Healthcare Sector Data Breaches and Regulatory Action on Health Data Privacy
Multiple healthcare organizations have reported significant data breaches involving unauthorized access to patient information. CareOregon and Health Share of Oregon notified patients of a breach where protected health information, including names, dates of birth, health plan details, and Medicaid/Medicare numbers, was accessed without authorization, raising concerns about potential insurance fraud. Canopy Health, a major New Zealand oncology provider, disclosed a cyberattack that resulted in unauthorized access to administrative systems and possible data exfiltration, with the incident being contained and legal action taken to prevent misuse of the compromised data. Additionally, a Manhattan plastic surgery practice suffered a cyberattack in which sensitive patient images and personal information were stolen and published online, with extortion attempts made directly to patients; this attack is linked to a series of similar incidents targeting plastic surgery practices.
In parallel to these incidents, California authorities have taken regulatory action against Datamasters, a marketing firm found to be illegally selling health and personal data of millions of individuals without proper registration as a data broker. The company was fined and banned from selling Californians' personal information after it was discovered to have traded in sensitive data, including health conditions and demographic details, for targeted advertising. These events highlight ongoing risks to health data privacy from both cyberattacks and improper commercial data practices, as well as the increasing regulatory scrutiny and enforcement in this sector.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
6 events from the most recent confirmed update back to the earliest known activity.
CareOregon and Health Share notify patients and warn of fraud risk
CareOregon and Health Share of Oregon notified affected patients about the breach and warned of potential insurance fraud. They also reported the incident to law enforcement, remediated the issue, and retrained staff.
CalPrivacy penalizes Datamasters over health data resale
The California Privacy Protection Agency took enforcement action against Rickenbacher Data LLC, doing business as Datamasters, for operating as an unregistered data broker and reselling sensitive health and personal data. The agency fined the company $45,000, barred further sales of Californians' personal information, and ordered deletion of previously purchased Californians' data.
CalPrivacy fines S&P Global for unregistered data broker lapse
The California Privacy Protection Agency fined S&P Global Inc. $62,600 for failing to register as a data broker for 2024 by the required deadline. The agency said the company remained unregistered for 313 days before the enforcement action was announced.
CareOregon breach discovered after unauthorized access to PHI
CareOregon and Health Share of Oregon discovered unauthorized access to protected health information on 2025-10-27. Exposed data included names, dates of birth, health plan information, Medicaid/Medicare numbers, and primary care provider details, but not Social Security or financial data.
Andover Eye Associates discovers email account breach
Andover Eye Associates discovered in June 2025 that two employee email accounts had been accessed without authorization. The incident exposed names and Social Security numbers of 1,638 patients.
California deadline passes for 2024 data broker registration
California required data brokers to register annually, and S&P Global Inc. missed the January 31, 2025 deadline for 2024 registration. CalPrivacy later said the lapse continued for 313 days and was attributed to an administrative error.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
CareOregon and Health Share of Oregon Warn of Potential Insurance Fraud After Data Breach
hipaajournal.com
Open sourceAnother plastic surgery practice fell prey to a cyberattack with extortion attempt
databreaches.net
Open sourceSecond NZ health provider, Canopy Health, reveals cyberattack
databreaches.net
Open sourceCalifornia bans data broker reselling health data of millions
bleepingcomputer.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


