Data Breaches
Medtronic Warns Pacemaker Patients Health Data May Have Been Exposed in Cyber Incident
A medical-device-manufacturer disclosure with sector-advisory implications — patient notification in focus this week.
Analyzing the security of Protected Health Information. Insights on PHI discovery, data masking, and HIPAA Breach Notification compliance.
Data Breaches
A medical-device-manufacturer disclosure with sector-advisory implications — patient notification in focus this week.
Healthcare Cybersecurity
Another healthcare-sector disclosure at scale — a single phishing email at an AI utilization-management vendor exposed the protected health information of nearly 1.4 million patients, and it reads as sector-advisory work for the week.
Healthcare Cybersecurity
A medical-device company's patient-records disclosure — sector-advisory work begins. iRhythm told the SEC a threat actor obtained patient protected health information from third-party-hosted business applications, and judged the incident material.
Data Breaches
Three breach disclosures landed in one cycle — Radiology Associates of Richmond (266,183 people), DocketWise (143,480), and a vendor breach at the Oncology Institute. None is a novel attack. Together they map 2026's two structural failures: repeat victimization and third-party risk.
Trending
More than 40 million people ask ChatGPT a healthcare-related question every day. OpenAI's ChatGPT Health and Anthropic's Claude for Healthcare are not HIPAA-compliant for consumers — and that is by design.
Ransomware
Sandhills Medical Foundation discloses a ransomware breach by Inc Ransom affecting 169,017 patients — nearly 12 months after the attack was detected and 10 months after stolen data was published publicly.
Data Breaches
The delayed 2026 notification of a massive 1.7-million-record exposure at Kettering Health highlights the "long tail" of healthcare ransomware, where the clinical recovery of a hospital often precedes the true regulatory and legal fallout by nearly a year. DAYTON, OH — A 2025 ransomware attack on
Settlements
HHS cracks down on four healthcare entities after risk analysis failures allowed PYSA and other ransomware to encrypt servers and exfiltrate patient data. WASHINGTON, D.C. — In a decisive move against systemic negligence in the medical sector, the HHS Office for Civil Rights (OCR) has announced a collective $1.165
Data Breaches
Minidoka Memorial Hospital transferred emergency patients after an imaging outage; a new ransomware group demands payment for an alleged 2.3 million files. RUPERT, ID — A quiet Easter morning in rural Idaho was shattered on April 5, 2026, when Minidoka Memorial Hospital (MMH) fell victim to a cyberattack that paralyzed
Data Breaches
UK Biobank's complete dataset exposed via three Chinese research institutions; listings removed after UK-China government intervention. LONDON, UK — In what is being described as a geopolitical health data security scandal, the UK government has confirmed that confidential medical and genomic data belonging to all 500,000 UK
Data Breaches
The developer of wireless cardiac pacing technology confirms unauthorized access to limited network data, joining a growing list of Australian healthcare targets in 2026. BRISBANE, AU — EBR Systems (ASX: EBR), a prominent medical technology firm specializing in wireless cardiac pacing, has officially reported a "contained" cybersecurity incident affecting
Data Breaches
Cookeville Regional Medical Center (CRMC) confirms a month-long unauthorized access incident that exposed sensitive medical records, Social Security numbers, and financial data. COOKEVILLE, TN — Cookeville Regional Medical Center (CRMC) has begun notifying 337,917 individuals that their highly sensitive personal and medical information was compromised during a sophisticated cyberattack.