Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance
Settlements have been agreed to resolve class action data breach lawsuits against McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts. McKenzie Health System Data Breach Settlement McKenzie Health System, the operator of the McKenzie Memorial Hospital, a critical access hospital in Sanilac County, Michigan, has settled a class action lawsuit that was filed in response to an April 2025 cyberattack and data breach. McKenzie Health identified unauthorized access to its computer network on April 15, 2025. The forensic investigation determined that an unauthorized third party accessed its network between April 14, 2025, and April 15, 2025, and potentially obtained files containing patient information. Data potentially compromised in the incident included names, addresses, birth dates, Social Security numbers, patient account numbers, medical record numbers, diagnosis and treatment information. The data breach was reported to the HHS’ Office for Civil Rights as affecting 58,839 individuals, who started to be notified on or around July 24, 2025. Several class...
Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced that two settlements have been agreed to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA). EMTALA was enacted by Congress in 1986 to ensure public access to emergency medical services. EMTALA requires Medicare-participating hospitals that offer emergency services to provide a medical screening examination (MSE) to patients who present to their emergency department requesting an examination or treatment for an emergency medical condition, regardless of the patient’s ability to pay. A patient must be provided with stabilizing treatment if the MSE determines that they have an emergency medical condition. If the hospital lacks the capability to provide stabilizing treatment, or if requested by the patient, they must initiate an appropriate transfer. The receiving hospital must have the available space and qualified personnel and must agree to accept the transfer. The transferring hospital must send all medical records related to the emergency condition...
Unlimited Technology Systems Data Breach Affects 3.8 Million Patients
On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Cincinnati, Ohio-based provider of revenue cycle management and practice management software. At the time, the scale of the data breach had yet to be made public, but it has recently been confirmed to be the second-largest healthcare data breach of the year to date, ahead of the 3.4 million-record data breach at Trizetto Provider Solutions, but behind the 15 million-record breach at DentaQuest. According to the breach summary on the HHS’ Office for Civil Rights data breach portal, the Unlimited Technology Systems data breach involved the protected health information of 3,803,750 individuals. While the incident was confirmed in July, it was first identified in October 2025. The threat actor had access to its network between October 5 and October 10, 2025, and potentially exfiltrated files containing patient data (as detailed below). No threat group appears to have claimed responsibility for the cyberattack. Business associates of healthcare organizations are attractive targets for...
Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic
Settlements have been agreed to resolve class action data breach lawsuits against Omni Healthcare Financial Holdings and its subsidiaries, and Western Montana Clinic. Omni Healthcare Financial Holdings Data Breach Settlement Omni Healthcare Financial Holdings, along with defendants Omni Healthcare Financial, LLC, and Injury Finance, LLC (Omni Healthcare), have settled class action litigation over a January 2024 cybersecurity incident involving the protected health information of 16,852 individuals. Omni Healthcare, a provider of financial solutions to healthcare organizations and patients, experienced a cybersecurity incident involving unauthorized network access between January 18 and January 19, 2024. Information exposed in the incident included names, contact information, dates of birth, Social Security numbers, diagnosis & treatment information, medical record numbers, treatment costs, provider names, and other information. The affected individuals were notified in April 2025, 15 months after the breach was first detected. In total, Omni Healthcare mailed around 42,000...
Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data
The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts to track consumer product-related injuries. By the end of the year, CPSC hopes that more than 100 hospitals will provide the requested records to the Kansas-based government contractor Konza Health, which was awarded a $15.9 million contract last year to support the National Electronic Injury Surveillance System (NEISS) Remodel project. NEISS has been in operation for more than 5 decades, and its primary purpose is to collect data on consumer product-related injuries in the United States. NEISS is an important public health research tool; however, data collection is labor-intensive and involves a manual review and coding of medical records from around 70 of the nation’s 5,000+ hospital emergency departments. Currently, 14 states do not have any participating hospitals, which limits the geographic reach of the system and has reduced CPSC’s ability to identify rare and emerging product hazards. Under the planned NEISS Remodel (NEISS-R) project, coverage...



