Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationmass-credential-exposurethird-party-vendor-breach

Healthcare Data Breaches and Patient Record Exposure at Providers and Vendors

Updated 3mo agoFirst seen Mar 3, 20264 sources

Multiple healthcare entities reported unauthorized access and patient data exposure, with incidents spanning direct provider compromises and third-party vendor breaches. Insight Hospital and Medical Center (Chicago) disclosed suspicious activity in its IT environment, with investigators confirming unauthorized network access from Aug 22 to Sep 11, 2025; the organization said the review is ongoing but potentially impacted data includes names, DOB, SSNs, passport numbers, financial account data, treatment information, and insurance details. Two extortion groups publicly claimed responsibility: LockBit alleged theft of ~200 GB and Termite claimed 360 GB, stating it leaked data in late February 2026.

In France, attackers stole about 15.8 million administrative files after breaching health-ministry software supplier Cegedim Santé, impacting its MonLogicielMedical (MLM) product used by thousands of doctors; the stolen data reportedly included identity and contact details, and in a smaller subset (~165,000 files) free-text doctors’ notes that in limited cases contained sensitive medical-history details. Separately, OCAT, LLC d/b/a Evoke Wellness at Hilliard updated a breach notification describing unauthorized network activity and potential access to patient information; reporting also tied the matter to an insider misuse investigation in which a former employee allegedly accessed and sold patient data, though public filings contained inconsistent timelines about when the underlying incident occurred and when it was discovered.

Share:
Healthcare Data Breaches and Patient Record Exposure at Providers and Vendors
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Mar 3, 20264mo ago

Insight attack publicly claimed by LockBit5 and Termite

By the time of Insight Hospital's disclosure, the LockBit5 and Termite extortion groups had each claimed responsibility for the attack and alleged that large volumes of stolen data had been leaked on their sites.

Feb 27, 20264mo ago

Evoke breach notification filed with Maine AG

External counsel for Evoke Wellness at Hilliard submitted a breach notification to the Maine Attorney General on February 27, 2026, describing unauthorized network activity and possible access to patient data. The filing reportedly listed 261 affected individuals, adding to inconsistencies in the case record.

Feb 2, 20265mo ago

Deaconess discloses MediCopy vendor data breach

Deaconess Health System disclosed that an unauthorized actor accessed MediCopy's cloud-based file-sharing software on January 13, 2026 and downloaded files tied to release-of-information requests. Deaconess said the incident, reported to it on February 2, affected patients of Deaconess Henderson Hospital and Deaconess Union County Hospital, while its own IT and EHR systems were not accessed.

Deaconess Health System Affected by Vendor Data Breach
Dec 1, 20257mo ago

Cegedim Santé breach confirmed after theft of 15.8M records

A breach affecting Cegedim Santé, a software supplier to France's health ministry, was confirmed in late 2025. Attackers stole about 15.8 million patient administrative files, including roughly 165,000 records containing doctors' free-text notes with limited sensitive medical details.

Sep 1, 202510mo ago

Insight Hospital identifies data security incident

Insight Hospital and Medical Center disclosed that it identified the security incident in September 2025 after the period of unauthorized access. Its review of affected individuals and data types remained ongoing at the time of reporting.

Aug 22, 202510mo ago

Insight Hospital network accessed by unauthorized actor

Insight Hospital and Medical Center said unauthorized access to its network occurred between August 22 and September 11, 2025. The organization later began assessing what information and how many individuals were affected.

Jul 1, 20251y ago

FTC finalizes separate settlement with Evoke

DataBreaches.net noted that the FTC finalized a settlement with Evoke in July 2025 over advertising-related allegations. The settlement was described as unrelated to the breach matter.

May 20, 20251y ago

Evoke says it learned of issue from law enforcement

Evoke Wellness at Hilliard's amended patient notice stated the organization was informed by law enforcement of the issue on May 20, 2025, contradicting other accounts that suggested internal discovery later in the year.

Jul 7, 20242y ago

Unauthorized activity allegedly begins at Evoke Wellness at Hilliard

Notification materials cited by DataBreaches.net state an incident at OCAT, LLC dba Evoke Wellness at Hilliard occurred on July 7, 2024, though the reporting notes conflicting timelines and uncertainty around the breach chronology.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Threat actors
3 linked
Organizations
11 linked
Deaconess Health SystemMRO CorpMediCopyConduentGoogleInsight Hospital and Medical CenterOCAT, LLC10TV NewsEvoke Wellness at HilliardCommunity Health Action of Staten IslandBlueCross BlueShield of Tennessee
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.