QualDerm Partners Data Breach Affects More Than 3 Million Individuals
In late February, The HIPAA Journal reported on a QualDerm Partners data breach, the scale of which was currently unknown, except that it affected 174,837 Texas residents. The data breach was likely to have affected considerably more individuals, given that QualDerm Partners does business in 17 U.S. states and serves more than 15 million patients annually. The scale of the data breach is now clearer, as the Oregon Attorney General and the HHS’ Office for Civil Rights have been notified that 3,117,874 individuals have been affected. Notification letters started to be mailed to those individuals on February 22, 2026. February 25, 2026: QualDerm Partners Confirms Significant Data Breach QualDerm Partners, LLC, a provider of healthcare management services to 158 dermatology and skin care practices in 17 U.S. states, has announced a security incident involving unauthorized access to its computer network. Unauthorized network activity was identified on December 24, 2025, and immediate action was taken to contain the incident and secure its network and computer systems. Third-party...
University of Hawai’i Cancer Center: 1.15 Million Individuals Affected by 2025 Ransomware Attack
The University of Hawai’i Cancer Center (UHCC) has confirmed that up to 1.15 million individuals may have been affected by its August 2025 ransomware attack. The HIPAA Journal previously reported on the incident in January 2026 (see below), when the attack and data breach were first announced; however, at the time, the file review was ongoing, and the number of affected individuals had yet to be announced. UHCC explained that the notification delay was due to the volume of data impacted, the complexity of the encrypted data, and the age of the studies and records. In a report to the state legislature, UHCC provided additional information about the attack and data breach, confirming that the ransomware attack had no impact on patient care, clinical trials operations, its Basic Science and Prevention Division, and there was no unauthorized access to student records. The forensic investigation determined that the threat actor accessed the UHCC Epidemiology Division’s research files, exfiltrated files, and encrypted data. The initial findings of the investigation found that a majority...
Trizetto Data Breach: PHI of 3.4 Million Individuals Exposed
It has been more than four months since TriZetto Provider Solutions discovered unauthorized access to its IT environment, and it has now been confirmed that the protected health information of at least 3,433,965 individuals was exposed or compromised in the incident. The data breach has recently been added to the HHS’ Office for Civil Rights breach portal. At more than 3.4 million affected individuals, it ranks as one of the largest healthcare data breaches to be confirmed this year. TriZetto identified suspicious activity within its web portal on October 2, 2025. The web portal is used by its clients to access TriZetto systems. TriZetto took immediate action to prevent further unauthorized access to its systems and has not detected any further unauthorized activity since that date. The forensic investigation revealed that the threat actor first gained access to data almost a year before the unauthorized access was detected. The first unauthorized access to records occurred in November 2024. The data breach affected the revenue cycle management side of the business and the...
How Much are HHS OIG Penalties?
HHS OIG penalties vary depending on the nature of the offense, the scale of the offense, and the cooperation of the violating party during the investigation of the offense. Other factors that can influence HHS OIG penalties include the regulatory limits applied to each type of violation and the violating party’s previous history of compliance with healthcare regulations. Among its many roles, the Department of Health and Human Services (HHS) Office of Inspector General (OIG) is responsible for investigating allegations of fraud, waste, and abuse in Federal healthcare programs. When HHS OIG identifies fraud, waste, or abuse, it has the authority to recover funds, exclude individuals and organizations from Federal healthcare programs, and pursue civil monetary penalties or criminal penalties depending on the nature of the offense. The amount of HHS OIG penalties is calculated on a case-by-case basis, and quite often cases can be settled for a mutually agreed amount to avoid potential litigation. The amount of HHS OIG penalties can also be reduced if the violating individual or...
Asheville Eye Associates Settles Lawsuit Stemming from DragonForce Ransomware Attack
Asheville Eye Associates, an eye care provider serving patients in Western North Carolina, has agreed to settle class action litigation stemming from a November 2024 cyberattack and data breach. A cyber threat actor accessed its network and potentially viewed or obtained patient information, including names, addresses, health insurance information, and medical treatment information. The Asheville Eye Associates data breach was reported to the HHS’ Office for Civil Rights as affecting 204,984 individuals. The DragonForce ransomware group took credit for the attack and claimed to have exfiltrated 540 GB of data before encrypting files. The data was leaked when the ransom was not paid. The affected individuals were notified about the attack in early February 2024. Multiple lawsuits were filed in response to the data breach by plaintiffs Robert Woodsmall, Mimi Reynolds, Dena Brito, Robert Ricchetti, and Christopher Miller. The lawsuits were consolidated, In re Asheville Eye Associates Data Incident Litigation, in South Carolina’s General Court of Justice Superior Court Division. The...



