[
  {
    "organization_name": "Arkansas Oncology Group",
    "organization_type": "Healthcare Provider / Oncology",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Little Rock",
    "hq_county": "Pulaski",
    "discovery_date": "Unknown",
    "disclosure_date": "Unknown",
    "executive_summary": "Ransomware attack on Arkansas Oncology Group affecting approximately 113,500 individuals. Referenced in HIPAA Journal breach coverage. Specific timing and threat actor not available in public reporting.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 113500,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; HIPAA Journal breach listings reference 113,500-individual ransomware attack on AR Oncology Group; limited independent detail; dates not confirmed",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00001",
    "year": 0,
    "lat": 34.7465,
    "lng": -92.2896,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Corewell Health (formerly Spectrum Health) \u2014 no separate qualifying incident beyond vendor breaches",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MI",
    "hq_city": "Grand Rapids",
    "hq_county": "Kent",
    "discovery_date": "Not applicable",
    "disclosure_date": "Not applicable",
    "executive_summary": "Spectrum Health rebranded as Corewell Health in 2022. Qualifying Corewell-specific cyber incidents are documented as MW-011 (Welltok/MOVEit), MW-012 (HealthEC), and MW-052 (Pinnacle Holdings). No additional separate qualifying Spectrum/Corewell direct cyber incident beyond these vendor breaches has been identified in the 2019\u20132026 timeframe.",
    "attack_type": "Not applicable \u2014 all incidents captured in MW-011, MW-012, MW-052",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Captured in other entries",
    "residents_affected_in_state": "Michigan",
    "financial_impact": "Not applicable",
    "operational_impact": "Not applicable",
    "remediation_disclosed": "Not applicable",
    "primary_source_url": "https://www.michigan.gov/ag/news/press-releases/2023/12/01/corewell-health-data-breach-exposes-info-of-one-million-michigan-patients",
    "secondary_source_urls": [],
    "confidence_notes": "Note entry \u2014 all qualifying Corewell/Spectrum incidents captured in MW-011, MW-012, MW-052.",
    "sources_used": [
      "Michigan AG"
    ],
    "id": "INC-00002",
    "year": 0,
    "lat": 42.9634,
    "lng": -85.6681,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Gundersen Health System",
    "organization_type": "Nonprofit Integrated Health System (WI/MN/IA)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WI",
    "hq_city": "La Crosse",
    "hq_county": "La Crosse",
    "discovery_date": "Unknown",
    "disclosure_date": "Unknown",
    "executive_summary": "Gundersen Health System, a nonprofit integrated healthcare network headquartered in La Crosse, Wisconsin serving 21 counties in western Wisconsin, southeastern Minnesota, and northeast Iowa, has not been identified in publicly reported cyber incidents meeting the inclusion criteria for this dataset in the 2019\u20132026 timeframe based on available sources. No HHS OCR large breach portal entries or major media coverage of a qualifying cyber incident found for Gundersen Health in this period.",
    "attack_type": "Not applicable \u2014 no qualifying incident found",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not applicable",
    "residents_affected_in_state": "Not applicable",
    "financial_impact": "Not applicable",
    "operational_impact": "Not applicable",
    "remediation_disclosed": "Not applicable",
    "primary_source_url": "https://www.marshfieldclinic.org/news/news-articles/mchs-gundersen",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence of incident. No qualifying cyber incident found for Gundersen in available sources 2019-2026. Included as verified negative.",
    "sources_used": [
      "Comprehensive web search \u2014 no qualifying incident found"
    ],
    "id": "INC-00003",
    "year": 0,
    "lat": 43.8122836,
    "lng": -91.2514355,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ProMedica Health System",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Toledo",
    "hq_county": "Lucas",
    "discovery_date": "Unknown",
    "disclosure_date": "Unknown",
    "executive_summary": "ProMedica Health System, based in Toledo, Ohio, does not have a confirmed major qualifying cyber incident (hacking/ransomware/IT breach) in the 2019\u20132026 timeframe identified in available sources. Earlier incidents include a 2015 criminal HIPAA employee violation (indictment) and a 2016 EHR snooping breach (not cyber hacking events as defined by inclusion criteria). ProMedica confirmed in late 2023 that it does not use Perry Johnson & Associates' transcription services. No qualifying 2019\u20132026 cyber incident found.",
    "attack_type": "No qualifying cyber incident found in 2019-2026",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not applicable",
    "residents_affected_in_state": "Not applicable",
    "financial_impact": "Not applicable",
    "operational_impact": "Not applicable",
    "remediation_disclosed": "Not applicable",
    "primary_source_url": "https://healsecurity.com/mercy-health-uses-third-party-vendor-hit-by-cyber-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence of qualifying 2019-2026 incident. No qualifying event found for ProMedica in available sources in target time period. Included as verified negative.",
    "sources_used": [
      "HIPAA Journal (contextual)",
      "Heal Security (ProMedica noted as not using PJ&A)"
    ],
    "id": "INC-00004",
    "year": 0,
    "lat": 41.6528,
    "lng": -83.5379,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Texas Digestive Specialists (formerly Gastroenterology Consultants of South Texas)",
    "organization_type": "Healthcare Provider / Gastroenterology",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "McAllen",
    "hq_county": "Hidalgo",
    "discovery_date": "2025-06-03",
    "disclosure_date": "Unknown",
    "executive_summary": "InterLock ransomware breached Texas Digestive Specialists in June 2025, claiming 263 GB exfiltrated (16,920 folders, 215,245 files) including lab pathology reports with PHI. Rio Grande Valley practice. Patient count not yet disclosed to HHS or TX AG at time of research.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "InterLock",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "263 GB including patient lab reports stolen and leaked",
    "remediation_disclosed": "Not publicly disclosed at time of research",
    "primary_source_url": "https://databreaches.net/2025/06/03/texas-gastroenterology-and-surgical-practice-victim-of-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.globenewswire.com/news-release/2025/07/03/3109617/0/en/TEXAS-DIGESTIVE-SPECIALISTS-DATA-BREACH-ALERT-Bragar-Eagel-Squire-P-C-is-Investigating-Texas-Digestive-Specialists-on-Behalf-of-Texas-Digestive-Specialists-Customers-and-Encourages.html"
    ],
    "confidence_notes": "High confidence for occurrence; InterLock dark web listing; DataBreaches.net confirmed PHI in leaked lab reports; class action investigation announced",
    "sources_used": [
      "DataBreaches.net",
      "GlobeNewswire"
    ],
    "id": "INC-00005",
    "year": 2025,
    "lat": 26.204114,
    "lng": -98.2300605,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Oregon Health & Science University (OHSU) \u2014 HIPAA investigation",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2013-01-01",
    "disclosure_date": "2013-01-01",
    "executive_summary": "OCR's 2013 investigation into OHSU revealed widespread HIPAA Security Rule violations following reports of an unencrypted laptop theft and an unencrypted thumb drive theft, plus storage of 3,000+ individuals' ePHI on a cloud server without a business associate agreement. OHSU paid a $2.7 million settlement in 2016 (outside the 2019 window). Separately, in 2019\u20132021, OHSU failed to timely provide a patient's medical records upon request (right of access), resulting in a $200,000 civil monetary penalty imposed in December 2024 (within the window). The right-of-access violation is documented here as the in-window enforcement action.",
    "attack_type": "Right of Access violation (not a cyberattack)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1,
    "residents_affected_in_state": "Individual patient affected",
    "financial_impact": "$200,000 civil monetary penalty (December 2024)",
    "operational_impact": "Failure to provide patient records within HIPAA-required 30-day window",
    "remediation_disclosed": "OHSU waived right to hearing; $200,000 CMP paid",
    "primary_source_url": "https://www.hunton.com/privacy-and-cybersecurity-law-blog/ocr-imposes-200-000-penalty-against-oregon-health-science-university-for-hipaa-right-of-access-violations",
    "secondary_source_urls": [
      "https://greenlighthealth.com/hhs-office-civil-rights-imposes-200000-penalty-against-oregon-health-science-university-failure-provide-timely-access-patient-record/"
    ],
    "confidence_notes": "This is a right-of-access violation, not a cyber incident per se; included as it represents an OCR enforcement action within the window. Marked separately.",
    "sources_used": [
      "Hunton Andrews Kurth",
      "Greenlight Health"
    ],
    "id": "INC-00006",
    "year": 2013,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "NewYork-Presbyterian / Columbia University (2010 breach - 2014 OCR settlement)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York City",
    "hq_county": "New York",
    "discovery_date": "2010-09-01",
    "disclosure_date": "2014-05-07",
    "executive_summary": "NewYork-Presbyterian Hospital and Columbia University Medical Center reached the then-largest HIPAA settlement in history\u2014$4.8 million ($3.3M NYP + $1.5M Columbia)\u2014in 2014, following the 2010 exposure of approximately 6,800 patients' electronic records on the internet. The breach occurred when a physician attempted to deactivate a personal server connected to the NYP network, inadvertently exposing patient data to public internet searches. While this breach predates 2019, the settlement and subsequent corrective actions established precedent relevant to ongoing NYP cybersecurity issues.",
    "attack_type": "Unauthorized network access / misconfiguration",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 6800,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4.8 million HHS OCR settlement (2014) - largest at time",
    "operational_impact": "Patient records exposed on public internet; accessible via Google searches",
    "remediation_disclosed": "HHS OCR settlement with comprehensive corrective action plan; network segmentation improvements",
    "primary_source_url": "https://www.hinshawlaw.com/en/insights/healthcare-alert/two-new-york-hospitals-enter-into-largest-ever-hipaa-settlement-after-electronic-data-breach",
    "secondary_source_urls": [],
    "confidence_notes": "Historical incident pre-2019; included for context; landmark HIPAA case; well documented; marked as pre-2019",
    "sources_used": [
      "Hinshaw & Culbertson",
      "HHS OCR"
    ],
    "id": "INC-00007",
    "year": 2014,
    "lat": 40.7127281,
    "lng": -74.0060152,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Anthem, Inc.",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2015-01-29",
    "disclosure_date": "2015-02-04",
    "executive_summary": "On January 29, 2015, Anthem, Inc., then the second-largest U.S. health insurer, discovered that attackers had gained access to its enterprise data warehouse between December 2, 2014 and January 27, 2015. The breach resulted from a sophisticated spear-phishing attack on an Anthem subsidiary that allowed threat actors to move laterally to the main data warehouse. The protected health information of 78.8 million individuals was exfiltrated, including names, Social Security numbers, dates of birth, addresses, email addresses, employment information, and member health ID numbers \u2014 but not clinical records or payment card data. Mandiant attributed the attack to an advanced persistent threat actor operating on behalf of the Chinese government. Anthem paid $115 million to settle a consumer class action in 2017 and a record $16 million HHS OCR HIPAA settlement in 2018.",
    "attack_type": "Advanced Persistent Threat / Spear Phishing / Data Exfiltration",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "APT (Chinese state-sponsored; Mandiant attribution)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 78800000,
    "residents_affected_in_state": 1700000,
    "financial_impact": "$115M class action settlement (2017). $16M HHS OCR HIPAA settlement (2018) \u2014 then-largest HIPAA settlement in history. $110M+ in credit monitoring and security improvements. Total breach response estimated >$260M.",
    "operational_impact": "No EHR disruption or clinical system outages reported. Data warehouse access only. Massive downstream identity theft risk for 78.8M members and employees.",
    "remediation_disclosed": "Mandiant engaged for forensics. FBI notified. Credit monitoring offered. Enterprise-wide risk analysis mandated under 2018 OCR CAP. Multi-factor authentication and access controls strengthened.",
    "primary_source_url": "https://www.hipaajournal.com/16-million-anthem-hipaa-breach-settlement-takes-ocr-hipaa-penalties-past-100-million-mark/",
    "secondary_source_urls": [
      "https://en.wikipedia.org/wiki/Anthem_medical_data_breach",
      "https://www.bankinfosecurity.com/anthem-breach-tally-788-million-affected-a-7946",
      "https://tax.thomsonreuters.com/blog/anthem-data-breach-results-in-record-16-million-hipaa-settlement/",
      "https://businessinsights.bitdefender.com/anthem-agrees-to-16-million-settlement-following-compromise-of-80-million-health-records"
    ],
    "confidence_notes": "Extremely high confidence. Disclosed in SEC filings. Multiple regulatory settlements. Congressional attention. Mandiant forensic report detailed. Wikipedia entry well-sourced.",
    "sources_used": [
      "HIPAA Journal",
      "Wikipedia",
      "BankInfoSecurity",
      "Thomson Reuters Tax",
      "Bitdefender",
      "HHS OCR press release"
    ],
    "id": "INC-00008",
    "year": 2015,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Excellus Health Plan, Inc. (Excellus BlueCross BlueShield)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NY",
    "hq_city": "Rochester",
    "hq_county": "Monroe",
    "discovery_date": "2015-08-05",
    "disclosure_date": "2015-09-09",
    "executive_summary": "Excellus BlueCross BlueShield, a Rochester, NY-based regional health insurer, discovered in August 2015 that attackers had infiltrated its systems in a multi-year intrusion beginning December 23, 2013, going undetected for approximately 18 months. Hackers installed malware, performed reconnaissance, and accessed the protected health information of 9,358,891 individuals \u2014 approximately 7 million Excellus Health Plan members and 2.5 million Lifetime Healthcare (a non-BlueCross subsidiary) members \u2014 including names, addresses, dates of birth, Social Security numbers, member ID numbers, financial account information, and claims data. HHS OCR imposed a $5.1 million civil monetary penalty in January 2021. A class action lawsuit settled for $4.35 million (injunctive relief; final approval April 2022).",
    "attack_type": "Advanced Persistent Threat / Malware / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown (APT characteristics; no public attribution confirmed)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 9358891,
    "residents_affected_in_state": "NY: majority (regional insurer); exact NY count not separately disclosed",
    "financial_impact": "$5.1M HHS OCR HIPAA civil monetary penalty (January 2021). $4.35M class action settlement for injunctive relief (April 2022). Extensive security remediation costs not separately disclosed.",
    "operational_impact": "No clinical EHR disruption. Data breach only. 18 months of undetected attacker dwell time on systems containing 9.3M member records.",
    "remediation_disclosed": "External forensics engaged. OCR investigation spanning 2015\u20132021. Zero trust controls begun post-breach. Data archiving/retention overhaul required under class settlement. Enhanced network monitoring, access controls, and incident response policies.",
    "primary_source_url": "https://www.hipaajournal.com/excellus-health-plan-settles-hipaa-violation-case-and-pays-5-1-million-penalty/",
    "secondary_source_urls": [
      "https://thenationaltriallawyers.org/article/excellus-bluecross-blueshield-agrees-to-a-5-1m-settlement-for-the-2015-cyberattack/",
      "https://www.scworld.com/analysis/4-35m-excellus-breach-lawsuit-settlement-requires-data-retention-security-overhaul",
      "https://www.kellerrohrback.com/currentcases/excellus-bluecross-blueshield-data-breach"
    ],
    "confidence_notes": "High confidence. HHS OCR civil monetary penalty public record. Class action settlement documented in federal court. HHS OCR breach portal lists 9,358,891 affected.",
    "sources_used": [
      "HIPAA Journal",
      "National Trial Lawyers",
      "SC Media",
      "Keller Rohrback (plaintiff firm)"
    ],
    "id": "INC-00009",
    "year": 2015,
    "lat": 43.1566,
    "lng": -77.6088,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Montefiore Medical Center",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "Bronx",
    "discovery_date": "2015-09-01",
    "disclosure_date": "2015-09-03",
    "executive_summary": "Montefiore Medical Center in the Bronx, New York disclosed in 2015 that a former employee had stolen and sold protected health information of patients to an identity theft ring over a period from January 2013 to June 2013. The perpetrator, a billing department employee, stole the records of approximately 12,517 patients including names, addresses, dates of birth, Social Security numbers, and health insurance information and sold them to Maksim Aleksandrovich Mikheev, a Russian national who used the data for healthcare fraud. HHS OCR investigated and in 2019 reached a $2.2 million settlement with Montefiore for HIPAA violations related to the breach, including failure to implement appropriate safeguards. This case was notable as one of the first major HHS OCR HIPAA enforcement actions specifically related to insider theft.",
    "attack_type": "Insider Theft / Data Sale to Criminal Network",
    "attack_category": "Insider threat",
    "threat_actor_name": "Former billing employee (unnamed) / Maksim Aleksandrovich Mikheev",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 12517,
    "residents_affected_in_state": "NY: majority (Bronx NY-based hospital)",
    "financial_impact": "$2.2M HHS OCR HIPAA settlement (2019). Corrective action plan implemented.",
    "operational_impact": "Healthcare fraud committed using stolen records. No EHR or clinical system disruption.",
    "remediation_disclosed": "Former employee terminated and criminally prosecuted. Buyer (Mikheev) prosecuted. HHS OCR $2.2M HIPAA settlement. Corrective action plan including enhanced access controls and monitoring.",
    "primary_source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/montefiore/index.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/montefiore-medical-center-hipaa-settlement-2-2-million/",
      "https://www.hipaajournal.com/biggest-healthcare-data-breaches-2024/"
    ],
    "confidence_notes": "High confidence. HHS OCR official settlement page. HIPAA Journal corroborates. Criminal prosecution is public record.",
    "sources_used": [
      "HHS OCR official agreement page",
      "HIPAA Journal"
    ],
    "id": "INC-00010",
    "year": 2015,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Montefiore Medical Center (2013 insider theft - 2024 OCR settlement)",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "Bronx",
    "discovery_date": "2015-05-01",
    "disclosure_date": "2015-07-22",
    "executive_summary": "Montefiore Medical Center discovered in May 2015 (via NYPD tip) that an employee had accessed and sold the PHI of 12,517 patients to an identity theft ring from January-June 2013. The employee accessed records through the EMR system without authorization for 6 months before discovery. OCR investigated and in February 2024 reached a $4.75 million settlement for HIPAA Security Rule violations including failure to conduct risk analysis and monitor system activity.",
    "attack_type": "Malicious insider / unauthorized PHI access and sale",
    "attack_category": "Insider threat",
    "threat_actor_name": "Former Montefiore employee (unnamed)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 12517,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4.75 million OCR settlement (2024)",
    "operational_impact": "12,517 patients' SSNs, addresses, and PHI stolen and sold to identity theft ring",
