Nationwide Home Health Care Provider Announces Major Data Breach
Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir Medical Corporation in California, and Central Arkansas Pediatrics. LHC Group LHC Group, a Lafayette, Louisiana-based provider of home health, hospice, and home- and community-based services in 28 U.S. states and the District of Columbia, has been affected by a data security incident involving a third-party technology vendor. The unnamed vendor assisted LHC Group with referral management, care coordination, and clinical workflows, and the provision of those services required access to patients’ personal and protected health information. LHC Group said it became aware on April 7, 2026, that an employee may have fallen victim to a voice phishing attack. LHC’s vendor subsequently reported suspicious activity within the vendor’s platform associated with an LHC user account. LHC worked closely with its vendor to secure systems and investigate the activity, and third-party cybersecurity experts were engaged to assist with those...
Hacking Incident Affects 46,000 Hawaii Family Dental Patients
A hacking incident at Hawaii Family Dental has affected almost 46,000 individuals. Data breaches have also been announced by Life Bridges in Tennessee, Westchester Institute for Human Development in New York, Community Health Care in Ohio, and Shoshone Medical Center in Idaho. Hawaii Family Dental Hawaii Dental Group, Inc., doing business as Hawaii Family Dental, a Honolulu-based operator of a dozen dental clinics in Hawaii, has started notifying 45,853 individuals about a July 2026 hacking incident that involved unauthorized access to their personal and protected health information. Suspicious activity was identified within its computer network on July 20, 2026. The forensic investigation confirmed that an unauthorized third party accessed its systems between July 19 and July 20, 2026, including systems where patient information was stored. Files exposed and potentially copied in the incident included names, phone numbers, addresses, email addresses, dates of birth, medical and dental treatment information, and health insurance information. Patients were informed that financial...
FTC Rescinds 2021 Policy Statement on Health App Data Breaches
In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA). On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having been superseded by rulemaking. The Health Breach Notification Rule was issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act and applies to vendors of personal health records (PHRs) and related entities that are not subject to HIPAA. In 2021, the FTC determined that because health apps were mainstream and increasingly collected consumers’ sensitive health and personal information, the developers of the apps should have a responsibility to ensure that the data they collect is secured, protected against unauthorized access, and that consumer notifications are required when there is a breach of that information or an unauthorized disclosure. Per the 2021 policy...
Conti Ransomware Member Sentenced to 4 Years in Jail
A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and other countries has been sentenced to four years in jail for his role in the attacks. The Conti ransomware group was a major ransomware operation that engaged in double extortion tactics, breaching victims’ networks, stealing sensitive data, and encrypting devices for financial gain. The Conti ransomware operation emerged after the shutdown of the Ryuk ransomware group in 2020 and was active until 2022. During that time, the group conducted ransomware attacks on an estimated 1,000 entities in 31 foreign countries, 47 U.S. states, the District of Columbia, and Puerto Rico. While some ransomware groups prohibited attacks on healthcare providers, Conti had no such restrictions and actively targeted healthcare organizations. The group reached peak activity in 2021, when many critical infrastructure entities were attacked, including the Health Service Executive in Ireland and many U.S. hospitals, such as Scripps Health in San Diego. According to the U.S. Department of...
FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices
The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI (GenAI)-enabled medical devices. As a regulator of all medical devices, the FDA is considering whether new regulations are required for GenAI-enabled medical devices to ensure patients are provided with timely access to safe and effective devices. GenAI-enabled medical devices have the potential to transform patient care, yet the devices may introduce unique risks compared to traditional software and artificial intelligence (AI)-enabled medical devices. Current regulatory frameworks, such as those used for traditional medical devices, may not be appropriate for GenAI-enabled devices, which present unique challenges and risks. The devices have unique characteristics and behaviours, including the capability to produce variable outputs, which change over time as the devices incorporate continuously learning systems. GenAI devices can accept open-ended inputs, and it is not feasible to test the full range of inputs and assess outputs using traditional...



