Emergency Medical Services Authority & Compassion Health Care Settle Data Breach Litigation
Emergency Medical Services Authority in Oklahoma and Compassion Health Care in North Carolina were sued over cyberattacks and data breaches. Settlements have now been agreed to resolve both class action lawsuits. Emergency Medical Services Authority Data Breach Settlement Emergency Medical Services Authority (EMSA), the largest provider of pre-hospital emergency medical care in the state of Oklahoma, has agreed to settle a class action lawsuit stemming from a cyberattack detected on February 13, 2024. EMSA determined that hackers accessed its network between February 10, 2024, and February 13, 2024, and acquired files containing patient and employee data. The data breach affected 611,743 individuals and included names, addresses, dates of birth, dates of service, and Social Security numbers. Two class action lawsuits were filed in response to the data breach, which were consolidated in the Oklahoma District Court of Oklahoma County – Wade Quick and Laura Lance v Emergency Medical Services Authority. EMSA denies all claims of liability, fault, and wrongdoing, and sought to...
Healthcare Sector Most Targeted by Ransomware Groups as Attacks Increase 49% YOY
A new record was set for ransomware attacks last year, with disclosed ransomware attacks increasing by 49% year-over-year to a record-high of 1,174 attacks, according to Black Fog’s 2025 State of Ransomware Report. There was also a 37% year-over-year increase in undisclosed attacks, with 7,079 victims added to dark web data leak sites in 2025. The figures indicate that globally, 86% of ransomware attacks are not disclosed by victims. Data theft almost always occurs with ransomware attacks. In 2025, 96% of attacks involved data exfiltration prior to file encryption, which results in greater organizational harm. Data exfiltration has contributed to the significant increase in breach costs, as data theft results in greater reputational harm and increased regulatory exposure. In 2025, the average cost of a data breach was $4.44 million globally, and $7.42 million for healthcare data breaches. Healthcare retained its position as the sector most targeted by ransomware groups in 2025, accounting for 22% of disclosed attacks. All sectors experienced an increase in attacks in 2025, apart...
Data Breaches Announced by MedRevenu & EyeCare Partners
Data breaches have been confirmed by the revenue cycle management company MedRevenu Inland Physicians Hospitalist Services, and the Missouri-based eye care provider, EyeCare Partners. MedRevenu Inland Physicians Hospitalist Services MedRevenu Inland Physicians Hospitalist Services, a Montclair, CA-based vendor that provides revenue cycle management services to healthcare providers, has recently notified the California Attorney General about a cybersecurity incident. The incident occurred on or around December 12, 2024, and caused disruption to its network. The forensic investigation determined that files containing personal and protected health information may have been accessed or acquired in the incident, including names, dates of birth, Social Security numbers, driver’s license numbers/government identification numbers, health insurance information, medical information, financial account numbers, payment card numbers, and access information. MedRevenu said it is reviewing and enhancing its cybersecurity measures and has offered the affected individuals complimentary...
Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised
We previously reported that the Aflac data breach had affected 22.65 million individuals worldwide; however, it was unclear exactly how many of those individuals were in the United States or how many individuals had protected health information (PHI) compromised in the incident. PHI is personally identifiable information related to healthcare that is afforded additional protections under the Health Insurance Portability and Accountability Act (HIPAA). The HIPAA Breach Notification Rule requires notifications to be issued to the affected individuals and for the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) to be notified about a data breach within 60 days of the discovery of a breach. If the number of affected individuals has not been determined by the breach reporting deadline, OCR requires an estimate to be provided for the number of affected individuals. Many entities use a placeholder figure of 500 or 501 affected individuals in such cases. Aflac reported the data breach using a 500 placeholder figure. Aflac has recently provided an update to OCR...
Pinehurst Radiology Associates & Tallahassee Memorial HealthCare Settle Class Action Data Breach Lawsuits
Pinehurst Radiology Associates has agreed to settle a class action lawsuit over a January 2025 data breach, and Tallahassee Memorial HealthCare has agreed to settle class action litigation over its use of pixels on its website. Pinehurst Radiology Associates Settlement Pinehurst Radiology Associates, a medical diagnostic imaging center in Pinehurst, North Carolina, has agreed to settle a class action lawsuit over a January 2025 security incident that affected 8,682 individuals. Pinehurst Radiology Associates identified a cybersecurity incident on January 20, 2025, and determined that patients’ protected health information had been exposed. Data exposed in the incident included names, addresses, dates of birth, Social Security numbers, diagnoses, treatment information, medical record numbers, health insurance information, and Medicare/Medicaid numbers. The affected patients were notified on or around May 22, 2025. Two class action lawsuits were filed in response to the data breach, which were consolidated in the Superior Court of Moore County, North Carolina – McNeill, et al....



