Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationenforcement-actionmass-credential-exposure

Healthcare Sector Data Breaches and Regulatory Action on Health Data Privacy

Updated 3mo agoFirst seen Jan 12, 20264 sources

Multiple healthcare organizations have reported significant data breaches involving unauthorized access to patient information. CareOregon and Health Share of Oregon notified patients of a breach where protected health information, including names, dates of birth, health plan details, and Medicaid/Medicare numbers, was accessed without authorization, raising concerns about potential insurance fraud. Canopy Health, a major New Zealand oncology provider, disclosed a cyberattack that resulted in unauthorized access to administrative systems and possible data exfiltration, with the incident being contained and legal action taken to prevent misuse of the compromised data. Additionally, a Manhattan plastic surgery practice suffered a cyberattack in which sensitive patient images and personal information were stolen and published online, with extortion attempts made directly to patients; this attack is linked to a series of similar incidents targeting plastic surgery practices.

In parallel to these incidents, California authorities have taken regulatory action against Datamasters, a marketing firm found to be illegally selling health and personal data of millions of individuals without proper registration as a data broker. The company was fined and banned from selling Californians' personal information after it was discovered to have traded in sensitive data, including health conditions and demographic details, for targeted advertising. These events highlight ongoing risks to health data privacy from both cyberattacks and improper commercial data practices, as well as the increasing regulatory scrutiny and enforcement in this sector.

Share:
Healthcare Sector Data Breaches and Regulatory Action on Health Data Privacy
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 12, 20265mo ago

CareOregon and Health Share notify patients and warn of fraud risk

CareOregon and Health Share of Oregon notified affected patients about the breach and warned of potential insurance fraud. They also reported the incident to law enforcement, remediated the issue, and retrained staff.

Jan 11, 20265mo ago

CalPrivacy penalizes Datamasters over health data resale

The California Privacy Protection Agency took enforcement action against Rickenbacher Data LLC, doing business as Datamasters, for operating as an unregistered data broker and reselling sensitive health and personal data. The agency fined the company $45,000, barred further sales of Californians' personal information, and ordered deletion of previously purchased Californians' data.

CalPrivacy fines S&P Global for unregistered data broker lapse

The California Privacy Protection Agency fined S&P Global Inc. $62,600 for failing to register as a data broker for 2024 by the required deadline. The agency said the company remained unregistered for 313 days before the enforcement action was announced.

Oct 27, 20258mo ago

CareOregon breach discovered after unauthorized access to PHI

CareOregon and Health Share of Oregon discovered unauthorized access to protected health information on 2025-10-27. Exposed data included names, dates of birth, health plan information, Medicaid/Medicare numbers, and primary care provider details, but not Social Security or financial data.

Jun 1, 20251y ago

Andover Eye Associates discovers email account breach

Andover Eye Associates discovered in June 2025 that two employee email accounts had been accessed without authorization. The incident exposed names and Social Security numbers of 1,638 patients.

Jan 31, 20251y ago

California deadline passes for 2024 data broker registration

California required data brokers to register annually, and S&P Global Inc. missed the January 31, 2025 deadline for 2024 registration. CalPrivacy later said the lapse continued for 313 days and was attributed to an administrative error.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Organizations
2 linked
S&P GlobalRickenbacher Data
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.