Skip to main content
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationmass-credential-exposurethird-party-vendor-breach

Healthcare Data Breach Notifications and Settlement Involving Patient Information Exposure

Updated 2mo agoFirst seen Mar 18, 20263 sources

Multiple healthcare-related organizations disclosed separate incidents involving exposure or theft of patient data. Delta Medical Systems reported unauthorized access to its email environment on July 15, 2025, with potentially exposed data including names, dates of birth, Social Security numbers, driver’s license information, bank details, insurance information, and medical information. A separate HIPAA Journal report described additional incidents at Cedar Valley Services, Community Nurse, and Health Dimensions Group, including a likely Qilin ransomware intrusion at Cedar Valley Services and a vendor-linked compromise affecting Community Nurse through Doctor Alliance, where files may have been accessed between October 31 and November 17, 2025.

In a different but related healthcare privacy matter, a judge approved a $5 million settlement in litigation against Geisinger Health and Nuance Communications over the theft of medical records affecting roughly 1.3 million patients by a former Nuance employee. The stolen records reportedly included names, birthdates, addresses, medical record numbers, treatment details, and insurance information. While all three reports concern healthcare data exposure, they describe distinct incidents rather than one unified breach event, spanning direct compromises, third-party/vendor exposure, suspected ransomware activity, and post-incident legal resolution.

Share:
Healthcare Data Breach Notifications and Settlement Involving Patient Information Exposure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Mar 18, 20262mo ago

Deadline set for Geisinger settlement claims

Victims in the Geisinger-Nuance case were given until March 18, 2026, to file claims for compensation or enroll in complimentary credit monitoring. The settlement covered approximately 1.3 million affected patients.

Mar 17, 20262mo ago

Judge approves Geisinger-Nuance settlement

A judge approved the $5 million settlement in the civil case involving Geisinger Health and Nuance Communications over stolen patient records. The case stemmed from a former Nuance employee's theft of Geisinger patient data while Nuance was providing clinical documentation services.

Mar 5, 20263mo ago

About 97,000 Geisinger victims sign up for cash payments

As of March 5, around 97,000 victims in the Geisinger-Nuance settlement had enrolled for direct cash payments. The settlement also allowed victims to seek complimentary credit monitoring.

Mar 1, 20263mo ago

Geisinger and Nuance agree to $5 million settlement

Geisinger Health and Nuance Communications agreed earlier in March 2026 to settle civil litigation over the theft of medical records affecting about 1.3 million patients. The settlement provides compensation and credit monitoring while denying wrongdoing or additional liability.

Feb 11, 20263mo ago

Delta Medical Systems completes identification and notification work

By February 11, 2026, Delta Medical Systems had identified affected individuals from its July 2025 email compromise and notified them. The company also offered credit monitoring and identity theft protection.

Dec 1, 20256mo ago

Qilin lists Cedar Valley Services on leak site

The Qilin ransomware group listed Cedar Valley Services on its leak site and claimed to have exfiltrated sensitive data. This public claim linked the organization's hacking incident to a known ransomware operation.

Nov 17, 20256mo ago

Doctor Alliance unauthorized access window closed

The period during which a threat actor may have accessed files at Doctor Alliance ended on November 17, 2025. Community Nurse later disclosed the vendor incident as affecting thousands of individuals.

Oct 31, 20257mo ago

Doctor Alliance files potentially accessed in vendor incident

Community Nurse said a threat actor may have accessed files at document management and billing vendor Doctor Alliance during a security incident. The exposure window began on October 31, 2025, and ultimately affected 6,746 individuals tied to Community Nurse.

Oct 1, 20258mo ago

Health Dimensions Group suffers cybersecurity incident

Health Dimensions Group said files containing independent contractors' personal data were obtained during a cybersecurity incident in October 2025. The organization later offered credit monitoring and identity theft protection to affected individuals.

Sep 30, 20258mo ago

Ansell Healthcare Products discovers anomalous activity

Ansell Healthcare Products reported discovering anomalous activity affecting employee data. The incident ultimately affected 2,061 individuals and exposed names and Social Security numbers.

Aug 14, 20259mo ago

FuturHealth unauthorized access period ended

The unauthorized access and exfiltration activity in FuturHealth's environment concluded by mid-August 2025, according to the company's disclosure. The incident involved sensitive personal and health-related information.

Aug 8, 202510mo ago

FuturHealth network intrusion and data exfiltration occurred

FuturHealth disclosed that an unauthorized party accessed its network and exfiltrated data over a period in August 2025. Exposed information included names, health insurance information, and other sensitive personal data.

Jul 15, 202510mo ago

Delta Medical Systems email environment accessed

Delta Medical Systems said an unauthorized party accessed its email environment, potentially exposing patient data including protected health information and financial information. The company later identified affected individuals and provided notice and remediation support.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.