NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

WindRose Health Network Discloses Data Breach Affecting 33K Individuals

Data breaches have been announced by WindRose Health Network and Advantage Home Health Care in Indiana, Camden-on-Gauley Medical Center in West Virginia, and Lakes Region Visiting Nursing Association in New Hampshire.

WindRose Health Network, Indiana

WindRose Health Network, a network of Federally Qualified Health Centers that provide primary care and behavioral health services at several locations in central Indiana, has started notifying 33,158 individuals about a cybersecurity incident that exposed limited patient data. An unauthorized third party gained access to a limited part of its network by exploiting a previously undisclosed vulnerability in a remote access tool used by one of its vendors. The vendor informed WindRose Health Network about the vulnerability on August 4, 2026. Immediate action was taken to secure its environment, and cybersecurity experts were engaged to investigate.

The investigation determined that the vulnerability had been exploited, resulting in unauthorized network access between August 3 and August 4, 2026. The remote access tool could not be used to access patients’ medical records; however, patient data was stored in files on the affected parts of its network. The data review determined that patient names, patient ID numbers, health insurance information, dates of service, and provider names were potentially accessed or copied. The affected patients have been advised to remain vigilant against identity theft and fraud.

Advantage Home Care, Missouri

Advantage Home Health Care (AHHC), one of the largest home healthcare providers in the state of Indiana, has notified 19,851 individuals about a recent cybersecurity incident. The home health care agency learned on June 16, 2026, that an unauthorized third party had gained access to one of its computer servers. The forensic investigation determined that its systems were first accessed on June 9, 2026. On June 26, 2026, AHCC learned that the files containing patient data had been acquired in the incident, including patients’ first and last names, birth dates, addresses, phone numbers, Social Security numbers, and medical information related to the care received.

Employee data was also compromised related to the AHHC employee health plan, including health insurance and plan enrolment information, claims information, healthcare provider information, and health benefits information. Adults and minors affected by the incident have been offered 12 months of complimentary single-bureau credit monitoring, credit report, and credit score services. While not specifically mentioned in the notification letter, the group behind the attack appears to be The Gentlemen, a prolific ransomware group that has claimed many healthcare victims.

Camden-on-Gauley Medical Center, West Virginia

Camden Family Health, a network of community health centers serving the Mountain Lake Region in West Virginia, has identified unauthorized access to parts of its computer network. Suspicious activity was identified on July 18, 2026; steps were immediately taken to secure its systems, and an investigation was launched to determine the cause of the activity.

The investigation confirmed that an unauthorized third party accessed its network on July 18, 2026, and potentially viewed or obtained files containing the information of patients of Camden-on-Gauley Medical Center. The review of the affected files confirmed that patients’ medical information and health insurance information were potentially accessed or acquired. The number of affected individuals has not yet been publicly disclosed. The incident has been reported to the HHS’ Office for Civil Rights using an estimate of at least 501 individuals.

Lakes Region Visiting Nursing Association, New Hampshire

Lakes Region Visiting Nursing Association, a non-profit Medicare-certified home health and hospice agency based in Meredith, New Hampshire, has notified 1,274 individuals about a recent security incident. Suspicious activity was identified within its email environment on June 2, 2026. Its incident response protocols were immediately implemented, and third-party cybersecurity specialists were engaged to investigate the activity. They confirmed that an unauthorized third party had gained access to a single employee email account.

The account was reviewed, and on August 13, 2026, it was confirmed that patient data had been exposed. The exact types of data are not detailed in the substitute breach notification letter on its website. The affected individuals have been offered complimentary credit monitoring and identity theft protection services, and steps have been taken to improve security. In addition to a password reset, multifactor authentication has been implemented throughout its email tenant.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist