NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack

Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US).

Midwest Spine and Brain Institute (3C Care Systems)

Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems. According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation.

The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C Care Systems. The investigation concluded on June 18, 2026, revealing that personally identifiable information and protected health information was potentially involved, including first and last names in combination with one or more of the following: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service, and health insurance claim and/or policy information.

MSBI is mailing notification letters to the affected individuals and has offered complimentary identity monitoring and protection services to individuals whose Social Security numbers were involved. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many MSBI patients have been affected.

No information was provided as to the nature of the data breach, but this appears to have been a ransomware attack by the now-disbanded RansomHub ransomware operation on or around November 21, 2024. RansomHub claimed it had exfiltrated 100 GB of data from 3C Care Systems, although no separate breach announcement appears to have been made by the IT company, and those claims remain unverified. It is unclear if clients other than MSBI had data compromised in the incident.

Brookhaven ENT Allergy and Facial Surgery

Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, has notified 30,403 individuals that some of their personal and protected health information was compromised in a recent cybersecurity incident. The incident involved a third-party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. The CareCloud breach listing on the OCR data breach portal indicates that 3.75 million individuals were affected.

The incident occurred between March 10, 2026, and March 16, 2026, and the file review determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information had potentially been compromised. You can read more about the CareCloud data breach in this post. At the time of issuing notifications, no actual or attempted misuse of the impacted data had been identified.

Silver Summit Medical Corporation (Digestive Disease Center and Heart Vascular & Leg Center), California

Silver Summit Medical Corporation, doing business as the Digestive Disease Center and Heart Vascular & Leg Center, has notified certain patients about a cybersecurity incident at a third-party vendor that exposed some of their protected health information. The Bakersfield, California-based ambulatory surgical center learned about the incident on or around July 20, 2026. The investigation determined that an unauthorized third party accessed the unnamed vendor’s systems from November 27, 2025, to November 30, 2025, and exfiltrated files containing personal and protected health information.

The data review determined that the exfiltrated files contained names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, taxpayer identification numbers, passport numbers, and/or other government identifiers. Protected health information included diagnoses, treatment information, prescription information, and health insurance information. The affected individuals were notified on August 19, 2026, and complimentary credit monitoring and identity theft protection services have been made available. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so the number of affected individuals is not yet known.

Premier Medical Group of the Hudson Valley, New York

Premier Medical Group of the Hudson Valley, a Poughkeepsie, New York-based multispecialty practice, has started notifying patients impacted by a cybersecurity incident this summer. The incident disrupted certain IT systems, and the forensic investigation determined that there was unauthorized access to files containing patient information on June 14, 2026. The substitute data breach notice on the practice’s website does not state when the incident was detected.

The review of the affected data determined on July 14, 2026, that the exposed files included patient names, contact information, dates of birth, health insurance information, provider names, patient identification numbers, dates of service, medications, and diagnostic and treatment information. Premier Medical Group said it will continue to evaluate and implement enhanced safeguards and security measures to protect its systems from unauthorized access and continue to provide security training to its workforce. The number of affected individuals has yet to be publicly disclosed.

Risk Program Administrators

Risk Program Administrators LLC (RPA), a California-based insurance program administration and management firm, has notified 8,309 individuals about the exposure of some of their personal and protected health information earlier this year. On or around June 16, 2026, RPA identified suspicious activity within an employee’s email account. The account was secured, and an investigation was launched, which confirmed that the account, and certain emails within that account, had been accessed by an unauthorized third party between May 27, 2025, and June 16, 2025.

The account was reviewed and found to contain information such as names, dates of birth, Social Security numbers, financial account information, health insurance information, and medical information, including treatment types, locations, costs, physician information, mental or physical condition, subscriber member numbers, and admission dates.

TELUS Health (US)

TELUS Health (US) LTD., a Canton, Massachusetts-based digital health and wellness provider part of the Canadian telecommunications company TELUS, has disclosed a data breach that involved unauthorized access to systems containing protected health information. Telus Health’s announcement on its website states that the investigation is ongoing, and it has yet to publicly disclose the types of information compromised in the incident. It is unclear exactly when the attack occurred; however, it appears to have occurred in January 2026. The ShinyHunters threat group claimed responsibility for the attack and the exfiltration of 1 petabyte (1,000 TB) of data.

The threat group communicated with Bleeping Computer, which reported in March 2026 that systems were breached using compromised Google Cloud credentials obtained in the Salesloft Drift breach. While the breach had the potential to be massive, it was recently reported to the HHS’ Office for Civil Rights as involving the protected health information of just 2,641 individuals. TELUS Health said it has implemented additional security safeguards to better safeguard the data within its environment.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist