Lakeview Health Systems Settles Class Action Data Breach Lawsuit
A settlement has been negotiated to resolve a class action lawsuit against Lakeview Health Systems LLC. The lawsuit stemmed from a January 2024 cyberattack that exposed the personal and protected health information of 10,772 individuals. Hackers breached its network and accessed and potentially obtained files containing names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account numbers, patient IDs, diagnoses, treatment information, prescription information, and health insurance information. Shortly after being notified about the breach, some of the affected individuals filed lawsuits against Lakeview Health, alleging negligence for failing to adequately protect sensitive data stored on its network. The plaintiffs claimed the data breach could have been and should have been prevented. Lakeview Health maintains that there was no wrongdoing and is no liability. The lawsuits made similar claims and were consolidated – Skov et al., v. Lakeview Health Systems, L.L.C – in the Circuit Court of Duval County, Florida. The lawsuit is pending;...
Connecticut Medicaid Portal Breach Affects 22,500 Hartford HealthCare Patients
The personal and protected health information of approximately 22,500 Hartford HealthCare patients has been exposed in a security incident. Data breaches have also been announced by the New York City cosmetic surgery practice of Ira L. Savetsky, MD, and the mobility and rehabilitation product provider ERMI, LLC. Hartford HealthCare The Connecticut Department of Social Services and Gainwell Technologies, a vendor that provides fiscal agent and account administration services for the Connecticut Medicaid program (HUSKY), have identified unauthorized access to certain payment accounts on the HUSKY provider portal website. Suspicious activity was identified on March 25, 2026, and the forensic investigation confirmed unauthorized access to a small number of Hartford HealthCare’s payment accounts on the website. The accounts were accessed on March 4, 2026, using the compromised credentials of Hartford Healthcare employees. Immediate action was taken to prevent further unauthorized access, and assisted by third-party cybersecurity experts, the incident was determined to have been...
Extortion Group Conducts Social Engineering Campaign Impersonating IT Support Staff
Silent Ransom Group, a data theft and extortion group that targets law firms, healthcare organizations, and insurance and finance companies, is conducting a social engineering campaign posing as IT support workers. Silent Ransom Group (aka Luna Moth, Chatty Spider, UNC3753) is a financially motivated threat group that, as the name suggests, quietly infiltrates networks, exfiltrates sensitive data, and demands payment to prevent the stolen data from being publicly leaked or sold. The group does not use ransomware to encrypt files. Silent Ransom Group has demonstrated a penchant for attacking U.S. law firms, although it has conducted attacks on other sectors such as insurance, finance, and healthcare, where the leaking of sensitive data can cause significant reputational harm and regulatory scrutiny. Silent Ransom Group has conducted phishing campaigns in the past, using social engineering techniques to trick employees into installing remote access software. One such campaign involved phishing emails notifying the recipient about a subscription for a service that was about to incur a...
How to Get Small Practices HIPAA Compliant in a Few Hours
A small practice can build a complete HIPAA program, including a HIPAA Security Risk Analysis, policies, HIPAA training, and business associate and vendor agreements, in a matter of hours when the process is generated around the practice rather than assembled by hand from separate documents and templates. The time required is not solely driven by the size of the practice, but also by whether the process is structured or manual. Why Manual Compliance Takes Months, Not Hours Building a HIPAA program manually typically requires researching requirements, locating or purchasing templates, adapting them to the practice’s specific systems, scheduling and tracking staff training, and organizing documentation in a format that can be produced later. Each step depends on the one before it, and most practices are doing this work alongside patient care, billing, and staffing, with no dedicated compliance role. Under these conditions, a program that could be built in hours often stretches across months, and in many practices it is never fully completed. The delay is not a sign of a...
The Oncology Institute Confirms Vendor Breach Involved Patient Data
The Oncology Institute, a publicly traded provider of cancer care through more than 100 clinics in California, Oregon, Nevada, Arizona, and Florida, has recently confirmed that patient data was potentially accessed by an unauthorized third party as a result of a security incident at one of its vendors. In a November 3, 2025, filing with the U.S. Securities and Exchange Commission (SEC), The Oncology Institute said that it determined on November 3, 2025, that a cybersecurity incident at one of its information technology software providers would potentially delay fee-for-service collections. At the time of the notice, The Oncology Institute said its vendor was unable to confirm whether patient data had been accessed in the attack, and that at the time of issuing the filing, it was unaware of any unauthorized access to patient data as a result of the incident, but the investigation into the incident was ongoing. In an updated SEC filing, the Oncology Institute said further information has come to light indicating that certain vendor systems were subject to unauthorized access by a...