    "remediation_disclosed": "Employee terminated and prosecuted; monitoring expanded; $4.75M OCR settlement; corrective action plan; 2-year federal monitoring",
    "primary_source_url": "https://www.hipaajournal.com/montefiore-medical-center-malicious-insider-hipaa-penalty/",
    "secondary_source_urls": [
      "https://compliancy-group.com/montefiore-medical-center-hhs-settlement/",
      "https://www.jdsupra.com/legalnews/montefiore-medical-center-settles-hipaa-6623771/"
    ],
    "confidence_notes": "Breach initially 2013; OCR investigation launched 2015; $4.75M OCR settlement February 2024. Note: Original breach pre-dates 2019 range but OCR enforcement in 2024 range",
    "sources_used": [
      "HIPAA Journal",
      "Compliancy Group",
      "JD Supra"
    ],
    "id": "INC-00011",
    "year": 2015,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Premera Blue Cross",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Mountlake Terrace",
    "hq_county": "Snohomish",
    "discovery_date": "2015-01-29",
    "disclosure_date": "2015-03-17",
    "executive_summary": "Premera Blue Cross, the largest health insurer in the Pacific Northwest, disclosed in March 2015 that attackers had breached its systems via a phishing email on May 5, 2014, and maintained undetected access for approximately eight months. The attack, attributed to Chinese state-sponsored hackers by forensics firm Mandiant, compromised the sensitive personal and medical information of approximately 10.6\u201311 million plan members and employees, including Social Security numbers, bank account information, dates of birth, member ID numbers, email and physical addresses, medical claims data, and other protected health information. Both internal and external audits had identified significant security deficiencies at Premera from 2011 through 2014 that went unaddressed. The company settled a class action for $74 million in 2019 (final approval March 2020) and paid $6.85 million in a 30-state multi-state regulatory agreement.",
    "attack_type": "Advanced Persistent Threat / Phishing / Data Exfiltration",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "APT (Chinese state-sponsored; Mandiant attribution)",
    "attribution_status": "reported",
    "individuals_affected_reported": 10600000,
    "residents_affected_in_state": 30,
    "financial_impact": "$74M class action settlement (final approval March 2020): $32M to victims, $42M to security improvements. $6.85M multi-state AG settlement (WA: $5.4M). No separate HHS OCR HIPAA monetary settlement announced.",
    "operational_impact": "No clinical system disruption. Data warehouse compromise only. Broad identity theft risk for 10.6M members. Fraudulent tax returns, unauthorized bank charges, and medical claims reported by victims post-breach.",
    "remediation_disclosed": "Mandiant forensics. FBI notified. Eight months of undetected access. Post-breach: credit monitoring, HITRUST certification achieved, annual third-party security audits mandated, encryption of sensitive data, enhanced email security.",
    "primary_source_url": "https://www.hipaajournal.com/74-million-settlement-proposed-to-resolve-premera-blue-cross-class-action-lawsuit/",
    "secondary_source_urls": [
      "https://tax.thomsonreuters.com/blog/court-approves-74-million-settlement-in-premera-data-breach-class-action/",
      "https://www.govtech.com/security/Premera-Blue-Cross-to-Pay-74M-Over-Data-Breach.html",
      "https://compliancy-group.com/settlement-reached-with-premera-over-data-breach-exposing-phi-of-10-4-million/",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/premera-blue-cross-security-incident-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. Class action settlement documented in federal court order. 30-state AG settlement documented. Mandiant attribution cited in court records. Breach discovery date confirmed by litigation.",
    "sources_used": [
      "HIPAA Journal",
      "GovTech",
      "Thomson Reuters Tax",
      "Top Class Actions",
      "Compliancy Group"
    ],
    "id": "INC-00012",
    "year": 2015,
    "lat": 47.7909667,
    "lng": -122.3066395,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Premera Blue Cross (2014 breach / 2020 OCR settlement)",
    "organization_type": "Health Plan (Health Insurance)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Mountlake Terrace",
    "hq_county": "Snohomish",
    "discovery_date": "2015-01-29",
    "disclosure_date": "2015-03-17",
    "executive_summary": "Hackers accessed Premera Blue Cross's computer network beginning in May 2014, with the breach not discovered for approximately nine months until January 29, 2015. The breach exposed names, addresses, dates of birth, Social Security numbers, bank account information, and clinical data for 10.4 million individuals \u2014 the largest health insurer breach in Washington state history. On September 25, 2020, HHS OCR announced a $6.85 million settlement with Premera \u2014 at the time, the second-largest HIPAA settlement ever \u2014 to resolve potential violations including failure to conduct adequate risk analysis. A separate $74 million class-action settlement was reached with affected consumers. The OCR enforcement action and class-action settlement both fall within the 2019\u20132026 window even though the underlying breach predates it.",
    "attack_type": "Advanced persistent threat / Nation-state level intrusion",
    "attack_category": "Nation-state intrusion",
    "threat_actor_name": "Suspected Winnti/APT41 (Chinese state-linked group, based on attribution by security researchers)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 10400000,
    "residents_affected_in_state": 6000000,
    "financial_impact": "$6.85 million HHS OCR settlement (Sept 2020); $74 million class-action settlement",
    "operational_impact": "9 months of undetected access; clinical and financial data of 10.4M individuals compromised; systemic HIPAA noncompliance identified",
    "remediation_disclosed": "Corrective action plan implemented; security overhaul completed; two years of credit monitoring provided to affected individuals",
    "primary_source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/premera/index.html",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/premera-blue-cross-security-incident-class-action-settlement/",
      "https://natlawreview.com/article/premera-blue-cross-s-685-million-settlement-second-largest-hipaa-settlement-to-date",
      "https://www.techtarget.com/healthtechsecurity/news/366595555/Premera-Pays-OCR-685M-to-Settle-HIPAA-Violations-Breach-of-104M"
    ],
    "confidence_notes": "High confidence: HHS.gov official settlement page; underlying breach pre-dates window (2014) but included because OCR enforcement ($6.85M, Sept 2020) and class-action settlement ($74M) both fall within 2019\u20132026. Flag for parent agent review regarding pre-2019 breach date policy.",
    "sources_used": [
      "HHS.gov OCR",
      "Top Class Actions",
      "National Law Review",
      "TechTarget HealthTech Security"
    ],
    "id": "INC-00013",
    "year": 2015,
    "lat": 47.7909667,
    "lng": -122.3066395,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "UCLA Health",
    "organization_type": "Academic medical center / health system (4 hospitals, 150+ offices, University of California)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles County",
    "discovery_date": "2014-10-01",
    "disclosure_date": "2015-07-17",
    "executive_summary": "UCLA Health first detected suspicious network activity in October 2014, and the FBI was notified. A May 5, 2015 determination confirmed that attackers had accessed parts of the network containing personal and medical information of up to 4.5 million patients and staff, potentially dating back to September 2014. Exposed data included names, addresses, DOBs, SSNs, Medicare/health plan IDs, and some medical information. No direct evidence of data acquisition was confirmed, though the breach was attributed to a sophisticated, likely offshore threat actor. A $7.5 million class-action settlement was reached in 2019.",
    "attack_type": "Network intrusion / hacking (advanced persistent threat)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "reported",
    "individuals_affected_reported": 4500000,
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'litigation_settlement': 7500000, 'notes': '$7.5M settlement (2019): $2M for unreimbursed losses/preventive measures claims; $5.5M cybersecurity enhancement fund. Patients could receive up to $5,000 for preventive costs and up to $20,000 for losses.'}",
    "operational_impact": "No clinical disruption publicly reported. FBI investigation ongoing.",
    "remediation_disclosed": "FBI notified; private computer forensic experts engaged; enhanced cybersecurity investment; credit monitoring (12 months) and identity theft restoration services offered to affected individuals.",
    "primary_source_url": "https://www.hipaajournal.com/ucla-health-system-hacked-4-5-million-patient-records-exposed-8033/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366595898/UCLA-Health-Reaches-75M-Settlement-Over-2015-Breach-of-45M",
      "https://www.mainepublic.org/2015-07-17/ucla-health-says-4-5m-may-be-affected-in-data-breach",
      "https://www.npr.org/sections/thetwo-way/2015/07/17/423893626/ucla-health-says-4-5m-may-be-affected-in-data-breach"
    ],
    "confidence_notes": "Attack likely began September 2014; network alarms triggered October 2014; PHI access confirmed May 5, 2015; public disclosure July 17, 2015 (10-week delay after confirmation). Note: Task said '2015 + any newer' \u2014 no major new UCLA Health cyber incidents found in the 2018\u20132025 window meeting landmark criteria (beyond vendor-related events).",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00014",
    "year": 2015,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "University of California, Los Angeles (UCLA) Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles",
    "discovery_date": "2014-09 to 2015-05 (prolonged unauthorized access)",
    "disclosure_date": "2015-07-17",
    "executive_summary": "Sophisticated cyberattack on UCLA Health network where hackers gained access to parts of the network hosting personally identifiable medical information. UCLA Health initially did not encrypt patient data. Disclosed July 2015.",
    "attack_type": "Hacking/IT Incident \u2014 Advanced persistent threat (APT) / network intrusion; patient data not encrypted",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Chinese state-sponsored actors (suspected, not confirmed publicly)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 4500000,
    "residents_affected_in_state": "Not separately reported (primarily CA patients)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No reported clinical operational disruption",
    "remediation_disclosed": "Computer forensic experts hired; network secured; encryption improvements announced",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.cyberlands.io/toptencybersecuritybreachesincalifornia",
      "https://www.hipaajournal.com/healthcare-data-breach-statistics/"
    ],
    "confidence_notes": "Landmark pre-2019 case included as contextual landmark. Ranked #23 largest healthcare breach of all time. PHI included names, addresses, SSNs, DOBs, medical record numbers, Medicare/Medicaid IDs, health plan info, diagnoses, procedures.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00015",
    "year": 2015,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Banner Health",
    "organization_type": "Healthcare Provider (Nonprofit Hospital System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2016-07-07",
    "disclosure_date": "2016-08-03",
    "executive_summary": "Banner Health, Arizona's largest health system, suffered a major cyberattack in 2016 when hackers first targeted payment card processing at food and beverage outlets, then spread to access patient and health plan data. Approximately 3,620,000\u20133,700,000 individuals were affected including patients, health plan members, food/beverage customers, and physicians. In February 2023, HHS OCR announced Banner Health paid $1.25M to settle HIPAA Security Rule violations. OCR found failures in risk analysis, system activity review, access controls, and technical safeguards.",
    "attack_type": "Hacking/IT Incident \u2013 Payment System Hack + PHI Server Breach",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3620000,
    "residents_affected_in_state": "Not separately reported (primarily Arizona/Western US)",
    "financial_impact": "$1.25M HIPAA settlement with OCR (2023)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "HIPAA Security Rule corrective action plan; OCR monitoring for 2 years; system security improvements",
    "primary_source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/banner-health/index.html",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/arizona-hospital-pays-1-25-million-in-5757157/",
      "https://www.kellerrohrback.com/news/keller-rohrback-investigates-data-breach-involving-3-7-million-banner-he"
    ],
    "confidence_notes": "High confidence; HHS OCR official settlement page; included for historical significance and 2023 HIPAA settlement in scope",
    "sources_used": [
      "HHS.gov official OCR settlement, JD Supra, Keller Rohrback"
    ],
    "id": "INC-00016",
    "year": 2016,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MedStar Health",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Columbia",
    "hq_county": "Howard",
    "discovery_date": "2016-03-28",
    "disclosure_date": "2016-03-28",
    "executive_summary": "MedStar Health, operating 10 hospitals and 250 outpatient facilities in the Baltimore-Washington metro area, was struck by SamSam ransomware on March 28, 2016. The attack exploited an unpatched JBoss web application server vulnerability. Systems were taken offline across all facilities. MedStar restored systems without paying ransom. Two Iranian hackers were later indicted by the DOJ in 2018 for the attack.",
    "attack_type": "Ransomware (SamSam)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri (Iranian APT)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 0,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; part of ~$6M in total ransom from attackers across all victims",
    "operational_impact": "10 hospitals and 250 outpatient facilities affected; EHR and email offline; staff reverted to paper; patients diverted",
    "remediation_disclosed": "Systems restored without paying ransom; FBI investigation; two Iranians indicted November 2018",
    "primary_source_url": "https://www.cbsnews.com/baltimore/news/medstar-health-cybercrime-victim/",
    "secondary_source_urls": [
      "https://medcitynews.com/2016/03/hackers-medstar-ransonware/",
      "https://arstechnica.com/information-technology/2016/04/maryland-hospital-group-denies-ignored-warnings-allowed-ransomware-attack/"
    ],
    "confidence_notes": "DOJ indictment confirms; FBI investigation; outside scope (2016) but significant NE anchor incident; Note: Year 2016 is before 2019 range but included as major reference",
    "sources_used": [
      "CBS Baltimore",
      "MedCity News",
      "Ars Technica"
    ],
    "id": "INC-00017",
    "year": 2016,
    "lat": 39.2037,
    "lng": -76.861,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Cascade Eye and Skin Centers, P.C.",
    "organization_type": "Healthcare Provider (Ophthalmology/Dermatology)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Kennewick",
    "hq_county": "Benton",
    "discovery_date": "2017-03-01",
    "disclosure_date": "2017-05-26",
    "executive_summary": "Cascade Eye and Skin Centers, a multi-location Washington healthcare provider, suffered a ransomware attack in March 2017. Approximately 291,000 files containing electronic protected health information were encrypted. OCR launched an investigation in May 2017 and identified HIPAA Security Rule violations including failure to conduct a comprehensive risk analysis and failure to monitor system activity. Cascade agreed to pay $250,000 and implement a corrective action plan in September 2024 (the settlement was delayed pending OCR review). Note: though the attack occurred in 2017, the OCR settlement was finalized in 2024.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 291000,
    "residents_affected_in_state": "WA-based patients",
    "financial_impact": "$250,000 OCR HIPAA settlement (2024)",
    "operational_impact": "PHI files encrypted; 291,000 files containing ePHI affected",
    "remediation_disclosed": "Risk analysis completed; policies revised; 2-year OCR monitoring; $250,000 penalty paid",
    "primary_source_url": "https://www.hipaajournal.com/cascade-eye-and-skin-centers-hipaa-settlement/",
    "secondary_source_urls": [
      "https://www.hunton.com/privacy-and-cybersecurity-law-blog/hhs-announces-settlement-agreement-with-washington-chain-of-eye-and-skin-clinics-following-ransomware-investigation"
    ],
    "confidence_notes": "Attack in 2017; OCR investigation ran 2017-2024; settlement finalized September 2024",
    "sources_used": [
      "HIPAA Journal",
      "Hunton Andrews Kurth"
    ],
    "id": "INC-00018",
    "year": 2017,
    "lat": 46.2087066,
    "lng": -119.119919,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Heritage Valley Health System",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Beaver",
    "hq_county": "Beaver",
    "discovery_date": "2017-06-27",
    "disclosure_date": "2017-06-27",
    "executive_summary": "Heritage Valley Health System was struck by the NotPetya malware attack on June 27, 2017 (originating from a Ukrainian accounting software update), which spread via a shared VPN connection with Nuance Communications. Electronic medical records were inaccessible across the health system. Heritage Valley subsequently sued Nuance in federal court. In 2024, HHS OCR reached a $950,000 settlement with Heritage Valley for HIPAA violations stemming from the attack.",
    "attack_type": "NotPetya malware / Destructive wiper",
    "attack_category": "Malware",
    "threat_actor_name": "Sandworm (Russian GRU, NotPetya authors)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$950,000 OCR settlement (2024)",
    "operational_impact": "EHR inaccessible system-wide; significant operational disruption at 3 hospitals and numerous outpatient centers",
    "remediation_disclosed": "Systems restored; Nuance sued in federal court (dismissed 2020); $950K OCR settlement with corrective action plan",
    "primary_source_url": "https://www.hhs.gov/about/news/2024/07/01/hhs-office-civil-rights-settles-hipaa-security-rule-enforcement-action-heritage-valley-health-system.html",
    "secondary_source_urls": [
      "https://shawnetuma.com/2024/07/02/ocr-settles-hipaa-security-rule-enforcement-action-with-heritage-valley-health-system-stemming-from-ransomware-attack/",
      "https://compliancy-group.com/heritage-valley-ocr-settlement/",
      "https://www.govtech.com/security/health-system-to-pay-950k-to-settle-privacy-issues-after-hack"
    ],
    "confidence_notes": "OCR settlement officially announced; Heritage Valley lawsuit against Nuance documented; 2017 incident but settlement in 2024",
    "sources_used": [
      "HHS OCR",
      "Business Cyber Risk",
      "Compliancy Group",
      "GovTech"
    ],
    "id": "INC-00019",
    "year": 2017,
    "lat": 40.6916624,
    "lng": -80.3709999,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Atrium Health (NC) \u2013 AccuDoc Solutions Breach",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Charlotte",
    "hq_county": "Mecklenburg",
    "discovery_date": "2018-10-01",
    "disclosure_date": "2018-11-27",
    "executive_summary": "AccuDoc Solutions, Atrium Health's billing vendor, experienced a data breach between September 22 and September 29, 2018. Hackers accessed AccuDoc's databases containing PHI of 2,650,000 Atrium Health patients. Approximately 700,000 SSNs were also exposed. No clinical/medical records or financial information were affected. AccuDoc settled HIPAA violations. This is the NC-registered entity for the AccuDoc breach.",
    "attack_type": "Unauthorized Database Access via Vendor (Business Associate Breach)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2652537,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient billing data and ~700K SSNs exposed via vendor",
    "remediation_disclosed": "AccuDoc systems secured; Atrium notified October 1, 2018; identity monitoring offered to SSN-affected patients",
    "primary_source_url": "https://www.hipaajournal.com/2-65-million-atrium-health-patients-impacted-by-business-associate-data-breach/",
    "secondary_source_urls": [
      "https://medcitynews.com/2018/11/atrium-health-billing-vendor-patients/"
    ],
    "confidence_notes": "HHS OCR lists 2,652,537 affected (AccuDoc Solutions, NC). Well-documented across multiple reliable sources.",
    "sources_used": [
      "HIPAA Journal",
      "MedCity News"
    ],
    "id": "INC-00020",
    "year": 2018,
    "lat": 35.2271,
    "lng": -80.8431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Augusta University Health (AU Health)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Augusta",
    "hq_county": "Richmond",
    "discovery_date": "2017-09-11",
    "disclosure_date": "2018-08-17",
    "executive_summary": "Augusta University Health experienced two phishing-related cyberattacks. The first, detected September 11, 2017, involved employee email accounts compromised by phishing. A second, smaller attack occurred July 11, 2018. The combined breach affected approximately 417,000 patients, faculty members, and students. PHI including addresses, DOBs, medical record numbers, diagnoses, lab results, medications, treatment info, and for a small percentage, SSNs and driver's licenses, was exposed. Notification was delayed nearly a year.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 417000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI of 417K individuals exposed; ~10-month notification delay for first breach",
    "remediation_disclosed": "Email accounts secured; investigation; notifications issued August 2018",
    "primary_source_url": "https://www.hipaajournal.com/417000-individuals-affected-by-augusta-university-health-phishing-attack/",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/417000-augusta-university-health-patient-records-breached-nearly-one-year-ago",
      "https://www.augusta.edu/notice/"
    ],
    "confidence_notes": "HHS OCR lists 417,000. AU Health official notice corroborates. Note: 2017 occurrence but publicly disclosed 2018; included as it falls within research scope period (pre-2019 for awareness context).",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare IT News",
      "Augusta University (official)"
    ],
    "id": "INC-00021",
    "year": 2018,
    "lat": 33.4735,
    "lng": -82.0105,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Confluence Health",
    "organization_type": "Healthcare Provider (Health System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Wenatchee",
    "hq_county": "Chelan",
    "discovery_date": "2018-05-29",
    "disclosure_date": "2018-07-30",
    "executive_summary": "Confluence Health, operator of Wenatchee Valley Hospital and Central Washington Hospital, suffered a phishing attack in which an employee's email account was compromised on May 28 and 30, 2018. Patient names and treatment information were potentially exposed. 33,821 patients were affected. The incident was reported to HHS OCR. Confluence had security defenses in place, but phishing bypassed them.",
    "attack_type": "Phishing / Email compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 33821,
    "residents_affected_in_state": "Majority WA-based (Central/North WA)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI in compromised email account potentially accessed",
    "remediation_disclosed": "Email security controls enhanced; additional monitoring implemented",
    "primary_source_url": "https://www.hipaajournal.com/confluence-health-informs-patients-of-phishing-incident/",
    "secondary_source_urls": [
      "https://www.hipaaguide.net/confluence-health-encounters-phishing-attack/"
    ],
    "confidence_notes": "Breach occurred May 2018, disclosed July 2018; included as it appears in 2018 and may straddle the reporting period (HHS OCR reported in 2018 and disclosed publicly July 2018). Included at the edge of the 2019 cutoff for completeness.",
    "sources_used": [
      "HIPAA Journal",
      "HIPAA Guide"
    ],
    "id": "INC-00022",
    "year": 2018,
    "lat": 47.4235,
    "lng": -120.3103,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Legacy Health (phishing breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2018-06-21",
    "disclosure_date": "2018-08-20",
    "executive_summary": "Portland, Oregon-based Legacy Health discovered on June 21, 2018, that an unauthorized individual had gained access to multiple employee email accounts via phishing attacks beginning in May 2018. Approximately 38,000 patients were potentially affected. Compromised data included names, dates of birth, health insurance details, medical information, billing information, and for some patients, Social Security numbers and driver's license numbers. This was Legacy Health's second phishing breach in 2018.",
    "attack_type": "Phishing / Email compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 38000,
    "residents_affected_in_state": "Majority OR-based (Portland metro)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Multiple employee email accounts compromised; PHI potentially accessed for weeks",
    "remediation_disclosed": "Third-party forensic firm engaged; enhanced access restrictions; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/phishing-attack-legacy-health/",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/phishing-attack-breaches-38000-patient-records-legacy-health"
    ],
    "confidence_notes": "Reported to HHS OCR and to The Oregonian; breach discovered June 2018 (pre-2019 window but HHS reporting may fall within window)",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare IT News"
    ],
    "id": "INC-00023",
    "year": 2018,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Providence Medical Institute",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Torrance",
    "hq_county": "Los Angeles",
    "discovery_date": "2018-02 to 2018-03",
    "disclosure_date": "2018 (ransomware occurred Feb-Mar 2018)",
    "executive_summary": "Ransomware attack on Providence Medical Institute. Servers containing ePHI encrypted three times. OCR investigation found violations of HIPAA Security Rule.",
    "attack_type": "Hacking/IT Incident \u2014 Ransomware (servers encrypted 3 times)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 85000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$240,000 civil monetary penalty from OCR",
    "operational_impact": "Servers encrypted and unavailable",
    "remediation_disclosed": "Systems eventually restored; OCR corrective action plan",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/hipaa-violation-cases/"
    ],
    "confidence_notes": "Pre-2019 case included as landmark. OCR found failure to restrict access to ePHI and lack of business associate agreement. $240,000 CMP imposed.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00024",
    "year": 2018,
    "lat": 33.8358,
    "lng": -118.3406,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "UnityPoint Health \u2014 2017 Phishing Attack",
    "organization_type": "Nonprofit Regional Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2018-02-15",
    "disclosure_date": "2018-04-01",
    "executive_summary": "UnityPoint Health suffered its first of two phishing attacks, with the breach window November 1, 2017 through February 7, 2018. This initial breach was discovered February 15, 2018 but not disclosed until April 2018. PHI of approximately 16,400 patients was initially believed affected. The class action lawsuit (combined with the 2018 breach) alleged UnityPoint misrepresented the breach's scope and delayed notification. Combined 2017-2018 settlement of $2.8 million covered both events.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 16400,
    "residents_affected_in_state": "Iowa Wisconsin Illinois patients",
    "financial_impact": "Covered under combined $2.8M settlement (with 2018 breach)",
    "operational_impact": "Email system compromised; payment diversion attempt suspected",
    "remediation_disclosed": "Yes \u2014 credentials reset; patients notified April 2018",
    "primary_source_url": "https://www.fiercehealthcare.com/tech/unitypoint-health-agrees-to-2-8m-settlement-2018-data-breach-case",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. FierceHealthcare settlement coverage, Iowa AG notification letter.",
    "sources_used": [
      "FierceHealthcare"
    ],
    "id": "INC-00025",
    "year": 2018,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UnityPoint Health \u2014 2018 Phishing Attack",
    "organization_type": "Nonprofit Regional Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2018-05-31",
    "disclosure_date": "2018-07-30",
    "executive_summary": "UnityPoint Health discovered on May 31, 2018 that a phishing email attack had compromised its business email system with access occurring between March 14 and April 3, 2018. Attackers impersonated a trusted executive ('business email compromise') and tricked employees into providing sign-in credentials. PHI of approximately 1.4 million individuals was potentially exposed. The Iowa Attorney General was notified that 960,561 Iowa residents were potentially affected. A second earlier breach (November 2017 \u2013 February 2018) also occurred. A combined $2.8 million class action settlement was reached in 2020.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown (business email compromise actors)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1400000,
    "residents_affected_in_state": 960561,
    "financial_impact": "$2.8 million class action settlement; $1.57M attorneys' fees cap; up to $7,000 per class member",
    "operational_impact": "Email system breach; EHR and billing systems not affected; financial fraud attempt suspected",
    "remediation_disclosed": "Yes \u2014 passwords reset; MFA implemented; employee training; attorney general notified; notifications mailed July 2018",
    "primary_source_url": "https://www.iowaattorneygeneral.gov/media/cms/073018_Unity_Point_Health_87A0A0D52C8A3.pdf",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/tech/unitypoint-health-agrees-to-2-8m-settlement-2018-data-breach-case",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/unitypoint-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. Iowa AG official PDF, Fierce Healthcare, settlement coverage.",
    "sources_used": [
      "Iowa AG",
      "FierceHealthcare",
      "Top Class Actions"
    ],
    "id": "INC-00026",
    "year": 2018,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Yakima Valley Memorial Hospital",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Yakima",
    "hq_county": "Yakima",
    "discovery_date": "2018-02-28",
    "disclosure_date": "2018-02-28",
    "executive_summary": "Yakima Valley Memorial Hospital, a nonprofit community hospital, reported that 23 security guards working in its emergency department had improperly used their login credentials to access the medical records of 419 patients without job-related purposes. Compromised data included names, dates of birth, medical record numbers, addresses, treatment notes, and insurance information. OCR investigated and in June 2023 reached a $240,000 settlement with a 2-year corrective action plan. Though reported in 2018, the OCR settlement falls in the 2019-2026 window.",
    "attack_type": "Insider threat / Unauthorized access (internal snooping)",
    "attack_category": "Insider threat",
    "threat_actor_name": "Internal (23 hospital security guards)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 419,
    "residents_affected_in_state": 419,
    "financial_impact": "$240,000 OCR HIPAA settlement (2023)",
    "operational_impact": "Unauthorized employee access to patient records in EMR system",
    "remediation_disclosed": "Revised HIPAA policies; enhanced workforce training; 2-year OCR monitoring",
    "primary_source_url": "https://www.morganlewis.com/blogs/healthlawscan/2023/09/ocr-announces-settlement-agreement-in-phi-breach",
    "secondary_source_urls": [
      "https://ankura.com/insights/medical-record-snooping-case-leads-to-a-240k-hipaa-settlement/"
    ],
    "confidence_notes": "Breach reported to OCR February 2018; OCR settlement June 2023. Categorized here for the 2023 settlement date within window.",
    "sources_used": [
      "Morgan Lewis",
      "Ankura"
    ],
    "id": "INC-00027",
    "year": 2018,
    "lat": 46.601557,
    "lng": -120.510842,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "AltaMed Health Services Corporation",
    "organization_type": "Federally Qualified Health Center (FQHC)",
    "organization_type_bucket": "FQHC / Community health",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2018-05-21",
    "disclosure_date": "2019-05-30",
    "executive_summary": "In its letter to AltaMed, SHDS stated that it first detected abnormal activity within its network on June 22, 2018. Upon detecting this activity, SHDS launched an investigation and engaged a forensics firm to support its inquiry. SHDS ultimately determined that an unauthorized third-party gained access to SHDS\u2019s network as early as May 21, 2018 and acquired files containing patient information. SHDS also notified the Federal Bureau of Investigation (\u201cFBI\u201d) about this incide",
    "attack_type": "Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/AltaMed%20--%20SHDS%20--%20Supplemental%20Consumer%20Notification%20Letter%20Proof%20%282019.05.28%29_0.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00028",
    "year": 2019,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Aveanna Healthcare (Massachusetts breach / MA AG settlement)",
    "organization_type": "Healthcare Provider (Home Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Boston",
    "hq_county": "Suffolk",
    "discovery_date": "2019-07-01",
    "disclosure_date": "2019-10-01",
    "executive_summary": "Aveanna Healthcare, a home health agency with significant Massachusetts operations, suffered a phishing-based cyberattack that compromised patient and employee data. The Massachusetts Attorney General reached a $425,000 settlement in 2022 for lack of adequate safeguards against phishing. The breach affected Aveanna's operations across multiple states including Massachusetts.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$425,000 MA AG settlement (2022)",
    "operational_impact": "Home health patient and employee data compromised across MA operations",
    "remediation_disclosed": "MA AG settlement with corrective security measures mandated",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2022 AG penalties table confirms $425K MA AG settlement for phishing failures; MA operations confirmed",
    "sources_used": [
      "HIPAA Journal",
      "MA AG"
    ],
    "id": "INC-00029",
    "year": 2019,
    "lat": 42.3601,
    "lng": -71.0589,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Beth Israel Lahey Health (MA - email/IT compromise)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Burlington",
    "hq_county": "Middlesex",
    "discovery_date": "2019-07-01",
    "disclosure_date": "2019-10-01",
    "executive_summary": "Beth Israel Lahey Health (BILH), a major Massachusetts health system formed in 2019 from the merger of Beth Israel Deaconess Medical Center and Lahey Health, reported a data security incident shortly after its formation. The breach involved unauthorized access to patient information at legacy Lahey Health facilities, exposing patient records including names, medical record numbers, and clinical information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "MA major health system patient PHI compromised at legacy facilities",
    "remediation_disclosed": "HHS OCR and patients notified; merged health system security reviewed",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2019; major MA academic health system; BILH formed 2019; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00030",
    "year": 2019,
    "lat": 42.5048167,
    "lng": -71.1956111,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "California Physicians' Service d/b/a Blue Shield of California",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2018-05-22",
    "disclosure_date": "2019-02-15",
    "executive_summary": "Sharecare Health Data Services (\u201cSharecare\u201d), formerly known as \u201cBACTES\u201d, provides medical records management services to one or more of your doctors or other health care professionals. At times, Blue Shield needs to obtain information contained in your medical records to pay claims related to your treatment or for other healthcare operations purposes. Your doctor requires that Blue Shield obtain copies of these medical records from Sharecare. On December 31, 2018, Sharecare notified Blue Shield",
    "attack_type": "Hacking / Security Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/BS%20No%20SSN%20Notice_0.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00031",
    "year": 2019,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Cheyenne Regional Medical Center",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WY",
    "hq_city": "Cheyenne",
    "hq_county": "Laramie",
    "discovery_date": "2019-04-05",
    "disclosure_date": "2019-12-12",
    "executive_summary": "Cheyenne Regional Medical Center experienced a phishing attack between March 27 and April 8, 2019 that compromised employee email accounts. While the attack appeared aimed at employee payroll data, patient information contained in email accounts may also have been accessed. The full patient list of 17,549 individuals was not confirmed until November 2019, delaying notifications.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 17549,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal reported clinical disruption; targeted employee payroll systems",
    "remediation_disclosed": "Identity protection and credit monitoring offered; enhanced email security",
    "primary_source_url": "https://www.hipaajournal.com/patients-notified-of-phishing-attack-at-cheyenne-regional-medical-center/",
    "secondary_source_urls": [
      "https://www.healthdatamanagement.com/articles/hackers-hit-cheyenne-regional-in-attack-for-payroll-data?id=201"
    ],
    "confidence_notes": "High confidence; HIPAA Journal and HDM both confirmed; OCR breach portal listed",
    "sources_used": [
      "HIPAA Journal, Health Data Management"
    ],
    "id": "INC-00032",
    "year": 2019,
    "lat": 41.14,
    "lng": -104.8202,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Clinical Pathology Laboratories, Inc.",
    "organization_type": "Healthcare Provider (Laboratory)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "TX",
    "hq_city": "Austin",
    "hq_county": "Travis",
    "discovery_date": "2019-05-01",
    "disclosure_date": "2019-07-15",
    "executive_summary": "Clinical Pathology Laboratories was affected by the AMCA (American Medical Collection Agency) data breach, in which hackers accessed AMCA's billing/collections payment website between August 2018 and March 2019. Approximately 2.2 million CPL patients had names, addresses, phone numbers, dates of birth, dates of service, balance information, and in some cases credit card or banking information exposed.",
    "attack_type": "Hacking/IT Incident \u2013 Third-party payment processor breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2200000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "AMCA subsequently filed for bankruptcy; 41-state AG settlement of $21M (across all AMCA victims)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Breach limited to AMCA systems; CPL offered credit monitoring to ~34,500 patients",
    "primary_source_url": "https://www.prnewswire.com/news-releases/clinical-pathology-laboratories-inc-notifies-patients-of-data-security-incident-300885218.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/2-2-million-clinical-pathology-laboratories-patients-affected-by-amca-breach/",
      "https://www.fiercehealthcare.com/tech/clinical-pathology-laboratories-reports-2-2m-patients-affected-by-amca-breach"
    ],
    "confidence_notes": "Well-documented; AMCA breach among largest of 2019; OCR reports 1,733,836 for this entity specifically",
    "sources_used": [
      "HIPAA Journal, PR Newswire, FierceHealthcare, HHS OCR breach statistics page"
    ],
    "id": "INC-00033",
    "year": 2019,
    "lat": 30.2672,
    "lng": -97.7431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CompuNet Clinical Laboratories (Ohio \u2014 AMCA breach)",
    "organization_type": "Clinical Laboratory",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "OH",
    "hq_city": "Dayton",
    "hq_county": "Montgomery",
    "discovery_date": "2019-05-01",
    "disclosure_date": "2019-08-01",
    "executive_summary": "CompuNet Clinical Laboratories, a Dayton, Ohio-based clinical laboratory, was among 24 healthcare organizations whose patient data was exposed in the American Medical Collection Agency (AMCA) data breach. AMCA, a third-party billing collections vendor, had its payment portal hacked, enabling unauthorized access to patient payment and PHI data from approximately August 2018 through March 2019. CompuNet CFO confirmed approximately 111,555 patients served by CompuNet were affected. Data exposed included names, addresses, phone numbers, dates of birth, payment card/banking information, Social Security numbers, and medical information.",
