NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

NFI North Data Breach Affects Almost 50,000 Individuals

Data breaches have been announced by NFI North in New Hampshire, Nephrology Associates in Kansas, PAMCAH-UA Local 675 Health and Welfare Fund in Hawaii, and Indico Data Solutions in Massachusetts.

NFI North, Inc.

NFI North, Inc., a Contoocook, New Hampshire-based nonprofit human services organization that provides mental health, behavioral, and educational support services in New Hampshire and Maine, has notified the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) about a breach of the protected health information of 49,540 individuals.

According to the NFI North substitute breach notice, suspicious activity was identified within its network on or around September 6, 2025. The investigation and data review concluded on July 6, 2026, when it was confirmed that data compromised in the incident included names, addresses, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. NFI North engaged cybersecurity professionals to assist with the investigation, and additional technical safeguards have been implemented to prevent similar incidents in the future.

Nephrology Associates

Nephrology Associates, M.D., P.A., a network of clinics in Kansas and Missouri that provide care to patients with chronic kidney disease and other kidney disorders, has announced a data security incident that has affected 24,088 individuals. Suspicious network activity was identified on or around April 9, 2026. Assisted by third-party cybersecurity experts, the practice determined that its network had been accessed by an unauthorized third party between January 17, 2026, and April 9, 2026. The affected systems were reviewed and, on July 1, 2026, the practice confirmed that data exposed in the incident included names, birth dates, Social Security numbers, driver’s license numbers/state identification numbers, other government identifiers, diagnosis and treatment information, and health insurance information.

On or around July 30, 2026, notification letters started to be mailed to the affected individuals. At the time of issuing the notifications, Nephrology Associates was unaware of any actual or attempted misuse of the exposed data. As a precaution against identity theft and fraud, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While not mentioned in the data breach notice, this appears to have been an attack by the cybercriminal group called The Gentlemen. No data appears to have been leaked; however, the group has offered the data for sale.

PAMCAH-UA Local 675 Health and Welfare Fund

PAMCAH-UA Local 675 Health and Welfare Fund, a multiemployer trust fund in Honolulu, Hawaii, that provides medical, dental, vision, and welfare benefits to union plumbers and fitters and their families, has identified unauthorized access to the email accounts of some of its employees.

The forensic investigation determined that certain employee email accounts were accessed by an unauthorized third party between September 23, 2025, and October 9, 2025. During that time, emails and files in the account may have been viewed or acquired. The accounts were reviewed and found to contain the personal and protected health information of 8,319 individuals, including names, dates of birth, medical information, health insurance information, driver’s license numbers, and Social Security numbers. Notification letters have now been mailed to the affected individuals with information on how they can protect themselves against data misuse.

Indico Data Solutions

Indico Data Solutions, Inc., a Massachusetts-based AI-powered software company whose products include an intake and orchestration platform, has announced a data security incident involving the protected health information of 4,840 individuals. It is unclear from the data breach notice when the incident was detected or for how long unauthorized individuals had access to its systems, only that a cybersecurity incident was confirmed by Indico Data Solutions on May 7, 2026. Data potentially compromised in the incident includes names, addresses, and Social Security numbers.

Indico Data Solutions has taken several steps in response to the incident, including rotating access credentials, tightening access controls, and implementing additional monitoring tools. The affected corporate customers have been notified, and Indico Data Solutions has mailed notification letters to the affected individuals and has offered complimentary credit monitoring and identity restoration services.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist