Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationthird-party-vendor-breachransomware-group-operation

Healthcare Data Breach and Ransomware Incident Roundup

Updated 2mo agoFirst seen Mar 17, 20265 sources

Several healthcare-related organizations disclosed separate data breach incidents involving ransomware, unauthorized network access, and third-party compromise. CommonSpirit Health said patient data was exposed through a downstream vendor chain after Pinnacle Holdings Ltd suffered a ransomware attack, with attackers present in the network from November 11 to November 25, 2024, and exfiltrating files before the incident was later relayed through NorthGauge Healthcare Advisors. Meadowlark Hills and MedPeds also disclosed breaches tied to the Beast ransomware group, while Tieu Dental reported unauthorized access to its network in July 2025 that exposed patient information including Social Security numbers, medical and insurance data. These incidents led to regulatory notifications and offers of credit monitoring or identity theft protection for affected individuals.

A separate legal development involved Geisinger Health and Nuance Communications, where a judge approved a $5 million settlement over claims tied to a former Nuance employee's theft of medical records affecting about 1.3 million patients. That matter differs from the ransomware and breach notifications because it concerns civil litigation over an earlier insider data theft rather than a newly disclosed intrusion. Overall, the reporting reflects ongoing exposure of protected health information across the healthcare sector through both direct attacks and third-party relationships, with delayed notification timelines and incomplete early visibility into the full scope of compromised data remaining recurring issues.

Share:
Healthcare Data Breach and Ransomware Incident Roundup
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

17 events from the most recent confirmed update back to the earliest known activity.

17 EVENTS
Mar 28, 20263mo ago

Corewell Health discloses Pinnacle breach affected 19,000 patients

Corewell Health disclosed that the 2024 Pinnacle Holdings vendor breach affected about 19,000 of its patients after reviewing the exposure. The compromised data included personal and medical information such as names, contact details, Social Security numbers, medical information, and insurance details.

Thousands of Corewell Health patients affected by security breach - DataBreaches.Net
Mar 17, 20263mo ago

Beast ransomware group claims MedPeds attack

By 2026-03-17, the Beast ransomware group had claimed the MedPeds Associates of Sarasota breach and said it stole 400 GB of data. The allegedly stolen MedPeds data had not been published at the time of reporting.

Beast ransomware group claims Meadowlark Hills attack

By 2026-03-17, the Beast ransomware group had claimed an attack on Meadowlark Hills, alleging it stole 750 GB of data. Meadowlark Hills had reported unauthorized network access and data exfiltration between 2025-07-12 and 2025-07-21 affecting 14,442 individuals.

Mar 16, 20263mo ago

SafePay ransomware group claims Children's Council attack

By the time of public reporting, the SafePay ransomware group had claimed responsibility for the Children's Council of San Francisco breach. The claim followed the organization's investigation into the August 2025 intrusion.

Mar 2, 20264mo ago

Children's Council mails breach notifications and offers protection

On 2026-03-02, Children's Council of San Francisco mailed notification letters to affected individuals and offered complimentary credit monitoring and identity theft protection. The organization had also notified the FBI.

Feb 2, 20265mo ago

NorthGauge notifies CommonSpirit Health of vendor breach

On 2026-02-02, NorthGauge informed CommonSpirit Health that patient data had been affected through the Pinnacle ransomware incident. CommonSpirit then moved toward notifying impacted patients.

Jan 30, 20265mo ago

NorthGauge identifies affected individuals in Pinnacle breach

NorthGauge Healthcare Advisors confirmed the identities of individuals affected by the Pinnacle incident on 2026-01-30. The breach was later disclosed as affecting CommonSpirit Health patients, including 19,027 Washington residents.

Jan 11, 20265mo ago

Tieu Dental confirms what patient data was exposed

On 2026-01-11, Tieu Dental confirmed the categories of patient data affected by the 2025 intrusion. The company said it had not identified misuse of the data at the time of disclosure.

Dec 31, 20256mo ago

Tieu Dental begins notifying affected patients

Tieu Dental said it began notifying affected patients in 2025 following its July network intrusion. The company later offered credit monitoring and identity theft protection services.

Nov 1, 20258mo ago

Pinnacle notifies NorthGauge after exposed-data review

In November 2025, Pinnacle notified NorthGauge Healthcare Advisors after a third-party review of exposed data from the 2024 ransomware incident. This set in motion downstream notifications involving CommonSpirit Health.

Sep 2, 202510mo ago

MedPeds discovers ransomware and unauthorized access

MedPeds Associates of Sarasota discovered unauthorized access and ransomware-based file encryption on 2025-09-02. The breach affected 21,430 individuals and exposed sensitive personal and protected health information.

Aug 3, 202511mo ago

Children's Council detects network-disrupting incident

On 2025-08-03, Children's Council of San Francisco identified a network-disrupting incident that led to an investigation. The breach ultimately affected 12,655 individuals.

Aug 1, 202511mo ago

Children's Council of San Francisco network accessed

Children's Council of San Francisco later determined that an unknown hacker accessed its network on 2025-08-01 and acquired files containing names and Social Security numbers.

Jul 28, 202511mo ago

Tieu Dental network accessed by unauthorized third party

Tieu Dental Corporation said an unauthorized third party accessed its network between 2025-07-28 and 2025-07-29, exposing patient data including Social Security numbers, medical records, treatment plans, prescription information, and insurance data.

Jul 27, 202511mo ago

Legend Senior Living breach begins with unauthorized access

Legend Senior Living discovered unauthorized access on or around 2025-08-15, and forensic investigators determined attackers had access between 2025-07-27 and 2025-08-15. Files containing personal and protected health information may have been viewed or acquired, and Texas was later told 5,006 residents were affected.

Two Senior Care Providers Affected by Ransomware Attacks
Nov 25, 20242y ago

Ransomware disrupts Pinnacle Holdings' network

Pinnacle Holdings Ltd suffered a ransomware attack that caused network disruption on 2024-11-25. The company was a vendor to NorthGauge Healthcare Advisors, a business associate of CommonSpirit Health.

Nov 11, 20242y ago

Pinnacle vendor attackers gain access and exfiltrate data

In a downstream incident later affecting CommonSpirit Health patients, attackers had access to Pinnacle Holdings Ltd's network from 2024-11-11 to 2024-11-25 and exfiltrated files during that period.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Organizations
7 linked
Buena Vista Management Services, LLCLegend Senior Living, LLCPinnacle SystemsCorewell HealthManhattan Retirement FoundationMedPeds Associates of SarasotaFox2
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.