    "attack_type": "Third-Party Vendor Breach (AMCA payment portal hacking)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 111555,
    "residents_affected_in_state": "Ohio residents primarily (CompuNet serves the Dayton/Southwest Ohio region)",
    "financial_impact": "Not separately disclosed for CompuNet; AMCA filed for bankruptcy following breach",
    "operational_impact": "Patient payment data and medical information exposed; AMCA systems taken offline",
    "remediation_disclosed": "Yes \u2014 AMCA notified covered entities; CompuNet notified patients; AMCA filed bankruptcy Chapter 11",
    "primary_source_url": "https://www.bankinfosecurity.com/two-more-lab-firms-say-they-were-amca-breach-victims-a-12888",
    "secondary_source_urls": [
      "https://firecompass.com/american-medical-collection-agency-amca-data-breach-why-it-happened-what-can-you-learn-24-million-customers-affected/"
    ],
    "confidence_notes": "High confidence. BankInfoSecurity confirmed CompuNet CEO statement (111,000 patients). AMCA breach is one of the largest healthcare data breaches of 2019.",
    "sources_used": [
      "BankInfoSecurity",
      "FireCompass",
      "HIPAA Journal (contextual)"
    ],
    "id": "INC-00034",
    "year": 2019,
    "lat": 39.7589,
    "lng": -84.1916,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Conway Medical Center",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Conway",
    "hq_county": "Horry",
    "discovery_date": "2019-10-07",
    "disclosure_date": "2019-12-19",
    "executive_summary": "Conway Medical Center (CMC) in South Carolina fell victim to a phishing attack discovered October 7, 2019. Employee email accounts were compromised, with initial access occurring in or before July 2019. Emails potentially synchronized with the attacker's computer. The breach exposed patient names, addresses, SSNs, dates of birth, admission/discharge dates, and account information. SC Consumer Affairs lists 30,087 SC residents affected.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 30087,
    "residents_affected_in_state": 30087,
    "financial_impact": "Not publicly disclosed; identity theft protection offered",
    "operational_impact": "Multiple employee email accounts compromised; PHI and guarantor financial information potentially exfiltrated",
    "remediation_disclosed": "Unauthorized access terminated; external cybersecurity experts engaged; identity theft protection services offered; enhanced email security implemented",
    "primary_source_url": "https://www.conwaymedicalcenter.com/notice-of-data-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/email-security-breaches-reported-by-conway-medical-center-and-equinox-inc/",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 CMC official breach notice, HIPAA Journal reporting, SC Consumer Affairs listing.",
    "sources_used": [
      "Conway Medical Center Official Notice",
      "HIPAA Journal",
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00035",
    "year": 2019,
    "lat": 33.8360035,
    "lng": -79.0478143,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "DCH Health System",
    "organization_type": "Healthcare Provider / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AL",
    "hq_city": "Tuscaloosa",
    "hq_county": "Tuscaloosa",
    "discovery_date": "2019-10-01",
    "disclosure_date": "2019-10-02",
    "executive_summary": "Ryuk ransomware attack forced all three DCH Health System hospitals (DCH Regional Medical Center, Northport Medical Center, Fayette Medical Center) to close to new patients on October 1, 2019. DCH paid the threat actor for a decryption key to restore access to locked systems. No patient data theft was confirmed but the attack caused significant operational disruption.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Ryuk (attributed to Russian threat actors)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Ransom paid (amount undisclosed); operational costs significant",
    "operational_impact": "All three hospitals closed to new non-critical patients; manual paper-based operations; significant service disruption",
    "remediation_disclosed": "Paid ransom for decryption key; used DCH backup files to rebuild systems; engaged independent IT security and forensics experts",
    "primary_source_url": "https://www.hipaajournal.com/dch-health-system-ransomware-attack-temporarily-cripples-3-alabama-hospitals/",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/alabama-hospital-system-dch-pays-restore-systems-after-ransomware-attack",
      "https://www.alreporter.com/2019/10/05/dch-hospital-system-pays-russian-hackers-in-ransomware-attack/"
    ],
    "confidence_notes": "High confidence \u2014 multiple news sources, HIPAA Journal reporting, Alabama Political Reporter coverage.",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare IT News",
      "Alabama Political Reporter",
      "Heimdal Security"
    ],
    "id": "INC-00036",
    "year": 2019,
    "lat": 33.2098,
    "lng": -87.5692,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Elgon Information Systems (2019 breach)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MA",
    "hq_city": "Boston",
    "hq_county": "Suffolk",
    "discovery_date": "2019-01-01",
    "disclosure_date": "2019-06-01",
    "executive_summary": "Elgon Information Systems, a Massachusetts healthcare IT company, had an earlier data breach in 2019 before the 2023 ransomware attack that resulted in the OCR $80K settlement. Details of the 2019 incident are limited; this reflects an earlier cyber incident at the same Massachusetts entity. Note: primary reference is the 2023 incident.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare IT billing data potentially compromised",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://therecord.media/massachusetts-health-firm-reaches-settlement",
    "secondary_source_urls": [],
    "confidence_notes": "The 2023 breach is better documented; this 2019 reference has limited verifiable details",
    "sources_used": [
      "The Record"
    ],
    "id": "INC-00037",
    "year": 2019,
    "lat": 42.3601,
    "lng": -71.0589,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Hackensack Meridian Health",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Edison",
    "hq_county": "Middlesex",
    "discovery_date": "2019-12-02",
    "disclosure_date": "2019-12-13",
    "executive_summary": "Hackensack Meridian Health, New Jersey's largest health network, suffered a ransomware attack on December 2, 2019 that encrypted files and took its network offline for two days. The attack forced cancellation of non-emergency procedures and required staff to revert to pen-and-paper processes across 17 hospitals. HMH paid an undisclosed ransom to restore systems more quickly. Patient data including names, SSNs, and medical information was potentially compromised.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Ransom paid (amount undisclosed); cybersecurity insurance coverage confirmed",
    "operational_impact": "2-day network outage across 17 hospitals; non-emergency procedures cancelled; staff reverted to paper records",
    "remediation_disclosed": "Ransom paid; outside cybersecurity experts engaged; law enforcement notified",
    "primary_source_url": "https://www.hipaajournal.com/hackensack-meridian-health-recovering-from-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/hackensack-meridian-health-hit-with-class-action-lawsuit-over-dec.-2019-ransomware-attack",
      "https://www.law360.com/healthcare-authority/articles/1244179/patients-sue-nj-hospital-chain-over-2019-ransomware-attack"
    ],
    "confidence_notes": "Widely reported; class action filed; HIPAA breach report filed",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "Law360"
    ],
    "id": "INC-00038",
    "year": 2019,
    "lat": 40.5187,
    "lng": -74.4121,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Inmediata Health Group (CT residents affected)",
    "organization_type": "Business Associate / Health Clearinghouse",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "PR",
    "hq_city": "San Juan",
    "hq_county": "San Juan",
    "discovery_date": "2019-01-15",
    "disclosure_date": "2019-04-30",
    "executive_summary": "Inmediata Health Group, a Puerto Rico-based healthcare clearinghouse, had a coding error that exposed PHI of approximately 1.5 million consumers online for nearly 3 years, starting January 2019. The OCR alerted Inmediata on January 15, 2019. CT AG Tong led a 33-state multistate settlement resulting in $1.4 million paid by Inmediata, with Connecticut receiving $60,154. Notification was delayed by over 3 months.",
    "attack_type": "Misconfiguration / unauthorized online exposure",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1500000,
    "residents_affected_in_state": "Not separately reported for CT",
    "financial_impact": "$1.4 million multistate settlement; CT received $60,154",
    "operational_impact": "1.5M consumers' PHI accessible via online search for ~3 years",
    "remediation_disclosed": "Website access removed; multistate AG settlement; HIPAA corrective action; 5-year annual third-party assessments",
    "primary_source_url": "https://portal.ct.gov/AG/Press-Releases/2023-Press-Releases/AG-Tong-Announces-Multistate-Settlement-with-Health-Care-Clearinghouse-Inmediata-for-Data-Breach",
    "secondary_source_urls": [],
    "confidence_notes": "CT AG press release; 33-state multistate settlement; OCR initially alerted Inmediata",
    "sources_used": [
      "CT AG"
    ],
    "id": "INC-00039",
    "year": 2019,
    "lat": 18.4655,
    "lng": -66.1057,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Inmediata Health Group, LLC",
    "organization_type": "Healthcare Clearinghouse",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PR",
    "hq_city": "San Juan",
    "hq_county": "San Juan",
    "discovery_date": "2019-01-23",
    "disclosure_date": "2019-01-23",
    "executive_summary": "Puerto Rico-based Inmediata Health Group (medical data processing/clearinghouse) had PHI of 1,565,338 individuals publicly accessible online between May 2016 and January 23, 2019 due to a misconfigured web page that was indexed by Google. PHI included names, DOBs, home addresses, SSNs, claims information, diagnoses, and treatment information. Inmediata settled with OCR for $250,000 (2024), multi-state AG for $1.4M (2023), and class action for $1.125M (2022). Total penalties: ~$2.7M+.",
    "attack_type": "Web Application Misconfiguration / Unauthorized Public Exposure",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not applicable (misconfiguration)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1565338,
    "residents_affected_in_state": "Puerto Rico and mainland US; state breakdown not separately reported",
    "financial_impact": "$250K OCR settlement; $1.4M multi-state AG settlement; $1.125M class action settlement (total ~$2.775M)",
    "operational_impact": "PHI publicly accessible and indexed by Google for ~3 years",
    "remediation_disclosed": "Webpage secured January 2019; corrective action plan per multi-state AG settlement",
    "primary_source_url": "https://www.hipaajournal.com/ocr-settlement-inmediata-health-group-hipaa/",
    "secondary_source_urls": [
      "https://hipaatimes.com/inmediata-breach-exposes-1.6m-patients-data-causing-250k-settlement",
      "https://compliancy-group.com/ocr-enters-into-250000-settlement-with-healthcare-clearinghouse-over-potential-hipaa-violations/",
      "https://www.hipaajournal.com/ocr-settlement-inmediata-health-group-hipaa/",
      "https://www.techtarget.com/healthtechsecurity/news/366594869/Inmediata-Health-Reaches-113M-Settlement-After-2019-Data-Breach",
      "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/inmediata-health-group-ra-cap/index.html"
    ],
    "confidence_notes": "HHS OCR lists 1,565,338. OCR settlement confirmed December 2024. Multi-state AG and class action settlements well-documented. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Compliancy Group",
      "HHS.gov official settlement notice",
      "HIPAA Journal",
      "HIPAA Times",
      "Paubox/HIPAA Times",
      "TechTarget"
    ],
    "id": "INC-00040",
    "year": 2019,
    "lat": 18.4655,
    "lng": -66.1057,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kaiser Permanente",
    "organization_type": "Health Plan / Integrated Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Oakland, CA",
    "hq_county": "Alameda County",
    "discovery_date": "2019-08-12",
    "disclosure_date": "2019-09-26",
    "executive_summary": "On August 19, 2019, we learned that a Kaiser Permanente provider\u2019s email account containing your protected health information was compromised by an unknown individual for approximately thirteen hours on August 12, 2019. We do not have any evidence that your information was viewed, used or copied. However, because Kaiser Permanente takes the protection of our member data very seriously, we are obliged to notify you of this matter.",
    "attack_type": "Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately disclosed (email account compromise)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Passwords reset']",
    "primary_source_url": "https://oag.ca.gov/system/files/Member%20Letter%20Template_NCal%20email%20incident_092619_FINAL.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/kaiser-foundation-health-plan-data-breach/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00041",
    "year": 2019,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Kalispell Regional Healthcare (now Logan Health)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MT",
    "hq_city": "Kalispell",
    "hq_county": "Flathead",
    "discovery_date": "2019-08-01",
    "disclosure_date": "2019-11-01",
    "executive_summary": "Kalispell Regional Healthcare (later rebranded as Logan Health) suffered a phishing attack in May 2019 that compromised employee email accounts. An undetected monthslong data compromise affected approximately 130,000 patients, exposing Social Security numbers, dates of birth, contact information, medical histories, insurance data, medical record numbers, and other sensitive data. The organization did not detect the breach until August 2019.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 130000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4.2M class action settlement (December 2020)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Email security improved; employee phishing awareness training enhanced; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/kalispell-regional-healthcare-sued-over-130000-record-data-breach/",
    "secondary_source_urls": [
      "https://www.scworld.com/analysis/logan-health-agrees-to-4-3m-settlement-after-2021-health-data-breach",
      "https://compliancejunction.com/130000-record-data-breach-results-in-legal-action-against-kalispell-regional-healthcare/"
    ],
    "confidence_notes": "High confidence; confirmed through multiple sources; lawsuit settled; OCR listed",
    "sources_used": [
      "HIPAA Journal, SC Media, ComplianceJunction"
    ],
    "id": "INC-00042",
    "year": 2019,
    "lat": 48.1958,
    "lng": -114.3127,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Laboratory Corporation of America Holdings (LabCorp) / AMCA",
    "organization_type": "Lab (affected via billing BA breach)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "NC",
    "hq_city": "Burlington",
    "hq_county": "Alamance",
    "discovery_date": "2019-06-04",
    "disclosure_date": "2019-06-04",
    "executive_summary": "LabCorp disclosed via SEC filing on June 4, 2019, that the AMCA billing collections breach (August 2018 \u2013 March 2019) had exposed data on 7.7 million of its patients. Unlike Quest, the LabCorp data did not include Social Security numbers but did include names, addresses, phone numbers, dates of birth, dates of service, provider information, balance information, and some banking/credit card data (for approximately 200,000 individuals who used AMCA's payment portal). Combined with Quest's 11.9 million, the AMCA breach affected approximately 20 million patients from the two labs alone.",
    "attack_type": "Payment Portal Hacking / Web Skimming (via BA AMCA)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 7700000,
    "residents_affected_in_state": "Nationwide; not broken out by state",
    "financial_impact": "Financial credit card/bank data for ~200K individuals compromised. Multiple class action lawsuits. SEC filing disclosed impact.",
    "operational_impact": "No disruption to laboratory operations. Financial data theft from billing collections portal.",
    "remediation_disclosed": "LabCorp and AMCA notified law enforcement. Credit monitoring offered. AMCA took down payment portal.",
    "primary_source_url": "https://www.sec.gov/Archives/edgar/data/920148/000092014819000028/0000920148-19-000028-index.htm",
    "secondary_source_urls": [
      "https://krebsonsecurity.com/2019/06/labcorp-7-7m-consumers-hit-in-collections-firm-breach/",
      "https://www.hipaajournal.com/up-to-7-7-million-patients-of-labcorp-impacted-by-amca-breach/",
      "https://www.engadget.com/2019-06-05-quest-diagnostics-labcorp-amca-data-breach.html"
    ],
    "confidence_notes": "High confidence. LabCorp disclosed via SEC filing June 4, 2019. Count of 7.7M from LabCorp's own filing.",
    "sources_used": [
      "LabCorp SEC filing",
      "KrebsOnSecurity",
      "HIPAA Journal",
      "Engadget"
    ],
    "id": "INC-00043",
    "year": 2019,
    "lat": 36.0956918,
    "lng": -79.4377991,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Optum360 / Quest Diagnostics (via AMCA breach \u2014 Minnesota HQ)",
    "organization_type": "Healthcare IT / Medical Laboratory Business Associate",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "MN",
    "hq_city": "Eden Prairie",
    "hq_county": "Hennepin",
    "discovery_date": "2019-03-30",
    "disclosure_date": "2019-06-03",
    "executive_summary": "Optum360 LLC, a Minnesota-based healthcare IT and medical billing subsidiary of UnitedHealth Group (Eden Prairie, MN), was the largest reported victim of the 2019 American Medical Collection Agency (AMCA) breach, with 11.5 million Quest Diagnostics patients affected. AMCA, Optum360's billing collections contractor, had its payment portal hacked from approximately August 2018 through March 2019. The breach exposed names, addresses, phone numbers, dates of birth, payment card and banking information, Social Security numbers, and medical information for Quest Diagnostics patients nationally. This was the second-largest healthcare data breach in US history at the time. Optum360 is headquartered in Eden Prairie, Minnesota.",
    "attack_type": "Third-Party Vendor Breach (AMCA payment portal hacking)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11500000,
    "residents_affected_in_state": 11500000,
    "financial_impact": "AMCA filed for bankruptcy; multiple Quest Diagnostics lawsuits; settlement amounts not publicly confirmed",
    "operational_impact": "Payment portal data exposed; Optum360 terminated AMCA contract; Quest Diagnostics patient data compromised",
    "remediation_disclosed": "Yes \u2014 AMCA systems taken offline; Optum360/Quest notified patients; HHS OCR breach notification submitted",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [
      "https://firecompass.com/american-medical-collection-agency-amca-data-breach-why-it-happened-what-can-you-learn-24-million-customers-affected/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal breach statistics (all-time largest breaches table confirms Optum360 11.5M); HHS OCR breach portal. Midwest HQ (Eden Prairie MN) qualifies.",
    "sources_used": [
      "HIPAA Journal",
      "FireCompass",
      "HHS OCR"
    ],
    "id": "INC-00044",
    "year": 2019,
    "lat": 44.8546856,
    "lng": -93.470786,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Optum360, LLC (Quest Diagnostics / AMCA)",
    "organization_type": "BA/Vendor (Revenue Cycle Management)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "MN",
    "hq_city": "Eden Prairie",
    "hq_county": "Hennepin",
    "discovery_date": "2019-05-14",
    "disclosure_date": "2019-06-03",
    "executive_summary": "Optum360, LLC, a revenue cycle management company providing billing collections services for Quest Diagnostics, was among the largest victims of the American Medical Collection Agency (AMCA) breach of 2019. AMCA was breached by unauthorized actors between August 2018 and March 2019 \u2014 an eight-month intrusion undetected by AMCA. HHS OCR's breach portal separately attributes 11,500,000 individuals to Optum360 in connection with this breach. Quest Diagnostics (the covered entity served by Optum360 via AMCA) reported approximately 11.9 million individuals affected in its own breach notification. Compromised data included billing information, bank account details, personal data, and some medical information. AMCA's parent company (Retrieval-Masters Creditors Bureau) filed for Chapter 11 bankruptcy shortly after the breach due to associated costs exceeding $3.8 million in notifications alone.",
    "attack_type": "Third-Party Business Associate Breach / Unauthorized Web Payment Page Access",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11500000,
    "residents_affected_in_state": "Not separately reported by state",
    "financial_impact": "AMCA parent filed Chapter 11 bankruptcy (2019). Notification costs >$3.8M. Multistate AG settlement of $21M (suspended). Quest Diagnostics: class action lawsuits filed; LabCorp reported $11.5M in remediation costs.",
    "operational_impact": "AMCA web payment page compromised for 8 months undetected. No clinical disruption. Downstream impact on Quest, LabCorp, and other AMCA clients.",
    "remediation_disclosed": "AMCA terminated. Optum360/Quest terminated relationship with AMCA. AMCA notified law enforcement and engaged cybersecurity firm. Multiple state AG investigations. AMCA filed Chapter 11.",
    "primary_source_url": "https://hipaauniversity.com/blog/biggest-healthcare-data-breaches/",
    "secondary_source_urls": [
      "https://krebsonsecurity.com/2019/06/labcorp-7-7m-consumers-hit-in-collections-firm-breach/",
      "https://secureframe.com/blog/healthcare-data-breaches"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal attributes 11,500,000 to Optum360. Multiple AG investigations. AMCA bankruptcy public record. Note: Quest Diagnostics (ID 26) and LabCorp (ID 27) are separately tracked as covered entities in this dataset.",
    "sources_used": [
      "HIPAA University (citing HHS OCR)",
      "KrebsOnSecurity",
      "Secureframe"
    ],
    "id": "INC-00045",
    "year": 2019,
    "lat": 44.8546856,
    "lng": -93.470786,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Oregon Department of Human Services (2019 mass phishing)",
    "organization_type": "State Government / Healthcare Agency",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Salem",
    "hq_county": "Marion",
    "discovery_date": "2019-01-08",
    "disclosure_date": "2019-03-20",
    "executive_summary": "Oregon Department of Human Services (DHS) suffered a large-scale phishing attack on January 8, 2019, affecting nine DHS employees who clicked a phishing link and exposed their email credentials. The compromised email accounts were accessible to unauthorized actors from January 8 to January 28, 2019. Approximately 350,000 Oregonians' personal information was potentially exposed, including those receiving Medicaid, SNAP, child welfare, and other DHS services. Exposed data included names, addresses, dates of birth, Social Security numbers, case numbers, and some medical information. DHS notified the Oregon legislature and the public in March 2019.",
    "attack_type": "Phishing / Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown phishing actor",
    "attribution_status": "unknown",
    "individuals_affected_reported": 350000,
    "residents_affected_in_state": 350000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Nine employee email accounts compromised; 350,000 client records potentially exposed; 3-week unauthorized access window",
    "remediation_disclosed": "Accounts secured; multi-factor authentication accelerated; employee training enhanced; individual notifications mailed",
    "primary_source_url": "https://www.oregonlive.com/pacific-northwest-news/2019/03/oregon-department-of-human-services-data-breach-350000-people-affected.html",
    "secondary_source_urls": [
      "https://www.oregon.gov/dhs/ABOUT/Pages/News/2019/2019-0320-data-breach.aspx"
    ],
    "confidence_notes": "High confidence: OregonLive and Oregon DHS official news release confirm 350,000 affected; January 2019 incident falls within the 2019-2026 window; DHS is the healthcare/social services agency for Oregon",
    "sources_used": [
      "OregonLive",
      "Oregon DHS official news release"
    ],
    "id": "INC-00046",
    "year": 2019,
    "lat": 44.9429,
    "lng": -123.0351,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Oregon Health Authority / Oregon State Hospital",
    "organization_type": "Government Healthcare Provider (State Psychiatric Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Salem",
    "hq_county": "Marion",
    "discovery_date": "2019-05-06",
    "disclosure_date": "2019-05-15",
    "executive_summary": "A spear-phishing email was sent to an Oregon Health Authority Oregon State Hospital employee in May 2019, leading the employee to expose their credentials to an unauthorized entity. The compromised email account contained protected health information of psychiatric hospital patients, including names, dates of birth, medical record numbers, diagnoses, treatment care plans, and other treatment information. OHA could not confirm whether any PHI was copied or misused.",
    "attack_type": "Spear phishing / Email compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly specified (all Oregon State Hospital patients were notified)",
    "residents_affected_in_state": "OR-based psychiatric hospital patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI in employee email account accessible to unauthorized parties",
    "remediation_disclosed": "Forensic review initiated; staff notified; external forensic entity to be engaged",
    "primary_source_url": "https://www.oregon.gov/oha/erd/pages/oha-notify-public-state-hospital-data-breach.aspx",
    "secondary_source_urls": [],
    "confidence_notes": "Official OHA press release; breach discovered May 6, 2019",
    "sources_used": [
      "Oregon Health Authority official notice"
    ],
    "id": "INC-00047",
    "year": 2019,
    "lat": 44.9429,
    "lng": -123.0351,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Presbyterian Healthcare Services",
    "organization_type": "Healthcare Provider (Health System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NM",
    "hq_city": "Albuquerque",
    "hq_county": "Bernalillo",
    "discovery_date": "2019-06-01",
    "disclosure_date": "2019-08-27",
    "executive_summary": "Presbyterian Healthcare Services, New Mexico's largest health system, reported a phishing attack targeting employee email accounts that resulted in the exposure of protected health information for 183,370 patients and health plan members. Compromised data included names, dates of birth, Social Security numbers, and some clinical and health plan information.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 183370,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal reported operational disruption",
    "remediation_disclosed": "Enhanced email security; notifications mailed; credit monitoring offered",
    "primary_source_url": "https://www.fiercehealthcare.com/tech/presbyterian-healthcare-reports-phishing-scam-exposed-183k-patients-data",
    "secondary_source_urls": [
      "https://www.healthdatamanagement.com/news/more-than-180k-patients-affected-by-data-breach-at-presbyterian",
      "https://www.healthcareitnews.com/news/presbyterian-healthcare-phishing-scam-hits-183k-patient-records"
    ],
    "confidence_notes": "High confidence; OCR breach report confirmed 183,370 affected; HHS portal listed",
    "sources_used": [
      "FierceHealthcare, Healthcare IT News, Health Data Management"
    ],
    "id": "INC-00048",
    "year": 2019,
    "lat": 35.0844,
    "lng": -106.6504,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Prisma Health \u2013 Midlands",
    "organization_type": "Healthcare Provider / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Columbia",
    "hq_county": "Richland",
    "discovery_date": "2019-08-29",
    "disclosure_date": "2019-10-30",
    "executive_summary": "Prisma Health \u2013 Midlands (formerly Palmetto Health) learned on August 29, 2019 that an unauthorized individual obtained a Prisma Health employee's login credentials. Those credentials provided access to the Palmetto Health website containing patient pre-registration forms and volunteer registration information from 6 Midlands hospitals. Approximately 19,000 patients and 3,000 volunteers were affected.",
    "attack_type": "Credential Compromise / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 22000,
    "residents_affected_in_state": 14197,
    "financial_impact": "Not publicly disclosed; identity theft insurance offered to affected individuals",
    "operational_impact": "Patient pre-registration and volunteer registration data exposed for 6 Midlands hospitals",
    "remediation_disclosed": "Access blocked; employee password reset; identity theft insurance and credit monitoring offered; SC AG notified",
    "primary_source_url": "https://www.hipaajournal.com/prisma-health-website-breach-potentially-impacts-22000-individuals/",
    "secondary_source_urls": [
      "https://www.thestate.com/news/local/article236768133.html",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal, The State newspaper, SC Consumer Affairs breach listing (14,197 SC residents).",
    "sources_used": [
      "HIPAA Journal",
      "The State Newspaper",
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00049",
    "year": 2019,
    "lat": 34.0007,
    "lng": -81.0348,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Providence Health Plan (via Dominion National breach)",
    "organization_type": "Health Plan (Dental Program)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2019-04-24",
    "disclosure_date": "2019-08-20",
    "executive_summary": "Dominion National, the Virginia-based administrator of Providence Health Plan's dental program, disclosed on June 21, 2019, that an unauthorized party may have accessed its computer servers as early as August 25, 2010, through April 24, 2019 \u2014 a period of nearly nine years. Providence Health Plan notified approximately 122,000 of its dental plan members in Oregon that their personal information may have been exposed. Compromised data included names, addresses, email addresses, dates of birth, Social Security numbers, member identification numbers, group numbers, and subscriber numbers. Dominion National agreed to a $4.7 million class-action settlement. Providence's own servers were not breached; affected records were stored on Dominion's systems since 2015.",
    "attack_type": "Hacking / Unauthorized server access (multi-year)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2964778,
    "residents_affected_in_state": 122000,
    "financial_impact": "$4.7 million national class-action settlement (Dominion National)",
    "operational_impact": "Dental plan member data exposed for up to 9 years; delayed detection of access",
    "remediation_disclosed": "Dominion National notified FBI; heightened network security; notification letters sent; two years of credit monitoring provided",
    "primary_source_url": "https://www.thelundreport.org/content/data-breach-affects-122000-providence-dental-plan-patients",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/tech/providence-health-plan-notifying-122k-members-third-party-data-breach",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/dominion-national-4-7m-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "High confidence: Lund Report (OR health news outlet) confirmed 122,000 OR members; FierceHealthcare corroborates; Dominion National national total (2.96M) from HHS OCR; OR-specific count from Providence notification",
    "sources_used": [
      "The Lund Report",
      "FierceHealthcare",
      "Top Class Actions"
    ],
    "id": "INC-00050",
    "year": 2019,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Quest Diagnostics, Inc. / American Medical Collection Agency (AMCA)",
    "organization_type": "Lab (affected via billing BA breach)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "NJ",
    "hq_city": "Secaucus",
    "hq_county": "Hudson",
    "discovery_date": "2019-05-14",
    "disclosure_date": "2019-06-03",
    "executive_summary": "American Medical Collection Agency (AMCA), a billing collections vendor for Quest Diagnostics, LabCorp, and other medical testing companies, suffered a data breach via its web payment portal between August 1, 2018, and March 30, 2019. Quest Diagnostics first learned of the breach on May 14, 2019, and disclosed via an SEC filing June 3. AMCA's systems exposed the personal and financial data of approximately 11.9 million Quest patients including names, addresses, phone numbers, dates of birth, SSNs (for some), financial account information, and medical information (not lab results). AMCA subsequently filed for bankruptcy. The breach also affected approximately 7.7 million LabCorp patients (see separate entry).",
    "attack_type": "Payment Portal Hacking / Web Skimming",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11900000,
    "residents_affected_in_state": "Nationwide; not broken out by state",
    "financial_impact": "AMCA filed for bankruptcy following breach. Quest and LabCorp disclosed impact in SEC filings. Multiple class action lawsuits filed.",
    "operational_impact": "No disruption to laboratory operations. Financial and personal data theft from billing collections portal.",
    "remediation_disclosed": "AMCA took down web payments page. Quest notified law enforcement and regulators. Credit monitoring offered to affected individuals.",
    "primary_source_url": "https://www.sec.gov/Archives/edgar/data/920148/000092014819000027/0000920148-19-000027-index.htm",
    "secondary_source_urls": [
      "https://krebsonsecurity.com/2019/06/labcorp-7-7m-consumers-hit-in-collections-firm-breach/",
      "https://www.fiercehealthcare.com/tech/amca-breach-may-have-exposed-data-7-7m-labcorp-patients",
      "https://www.angeloslaw.com/personal-injury/medical-malpractice/quest-diagnostics-and-labcorp-data-breach/"
    ],
    "confidence_notes": "High confidence. Quest and LabCorp both disclosed via SEC filings. AMCA bankruptcy filing confirmed. Breach window confirmed August 2018 \u2013 March 2019.",
    "sources_used": [
      "Quest Diagnostics SEC filing",
      "KrebsOnSecurity",
      "Fierce Healthcare",
      "Peter Angelos Law"
    ],
    "id": "INC-00051",
    "year": 2019,
    "lat": 40.7899291,
    "lng": -74.0566735,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Salem Health Hospitals and Clinics",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Salem",
    "hq_county": "Marion",
    "discovery_date": "2019-08-01",
    "disclosure_date": "2019-11-09",
    "executive_summary": "Salem Health Hospitals and Clinics discovered on August 1, 2019, that an unauthorized individual had gained access to some employee email accounts on July 31, 2019. The breach potentially exposed patient names, dates of birth, and information about care received at Salem Health facilities. Salem Health could not confirm whether any patient data was actually viewed by the unauthorized party.",
    "attack_type": "Email compromise / Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly specified",
    "residents_affected_in_state": "OR-based Salem Health patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; PHI potentially accessed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.securitymagazine.com/articles/91246-salem-health-hospitals-and-clinics-victim-of-data-breach",
    "secondary_source_urls": [],
    "confidence_notes": "Reported by Security Magazine; official patient count not confirmed",
    "sources_used": [
      "Security Magazine"
    ],
    "id": "INC-00052",
    "year": 2019,
    "lat": 44.9429,
    "lng": -123.0351,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Solara Medical Supplies, LLC",
    "organization_type": "Direct-to-patient medical device distributor and pharmacy (diabetes supplies: CGMs, insulin pumps)",
    "organization_type_bucket": "Pharmacy",
    "state": "CA",
    "hq_city": "Chula Vista",
    "hq_county": "San Diego County",
    "discovery_date": "2019-06-28",
    "disclosure_date": "2019-11-13",
    "executive_summary": "Between April 2, 2019, and June 20, 2019, unknown actors gained access to eight Solara Medical Supplies employee Office 365 email accounts via a phishing campaign. On June 28, 2019, Solara identified suspicious activity. The breach exposed PHI of 114,007 patients/customers, including SSNs, DOBs, medical information, financial account details, and Medicare IDs. A subsequent breach occurred when 1,531 notification letters were mailed to incorrect addresses. HHS OCR settled for $3 million in January 2025. A class-action settlement of approximately $9.76 million was also reached.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 114007,
    "residents_affected_in_state": "Primarily CA given Chula Vista HQ and CA patient base",
    "financial_impact": "{'hhs_ocr_settlement': 3000000, 'litigation_settlement': 9760000, 'notes': 'OCR settlement: $3M + 2-year corrective action plan (Jan 14, 2025). Class-action settlement: $9.76M (preliminary approval ~2022; expanded from initial $5.06M proposal). Additional breach: 1,531 mis-mailed letters (Jan 2020 OCR report).'}",
    "operational_impact": "No care delivery disruption (distributor, not hospital). Data in employee email accounts compromised.",
    "remediation_disclosed": "Account passwords reset; policies and procedures reviewed and enhanced; law enforcement notified; OCR notified November 13, 2019. Credit monitoring and identity protection offered at no cost. Two-year OCR corrective action plan.",
    "primary_source_url": "https://www.prnewswire.com/news-releases/solara-medical-supplies-provides-notice-of-a-data-breach-300957962.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/solara-medical-supplies-hipaa-settlement/",
      "https://databreaches.net/2025/01/14/hhs-office-for-civil-rights-settles-hipaa-phishing-cybersecurity-investigation-with-solara-medical-supplies-llc-for-3000000/",
      "https://www.hipaajournal.com/solara-medical-supplies-proposes-5-million-settlement-to-resolve-class-action-data-breach-lawsuit/",
      "https://compliancy-group.com/solara-hipaa-phishing-settlement/",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf"
    ],
    "confidence_notes": "Notable for dual breach: original phishing (114,007 individuals) and subsequent mis-mailing (1,531 individuals). OCR investigation took nearly 5.5 years from breach discovery (Jun 2019) to settlement (Jan 2025). 154 Rhode Island residents affected per original notice. | Solara is a direct-to-consumer distributor of continuous glucose monitors and insulin pumps. PHI included driver's license numbers, SSNs, credit card, billing, and claims information. OCR also found violations for late notification and mailing error. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HHS OCR Breach Portal",
      "Organization notice / News / SEC"
    ],
    "id": "INC-00053",
    "year": 2019,
    "lat": 32.6401,
    "lng": -117.0842,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Solara Medical Supplies, LLC (AdaptHealth subsidiary)",
    "organization_type": "Medical Device / Pharmacy / Durable Medical Equipment",
    "organization_type_bucket": "Pharmacy",
    "state": "CA",
    "hq_city": "Chula Vista",
    "hq_county": "San Diego",
    "discovery_date": "2019-06-20",
    "disclosure_date": "2019-11-01",
    "executive_summary": "Solara Medical Supplies, the self-described largest U.S. supplier of continuous glucose monitors and insulin pumps (a Medicare provider partnering with 300+ insurers), suffered a phishing attack between April 2 and June 20, 2019, that compromised the email accounts of eight employees. The accounts contained the ePHI of 114,007 individuals. Additionally, Solara sent 1,531 breach notification letters to incorrect addresses, resulting in a second breach. OCR conducted an investigation, identified multiple HIPAA Security and Breach Notification Rule violations, and on January 14, 2025, announced a $3 million settlement with a two-year corrective action plan. A class action lawsuit was settled for $9.76 million.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 114007,
    "residents_affected_in_state": "Nationwide; not broken out by state",
    "financial_impact": "$3 million OCR HIPAA settlement (January 2025). $9.76 million class action settlement. Total >$12.76M in legal and regulatory costs.",
    "operational_impact": "No disruption to medical supply distribution. Email account access only.",
    "remediation_disclosed": "Compromised accounts secured. OCR corrective action plan for 2 years. Enhanced risk analysis, security measures, MFA (implied). Credit monitoring offered to affected patients.",
    "primary_source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/solara-medical-supplies/index.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/solara-medical-supplies-hipaa-settlement/",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/solara-medical-supplies-data-breach-9-76m-class-action-settlement/",
      "https://compliancy-group.com/solara-hipaa-phishing-settlement/"
    ],
    "confidence_notes": "High confidence. HHS.gov OCR settlement notice confirms facts and penalty amounts. Class action settlement confirmed by court records.",
    "sources_used": [
      "HHS.gov official OCR settlement",
      "HIPAA Journal",
      "Top Class Actions",
      "Compliancy Group"
    ],
    "id": "INC-00054",
    "year": 2019,
    "lat": 32.6400541,
    "lng": -117.084195,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Springhill Medical Center",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AL",
    "hq_city": "Mobile",
    "hq_county": "Mobile",
    "discovery_date": "2019-07-16",
    "disclosure_date": "2019-08-05",
    "executive_summary": "In July 2019, Springhill Medical Center in Mobile, Alabama experienced a ransomware attack that knocked out its computer systems for approximately eight days. The attack disrupted EHR and clinical monitoring systems at the hospital. A lawsuit filed in 2021 alleged that a baby, Nicko Silar, died in July 2019 due to complications that went undetected in part because nursing staff could not access normal EHR monitoring tools during the ransomware outage. If proved, this would represent the first alleged ransomware-linked patient death in the United States. The case (filed in Alabama state court) settled confidentially. The hospital did not publicly confirm ransomware as the cause but acknowledged a network outage affecting IT systems.",
    "attack_type": "Ransomware / System Outage",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "AL: Not separately reported",
    "financial_impact": "Confidential settlement reached in wrongful death lawsuit (Silar v. Springhill Medical Center). Settlement amount not disclosed.",
    "operational_impact": "Hospital IT/EHR systems offline for approximately 8 days. Clinical monitoring disrupted. Alleged link to neonatal death (Nicko Silar) filed in Alabama state court \u2014 first documented legal allegation of ransomware-linked patient death in U.S. history.",
    "remediation_disclosed": "Systems restored over approximately 8 days. No public statement confirming ransomware. Wrongful death lawsuit settled confidentially.",
    "primary_source_url": "https://www.wired.com/story/ransomware-hall-of-shame-springhill/",
    "secondary_source_urls": [
      "https://www.propublica.org/article/springhill-medical-center-ransomware-patients-lawsuit",
      "https://healthitsecurity.com/news/springhill-medical-center-ransomware-patient-death-allegation"
    ],
    "confidence_notes": "Moderate confidence on ransomware link \u2014 hospital did not publicly confirm. Wrongful death allegation documented in court filings and Wired, ProPublica reporting. Settlement terms sealed. PHI count not separately reported to HHS OCR.",
    "sources_used": [
      "Wired",
      "ProPublica",
      "Health IT Security"
    ],
    "id": "INC-00055",
    "year": 2019,
    "lat": 30.6954,
    "lng": -88.0399,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UAB Medicine (University of Alabama at Birmingham)",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Birmingham",
    "hq_county": "Jefferson",
    "discovery_date": "2019-08-07",
    "disclosure_date": "2019-10-04",
    "executive_summary": "UAB Medicine employees fell victim to a business email compromise / phishing attack on August 7, 2019. Hackers posed as an executive requesting completion of a business survey and obtained employee credentials, gaining access to email accounts and the payroll system. UAB prevented all payroll diversion attempts. The exposed email accounts contained PHI of 19,557 patients.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 19557,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Attempted payroll fraud prevented; no confirmed financial loss",
    "operational_impact": "Email accounts compromised; payroll system accessed but diversion prevented; PHI potentially viewed",
    "remediation_disclosed": "Affected accounts secured; passwords reset; MFA implemented for email; Kroll engaged for forensic investigation",
    "primary_source_url": "https://www.uab.edu/news/health-medicine/uab-medicine-notifies-patients-of-data-breach",
    "secondary_source_urls": [
      "https://compliancy-group.com/19500-uab-medicine-patients-affected-by-healthcare-phishing-attack/",
      "https://www.healthcareitnews.com/news/alabama-hospital-system-dch-pays-restore-systems-after-ransomware-attack"
    ],
    "confidence_notes": "High confidence \u2014 UAB Medicine official notification, HIPAA Journal, Compliancy Group coverage.",
    "sources_used": [
      "UAB Medicine Official Notice",
      "Compliancy Group",
      "Healthcare IT News"
    ],
    "id": "INC-00056",
    "year": 2019,
    "lat": 33.5186,
    "lng": -86.8104,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UW Medicine (University of Washington Medicine)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2018-12-26",
    "disclosure_date": "2019-02-20",
    "executive_summary": "A misconfigured server at UW Medicine exposed an internal database to public internet indexing from December 4 to December 26, 2018, affecting 974,000 patients. The error was discovered when a patient found their own data in a Google search result. Exposed files contained patient names, medical record numbers, and regulatory-disclosure data. No Social Security numbers, financial data, or medical records were exposed. UW Medicine worked with Google to remove cached files by January 10, 2019. A class-action lawsuit was filed in early 2020.",
    "attack_type": "Misconfiguration / Unauthorized Exposure",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "N/A (internal misconfiguration)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 974000,
    "residents_affected_in_state": "Not separately reported (UW Medicine primarily serves WA)",
    "financial_impact": "Not publicly disclosed; $750,000 HIPAA settlement in 2015 for prior breach (separate incident)",
    "operational_impact": "Patient data publicly accessible via Google for 22 days",
    "remediation_disclosed": "Server misconfiguration corrected; Google cache cleared; additional security controls implemented",
    "primary_source_url": "https://ecfirst.com/misconfiguration-leads-to-major-health-data-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/uw-medicine-faces-class-action-lawsuit-over-974000-record-data-breach/",
      "https://www.infosecurity-magazine.com/news/uw-medicine-facing-breach-lawsuit/"
    ],
    "confidence_notes": "Reported to HHS OCR; breach occurred Dec 2018, discovered/disclosed 2019; incident falls within the 2019-2026 reporting window",
    "sources_used": [
      "ECFirst",
      "HIPAA Journal",
      "Infosecurity Magazine"
    ],
    "id": "INC-00057",
    "year": 2019,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Wisconsin Diagnostic Laboratories (AMCA breach)",
    "organization_type": "Clinical Laboratory",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "WI",
    "hq_city": "Milwaukee",
    "hq_county": "Milwaukee",
    "discovery_date": "2019-05-01",
    "disclosure_date": "2019-07-01",
    "executive_summary": "Wisconsin Diagnostic Laboratories (WDL), a Milwaukee, Wisconsin-based clinical laboratory, was one of 24 healthcare organizations affected by the 2019 American Medical Collection Agency (AMCA) data breach. AMCA, a third-party billing collections vendor used by WDL, had its payment portal hacked from approximately August 2018 through March 2019. Approximately 114,985 WDL patients had their data exposed, including names, addresses, phone numbers, dates of birth, payment card and banking information, Social Security numbers, and medical information collected during billing interactions.",
    "attack_type": "Third-Party Vendor Breach (AMCA payment portal hacking)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 114985,
    "residents_affected_in_state": "Wisconsin residents primarily",
    "financial_impact": "Not separately disclosed; AMCA filed for bankruptcy",
    "operational_impact": "Patient payment and medical data exposed via third-party AMCA systems",
    "remediation_disclosed": "Yes \u2014 patients notified per HIPAA breach notification; AMCA systems taken offline",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [
      "https://firecompass.com/american-medical-collection-agency-amca-data-breach-why-it-happened-what-can-you-learn-24-million-customers-affected/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal breach statistics table lists Wisconsin Diagnostic Laboratories with 114,985 records in the AMCA breach.",
    "sources_used": [
      "HIPAA Journal",
      "FireCompass",
      "HHS OCR (contextual)"
    ],
    "id": "INC-00058",
    "year": 2019,
    "lat": 43.0389,
    "lng": -87.9065,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "ZOLL Services LLC (2019 breach)",
    "organization_type": "Healthcare Provider / Medical Device",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Chelmsford",
    "hq_county": "Middlesex",
    "discovery_date": "2019-02-21",
    "disclosure_date": "2019-03-08",
    "executive_summary": "ZOLL Medical Corporation reported a data breach in March 2019 that occurred during routine server migration. The breach compromised medical and personal data of 277,319 patients who used or were considered for ZOLL's LifeVest wearable cardioverter defibrillator. This was ZOLL's first major breach, followed by a second larger breach in 2023.",
    "attack_type": "Hacking/IT Incident (during server migration)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 277319,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "277K LifeVest patient records compromised",
    "remediation_disclosed": "HHS OCR breach filed; affected individuals notified",
    "primary_source_url": "https://milberg.com/news/zoll-data-breach-lawsuit/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach report; Milberg class action references earlier 2019 breach",
    "sources_used": [
      "Milberg"
    ],
    "id": "INC-00059",
    "year": 2019,
    "lat": 42.5968617,
    "lng": -71.3517602,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ZOLL Services LLC (2019 server migration breach)",
    "organization_type": "Healthcare Provider / Medical Device",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Chelmsford",
    "hq_county": "Middlesex",
    "discovery_date": "2019-02-01",
    "disclosure_date": "2019-03-11",
    "executive_summary": "ZOLL Medical Corporation reported a 2019 breach arising from a routine email server migration that exposed the medical and personal data of 277,319 LifeVest wearable defibrillator patients. This is distinct from the 2023 breach. PHI exposed included names, addresses, DOBs, medical device-related health information, and some SSNs.",
    "attack_type": "Hacking/IT Incident (during server migration)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 277319,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "277K LifeVest patient records compromised",
    "remediation_disclosed": "HHS OCR breach filed; affected individuals notified; security practices improved",
    "primary_source_url": "https://milberg.com/news/zoll-data-breach-lawsuit/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach report; Milberg references as first of two ZOLL breaches; 2019 dates confirmed",
    "sources_used": [
      "Milberg"
    ],
    "id": "INC-00060",
    "year": 2019,
    "lat": 42.5968617,
    "lng": -71.3517602,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Advocate Aurora Health \u2014 2020 Employee HR Phishing",
    "organization_type": "Nonprofit Integrated Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WI",
    "hq_city": "Downers Grove (IL) / Milwaukee (WI)",
    "hq_county": "DuPage County (IL) / Milwaukee County (WI)",
    "discovery_date": "2020-01-09",
    "disclosure_date": "2020-02-20",
    "executive_summary": "Advocate Aurora Health discovered on January 9, 2020 that unauthorized individuals had gained temporary access to its human resources system through an email phishing campaign. Employee credentials were captured via a phishing link clicked by one or more staff members, allowing the intruder to access HR data. The breach affected current and former employees primarily at Wisconsin Aurora locations, exposing Social Security numbers, bank account information used for direct deposit, dates of birth, and home addresses. This is a separate incident from the 2022 tracking pixel breach (MW-006). Employee notifications were sent in February 2020 and credit monitoring was offered.",
    "attack_type": "Phishing / HR System Unauthorized Access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly quantified \u2014 all current and some former Advocate Aurora Wisconsin employees",
    "residents_affected_in_state": "Wisconsin (and Illinois) employees",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "HR system temporarily compromised; employee financial information (direct deposit) potentially at risk",
    "remediation_disclosed": "Yes \u2014 credentials changed, intruder locked out on discovery, federal/state law enforcement notified, credit monitoring offered, enhanced security measures",
    "primary_source_url": "https://www.tmj4.com/news/local-news/current-former-advocate-aurora-health-employees-personal-information-accessed-in-phishing-scheme",
    "secondary_source_urls": [
      "https://www.fox6now.com/news/advocate-aurora-healths-hr-system-was-victim-to-email-phishing-campaign",
      "https://wtmj.com/news/2020/02/20/phishing-scheme-compromised-personal-info-for-employees-former-workers-at-advocate-aurora-health/"
    ],
    "confidence_notes": "Medium confidence. Local TV reporting (TMJ4, FOX6, WTMJ) confirmed incident. Number of employees affected not publicly disclosed.",
    "sources_used": [
      "TMJ4",
      "FOX6 Milwaukee",
      "WTMJ Radio",
      "Advocate Aurora Health statement"
    ],
    "id": "INC-00061",
    "year": 2020,
    "geocode_note": "Exact city not resolved; placed at WI state centroid.",
    "lat": 43.910433879080756,
    "lng": -89.94675865798189,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Allina Health (via Blackbaud breach)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2020-07-16",
    "disclosure_date": "2020-09-15",
    "executive_summary": "Allina Health was impacted by the Blackbaud ransomware attack (Feb\u2013June 2020) affecting its charitable foundation's donor database. More than 200,000 patients and donors were notified. The breach exposed names, addresses, and potentially dates of birth, dates of care, and names of doctors and departments visited. A second Allina-related breach occurred in early 2024 (former employee improper access to 715 patient records). Additionally, a Navvis breach in 2023 also affected Allina Health records (part of the SSM/Navvis incident).",
    "attack_type": "Ransomware (Third-Party Vendor \u2014 Blackbaud)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Blackbaud breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 200000,
    "residents_affected_in_state": 200000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No clinical disruption; donor/patient database backup exposed",
    "remediation_disclosed": "Yes \u2014 Blackbaud notified clients; Allina issued notifications September 2020",
    "primary_source_url": "https://seclists.org/dataloss/2020/q3/217",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for Blackbaud event. Victim count from Star Tribune/seclists reporting.",
    "sources_used": [
      "Risk Based Security/Star Tribune via seclists"
    ],
    "id": "INC-00062",
    "year": 2020,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Avalon Healthcare Management (Avalon Health Care Group)",
    "organization_type": "Healthcare Provider (Skilled Nursing / Senior Living Facilities)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2019-07-01",
    "disclosure_date": "2020-05-01",
    "executive_summary": "In July 2019, an employee at Avalon Healthcare Management (part of Avalon Health Care Group, which operates skilled nursing, therapy, senior living, and assisted living facilities in six states including Oregon) fell victim to a phishing scam. A scammer gained access to the employee's email account and may have accessed personal and protected health information of approximately 14,500 employees and patients. Compromised data included names, addresses, Social Security numbers, dates of birth, driver's license numbers, medical treatment information, and some financial information. Avalon delayed notification for approximately 10 months \u2014 a violation of Oregon's 45-day notification requirement. The Oregon and Utah Attorneys General investigated and announced a $200,000 joint settlement in December 2022, with Oregon receiving $100,000.",
    "attack_type": "Phishing / Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown phishing actor",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14500,
    "residents_affected_in_state": 1649,
    "financial_impact": "$200,000 joint settlement between OR and UT AGs (Dec 2022); OR received $100,000",
    "operational_impact": "Email account containing PHI compromised; 10-month notification delay violated OR law",
    "remediation_disclosed": "MFA implemented; email filtering; annual security training; incident response plan developed; compliance monitoring",
    "primary_source_url": "https://www.naag.org/wp-content/uploads/2025/07/2022.12.27-OR-Press-Release.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/avalon-healthcare-settles-hipaa-case-with-oregon-and-utah-state-ags-and-pays-200000-penalty/",
      "https://www.bankinfosecurity.com/avalon-breach-a-20845"
    ],
    "confidence_notes": "High confidence: Oregon AG press release confirms settlement; HIPAA Journal corroborates all key details; NAAG press release is primary source",
    "sources_used": [
      "National Association of Attorneys General (OR AG Press Release)",
      "HIPAA Journal",
      "BankInfoSecurity"
    ],
    "id": "INC-00063",
    "year": 2020,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Aveanna Healthcare (Massachusetts breach)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Atlanta",
    "hq_county": "Fulton",
    "discovery_date": "2019-07-09",
    "disclosure_date": "2020-01-02",
    "executive_summary": "Aveanna Healthcare, a pediatric home healthcare company, suffered phishing attacks in 2019 that compromised 166,000 individual patient records, including approximately 4,000 Massachusetts residents. The Massachusetts AG fined Aveanna $425,000 for lack of safeguards including multi-factor authentication and security awareness training. The attacks resulted in unauthorized access to employee email accounts.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 166000,
    "residents_affected_in_state": 4000,
    "financial_impact": "$425,000 MA AG fine",
    "operational_impact": "166K patient records compromised across multiple states",
    "remediation_disclosed": "$425K MA AG settlement; corrective action plan; MFA required; security training mandated",
    "primary_source_url": "https://www.hipaajournal.com/november-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "MA AG settlement confirmed 2022; phishing attack in 2019; included due to MA AG enforcement",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00064",
    "year": 2020,
    "lat": 33.7544657,
    "lng": -84.3898151,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "BJC HealthCare",
    "organization_type": "Nonprofit Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "St. Louis",
    "hq_county": "St. Louis",
    "discovery_date": "2020-03-06",
    "disclosure_date": "2020-05-05",
    "executive_summary": "A phishing attack compromised three BJC HealthCare employee email accounts on March 6, 2020 (detected same day). The breached accounts contained PHI of 287,873 patients of 19 affiliated hospitals, including names, DOBs, health insurance information, SSNs, driver's license numbers, medical record numbers, and clinical information. BJC settled a class action lawsuit in 2022, agreeing to spend $2.7 million implementing MFA and email security. BJC also suffered a second breach in March 2022 when unauthorized parties accessed physician email accounts affecting ~500+ individuals.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 287873,
    "residents_affected_in_state": "Primarily Missouri residents",
    "financial_impact": "$2.7 million MFA implementation commitment as settlement remedy; up to $250 per affected patient",
    "operational_impact": "Email system breach; PHI potentially accessed; no EHR breach reported",
    "remediation_disclosed": "Yes \u2014 accounts secured; patients notified May 2020; MFA implemented as settlement remedy",
    "primary_source_url": "https://www.hipaajournal.com/bjc-healthcare-settles-data-breach-lawsuit-stemming-from-2020-phishing-attack/",
    "secondary_source_urls": [
