Email Accounts Compromised at Four Healthcare Orgs
Email accounts have been compromised at Restorix Health in New York, INTERLINK Health Services in Oregon, RxSight in California, and Fillmore County Hospital in Nebraska, and patient data has been exposed. Restorix Health Restorix Health, a Tarrytown, New York-based wound care solutions company, discovered on May 30, 2024, that an employee email account had been subjected to unauthorized access. The investigation confirmed the breach was limited to a single account, and the forensic investigation revealed the account was accessed between May 7, 2024, and May 29, 2024. The review of the account was completed on November 27, 2024, and confirmed that some protected health information had been exposed. The affected healthcare partners were notified on December 18, 2024, and it has been confirmed that 38,553 individuals were affected. The data varied from individual to individual and may have included names, dates of birth, driver’s license numbers, government identification numbers, passport numbers, Social Security numbers, patient ID numbers, medical information, prescription...
Data Breaches Announced by Central New York Cardiology & Park Place Pediatric Dentistry
Central New York Cardiology has experienced a cyberattack involving unauthorized access to patient data, and an unencrypted laptop computer has been stolen from an employee of Park Place Pediatric Dentistry in Texas. Central New York Cardiology Central New York Cardiology fell victim to a cyberattack in December 2024 in which hackers accessed its network and potentially viewed or obtained patient data. The forensic investigation confirmed that the hackers could access parts of its network from December 26, 2024, to December 30, 2024. The file review is ongoing, and at the time of the breach announcement, the total number of affected individuals had not been determined; however, Central New York Cardiology has confirmed that the information compromised in the incident likely included first and last names together with one or more of the following: address, date of birth, driver’s license number, Social Security number, diagnosis/condition, health insurance information, provider name, other treatment information, and/or financial account information. Central New York Cardiology has...
New York Labor Union Settles Data Breach Lawsuit for $6 Million
The New York-based labor Union, UNITE HERE, has agreed to pay $6 million to resolve a consolidated class action lawsuit that alleged a failure to implement appropriate cybersecurity measures to protect the sensitive data it held. On October 20, 2023, UNITE HERE identified unauthorized access to its systems. Hackers were determined to have breached its network and gained access to files containing the personal and protected health information of members of certain local unions and health funds. It was not possible to determine exactly how many people were affected, so the decision was taken to send notification letters to all 791,273 potentially affected members. Data compromised in the incident included names, Social Security numbers, driver’s licenses, state identification numbers, alien registration numbers, tribal identification numbers, passport numbers, birth certificates, dates of birth, marriage licenses, signatures, financial account information, and medical information. Class action lawsuits were filed by union members, which were consolidated into a single lawsuit –...
Lawsuit Filed Against Amazon Alleging Unlawful Collection of Health & Location Data
A lawsuit has been filed against Amazon alleging its software development kit (SDK) has unlawfully collected consumers’ health and location data in violation of federal laws and consumer privacy laws in Washington state. An SDK is a suite of software development tools such as compilers, code libraries, and debuggers, that allows software developers to build applications quickly and in a standardized way. The Amazon SDK is embedded in thousands of third-party applications and runs in the background, allowing Amazon to collect information such as location data directly from consumer devices. The information collected by Amazon is used for advertising purposes, and the data can be sold to others. The lawsuit alleges the Amazon SDK has been integrated into more than 10,000 different apps. The lawsuit was filed in the U.S. District Court for the Western District of Washington at Seattle on February 20, 2025, on behalf of plaintiff Cassaundra Maxwell and similarly affected individuals. The lawsuit alleges Amazon is unlawfully tracking, collecting and profiting from users’ location...
Fred Hutchinson Cancer Center Settles Class Action Data Breach Lawsuit for $11.5M
Fred Hutchinson Cancer Center and the University of Washington have agreed to pay $11,500,000 to settle a proposed class action data breach lawsuit and have committed to investing $13,500,000 to improve cybersecurity. The lawsuit stems from a cyberattack and data breach discovered after the Thanksgiving weekend in 2023. Hackers breached its network and stole the protected health information of approximately 2.1 million individuals between November 10 and November 25, 2023, including names, contact information, medical information, and Social Security numbers. The attack was conducted by the Hunters International threat group, which demanded a ransom payment to prevent the publication of the stolen data. When the ransom was not paid, the affected patients were sent individual ransom demands and were told that they needed to pay $50 to have their stolen data deleted, otherwise, it would be published online. Several lawsuits were filed in response to the data breach, which were consolidated into a single lawsuit – In re: Fred Hutchinson Cancer Center Data Breach Litigation – in...



