25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Data Breaches Announced by Five Small Healthcare Organizations

Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of Raleigh; Arkansas Oral & Maxillofacial Surgeons; Alpine Agency of the Midlands; Princeton Family Eye Care; and James C. Standring, DDS.

Family Medical Associates of Raleigh, North Carolina

Family Medical Associates of Raleigh, a multi-provider family medical practice in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, and activated its incident response protocol. Steps were immediately taken to investigate, contain, and remediate the incident; law enforcement was notified, and third-party cybersecurity professionals were engaged. The investigation and data review are ongoing; however, it has been confirmed that certain systems were intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026, who potentially downloaded internal data, including files containing patients’ protected health information.

The data review has not yet been completed, but the types of data exposed in the incident include names, demographic information, contact information, medical and treatment information, health insurance information, financial/payment-related information, government-issued ID numbers, and other data related to the medical services provided. Family Medical Associates of Raleigh said it is unaware of any actual or attempted misuse of patient data as a result of the incident; however, patients have been advised to remain vigilant against identity theft and fraud by monitoring their accounts, free credit reports, and explanation of benefits statements.

Since the investigation has yet to conclude, the number of affected individuals is currently unknown. While the name of the threat actor behind the attack was not disclosed, the Genesis ransomware group claimed responsibility for the attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Arkansas Oral & Maxillofacial Surgeons, Arkansas

Arkansas Oral & Maxillofacial Surgeons, a Hot Springs, Arkansas-based provider of oral surgery, dental implants, and other dental and cosmetic dentistry services, has announced a data security incident that was first identified on April 7, 2026.

An investigation was initiated, and on June 2, 2026, it was confirmed that an unauthorized third party had accessed its network and exfiltrated files containing patient information. The files have been reviewed and were found to contain information such as names, contact information, birth dates, medical record numbers, government identification numbers (including Social Security numbers), diagnoses, treatment records, health insurance information, prescription histories, and payment information.

The affected individuals have been notified by mail and provided with recommendations on how to protect themselves against data misuse. Based on the substitute breach notice on the Arkansas Oral & Maxillofacial Surgeons website, credit monitoring and identity theft protection services do not appear to have been offered. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many patients have been affected.

This appears to have been a data theft and extortion attempt. The PEAR threat group claimed responsibility. PEAR does not encrypt files, as the group engages in data theft and extortion, threatening to publish stolen data if the ransom is not paid.

Alpine Agency of the Midlands, South Carolina

Alpine Agency of the Midlands, LLC, a small, independent health and benefits insurance company based in Columbia, South Carolina, has recently disclosed a security incident involving unauthorized access to its email system. Alpine provides services to insurance carriers, employers, and health plans, and is provided with certain health data by its clients in connection with the services it provides.

Unusual activity was identified within an employee email account in November 2025. The account was secured, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that the incident affected a single email account, which was first accessed by an unauthorized third party on October 28, 2026. Emails and associated attachments may have been copied by the attacker.

The account was reviewed and found to contain first and last names, addresses, dates of birth, health insurance information, and limited Social Security numbers. Notifications will be mailed to the affected individuals when the review is completed. In the meantime, the breach has been reported to the HHS’ Office for Civil Rights as affecting at least 500 individuals. The total will be updated when the file review is concluded.

Princeton Family Eye Care, Texas

Princeton Family Eye Care, a small optometry practice in Princeton, Texas, has notified certain patients about a recent data breach. On May 4, 2026, suspicious activity was identified within its email environment. Assisted by third-party cybersecurity experts, the practice secured its email systems, investigated the activity, and confirmed that a company email account had been accessed by an unauthorized third party.

A data review firm was engaged to determine the types of data involved and the individuals affected, and that process has recently been completed. The data exposed in the incident varied from individual to individual and may have included names in combination with one or more of the following: date of birth, contact information, government identification numbers (such as a driver’s license, passport, or Social Security number), and limited medical information (such as treatment details, health insurance records, or a medical record number).

No misuse of the affected information has been identified; however, the affected patients have been advised to remain vigilant against misuse of their information. The breach was reported to the Texas Attorney General as involving the data of 933 Texas residents.

James C. Standring, DDS, California

James C. Standring, DDS, a dental practice in Crescent City, California, has notified 6,658 patients about a data security incident involving unauthorized access to its computer systems. While the data breach was reported to the HHS’ Office for Civil Rights on July 17, 2026, this appears to have been a historical data breach.

According to the breach explanation on the dental practice website, unauthorized access to certain computer systems was first identified on September 2, 2024. Assisted by third-party cybersecurity specialists, the practice determined that the incident resulted in the exposure of the data of current and former patients, including names, addresses, email addresses, Social Security numbers, driver’s license/state ID numbers, medical information, health insurance information, financial account/payment card information, and other personal information maintained by the practice.

No misuse of the affected data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. No explanation was provided about why it took 22 months from the date of discovery to issue notification letters.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist