Skip to main content
Mallory
Mallory

Healthcare Data Breaches and HIPAA Security Challenges

HIPAAdata securityIT incidentssecurity measuressecurity policieshealthcareadaptive securityDepartment of Healthunauthorized accessbreachPHIemployee errorstelehealthcompromiseddisclosure
Updated December 18, 2025 at 01:02 AM3 sources

Get Ahead of Threats Like This

Know if you're exposed — before adversaries strike.

A cyberattack on NS Support LLC, a neurosurgical healthcare provider, resulted in unauthorized access to its network and the exfiltration of files containing protected health information (PHI) for nearly 93,000 patients. The compromised data included names and medical notes, but not Social Security numbers or financial information. In response, NS Support wiped and rebuilt affected systems, implemented additional security measures, and began reviewing and updating its data security policies. Notification letters were sent to affected individuals, and the incident was reported to the Department of Health and Human Services Office for Civil Rights (HHS OCR).

The healthcare sector continues to face a surge in data breaches, with over 700 large incidents reported annually from 2021 to 2024, compromising the PHI of more than 595 million individuals. Hacking and IT incidents are the primary causes, often facilitated by employee errors or lapses in cyber hygiene. Experts highlight the growing complexity of healthcare data ecosystems, especially with the rise of telehealth, and emphasize the need for robust data classification, continuous monitoring, and adaptive security controls to protect sensitive patient information. Regulatory frameworks like HIPAA remain central, but organizations must go beyond compliance to ensure comprehensive data protection across diverse platforms and partners.

Related Entities

Organizations

Sources

December 17, 2025 at 12:00 AM
December 16, 2025 at 12:00 AM

Related Stories

Healthcare Sector Data Breaches and Security Risks in Late 2025

Healthcare Sector Data Breaches and Security Risks in Late 2025

A significant reduction in the number of large healthcare data breaches was reported for October 2025, with only 28 incidents affecting 500 or more individuals, the lowest monthly total since May 2020. However, the number of individuals impacted surged by 540% to over 11 million, largely due to a few major breaches still under investigation. The reporting delay was attributed to a government shutdown that created a backlog at the HHS Office for Civil Rights, potentially causing underreporting for the month. Notably, the Bosch Choice Welfare Benefit Plan disclosed a breach affecting 55,000 members, stemming from a business associate's cybersecurity incident that exposed sensitive personal and health information. The affected business associate also notified other covered entities and implemented additional safeguards in response. Security risks in the healthcare sector remain acute, particularly for small practices with limited IT resources. A technical investigation highlighted the dangers of improper hardware disposal and lack of disk encryption, revealing that sensitive data and password hashes can be easily extracted from discarded computers. Industry experts emphasize that business associates are a major source of breached records, accounting for a disproportionate share of affected individuals despite submitting fewer incident reports. This underscores the need for robust vendor oversight and comprehensive HIPAA compliance strategies, especially for small and mid-sized healthcare organizations.

2 months ago
Recent Healthcare Data Breaches and Regulatory Actions in the United States

Recent Healthcare Data Breaches and Regulatory Actions in the United States

Multiple healthcare organizations across the United States have reported significant data breaches affecting the personal and protected health information of hundreds of thousands of patients and employees. Notable incidents include the compromise of NCH Corporation Employee Benefits Plan data via exploitation of a zero-day vulnerability in Oracle E-Business Suite, a ransomware attack on OrthopedicsNY resulting in a $500,000 fine by the New York Attorney General, and a major breach at Murfreesboro Medical Clinic & SurgiCenter attributed to the BianLian ransomware group. Other breaches involved unauthorized access to patient data at Fyzical Therapy & Balance Centers, exposure of client data through a law firm serving Goldman Sachs, and improper storage of thousands of medical records in a Memphis storage unit. Additionally, Health Share of Oregon and CareOregon notified members of unauthorized viewing of their information, though the exact nature of the incident remains unclear. Regulatory responses have included state attorney general enforcement actions, such as the fine imposed on OrthopedicsNY for failing to implement adequate cybersecurity measures. Organizations affected by these breaches have taken steps such as patching vulnerabilities, enhancing security policies, notifying affected individuals, and offering credit monitoring services. The incidents highlight ongoing risks to healthcare data security from ransomware, insider threats, third-party exposures, and improper data handling, as well as the increasing role of state regulators in enforcing HIPAA compliance and data protection standards.

2 months ago
Multiple Healthcare Data Breaches and Regulatory Actions in the US

Multiple Healthcare Data Breaches and Regulatory Actions in the US

Several healthcare providers in the United States have recently disclosed significant data breaches resulting from cyberattacks, with patient and employee information being compromised. AllerVie Health, based in Texas, confirmed unauthorized access to its network, exposing sensitive data such as names, Social Security numbers, and insurance details, allegedly due to a ransomware attack by the Anubis group. The attackers claim to have stolen records of over 30,000 patients, and affected individuals have been offered credit monitoring and identity theft protection. In a separate incident, OrthopedicsNY, a healthcare provider in New York, suffered a breach in 2023 after attackers gained remote access using compromised credentials, leading to the exposure of data belonging to more than 650,000 patients and employees. The New York Attorney General secured a $500,000 penalty from OrthopedicsNY for failing to implement adequate security measures, and the provider is now required to enhance its data protection practices. Additionally, Singing River Health System in Mississippi reported a cyber incident that led to the temporary shutdown of its patient portal and internet access as a precaution. While the threat was reportedly mitigated, the investigation is ongoing to determine if patient records were accessed. These incidents highlight the ongoing risks faced by healthcare organizations from ransomware groups and other cybercriminals, as well as the increasing regulatory scrutiny and financial penalties for failing to protect sensitive health information. Impacted organizations are responding with offers of credit monitoring and reviews of their security policies, but the breaches underscore the need for robust cybersecurity measures in the healthcare sector.

2 months ago

Get Ahead of Threats Like This

Mallory continuously monitors global threat intelligence and correlates it with your attack surface. Know if you're exposed — before adversaries strike.