Ransomware Attack on Good Samaritan Health Center Affects 10,000 Individuals
Data breaches have recently been announced by Good Samaritan Health Center, Wonderland Child & Family Services, and L.A. Care Health Plan. Good Samaritan Health Center Good Samaritan Health Center in Atlanta, Georgia, has notified 10,000 individuals about a February 9, 2026, ransomware attack on one of its internal servers. The attack was identified on February 9, 2026, and the server was isolated to contain the attack. The server was restored from backups on the same day. Good Samaritan Health Center said it has found no evidence to suggest that there has been any misuse of data stored on the server, nor was evidence found of any public disclosure of patient data after the attack; however, Good Samaritan Health Center could not rule out the possibility that data had been accessed or stolen. Data on the server was reviewed, and the files were found to contain names, dates of birth, zip codes, and limited clinical information. Social Security numbers and financial information were not compromised as they were not stored on the server. Good Samaritan Health Center said it has...
American Cybersecurity Professionals Given Jail Terms for BlackCat Ransomware Attacks
Two American cybersecurity professionals who signed up as affiliates for a ransomware group have each been sentenced to four years in prison. The third co-conspirator has yet to be sentenced and will learn his fate on July 9, 2026*. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, along with co-conspirator Angelo Martino, 41, of Florida, had signed up to work as affiliates of the BlackCat ransomware group between April 2023 and December 2023. Under that arrangement, they received 80% of any ransoms they generated, and paid the remaining 20% share to the BlackCat ransomware group in exchange for access to the ransomware encryptor and supporting infrastructure. Goldberg and Martin worked in cybersecurity and had the necessary skills and experience to secure computer systems against ransomware attacks, yet they chose to use their skills to inflict harm for financial gain. While a four-year jail term is no walk in the park, Goldberg and Martin can consider themselves fortunate, as they, along with co-conspirator Martino, faced up to 20 years in jail. “The court’s...
Sandhills Medical Foundation Ransomware Attack Affects 169,000 Patients
Sandhills Medical Foundation in South Carolina and Laurel Eye Clinic in Pennsylvania have experienced security incidents that exposed patient data. The ransomware attack on Sandhills Medical Foundation affected more than 169,000 individuals. Sandhills Medical Foundation, South Carolina Sandhills Medical Foundation, Inc., a federally qualified community health center (FQHC) that provides primary care, behavioral health, and immunization services to residents of Chesterfield, Kershaw, Lancaster, and Sumter Counties in South Carolina, has notified 169,017 individuals that some of their personal and health information was stolen by a ransomware group that compromised its network in May 2025. The ransomware attack was detected on May 8, 2025, when files were encrypted. Digital forensics experts were engaged to investigate the incident, who determined that the ransomware group had access to its network from May 2, 2025, to May 8, 2025. During that time, files were exfiltrated from its network. The exposed and stolen files have been reviewed and were found to contain names, dates of...
Vendor Data Breaches Announced by Six HIPAA-Regulated Entities
There have been several announcements about data breaches at business associates of HIPAA-regulated entities recently, including Providence St. Joseph Orange and Skin & Beauty Center in California, Management-ILA Managed Health Care Trust Fund in New York, and Ideal Home Care, Duncan Regional Home Care, and Chisholm Trail Hospice in Oklahoma. Providence St. Joseph Orange, California Providence St. Joseph Orange, a catholic general hospital in Orange, California, has been affected by a data security incident at its vendor, Pinnacle Holdings, LTD, a health care consulting company. Pinnacle experienced a network disruption in November 2024, and the forensic investigation confirmed unauthorized access to its network between November 11, 2024, and November 25, 2024, during which time files containing protected health information may have been exfiltrated from Pinnacle’s network. Data potentially compromised in the incident included patients’ first and last name, address, email address, date of birth, encounter ID number, health insurance claim number, health insurance policy number,...
Southern Illinois Healthcare Enterprises Pixel Settlement Approved
A settlement has been agreed to resolve litigation against defendants Southern Illinois Healthcare Enterprises, Southern Illinois Hospital Services, and Southern Illinois Medical Services over their use of website tracking technologies without website users’ knowledge or consent. Southern Illinois Healthcare Enterprises Pixel Settlement A class action lawsuit over the use of website tracking technologies has been settled. The lawsuit was filed by John Doe, individually and on behalf of similarly situated individuals, against the defendants Southern Illinois Healthcare Enterprises, Southern Illinois Hospital Services, and Southern Illinois Medical Services over an alleged impermissible disclosure of the plaintiff’s and class members’ private information to third parties. The lawsuit – Doe v. Southern Illinois Healthcare Enterprises, Inc. – was filed in Williamson County Circuit Court, Illinois, and alleged that personally identifiable information was disclosed to Meta (Facebook) via third-party tools on the defendants’ websites without the knowledge or permission of...



