Oncology Firm Novocure Announces Cyberattack and Data Breach
The medical technology and oncology company Novocure has recently confirmed that patient and employee data were exposed in a recent cyberattack. Novocure is a publicly traded company with approximately 1,300 employees worldwide. Its global HQ is in Baar, Switzerland, and its U.S. headquarters is in Portsmouth, New Hampshire. The company has developed a novel non-invasive cancer treatment called Tumor Treating Fields (TTFields), which uses low-intensity, alternating electrical fields to disrupt the division of cancer cells. Novocure explained in a September 1, 2026, Form-8K filing with the U.S. Securities and Exchange Commission (SEC), that it became aware of unauthorized access to some of its information systems via a subsidiary in mid-August 2026. Its incident response plan was activated, along with containment measures, and an investigation was launched, with assistance provided by third-party cybersecurity forensics experts. While employee and patient data were stored on the compromised systems, the impact of the data breach was limited. Based on the investigation to date,...
Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack
Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma, has agreed to settle class action litigation stemming from a 2025 ransomware attack and data breach that affected 113,575 individuals. The ransomware attack was identified by Highlands Oncology Group on or around June 2, 2025. While the attack was identified in early June, the investigation determined that the ransomware group first gained access to its network as early as January 21, 2025. Data accessed and/or exfiltrated included names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information. The affected individuals were notified on August 1, 2025, and the first class action lawsuit was filed on August 5, 2025. In total, thirteen class action lawsuits were filed in response to the...
Hacking Incidents Announced by Rehabilitative Care Providers and Senior Living Facilities
Data breaches have been announced by multiple North Carolina rehabilitative care practices, senior living and skilled nursing care providers in Ohio and Washington, and the California-based nonprofit foundation The Health Trust and its subsidiary, FASS. North Carolina Rehabilitation Practices Notify Patients About November Hacking Incident The operator of multiple clinical, long-term, and rehabilitative care practices in North Carolina has reported a data security incident that has affected almost 4,000 patients of Elevate Health & Rehabilitation, Bear Mountain Health and Rehabilitation, and Swannanoa Valley Health and Rehabilitation. On June 1, 2026, the operator learned that there had been unauthorized access to files maintained by an unnamed third-party vendor, and some of those files had been copied by a bad actor. The unauthorized third party used stolen credentials to log in to its system between November 25, 2025, and November 28, 2025. The obtained files contained patient information such as names, addresses, email addresses, dates of birth, Social Security numbers,...
DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation
In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some of the affected individuals took legal action in response to the data breach, which they claim has put them at risk of identity theft and fraud. Following extensive negotiations, a $15 million settlement has been proposed to bring the litigation to an end. DaVita operates more than 3,000 kidney dialysis centers in the United States and 14 other countries. On April 12, 2025, the Interlock ransomware group accessed its network, exfiltrated data, and encrypted files, causing temporary disruption to operations. The forensic investigation determined that the electronic protected health information of 2,689,826 individuals was compromised in the incident, including names, contact information, Social Security numbers, health insurance information, clinical information, and tax information. Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not...
Aesto Health Data Breach Affects 9.5 Million Patients
On August 14, 2026, we reported on a data breach at the Birmingham, Alabama-based healthcare technology company Aesto Health. While it was clear when we reported on the incident that it was a major breach, the number of individuals affected was unclear. We now know that at least 37 of the company’s healthcare provider clients were affected, as detailed in the list at the bottom of this page. The data breach has now been reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 9,540,683 individuals, which makes it the second-largest confirmed healthcare data breach of the year to date, behind the 15 million record data breach at DentaQuest. August 14, 2026: Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients A data breach at Aesto Health, a Birmingham, Alabama-based healthcare technology company, has affected several of its healthcare provider clients. Aesto Health provides secure data migration, legacy data archiving, and electronic health record (EHR) exchanges for medical practices and...



