California Critical Access Hospital Announces Cybersecurity Incident
Data breaches have been announced by Modoc Medical Center and Vista Del Mar Child and Family Services in California, Park Place Behavioral Healthcare in Florida, and Millstone Medical Outsourcing in Massachusetts.
Modoc Medical Center
Modoc Medical Center, a 12-bed critical access hospital and rural healthcare system based in Alturas, California, has identified unauthorized access to its computer network. The unauthorized access was detected on January 27, 2026, and cybersecurity specialists were engaged to help secure its systems and investigate and determine the nature and scope of the incident. The investigation confirmed that an unknown actor had access to parts of its computer network between January 19, 2026, and January 27, 2026, and downloaded certain files, some of which contained patients’ personal and protected health information.
The review of the data has been completed, and notification letters are now being sent to the affected individuals. The data types involved varied from individual to individual and are detailed in the individual notification letters. The data involved included names in combination with one or more of the following: Social Security number, driver’s license or state identification number, financial account information, payment card information, passport number, military identification number, medical information, and/or health insurance information.
The affected individuals have been offered 12 or 24 months of complimentary credit monitoring and identity theft protection services, and steps have been taken to strengthen security to prevent similar incidents in the future. The Worldleaks ransomware and data extortion group claimed responsibility for the attack. It is unclear whether ransomware was involved.
Vista Del Mar Child and Family Services
Vista Del Mar Child and Family Services, a Los Angeles, California-based nonprofit provider of mental health, education, and social services to children, adolescents, and their families, is reviewing the data exposed in a recent cybersecurity incident. Suspicious activity was identified within its computer systems on June 30, 2026, indicative of an intrusion. Its incident response protocols were activated, containment measures deployed, and an investigation was launched. Third-party cybersecurity professionals were engaged to help determine the nature and scope of the incident and confirmed that an unauthorized third party had accessed systems containing personal and protected health information.
There was no impact on its operations, and services continued to be provided to all individuals as scheduled. The data review is ongoing, and it is too early to confirm the number of individuals affected or the data types involved. Notification letters will be mailed to the affected individuals when those processes are completed. In the meantime, the data breach has been reported to the HHS’ Office for Civil Rights as involving the protected health information of at least 500 individuals. Vista Del Mar Child and Family Services said law enforcement has been notified, it is reviewing its security policies, protocols, and procedures, has implemented additional security controls, and is working on optimizing its endpoint monitoring software.
Park Place Behavioral Healthcare
Park Place Behavioral Healthcare (formerly Osceola Mental Health Inc.), a community behavioral health provider in Osceola County, Florida, that provides mental health and substance use services, has notified patients about a recent cybersecurity incident. Suspicious activity was identified within its computer network on July 23, 2026. Third-party cybersecurity experts were engaged to investigate the activity, and on August 19, 2026, the investigation was completed and confirmed that its network had been accessed by an unauthorized third party.
A file review was initiated, and on September 17, 2026, Park Place Behavioral Healthcare obtained the final list of individuals to notify. The data involved varied from person to person and may have included names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers/other government-issued ID numbers, financial account information, health information, and/or health insurance information.
Park Place Behavioral Healthcare said several steps have been taken in response to the incident, including resetting user account credentials, installing endpoint detection and response software for continuous monitoring, and refining the security of its remote access methods. The number of affected individuals has not currently been publicly disclosed. The Insomnia ransomware group claimed responsibility for the attack and listed the stolen data on its dark web data leak site, which indicates that the ransom was not paid.
Millstone Medical Outsourcing
Millstone Medical Outsourcing, a Fall River, Massachusetts-based medical device outsourcing company, has identified a cybersecurity incident that exposed personal and health information. The forensic investigation determined that an unauthorized third party first accessed parts of its network on December 15, 2025. The intrusion was detected on December 16, 2025, and the forensic investigation determined that its network had been accessed by an unauthorized third party between December 15, 2025, and December 19, 2025, during which time files were acquired.
The data review confirmed on July 15, 2026, that the stolen data included Social Security numbers, government identification numbers, financial account codes, credit/debit card information, and health records. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 24 months. No misuse of the affected information had been identified at the time of issuing notification letters. The number of affected individuals has not been publicly disclosed at the time of publication of this article.



