TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries
Data breaches have been announced by TriWest Healthcare Alliance, Texas Medicaid and Healthcare Partnership, the Minnesota Health Insurance Network, and Secure Health Plans of Georgia. TriWest Healthcare Alliance TriWest Healthcare Alliance, a contractor that manages care for active duty, retired, and National Guard and Reserve military personnel and their family members under the United States Department of Veterans Affairs VAPCCC program, has shared information on a data breach reported to the HHS’ Office for Civil Rights on May 21, 2026. According to the OCR breach report, the protected health information of 11,848 individuals was potentially compromised in the incident. The security incident was first identified on April 16, 2026. The forensic investigation confirmed that an unauthorized third party gained limited access to parts of its network and downloaded files containing protected health information. Data compromised in the incident includes names, Department of Defense Benefits Numbers, beneficiaries’ ZIP codes, and health-related information. Only 5 individuals had their...
Clover Health Assessing Impact of Social Engineering Incident
Clover Health Investments has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident first identified on July 4, 2026. Clover Health Investments is a publicly traded health insurer that provides Medicare Advantage plans, directly contracts with the U.S. government, and manages care for Medicare beneficiaries in 11 states. The company also provides technology and software tools to physicians. Unusual login activity was identified, and its forensic investigation confirmed that a hacker had accessed three employee email accounts after the employees had been tricked by social engineering into disclosing their credentials. Clover Health activated its incident response plan to contain the incident and believes that unauthorized access has been terminated. Clover Health said the compromised accounts belonged to non-managerial health plan employees who were responsible for handling member visit scheduling and broker-facing sales work. The accounts did not have permissions to access corporate financial or claims systems, but they could access some personal...
$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation
Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved unauthorized access to systems containing the personal and protected health information of 624,496 individuals. Healthcare Services Group is a Bensalem, PA-based provider of environmental, dining, and nutritional support services, and works with more than 3,000 healthcare facilities in 48 U.S. states. Suspicious network activity was identified on or around October 7, 2024, and the forensic investigation determined that its network was first breached by an unauthorized third party on September 27, 2024. Prompt action was taken to prevent further unauthorized access, but files containing protected health information had already been exfiltrated from its network. Those files contained information such as names, Social Security numbers, driver’s license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information. Notification letters started to be mailed to the affected...
Major Healthcare Software Vendor Investigating Cyberattack
The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was stolen in the attack, including employee data and some customer and partner records. Craneware is a UK company that heavily targets U.S. healthcare companies. The company makes healthcare accounting and billing software, and partners with 2,000 hospitals and health systems, and around 10,000 pharmacies and clinics, many of which are located in the United States. According to the Craneware website, its software and Trisus cloud platform underpin around 165 million unique patient encounters and impact half a trillion healthcare dollars. In 2021, the company acquired the pharmacy software vendor Sentry, providing the company with access to almost 150 million patient records. Craneware reports that the company quickly implemented its incident response plan and contained the incident, without any disruption to customer services or the company’s operations. The external investigators assisting with the response have not found any further signs of...
ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit
ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle a class action lawsuit stemming from a May 2025 ransomware attack. The attack was identified by ApolloMD on or around May 22, 2025, and the forensic investigation determined that a ransomware actor accessed its network between May 22 and May 23, 2025, potentially exfiltrating files containing the protected health information of patients of its healthcare provider clients. The Qilin ransomware group claimed responsibility for the attack. The ApolloMD data breach included names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers, and was reported to the HHS’ Office for Civil Rights as affecting 626,540 individuals. The first batch of notification letters was mailed to the affected individuals starting in September 2025, with a second wave of notifications issued in March 2026. The first class action lawsuits were filed shortly after the first round of...



