Data Breaches Reported by Sunshine Health; Health Payment Systems
A vishing attack on Sunshine Health, a Florida-based Medicaid and health insurance agency, involved the theft of the PHI of more than 41,000 individuals. Health Payment Systems, a Wisconsin healthcare billing company, has experienced an email security incident affecting more than 8,000 patients.
Sunshine Health
Sunshine Health, a Broward County, Florida-based Medicaid and health insurance agency, has recently discovered a vishing incident involving the impermissible disclosure of the protected health information of 41,569 individuals.
Vishing, or voice phishing, takes place over the phone and involves tricking an individual into providing the attacker with access to their device or sensitive information. In this case, an employee was tricked into sharing a limited number of health plan files by a caller pretending to be a trusted individual. The incident occurred on May 6, 2026, and was identified the same day. An investigation was launched, and the shared files were reviewed and were found to include names, dates of birth, medical information/histories, and health plan coverage information.
Sunshine Health said it has not found any evidence to suggest that the disclosed information has been misused at this time; however, to protect against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. Additional training has been provided to the workforce to raise awareness of the techniques that threat actors may use to gain access to internal systems and sensitive data.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Health Payment Systems
Health Payment Systems, Inc., a Wisconsin-based healthcare technology and billing software company, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,380 individuals.
On or around June 27, 2025, the company identified suspicious activity within its email environment. Immediate action was taken to secure the accounts and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident. Assisted by third-party cybersecurity specialists, Health Payment Systems confirmed that certain employee email accounts had been accessed by an unauthorized third party between June 24, 2025, and June 27, 2025, and certain emails were copied.
It has taken more than a year to investigate the incident and review the affected data. The HHS’ Office for Civil Rights was informed about the data breach on July 10, 2026, and notification letters are now being mailed to the affected individuals. Data exposed in the incident included names, addresses, birth dates, IDs, subscription IDs, and subscriber person IDs. For certain individuals, medical information, health insurance information, and Social Security numbers were also involved.
The affected individuals have been offered complimentary credit monitoring and identity theft protection services, and have been advised to monitor their explanation of benefits statements and account statements for signs of data misuse. Health Payment Systems said it has strengthened its security policies and has implemented additional cybersecurity measures to prevent similar incidents in the future.


