Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationmass-credential-exposure

Healthcare Data Breaches and HIPAA Security Challenges

Updated 3mo agoFirst seen Dec 18, 20253 sources

A cyberattack on NS Support LLC, a neurosurgical healthcare provider, resulted in unauthorized access to its network and the exfiltration of files containing protected health information (PHI) for nearly 93,000 patients. The compromised data included names and medical notes, but not Social Security numbers or financial information. In response, NS Support wiped and rebuilt affected systems, implemented additional security measures, and began reviewing and updating its data security policies. Notification letters were sent to affected individuals, and the incident was reported to the Department of Health and Human Services Office for Civil Rights (HHS OCR).

The healthcare sector continues to face a surge in data breaches, with over 700 large incidents reported annually from 2021 to 2024, compromising the PHI of more than 595 million individuals. Hacking and IT incidents are the primary causes, often facilitated by employee errors or lapses in cyber hygiene. Experts highlight the growing complexity of healthcare data ecosystems, especially with the rise of telehealth, and emphasize the need for robust data classification, continuous monitoring, and adaptive security controls to protect sensitive patient information. Regulatory frameworks like HIPAA remain central, but organizations must go beyond compliance to ensure comprehensive data protection across diverse platforms and partners.

Share:
Healthcare Data Breaches and HIPAA Security Challenges
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 17, 20256mo ago

NS Support notifies nearly 93,000 patients of PHI breach

By December 2025, NS Support disclosed the breach and sent notification letters to affected individuals about the compromise of their protected health information. The company said it had found no evidence of misuse and did not offer credit monitoring because Social Security numbers and financial data were not involved.

Dec 16, 20256mo ago

Ro security executive warns telehealth data sprawl is outpacing regulation

On 2025-12-16, Ro CIO/CISO Scott Bachand publicly described telehealth's expanding data flows across cloud, mobile, third-party platforms, and AI as a growing security challenge. He said legacy frameworks such as HIPAA lag behind these realities and called for standards-based, zero-trust, data-centric security controls.

May 29, 20251y ago

NS Support rebuilds systems and adds security measures after breach

Following the May 2025 incident, NS Support engaged third-party digital forensics specialists, wiped and rebuilt affected systems, and implemented additional security measures. The company also began reviewing and updating its data security policies and network security software.

NS Support detects unauthorized access and data exfiltration

On or around 2025-05-29, NS Support LLC detected a hacking-related incident involving unauthorized access to and exfiltration of files from its systems. The compromised data included patient names and medical notes, affecting up to 92,845 individuals.

Jan 1, 20215y ago

Healthcare breaches surpass 700 large incidents annually from 2021 to 2024

Between 2021 and 2024, the healthcare sector reported more than 700 large data breaches each year, collectively compromising the protected health information of more than 595 million people. Reporting cited hacking and IT incidents as the dominant category, with employee mistakes and poor cyber hygiene frequently contributing to the root cause.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Malware
1 linked
Organizations
6 linked
CvsVerizon CommunicationsHIPAAHl7Open Cybersecurity Schema FrameworkFhir
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.