25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents

Data breaches have been reported by the Boston Healthcare for the Homeless Program in Massachusetts, Monongalia County General Hospital Company in West Virginia, and Open Door Health Center of Illinois.

Boston Healthcare for the Homeless Program, Massachusetts

Boston Healthcare for the Homeless Program, a Boston, MA-based nonprofit organization that provides healthcare services for the homeless population, has notified state attorneys general about a network security incident first identified on November 11, 2025.

The incident was detected when it experienced a network disruption. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party accessed its network and potentially viewed or obtained files containing sensitive patient information.

The review of the affected data was completed on June 8, 2026, when it was learned that names, Social Security numbers, credit/debit card information, government identification numbers, financial account codes, medical information, health records, and health insurance information were involved. The affected individuals have been offered single-bureau credit score, credit report, and credit monitoring services for 12 months. While the total number of affected individuals is unclear, at least 184,914 Massachusetts residents have been affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Monongalia County General Hospital Company, West Virginia

Monongalia County General Hospital Company, aka Mon General, has recently confirmed a data breach that exposed the personal and medical information of certain patients. Suspicious activity was identified within its email system on May 6, 2026. Assisted by a digital forensics company, Mon General determined that a small number of employee email accounts had been accessed by an unauthorized third party. Employees had responded to phishing emails and disclosed their credentials.

The forensic investigation confirmed that the incident was limited to the email accounts; however, they did contain patient information such as first and last names, birth dates, email addresses, phone numbers, Social Security numbers, health information, and health insurance information. Notifications have been issued, and the affected patients have been offered two years of complimentary credit monitoring and identity theft protection services. The number of affected individuals has yet to be publicly disclosed.

Open Door Health Center of Illinois

Open Door Health Center of Illinois, a primary care and sexual health care clinic in Chicago, Illinois, has fallen victim to a cyberattack that appears to have involved the theft of patient data. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 affected individuals. There is currently no substitute breach notice on the Open Door Health Center of Illinois website, so the types of data involved are not yet known. This appears to have been a ransomware attack by the Inc Ransom ransomware group, which added Open Door Health Center of Illinois to its dark web data leak site on May 21, 2026. Inc Ransom is a ransomware group that engages in data theft and extortion. The group claims to have exfiltrated sensitive data.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist