Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationenforcement-actionransomware-group-operation

Recent Healthcare Data Breaches and Regulatory Actions in the United States

Updated 3mo agoFirst seen Dec 29, 20257 sources

Multiple healthcare organizations across the United States have reported significant data breaches affecting the personal and protected health information of hundreds of thousands of patients and employees. Notable incidents include the compromise of NCH Corporation Employee Benefits Plan data via exploitation of a zero-day vulnerability in Oracle E-Business Suite, a ransomware attack on OrthopedicsNY resulting in a $500,000 fine by the New York Attorney General, and a major breach at Murfreesboro Medical Clinic & SurgiCenter attributed to the BianLian ransomware group. Other breaches involved unauthorized access to patient data at Fyzical Therapy & Balance Centers, exposure of client data through a law firm serving Goldman Sachs, and improper storage of thousands of medical records in a Memphis storage unit. Additionally, Health Share of Oregon and CareOregon notified members of unauthorized viewing of their information, though the exact nature of the incident remains unclear.

Regulatory responses have included state attorney general enforcement actions, such as the fine imposed on OrthopedicsNY for failing to implement adequate cybersecurity measures. Organizations affected by these breaches have taken steps such as patching vulnerabilities, enhancing security policies, notifying affected individuals, and offering credit monitoring services. The incidents highlight ongoing risks to healthcare data security from ransomware, insider threats, third-party exposures, and improper data handling, as well as the increasing role of state regulators in enforcing HIPAA compliance and data protection standards.

Share:
Recent Healthcare Data Breaches and Regulatory Actions in the United States
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Jan 16, 20265mo ago

Final fairness hearing set for Murfreesboro settlement

A final fairness hearing for the Murfreesboro Medical Clinic settlement was scheduled for January 16, 2026. Affected individuals were given until April 14, 2026 to submit claims.

Dec 29, 20256mo ago

Murfreesboro Medical Clinic reaches breach lawsuit settlement

By December 29, 2025, Murfreesboro Medical Clinic had agreed to settle consolidated class action litigation over its 2023 breach. The settlement provides compensation, credit monitoring, identity theft protection, and requires enhanced security measures for at least three years.

New York Attorney General fines OrthoNY $500,000

On December 29, 2025, the New York Attorney General announced a $500,000 settlement with OrthoNY over its 2023 breach. The agreement requires credit monitoring for victims and major security improvements including MFA, encryption, monitoring, and annual risk assessments.

Fried Frank engages responders and notifies law enforcement

After the law firm breach, Fried Frank retained external cybersecurity experts, reported the incident to law enforcement, and began notifying affected clients. A proposed class action lawsuit was also filed against the firm by an investor in a Goldman Sachs fund.

Goldman Sachs warns fund investors of Fried Frank breach exposure

Goldman Sachs notified some alternative investment fund investors that their data may have been exposed in a cybersecurity incident at law firm Fried Frank Harris Shriver & Jacobson LLP. Goldman said its own systems were not affected.

Dec 28, 20256mo ago

CareOregon and Health Share breach reported to law enforcement

Following its investigation, Columbia Pacific CCO said it notified law enforcement and remediated the issue by changing access protocols and retraining staff. The organization said the cause had not been clarified and warned of possible fraudulent insurance claim misuse.

Columbia Pacific CCO identifies unauthorized access to member data

Columbia Pacific CCO disclosed unauthorized access to member information affecting CareOregon and Health Share of Oregon members. Exposed data included names, dates of birth, health plan details, Medicaid and Medicare ID numbers, and primary care provider information.

Thousands of medical records left in auctioned Memphis storage unit

After a storage unit owner failed to pay rent for three months, the unit was auctioned and buyer Jason Lederfine discovered thousands of sensitive medical records inside. The records belonged to former Memphis dentist Dr. Ajay Dave and included patient files, X-rays, billing records, and Social Security numbers.

Dec 1, 20257mo ago

One Community Health reports Trizetto-related PHI exposure

In late 2025, One Community Health disclosed a breach tied to Trizetto Provider Solutions in which unauthorized access to eligibility transaction reports exposed protected health information. The organization said it took remedial steps in response.

Foundation Health Partners discloses mailing error

In late 2025, Foundation Health Partners reported a mailing error that exposed limited patient information. The organization said it took remedial action after the disclosure.

Cl0p exploits Oracle E-Business Suite flaw to breach NCH plan data

In late 2025, the Cl0p ransomware group exploited zero-day CVE-2025-61882 in Oracle E-Business Suite to steal sensitive personal and health information from the NCH Corporation Employee Benefits Plan. The breach affected 3,098 plan members.

Nov 25, 20257mo ago

Fyzical investigation confirms scope of patient data exposure

On November 25, 2025, Fyzical concluded its investigation into the email breach and confirmed that sensitive patient information had been exposed. Notifications were later sent and credit monitoring was offered to affected individuals.

Dec 9, 20242y ago

Fyzical detects unauthorized access to email environment

Around December 9, 2024, Fyzical Acquisition Holdings detected unauthorized access to its email environment. The breach exposed patient personal and protected health information, including Social Security, financial, and medical data.

Dec 1, 20233y ago

INC Ransom attacks OrthoNY and steals patient data

In December 2023, Orthopedics NY LLP suffered a ransomware attack by the INC Ransom group using compromised credentials. Attackers exfiltrated unencrypted personal and health data, ultimately affecting 656,086 individuals.

Apr 1, 20233y ago

Murfreesboro Medical Clinic hit by BianLian ransomware

In April 2023, Murfreesboro Medical Clinic & SurgiCenter in Tennessee suffered a ransomware attack attributed to the BianLian group. The incident led to the exfiltration of protected health information affecting about 559,000 patients.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
3 linked
Malware
1 linked
Affected products
1 linked
E-Business Suite
Organizations
11 linked
NchGoldman SachsOracleTriZetto Provider SolutionsFried Frank Harris Shriver & Jacobson LLPGoldman Sachs Group Inc.One Community HealthFoundation Health PartnersColumbia Pacific CCOHealth Share OregonCareOregon
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.