Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatthird-party-vendor-breachmass-credential-exposure

Healthcare and public-sector data breaches and breach-related litigation

Updated 3mo agoFirst seen Jan 20, 20263 sources

Multiple organizations reported unauthorized access and data exposure events affecting large populations, with several incidents tied to third-party systems or business associates. The Minnesota Department of Human Services notified nearly 304,000 people after a user associated with a licensed healthcare provider accessed demographic records in the MnChoices system (managed by vendor FEI Systems) beyond what was authorized; most impacted records were demographic data, with a smaller subset including some medical information and, for some, the last four digits of SSNs. Monroe University reported a December 2024 intrusion with data exfiltration affecting about 320,973 individuals, with exposed data potentially including SSNs, government IDs, financial account information, and health/insurance data; notification letters began in early January 2026. Separately, Mid Michigan Medical Billing Service disclosed a March 2025 cyberattack that exposed PHI for 28,185 individuals across healthcare clients, and VillageCareMAX reported a breach involving business associate TMG Health (details referenced as part of a broader business-associate breach update).

Other items in the set describe distinct, unrelated security stories rather than the same incident: an underground-market sale of Raaga user data (10.2M records, including passwords stored as unsalted MD5 hashes), a settlement in litigation tied to the Veradigm breach (over 2M patients; $10.5M class-action settlement), and a ransomware incident at Valley Eye Associates where a group identified as Qilin claimed exfiltration (139 GB) and published data. Additional references include commentary on UK government handling of an Afghan data breach (spreadsheet emailed outside the MoD and use of an injunction) and broader analysis of healthcare breach trends and UK ambulance-service breach reporting; these provide context but do not describe the same specific event as the Minnesota DHS or other named incidents.

Share:
Healthcare and public-sector data breaches and breach-related litigation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Jan 16, 20265mo ago

Minnesota DHS sends breach notices to nearly 304,000 people

Minnesota DHS sent notification letters dated January 16, 2026, to nearly 304,000 individuals affected by unauthorized access to MnChoices records. The agency said no misuse had been identified and it was not offering free credit monitoring because of the limited nature of the data involved.

Jan 2, 20266mo ago

Monroe University begins notifying affected individuals

After a nine-month review of affected files, Monroe University began mailing notification letters on January 2, 2026. The university said it had not identified misuse of the stolen data at the time notices were sent.

Nov 1, 20258mo ago

FEI Systems reports MnChoices incident to Minnesota DHS

Third-party vendor FEI Systems reported the unauthorized MnChoices access issue to the Minnesota Department of Human Services in November 2025. This triggered the state's response and investigation into the scope of affected records.

Oct 30, 20258mo ago

Minnesota DHS removes user's MnChoices access

Minnesota DHS said the involved user's access to the MnChoices system was fully removed on October 30, 2025. The incident ultimately affected nearly 304,000 individuals, mostly through unauthorized access to demographic data.

Sep 21, 20259mo ago

Unauthorized MnChoices access ceases

In the Minnesota DHS incident, unauthorized access by a user tied to a licensed healthcare provider stopped on September 21, 2025. The user had legitimate limited access but was found to have viewed additional records beyond authorization.

Sep 19, 20259mo ago

TMG Health identifies unauthorized activity

TMG Health identified unauthorized activity on September 19, 2025, concluding that an unauthorized third party had maintained network access for about 10 months. The incident potentially affected VillageCareMAX members' protected health information.

Mar 27, 20251y ago

Mid Michigan Medical Billing Service detects suspicious activity

Mid Michigan Medical Billing Service identified suspicious network activity on March 27, 2025. A forensic investigation later found an unauthorized party had accessed and copied data affecting 28,185 individuals across its healthcare clients.

Dec 23, 20242y ago

Monroe University detects December 2024 cyberattack

Monroe University detected the intrusion on December 23, 2024, ending the attack window that investigators later said lasted from December 9 to December 23, 2024. The incident affected about 320,973 individuals.

Dec 9, 20242y ago

Monroe University attacker gains network access

Monroe University determined that an attacker had unauthorized access to its network starting on December 9, 2024. The compromise ultimately led to the exfiltration of sensitive personal, student, financial, and health-related information.

Nov 20, 20242y ago

TMG Health network intrusion begins affecting VillageCareMAX data

VillageCareMAX said its business associate TMG Health, owned by Cognizant, was accessed by an unauthorized third party beginning around November 20, 2024. The intrusion potentially exposed member PHI including names, member IDs, health information, and Social Security numbers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Organizations
5 linked
FEI SystemsCognizantTMG HealthMid Michigan Medical Billing Service, Inc.VillageCareMAX
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.