Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationransomware-group-operationmass-credential-exposure

Healthcare Data Breaches and Legal Responses in the United States

Updated 3mo agoFirst seen Dec 20, 20252 sources

Multiple healthcare organizations in the United States have experienced significant data breaches involving the exposure of protected health information (PHI) and other sensitive personal data. In Albemarle County, Virginia, a ransomware attack compromised the PHI of members of its self-insured health plan, as well as data belonging to current and former government and public school employees, their dependents, and individuals who interacted with the county. The compromised information included names, Social Security numbers, health insurance details, and other identifiers. The county has concluded its investigation, notified affected individuals, and is offering complimentary credit monitoring and identity theft protection services.

Separately, class action settlements have been reached with three healthcare providers—Hypertension Nephrology Associates, Asheville Arthritis and Osteoporosis Center, and Intermountain Planned Parenthood—following data breaches that exposed patient health and financial information. In one case, Hypertension Nephrology Associates agreed to a $625,000 settlement after a ransomware attack led to the theft of data from nearly 40,000 patients. The lawsuits alleged failures in security practices and delayed breach notifications, with affected individuals being offered credit monitoring services. These incidents highlight ongoing legal and regulatory consequences for healthcare organizations following data breaches involving PHI.

Share:
Healthcare Data Breaches and Legal Responses in the United States
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Dec 19, 20256mo ago

Albemarle County confirms PHI theft and offers credit monitoring

On December 19, 2025, Albemarle County confirmed that protected health information and other personal data were stolen in the June ransomware attack. The county began notifying affected individuals and offered 12 months of complimentary credit monitoring and identity theft protection.

Dec 18, 20256mo ago

Three healthcare providers agree to class action breach settlements

By December 18, 2025, Hypertension Nephrology Associates, Asheville Arthritis and Osteoporosis Center, and Intermountain Planned Parenthood had agreed to settle class action lawsuits over their 2024 data breaches. The settlements created funds of roughly $500,000 to $625,000 for losses, monitoring services, and legal and administrative costs, while the defendants denied wrongdoing.

Jun 11, 20251y ago

INC Ransom claims Albemarle County attack and leaks stolen data

Following the June 2025 intrusion, the INC Ransom group claimed responsibility for the Albemarle County attack, stating it had exfiltrated 229 GB of data. The group subsequently published the stolen information on its dark web leak site.

Albemarle County detects file access disruption and begins response

On June 11, 2025, county staff discovered they had lost access to certain files, confirming the operational impact of the ransomware attack. The county engaged law enforcement, cybersecurity experts, and HIPAA compliance specialists to investigate and respond.

Jun 10, 20251y ago

Albemarle County hit by ransomware attack

On June 10, 2025, Albemarle County, Virginia, was targeted in a ransomware attack that compromised county systems and led to data theft. The incident affected information tied to the county's self-insured health plan and other individuals connected to the county.

Jan 1, 20242y ago

Intermountain Planned Parenthood experiences 2024 data breach

Intermountain Planned Parenthood suffered a significant data breach in 2024 involving protected health and other sensitive information. The breach later resulted in a class action lawsuit and proposed settlement.

Asheville Arthritis and Osteoporosis Center suffers 2024 data breach

Asheville Arthritis and Osteoporosis Center experienced a 2024 breach involving unauthorized access to sensitive patient information. The incident prompted litigation alleging inadequate safeguards and delayed notification.

HNA detects unauthorized network access and data theft

Hypertension Nephrology Associates discovered suspicious activity in 2024 that led to a data breach affecting patients' sensitive information. The incident later became the basis for a class action lawsuit and settlement.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Threat actors
1 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.