affects 113,500 Individuals
Highlands Oncology Group, a comprehensive cancer care provider with six locations in Northwest Arkansas, has recently disclosed a cyberattack that was first identified on June 2, 2025. A hacker gained access to its network on January 21, 2025, and remained within the network undetected until June 2, 2025, when ransomware was used to encrypt files. Between those dates, there was intermittent access to the network, and patient data may have been viewed or acquired. The files were reviewed and found to contain protected health information such as names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information. The types of data exposed or stolen varied from individual to individual. The data breach was recently reported to the Maine Attorney General as involving the personal information of 113,575 individuals, and the HHS’ Office for Civil Rights breach...
New Data Breach Notification Requirements in Oklahoma
Oklahoma has enacted a bill that amends its data breach notification statute. The definition of personal information warranting notifications has been broadened, and the state Attorney General must be notified about any breach of the personal information of 500 or more state residents, or 1,000 or more residents for a breach of credit bureau systems. Individual notifications must be issued without unreasonable delay, and the state Attorney General must be notified within 60 days of individual notifications being mailed. The Attorney General must be informed of the date of the breach, the date it was determined that a data breach had occurred, the nature of the breach, the type(s) of information exposed or stolen, the number of state residents affected, any reasonable safeguards that the entity has implemented, and the estimated monetary impact of the breach, if it can be determined. Entities that are compliant with the Health Insurance Portability and Accountability Act (HIPAA), the Oklahoma Hospital Cybersecurity Protection Act, and/or the Gramm-Leach-Bliley Act (GBLA) will be...
More Than Half of Healthcare Orgs Attacked with Ransomware Last Year
A new report from the cybersecurity firm Semperis suggests ransomware attacks have decreased year-over-year, albeit only slightly. The ransomware risk report indicates healthcare is still a major target for ransomware gangs, with 77% of healthcare organizations targeted with ransomware in the past 12 months. 53% of those attacks were successful. The report is based on a Censuswide survey of 1,500 IT and security professionals across multiple sectors. While attacks are down slightly, 60% of attacked healthcare organizations report suffering multiple attacks. In 30% of cases, they were attacked more than once in the same month, 35% were attacked in the same week, 14% were attacked multiple times on the same day, and 12% faced simultaneous attacks. A general trend in recent years, as reported by several firms, is fewer victims of ransomware attacks paying ransoms, although across all industry sectors in the U.S., 81% attacked companies paid the ransom, an increase from last year. Ransom payment was far less common in healthcare. According to Semperis, 53% of healthcare victims paid a...
Trump Administration Announces Plan to Improve Patient Data Sharing
This week, the Trump Administration announced a new initiative aimed at improving interoperability and the exchange of healthcare data, and has obtained pledges from leading healthcare and technology firms to create a foundation for a next-generation digital health ecosystem, which will improve patient outcomes, reduce provider burden, and drive value. The initiative was announced during a HHS’ Centers for Medicare & Medicaid Services (CMS) hosted White House event dubbed “Make Health Tech Great Again,” and follows years of bipartisan efforts to improve interoperability and eradicate information blocking to improve the quality of care and eliminate waste. “For decades, bureaucrats and entrenched interests buried health data and blocked patients from taking control of their health,” said HHS Secretary Robert F. Kennedy, Jr. “That ends today. We’re tearing down digital walls, returning power to patients, and rebuilding a health system that serves the people. This is how we begin to Make America Healthy Again.” At the event, the CMS fleshed out its plan, which includes voluntary...
Florida Internal Medicine Practice Discloses November 2024 Data Breach
Hacking-related data breaches have been announced by Mid Florida Primary Care, Northwest Denture Center in Washington, Forward, The National Databank for Rheumatic Diseases in Kansas, and Equilibria Mental Health Services in Massachusetts. Inc Ransom claims to have attacked the West Virginia Primary Care Association. Mid Florida Primary Care On July 29, 2025, Mid Florida Primary Care, a specialized internal medicine practice in Leesburg, Florida, disclosed a cyberattack and data breach that was identified on or around January 23, 2025. An investigation was launched to determine the nature and scope of the activity, which confirmed that an unauthorized third party accessed its network and copied files between November 29, 2024, and December 11, 2024. The data review was completed on June 19, 2025. The information compromised in the incident includes names, addresses, dates of birth, email addresses, Social Security numbers, driver’s license numbers, health insurance information, Medicare/Medicaid numbers, health insurance information, diagnosis and/or treatment information,...



