Fairview Health Services Sues Change Healthcare After Incurring $7 Million in Losses
Change Healthcare is facing another class action lawsuit over its February 2024 ransomware attack. The latest lawsuit was filed by a healthcare provider to recover losses incurred due to the prolonged outage of Change Healthcare’s claims processing and payment functions. The ransomware attack was conducted by an affiliate of the BlackCat (ALPHV) ransomware group in February 2024. According to the latest estimate from Change Healthcare, the protected health information of 190 million individuals was stolen in the attack. Many class action lawsuits have already been filed against Change Healthcare over the breach, and they have been consolidated into a single lawsuit, which Change Healthcare is currently attempting to have dismissed. More than two dozen healthcare providers have also sued Change Healthcare to recover losses incurred due to the attack and the massive disruption to its clearinghouse services that followed. The latest lawsuit was filed by Fairview Health Services, a Minneapolis, MN-based integrated healthcare system that operates 10 hospitals and medical centers,...
Business Associate Sued By HIPAA-Covered Entity over Alleged HIPAA Security Rule Failures
A HIPAA-covered entity is suing one of its business associates over an alleged failure to comply with the terms of its business associate agreement (BAA), including not implementing appropriate HIPAA Security Rule safeguards. Molecular Testing Labs (MTL), a Vancouver, Washington-based laboratory specializing in precision laboratory diagnostics, discovered on March 12, 2025, that patient data had been compromised in a cyberattack on its managed service provider business associate, Ntirety. According to MTL’s investigation, a cybercriminal group, potentially of Russian origin, breached Ntirety’s network in a ransomware attack. MTL conducted a forensic investigation and determined that there were “significant deficiencies, shortcomings, and omissions” in Ntirety’s security practices and procedures, which were exploited by the threat actor to access its computer systems and sensitive MTL data. Further, as a result of the ransomware attack, Ntirety was unable to provide material support to MTL for several weeks, and when support was provided, it was conducted “slowly and incompetently.”...
Healthcare Organizations Struggling to Shift from Reactive to Proactive Cybersecurity
Healthcare organizations are still taking a reactive approach to cybersecurity rather than proactively taking steps to reduce risk, according to the findings of a 2025 Healthcare Cybersecurity Benchmarking Study. The study was conducted by KLAS Research in collaboration with Censinet, Health-ISAC, the Scottsdale Institute, the American Hospital Association, and the Healthcare & Public Health Sector Coordinating Councils Public-Private partnership. Many healthcare organizations are proactively reducing cybersecurity risks by adopting cybersecurity frameworks and best practices, including the NIST Cybersecurity Framework 2.0, Health Industry Cybersecurity Practices (HCIP), NIST AI Risk Management Framework (NIST AI RMF) and, a new addition for this year, the Department of Health and Human Services (HHS) Healthcare and Public Health Sector Cybersecurity Performance Goals (HPH CPGs). The study looked at self-reported coverage within these frameworks and gaps that persist around areas such as third-party risk management and asset management. This year, 69 healthcare and payer...
Email Accounts Breached at San Francisco Campus for Jewish Living & Altior Healthcare
Email account breaches have been announced by the San Francisco Campus for Jewish Living and Altior Healthcare in California, and Bassett Healthcare Network has confirmed the unauthorized acquisition of patient data by a former Bassett Healthcare Network physician. San Francisco Campus for Jewish Living Hebrew Home for Aged Disabled, doing business as San Francisco Campus for Jewish Living in California, has notified 2,568 individuals about the exposure of some of their protected health information in an email security incident. The substitute breach notice does not state when the email account breach was compromised, only that the unauthorized access was detected on December 27, 2024. The email account was immediately secured to prevent further access, and an investigation was launched to confirm the nature and scope of the unauthorized activity. The forensic investigation confirmed that the breach was limited to a single email account, with no other systems compromised. The account contained names, dates of birth, medical record numbers, dates of services, admission/discharge...
Vitruvian Health & Erlanger Health Affected by Nationwide Recovery Service Cyberattack
More healthcare providers have confirmed they were affected by the data breach at the debt collection agency Nationwide Recovery Service, including Vitruvian Health & Erlanger Health. Cyberattacks have also been reported by Howard Memorial Hospital and Boudreaux’s Specialty Compounding Pharmacy. Vitruvian Health & Erlanger Health Affected by Nationwide Recovery Service Breach Hamilton Health Care System, Inc., doing business as Vitruvian Health in Georgia and Tennessee, and Erlanger Health in Tennessee, have been affected by a cyberattack on its debt collection vendor, Nationwide Recovery Service. Suspicious activity was identified within the Nationwide Recovery Service network on July 11, 2024. The forensic investigation confirmed unauthorized network access between July 5, 2024, and July 11, 2024, during which time a threat actor exfiltrated sensitive data from the network. Vitruvian Health said the compromised data includes patient names, addresses, Social Security numbers, dates of birth, financial account information, and medical information. The breach was reported to...



