Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatmass-credential-exposurefinancial-sector-threat

Multiple Healthcare and Retail Data Breaches Impacting US Organizations

Updated 3mo agoFirst seen Jan 8, 20264 sources

Several US organizations have reported significant data breaches affecting thousands of individuals. Pearlman Aesthetic Surgery in New York disclosed a hacking incident compromising the protected health information of nearly 12,000 patients, though specific details remain undisclosed. Methodist Homes of Alabama and Northwest Florida notified residents and employees of a second breach within seven months, involving unauthorized access to an employee email account containing sensitive personal and medical information. Gulshan Management Services, which operates over 150 gas stations and convenience stores, confirmed a breach that exposed the personal data of more than 377,000 people, including Social Security numbers and financial information, with delayed notification to affected individuals. Community First Medical Center in Chicago reached a $1 million preliminary settlement following a 2023 breach that exposed the data of approximately 216,000 patients, with allegations of inadequate cybersecurity measures and delayed response.

These incidents have led to regulatory filings, class action lawsuits, and increased scrutiny over the timeliness and adequacy of breach notifications. The breaches highlight ongoing challenges in protecting sensitive data across healthcare and retail sectors, with attackers exploiting both network vulnerabilities and email accounts. Organizations are facing legal and reputational consequences, emphasizing the need for robust cybersecurity practices and prompt communication with affected individuals.

Share:
Multiple Healthcare and Retail Data Breaches Impacting US Organizations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Jan 8, 20266mo ago

Methodist Homes began notifying people about second breach

Methodist Homes of Alabama and Northwest Florida began notifying residents and employees about the 2025 email-account breach, its second disclosed data breach in seven months. The total number of people affected by the latest incident had not yet been publicly disclosed.

Healthcare entities reported additional patient data incidents

Associated Radiologists of the Finger Lakes reported unauthorized network access over two days and began reviewing the scope of exposed patient data, while Fast Pace Urgent Care disclosed that a business associate employee mistakenly emailed PHI for 2,072 patients to the wrong recipient, who confirmed deletion.

Pearlman Aesthetic Surgery disclosed hacking incident

Pearlman Aesthetic Surgery in Manhattan disclosed a hacking and IT incident affecting 11,764 individuals. Specific details about the intrusion were not provided in the report.

Jan 7, 20266mo ago

Judge preliminarily approves $1M Community First settlement

A federal judge preliminarily approved a $1 million settlement to resolve consolidated class action claims against Community First Medical Center over its 2023 breach. The proposed deal includes reimbursement for losses, a cash payment option, and one year of credit and medical monitoring for affected individuals.

Jan 5, 20266mo ago

Gulshan notified affected individuals of data breach

Gulshan Management Services notified affected individuals on January 5, 2026, more than three months after discovering the breach. Multiple class action lawsuits and investigations followed the disclosure.

Sep 27, 20259mo ago

Gulshan discovered the breach

Gulshan Management Services discovered the unauthorized access incident on September 27, 2025. The company later faced scrutiny over the delay in notifying affected individuals.

Sep 17, 20259mo ago

Gulshan attackers accessed external system over 10 days

Attackers gained unauthorized access to an external system used by Gulshan Management Services between September 17 and September 27, 2025, exposing personal and financial data of more than 377,000 individuals.

Jul 1, 20251y ago

Community First Medical Center breach exposed 216,000 patients

Community First Medical Center suffered a data breach in July 2023 that exposed protected health information of about 216,000 patients, including Social Security and Medicare numbers. The incident later led to consolidated class action litigation.

May 8, 20251y ago

Methodist Homes employee email account was compromised

An employee email account at Methodist Homes of Alabama and Northwest Florida was accessed without authorization between May 8 and May 21, 2025, exposing residents' and employees' sensitive personal and medical information.

Oct 1, 20242y ago

Methodist Homes reports first breach to HHS after October 2024 incident

Methodist Homes of Alabama and Northwest Florida experienced a data breach in October 2024. It was initially reported to HHS as affecting 908 patients, though later notifications indicated 25,579 people were impacted.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Organizations
3 linked
Fast Pace Urgent CarePearlman Aesthetic SurgeryAssociated Radiologists of the Finger Lakes
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple Healthcare and Retail Data Breaches Impacting US Organizations | Mallory