      "https://www.scworld.com/analysis/bjc-health-to-spend-2-7m-on-email-mfa-access-to-settle-breach-affecting-288k-patients"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, settlement coverage, SC World reporting.",
    "sources_used": [
      "HIPAA Journal",
      "SC World"
    ],
    "id": "INC-00065",
    "year": 2020,
    "lat": 38.627,
    "lng": -90.1994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "BST & Co. CPAs LLP (Albany NY - healthcare client breach)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "Albany",
    "hq_county": "Albany",
    "discovery_date": "2019-11-01",
    "disclosure_date": "2020-01-01",
    "executive_summary": "BST & Co. CPAs LLP, an Albany, New York accounting firm serving healthcare organizations as a HIPAA business associate, suffered a ransomware attack affecting healthcare client data. HHS OCR reached a $175,000 settlement in 2025 addressing HIPAA security rule deficiencies. The breach exposed protected health information of healthcare organization clients.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$175,000 HHS OCR settlement (2025)",
    "operational_impact": "Healthcare client PHI compromised via accounting firm BA",
    "remediation_disclosed": "HHS OCR settlement with corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2025 OCR penalties table confirms $175K settlement; NY-based healthcare BA",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00066",
    "year": 2020,
    "lat": 42.6526,
    "lng": -73.7562,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Baystate Health (MA - email compromise)",
    "organization_type": "Health System",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MA",
    "hq_city": "Springfield",
    "hq_county": "Hampden",
    "discovery_date": "2019-11-01",
    "disclosure_date": "2020-02-01",
    "executive_summary": "Baystate Health, a Springfield, Massachusetts health system operating Baystate Medical Center and multiple community hospitals, reported a data security incident in 2019-2020 involving unauthorized access to employee email accounts. Patient protected health information was potentially exposed at this western Massachusetts academic health system.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Western MA multi-hospital patient PHI potentially compromised via email",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2019-2020; major MA health system; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00067",
    "year": 2020,
    "lat": 42.1015,
    "lng": -72.5898,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Beaumont Health",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Southfield",
    "hq_county": "Oakland",
    "discovery_date": "2020-03-29",
    "disclosure_date": "2020-04-17",
    "executive_summary": "Beaumont Health, Michigan's largest health system, discovered on March 29, 2020 that employee email accounts had been accessed by unauthorized individuals between May 23 and June 3, 2019 \u2014 nearly 10 months earlier. A phishing email attack compromised employee email credentials. The breached accounts contained PHI of approximately 112,000 individuals (nearly 5% of Beaumont's 2.3 million patients), including names, DOBs, diagnoses, treatment information, and for ~460 patients, SSNs and financial account information.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 112000,
    "residents_affected_in_state": "Primarily Michigan residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal operational disruption; patient notification required; credit monitoring offered to ~460 with financial data exposed",
    "remediation_disclosed": "Yes \u2014 compromised accounts secured; patients notified; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/beaumont-health-notifies-112000-patients-about-may-2019-data-breach/",
    "secondary_source_urls": [
      "https://bridgemi.com/business-watch/beaumont-health-security-breach-puts-personal-information-112000-risk/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, Beaumont press release, Bridge Michigan reporting.",
    "sources_used": [
      "HIPAA Journal",
      "Bridge Michigan"
    ],
    "id": "INC-00068",
    "year": 2020,
    "lat": 42.4733689,
    "lng": -83.2218731,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Beaumont Health \u2014 2020 Employee Disclosure Incident",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Southfield",
    "hq_county": "Oakland",
    "discovery_date": "2020-01-01",
    "disclosure_date": "2020-01-31",
    "executive_summary": "Beaumont Health discovered in early 2020 that a former employee had been improperly accessing patient records from February 2017 through October 2019 and sharing information with an individual working on behalf of a personal injury attorney. Approximately 1,100-1,200 patients had sensitive information including names, addresses, DOBs, SSNs, financial/credit card numbers, banking information, driver's license records, and medical records transferred to a personal injury law firm. Beaumont was alerted by the Michigan Attorney Grievance Commission investigating a lawyer.",
    "attack_type": "Insider Unauthorized Access / Data Theft",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Beaumont employee (terminated) acting with personal injury attorney",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1182,
    "residents_affected_in_state": "Michigan patients",
    "financial_impact": "Not publicly disclosed; criminal investigation initiated",
    "operational_impact": "Patient data shared with personal injury law firm for solicitation purposes",
    "remediation_disclosed": "Yes \u2014 employee terminated; police investigation; notifications sent January 2020",
    "primary_source_url": "https://buckfirelaw.com/case-types/medical-malpractice/hospital-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Buckfire & Buckfire Michigan law firm, Healthcare IT News.",
    "sources_used": [
      "Buckfire & Buckfire Law"
    ],
    "id": "INC-00069",
    "year": 2020,
    "lat": 42.4733689,
    "lng": -83.2218731,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Blackbaud (affecting Allina Health, Children's Minnesota, Regions Hospital \u2014 2020)",
    "organization_type": "Nonprofit Fundraising Software Vendor (Business Associate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "SC",
    "hq_city": "Charleston SC (serves Midwest nonprofit hospitals)",
    "hq_county": "Charleston County SC",
    "discovery_date": "2020-05-14",
    "disclosure_date": "2020-07-16",
    "executive_summary": "Blackbaud Inc., a nonprofit fundraising and CRM software company, suffered a ransomware attack in May 2020 that affected hundreds of its healthcare and nonprofit clients, including multiple Midwest healthcare systems. The attacker had access to Blackbaud's self-hosted environment from February 7\u2013May 20, 2020 and stole backup data before deploying ransomware. Blackbaud paid the ransom and received confirmation the data was deleted (subsequently unconfirmed by regulators). Midwest healthcare organizations affected include: Allina Health (MN, ~200,000 donors), Children's Minnesota (MN, ~160,000), Regions Hospital/Gillette Children's (MN, ~52,795), Trinity Health (MI), and numerous other Midwest healthcare systems with philanthropy programs. The FTC fined Blackbaud $6.75M in 2024. This entry documents the Blackbaud breach as the common vendor event affecting multiple Midwest systems.",
    "attack_type": "Ransomware / Data Exfiltration (Blackbaud fundraising database)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 200000,
    "residents_affected_in_state": "Minnesota Michigan Wisconsin Ohio Indiana Illinois residents",
    "financial_impact": "Blackbaud paid undisclosed ransom; $6.75M FTC settlement (2024); $49.5M state AG settlement (2023); multiple class actions",
    "operational_impact": "Philanthropy and donor databases compromised across hundreds of Blackbaud clients; no clinical operations disrupted",
    "remediation_disclosed": "Yes \u2014 Blackbaud confirmed data deletion (later disputed); FTC and 49-state AG settlements; security improvements mandated",
    "primary_source_url": "https://seclists.org/dataloss/2020/q3/217",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/blackbaud-ransomware-attack-data-breach/"
    ],
    "confidence_notes": "High confidence. Blackbaud breach extensively documented; Midwest hospital victims confirmed in individual organizational disclosures. Separate Midwest-specific entries exist for Allina (MW-025), Children's MN (MW-024), Regions Hospital (MW-049), Trinity Health (MW-019).",
    "sources_used": [
      "Seclists DataLoss",
      "HIPAA Journal",
      "FTC"
    ],
    "id": "INC-00070",
    "year": 2020,
    "lat": 32.792293,
    "lng": -79.9408832,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Blackbaud \u2014 Alaska healthcare organizations (multi-state)",
    "organization_type": "Business Associate (Cloud Software for Healthcare/Nonprofits)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "AK",
    "hq_city": "Charleston",
    "hq_county": "Unknown",
    "discovery_date": "2020-05-14",
    "disclosure_date": "2020-07-16",
    "executive_summary": "Blackbaud, a cloud software provider used by thousands of healthcare, education, and nonprofit organizations, suffered a ransomware attack in May 2020 in which an unauthorized party accessed and exfiltrated backup data from multiple client databases. The attacker removed a subset of Blackbaud's backup environment and demanded a ransom, which Blackbaud paid. Alaska AG Treg Taylor participated in a 49-state $49.5 million settlement announced October 5, 2023. Alaska received $358,925 from the settlement. Alaskan healthcare organizations using Blackbaud \u2014 including hospitals and health systems \u2014 had donor and constituent data exposed. The Blackbaud breach is classified as a hacking/IT incident under HIPAA.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown ransomware operator",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5500000,
    "residents_affected_in_state": "Alaska healthcare/nonprofit clients and their donors/constituents",
    "financial_impact": "$49.5 million national AG settlement (Oct 2023); Alaska received $358,925",
    "operational_impact": "Healthcare client databases compromised; ransom paid; delayed and incomplete notifications to clients and affected individuals",
    "remediation_disclosed": "Blackbaud agreed to overhaul data security and breach notification practices; ransom paid to destroy stolen data (unverified); corrective action plan",
    "primary_source_url": "https://law.alaska.gov/press/releases/2023/100523-Blackbaud.html",
    "secondary_source_urls": [
      "https://www.adventisthealthcare.com/news/2020/informs-patients-affected-by-blackbaud-data-breach/"
    ],
    "confidence_notes": "Moderate confidence: Alaska AG press release confirms AK participation in Blackbaud settlement; specific Alaskan healthcare organizations affected not individually named in available sources; included as AK AG enforcement action",
    "sources_used": [
      "Alaska AG official press release",
      "Adventist HealthCare (Blackbaud victim example)"
    ],
    "id": "INC-00071",
    "year": 2020,
    "lat": 32.7884363,
    "lng": -79.9399309,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Blackbaud, Inc. (Healthcare Sector Impact)",
    "organization_type": "BA/Vendor (Cloud Data Services / Fundraising Software)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "SC",
    "hq_city": "Charleston",
    "hq_county": "Charleston",
    "discovery_date": "2020-05-14",
    "disclosure_date": "2020-07-16",
    "executive_summary": "In May 2020, Blackbaud, a cloud software company providing fundraising and data management services to nonprofits and healthcare systems, discovered that ransomware attackers had exfiltrated a subset of data from its self-hosted environment before Blackbaud paid the ransom and confirmed the data was destroyed. Blackbaud delayed public disclosure until July 2020. Healthcare sector victims included dozens of hospitals and health systems using Blackbaud for donor management, including Inova Health System, Atrium Health, Spectrum Health, Northwestern Memorial Hospital, and many others \u2014 collectively impacting millions of donor/patient records. The FTC reached a settlement in 2024 prohibiting Blackbaud from misrepresenting its security practices and requiring a comprehensive security program. The SEC fined Blackbaud $3 million in 2023 for misleading investors about the breach's scope. A 49-state AG coalition reached a $49.5 million settlement in October 2023.",
    "attack_type": "Ransomware / Data Exfiltration (ransom paid; attacker claimed deletion)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ransom paid by Blackbaud)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13000000,
    "residents_affected_in_state": 49,
    "financial_impact": "$49.5M 49-state AG settlement (October 2023). $3M SEC fine (2023) for misleading investors. FTC settlement (2024). Class action settlements. Total regulatory and legal costs exceed $100M.",
    "operational_impact": "Pure data theft. No clinical disruption at Blackbaud. Downstream healthcare organizations experienced unauthorized access to donor/patient data. Healthcare clients included Inova, Atrium, Spectrum, Northwestern Memorial, and many others.",
    "remediation_disclosed": "Ransom paid; attacker claimed deletion of stolen data (unverified). Blackbaud enhanced security post-breach. SEC investigation for misleading disclosures. FTC consent order requiring comprehensive security program. 49-state AG settlement requiring security overhaul.",
    "primary_source_url": "https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-takes-action-against-blackbaud-lax-security-practices-company-allowed-breach-expose-millions",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/blackbaud-data-breach/",
      "https://www.sec.gov/news/press-release/2023-199"
    ],
    "confidence_notes": "High confidence. FTC consent order, SEC fine, and 49-state AG settlement all public record. Healthcare sector victim count estimated at 13M based on Blackbaud's self-reported global breach exposure; exact healthcare count not separately broken out.",
    "sources_used": [
      "FTC press release",
      "HIPAA Journal",
      "SEC press release"
    ],
    "id": "INC-00072",
    "year": 2020,
    "lat": 32.7765,
    "lng": -79.9311,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Children's Hospital Colorado",
    "organization_type": "Healthcare Provider (Children's Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CO",
    "hq_city": "Aurora",
    "hq_county": "Arapahoe",
    "discovery_date": "2017-07-11",
    "disclosure_date": "2020-07-27",
    "executive_summary": "Children's Hospital Colorado experienced two separate phishing-related data breaches: the first in September 2017 (compromising one email account with PHI of 3,370 individuals) and the second in April 2020 (three email accounts compromised via social engineering of MFA, affecting 10,840 individuals). OCR investigated both and found HIPAA Privacy and Security Rule violations including MFA failures and inadequate risk analysis. HHS imposed a $548,265 civil monetary penalty in December 2024.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing / Email Account Compromise (x2 incidents)",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown (German IP address attacker in 2020; US IP attacker)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14210,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$548,265 OCR civil monetary penalty (December 2024)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "MFA improvements; risk analysis conducted (Feb 2021); $548,265 penalty paid",
    "primary_source_url": "https://www.hipaajournal.com/ocr-phishing-investigation-hipaa-training-failure-colorado-childrens-hospital/",
    "secondary_source_urls": [
      "https://www.cpr.org/2024/12/09/childrens-hospital-colorado-data-breach-fine-privacy-rules/",
      "https://www.hunton.com/privacy-and-cybersecurity-law-blog/hhs-imposes-penalty-against-childrens-hospital-for-violations-of-hipaa-privacy-rule-and-security-rule"
    ],
    "confidence_notes": "High confidence; OCR official action; CPR Colorado documented; $548,265 penalty confirmed",
    "sources_used": [
      "HIPAA Journal, Colorado Public Radio, Hunton Andrews Kurth"
    ],
    "id": "INC-00073",
    "year": 2020,
    "lat": 39.7294,
    "lng": -104.8319,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Children's Minnesota (via Blackbaud breach)",
    "organization_type": "Pediatric Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2020-07-16",
    "disclosure_date": "2020-09-15",
    "executive_summary": "Children's Minnesota was affected by the Blackbaud ransomware attack (Feb\u2013June 2020) affecting its charitable foundation's fundraising database. More than 160,000 families were notified. Exposed data included full names, DOBs, addresses, phone numbers, ages, genders, medical record numbers, dates and locations of treatment, names of treating doctors, and insurance status. The breach constituted Minnesota's second-largest healthcare data breach at the time.",
    "attack_type": "Ransomware (Third-Party Vendor \u2014 Blackbaud)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Blackbaud breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 160000,
    "residents_affected_in_state": 160000,
    "financial_impact": "Not publicly disclosed for Children's MN specifically",
    "operational_impact": "No clinical operations disrupted; donor/patient database backup exposed",
    "remediation_disclosed": "Yes \u2014 Blackbaud paid ransom for deletion confirmation; notifications issued September 2020",
    "primary_source_url": "https://seclists.org/dataloss/2020/q3/217",
    "secondary_source_urls": [
      "https://kffhealthnews.org/morning-breakout/childrens-hospitals-in-texas-minnesota-report-data-breaches/"
    ],
    "confidence_notes": "High confidence. Star Tribune/seclists breach summary, KFF Health News reporting.",
    "sources_used": [
      "Risk Based Security/Star Tribune via seclists",
      "KFF Health News"
    ],
    "id": "INC-00074",
    "year": 2020,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "ChristianaCare Health System (DE - email compromise 2020)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "DE",
    "hq_city": "Wilmington",
    "hq_county": "New Castle",
    "discovery_date": "2020-03-01",
    "disclosure_date": "2020-07-01",
    "executive_summary": "ChristianaCare Health System, Delaware's largest health system, reported an email account compromise in 2020 in which unauthorized actors gained access to employee email accounts containing patient health information. This is separate from the later 2025 Oracle Health breach. The 2020 breach affected an undisclosed number of patients receiving care at ChristianaCare's hospitals and outpatient facilities.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "DE health system patient PHI compromised via employee email accounts",
    "remediation_disclosed": "HHS OCR and patients notified; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2020; DE largest health system; note distinct from 2025 Oracle Health breach already in dataset",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00075",
    "year": 2020,
    "lat": 39.7391,
    "lng": -75.5398,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Cone Health (Alamance Skin Center)",
    "organization_type": "Healthcare Provider (Dermatology/Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Burlington",
    "hq_county": "Alamance",
    "discovery_date": "2020-10-21",
    "disclosure_date": "2020-11-04",
    "executive_summary": "Alamance Skin Center, a Cone Health practice in Burlington, NC, was hit by a ransomware attack. Investigators determined no patient data was stolen (likely phishing or brute force attack vector) but patient data at the practice is unrecoverable. The attack demonstrates a ransomware incident without data exfiltration but with operational impact due to data loss.",
    "attack_type": "Ransomware (data destroyed, no exfiltration confirmed)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "All patient data at the practice rendered unrecoverable",
    "remediation_disclosed": "Forensic investigation conducted; Cone Health confirmed no data theft",
    "primary_source_url": "https://www.conehealth.com/news/news-search/2020-news-releases/cone-health-practice-hit-in-ransomwear-attack/",
    "secondary_source_urls": [
      "https://www.bitdefender.com/en-us/blog/hotforsecurity/health-practice-loses-patient-data-in-ransomware-attack-tells-clients-to-call-before-visiting"
    ],
    "confidence_notes": "Cone Health's own press release is primary source. Patient count not disclosed. Bitdefender provides additional reporting.",
    "sources_used": [
      "Cone Health (official website)",
      "Bitdefender"
    ],
    "id": "INC-00076",
    "year": 2020,
    "lat": 36.0956918,
    "lng": -79.4377991,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Dental Care Alliance, LLC",
    "organization_type": "Business Associate (Dental Support Organization)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Sarasota",
    "hq_county": "Sarasota",
    "discovery_date": "2020-10-11",
    "disclosure_date": "2020-12-07",
    "executive_summary": "Sarasota-based Dental Care Alliance (320+ affiliated dental practices, 20 states) experienced unauthorized access to its network between September 18 and October 13, 2020. Attackers accessed confidential files of patients and employees. The breach initially reported 1,004,304 individuals; later amended to 1,723,375. Patient data included names, diagnoses, treatment info, account numbers, and payment card data. No confirmed evidence of data theft, but a $3 million class action settlement was reached.",
    "attack_type": "Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1723375,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3 million class action settlement",
    "operational_impact": "Confidential files accessed; no confirmed data exfiltration",
    "remediation_disclosed": "Network secured; forensic investigation; notifications issued December 2020; $3M settlement",
    "primary_source_url": "https://www.hipaajournal.com/dental-care-alliance-settles-class-action-data-breach-lawsuit-for-3-million/",
    "secondary_source_urls": [
      "https://www.bankinfosecurity.com/dca-settlement-a-19700"
    ],
    "confidence_notes": "HHS OCR lists 1,723,375 (amended figure). Settlement confirmed by BankInfoSecurity and HIPAA Journal.",
    "sources_used": [
      "HIPAA Journal",
      "BankInfoSecurity"
    ],
    "id": "INC-00077",
    "year": 2020,
    "lat": 27.3364,
    "lng": -82.5307,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "EyeMed Vision Care (Oregon patients \u2014 multistate AG settlement)",
    "organization_type": "Health Plan / Vision Benefits Provider",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Mason",
    "hq_county": "Unknown",
    "discovery_date": "2020-06-24",
    "disclosure_date": "2020-09-01",
    "executive_summary": "EyeMed Vision Care, an Ohio-based vision benefits provider serving customers nationwide including Oregon, suffered a data breach in June 2020 when an unauthorized party accessed an EyeMed email account and obtained personal information of approximately 2.1 million individuals. Oregon was one of four states (alongside New Jersey, Florida, and Pennsylvania) that participated in a joint multistate attorney general settlement announced in May 2023. Oregon received a portion of the $2.5 million multistate settlement. The breach involved names, contact details, dates of birth, health insurance account numbers, Medicaid/Medicare numbers, driver's license numbers, and other government ID numbers. EyeMed also paid $4.5 million to the New York AG in 2021 for NY residents.",
    "attack_type": "Phishing / Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2100000,
    "residents_affected_in_state": 2100000,
    "financial_impact": "$2.5 million multistate AG settlement (OR, NJ, FL, PA); $4.5 million NY AG settlement (2021); $5 million class-action settlement (2024)",
    "operational_impact": "Email account containing PHI compromised; large volume of sensitive vision/health data exposed",
    "remediation_disclosed": "Enhanced access controls; multifactor authentication; employee security training; security assessments; data retention limits",
    "primary_source_url": "https://www.doj.state.or.us/media-home/news-media-releases/what-you-need-to-know-about-the-data-breach-at-the-nations-largest-health-insurer/",
    "secondary_source_urls": [
      "https://thehipaaetool.com/eyemeds-data-breach-cost-12-6-million/",
      "https://www.eyemeddatasettlement.com"
    ],
    "confidence_notes": "Moderate confidence: EyeMed HQ is in Ohio, but Oregon AG participated in multistate settlement; OR DOJ consumer page cited. This entry captures Oregon's enforcement role and impact on OR residents; underlying breach was national. EyeMed is an EssilorLuxottica subsidiary.",
    "sources_used": [
      "Oregon DOJ",
      "The HIPAA E-Tool",
      "EyeMed Data Settlement website"
    ],
    "id": "INC-00078",
    "year": 2020,
    "lat": 42.4766945,
    "lng": -121.401261,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "EyeMed Vision Care LLC",
    "organization_type": "Health Plan / Vision Benefits",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NY",
    "hq_city": "Mason",
    "hq_county": "Warren",
    "discovery_date": "2020-06-24",
    "disclosure_date": "2020-08-28",
    "executive_summary": "EyeMed Vision Care suffered a phishing attack in June 2020 that compromised a shared employee email account used for enrolling customers in vision insurance. Attackers had access for approximately one week, potentially exposing PHI and PII of consumers. The NY AG fined EyeMed $600,000 and the NYDFS imposed a $4.5 million penalty for cybersecurity violations. The breach affected approximately 2.1 million individuals.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2100000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$600,000 NY AG settlement; $4.5 million NYDFS fine",
    "operational_impact": "Shared email account compromised for ~1 week; PHI of 2.1M+ exposed",
    "remediation_disclosed": "Accounts secured; NYDFS settlement; NY AG settlement; comprehensive cybersecurity risk assessment required",
    "primary_source_url": "https://www.arnoldporter.com/en/perspectives/blogs/enforcement-edge/2022/11/nydfs-imposes-fine-eyemed-cybersecurity-violation",
    "secondary_source_urls": [
      "https://www.dataprotectionreport.com/2022/02/new-york-shield-act-600000-settlement/"
    ],
    "confidence_notes": "NYDFS settlement confirmed; NY AG settlement confirmed; multistate AG investigation",
    "sources_used": [
      "Arnold & Porter",
      "Data Protection Report"
    ],
    "id": "INC-00079",
    "year": 2020,
    "lat": 44.3929449,
    "lng": -73.4063312,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "GenRx Pharmacy",
    "organization_type": "Pharmacy",
    "organization_type_bucket": "Pharmacy",
    "state": "CA",
    "hq_city": "Scottsdale, AZ / CA operations",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2020-09-27",
    "disclosure_date": "2020-12-18",
    "executive_summary": "On September 28, 2020, GenRx found evidence of ransomware on our system and immediately began an investigation, including hiring independent information security and technology experts to assist with incident response and forensic investigation. In a ransomware attack, cybercriminals attempt to disrupt the business by locking the business out of its own data. During the ransomware attack against GenRx, we had full access to all data with unaffected backups, and we were able to maintain continuous business operations as we investigated. Together with forensic experts, GenRx terminated the cyber",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Forensic investigation conducted', 'Additional security measures implemented']",
    "primary_source_url": "https://oag.ca.gov/system/files/2020-12-18%20GenRx%20-%20Template%20Notice%20Letters.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00080",
    "year": 2020,
    "lat": 37.23110341911956,
    "lng": -120.70059113999737,
    "is_multistate": true,
    "hq_outside_state": "Scottsdale",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Hartford HealthCare",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "Hartford",
    "hq_county": "Hartford",
    "discovery_date": "2020-02-14",
    "disclosure_date": "2020-04-13",
    "executive_summary": "Hartford HealthCare disclosed that attackers compromised two employee email accounts between February 13-14, 2020 (Valentine's Day). Up to 2,651 patients may have been affected. Data exposed included names, DOBs, medical record numbers, clinical information, and health insurance information. For 23 patients, an insurance account number containing a SSN was accessed.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2651,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Two employee email accounts compromised; limited patient data exposure",
    "remediation_disclosed": "Accounts secured; all employees required to change passwords; malicious software disabled; HHS OCR report filed; 2-year credit monitoring for 23 patients with SSNs exposed",
    "primary_source_url": "https://www.infosecurity-magazine.com/news/hartford-healthcare-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Hartford HealthCare confirmed; Infosecurity Magazine reporting; OCR breach report",
    "sources_used": [
      "Infosecurity Magazine"
    ],
    "id": "INC-00081",
    "year": 2020,
    "lat": 41.7658,
    "lng": -72.6734,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Hawaii Pacific Health / Straub Medical Center (insider breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "City and County of Honolulu",
    "discovery_date": "2020-01-17",
    "disclosure_date": "2020-03-17",
    "executive_summary": "Hawaii Pacific Health discovered on January 17, 2020, that an employee of Straub Medical Center had been snooping on patient medical records without authorization for more than five years. Analysis of access logs revealed the employee first accessed patient records in November 2014 and continued undetected until January 2020. Over this period, the employee viewed the records of 3,772 patients across Hawaii Pacific Health's hospital network, including Straub Medical Center, Kapiolani Medical Center for Women & Children, Pali Momi Medical Center, and Wilcox Medical Center. The reason for accessing the records was determined to be likely curiosity, but data theft could not be ruled out. The employee was terminated, and all affected patients were notified by mail on March 17, 2020.",
    "attack_type": "Insider threat / Unauthorized access (snooping)",
    "attack_category": "Insider threat",
    "threat_actor_name": "Unnamed Hawaii Pacific Health employee",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 3772,
    "residents_affected_in_state": 3772,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient records viewed without authorization across four Hawaii Pacific Health hospitals; terminated employee",
    "remediation_disclosed": "Employee terminated; new access monitoring systems implemented; internal policies reviewed and updated; one year of free credit monitoring and identity restoration services offered",
    "primary_source_url": "https://www.hipaajournal.com/hawaii-pacific-health-discovers-5-year-insider-data-breach/",
    "secondary_source_urls": [
      "https://www.calhipaa.com/hawaii-pacific-healths-5-year-insider-data-breach/"
    ],
    "confidence_notes": "High confidence: HIPAA Journal confirmed all key details; breach involved unauthorized access to PHI (classified as hacking/IT incident by HHS OCR); employee snooping is a recognized HIPAA violation category",
    "sources_used": [
      "HIPAA Journal",
      "CalHIPAA"
    ],
    "id": "INC-00082",
    "year": 2020,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "INTEGRIS Baptist Medical Center, Inc.",
    "organization_type": "Hospital / Health System (Multistate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Oklahoma City, OK (multistate; CA residents affected)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2019-10-17",
    "disclosure_date": "2020-09-04",
    "executive_summary": "We immediately conducted a thorough search for the hard drive, but were unable to locate it. We were able to locate a backup copy of the hard drive, and as part of our investigation, we thoroughly analyzed the entire contents of the backup hard drive to determine the patient information contained on the missing hard drive. Our investigation determined that some of your information was stored on the hard drive, and included your name, Social S",
    "attack_type": "Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2842669,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered']",
    "primary_source_url": "https://oag.ca.gov/system/files/INTEGRIS%20Notification.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/integris-health-data-breach/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00083",
    "year": 2020,
    "lat": 36.24979829449949,
    "lng": -120.46535247822649,
    "is_multistate": true,
    "hq_outside_state": "Oklahoma City",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Inova Health System (via Blackbaud)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Falls Church",
    "hq_county": "Fairfax",
    "discovery_date": "2020-07-16",
    "disclosure_date": "2020-09-11",
    "executive_summary": "Falls Church, VA-based Inova Health System was among a dozen health systems affected by a ransomware attack on its fundraising software vendor Blackbaud. Blackbaud was breached between February 7 and May 20, 2020. Attackers stole a backup copy of donor and patient data. Blackbaud paid the ransom. Inova reported 1,045,270 individuals affected. Data was primarily demographic (names, addresses, DOBs, donation history). No SSNs or financial account data were affected.",
    "attack_type": "Supply-Chain Ransomware (Business Associate - Blackbaud)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1045270,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed (Blackbaud paid ransom)",
    "operational_impact": "Donor and patient demographic data stolen via vendor",
    "remediation_disclosed": "Blackbaud paid ransom; HHS OCR notified; investigation launched with cybersecurity experts",
    "primary_source_url": "https://www.hipaajournal.com/inova-health-system-says-1-05-million-individuals-impacted-by-blackbaud-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/tech/inova-health-system-hit-by-software-vendor-breach-impacting-1m-people"
    ],
    "confidence_notes": "HHS OCR lists 1,045,270 affected. Multiple reliable sources corroborate Blackbaud attack details.",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare"
    ],
    "id": "INC-00084",
    "year": 2020,
    "lat": 38.8823,
    "lng": -77.1711,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kaiser Health Plan, Southern California",
    "organization_type": "Health Plan / Integrated Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Oakland, CA",
    "hq_county": "Alameda County",
    "discovery_date": "2019-10-06",
    "disclosure_date": "2020-02-28",
    "executive_summary": "During a project to improve mailing addresses for correspondence with Southern California members, an error caused your former address to be temporarily used for one or more mailings to you between October 6 and December 20, 2019. The error was first recognized November 1, 2019 and we began an analysis to identify and correct the source of the problem. Your address was updated in our system on December 20, 2019. Correspondence mailed to your former address may have included appointment reminders, care reminders, surveys, referral letters, and Explanations of Benefits.",
    "attack_type": "Web Tracking / Data Exposure (Improper Disclosure)",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Member%20Notification%20Letter.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/kaiser-foundation-health-plan-data-breach/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00085",
    "year": 2020,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Lehigh Valley Physician Group (LVPG) - separate from LVHN ransomware",
    "organization_type": "Healthcare Provider (Physician Group)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Allentown",
    "hq_county": "Lehigh",
    "discovery_date": "2020-06-01",
    "disclosure_date": "2020-08-01",
    "executive_summary": "Lehigh Valley Physician Group (LVPG), affiliated with Lehigh Valley Health Network, reported a data security incident in 2020 involving unauthorized access to employee email accounts containing patient health information. This is separate from the major February 2023 ALPHV/BlackCat ransomware attack on LVHN. The 2020 email compromise affected an undisclosed number of patients.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI in employee email accounts compromised",
    "remediation_disclosed": "HHS OCR and patients notified; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2020; LVPG/LVHN affiliation confirmed; note distinct from major 2023 LVHN ransomware incident",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00086",
    "year": 2020,
    "lat": 40.6084,
    "lng": -75.4902,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Magellan Health (serving Iowa/Wisconsin/Midwest) \u2014 2020 Ransomware",
    "organization_type": "Managed Behavioral Healthcare / Health Insurance",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CT",
    "hq_city": "Avon CT (serves Midwest including Wisconsin Medicaid, Iowa behavioral health)",
    "hq_county": "Hartford County CT",
    "discovery_date": "2020-04-11",
    "disclosure_date": "2020-06-15",
    "executive_summary": "Magellan Health Inc., a managed behavioral healthcare company serving state Medicaid programs including Wisconsin and Iowa, was targeted in a ransomware attack discovered April 11, 2020. The attack began as a phishing attack impersonating a client, deployed five days before ransomware. Member/patient data potentially stolen included names, addresses, medical information, health insurance account information, member IDs, and some Social Security numbers. Wisconsin members (four Wisconsin residents specifically listed in DATCP archive) were among those affected. Magellan reported the breach to HHS OCR. Wisconsin DATCP documented Wisconsin resident exposure.",
    "attack_type": "Ransomware (preceded by social engineering phishing)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4,
    "residents_affected_in_state": "Wisconsin and Iowa residents among those affected nationally",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Managed care operations disrupted; behavioral health member data compromised; law enforcement and FBI engaged",
    "remediation_disclosed": "Yes \u2014 FBI notified, forensics engaged, additional security protocols implemented, members notified",
    "primary_source_url": "https://datcp.wi.gov/Pages/Programs_Services/DataBreachArchive.aspx",
    "secondary_source_urls": [
      "https://www.goanywhere.com/blog/the-top-10-healthcare-data-breaches-of-2020"
    ],
    "confidence_notes": "Medium confidence. Wisconsin DATCP archive lists Magellan Health 2020 incident. GoAnywhere identifies it as a top 2020 healthcare breach. Wisconsin and Iowa Medicaid managed care confirmed.",
    "sources_used": [
      "Wisconsin DATCP",
      "GoAnywhere/Fortra blog"
    ],
    "id": "INC-00087",
    "year": 2020,
    "lat": 41.5371076,
    "lng": -72.6247312,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Magellan Health, Inc.",
    "organization_type": "Health Plan / Managed Care",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "AZ",
    "hq_city": "Scottsdale",
    "hq_county": "Maricopa",
    "discovery_date": "2020-04-11",
    "disclosure_date": "2020-04-11",
    "executive_summary": "Magellan Health, a Fortune 500 managed care company, was targeted via spear phishing on April 6, 2020, when an email impersonating a Magellan client was sent to an employee. The attacker installed credential-harvesting malware, gained access to a corporate server, exfiltrated data, and deployed ransomware within five days. The compromised server contained employee W-2 data, Social Security numbers, and patient health insurance and treatment information. Multiple Magellan subsidiaries and affiliated healthcare providers separately reported the breach. Total across all entities: approximately 365,000 individuals. The breach disproportionately affected University of Florida Health affiliates and Merit Health Insurance.",
    "attack_type": "Ransomware / Data Exfiltration (preceded by spear phishing and credential theft)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 365000,
    "residents_affected_in_state": 76,
    "financial_impact": "Not publicly disclosed. No ransom payment confirmed. Class action lawsuits filed.",
    "operational_impact": "Single corporate server encrypted. No hospital facility closures. Patient care operations at affiliated hospitals continued.",
    "remediation_disclosed": "Single server isolated. Forensic investigation conducted. Employee notifications and patient notifications. Credit monitoring offered.",
    "primary_source_url": "https://www.magellanhealth.com/media/press-releases/security-incident-notice.aspx",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/extent-of-magellan-health-ransomware-becomes-clear-more-than-364000-individuals-affected/",
      "https://www.techtarget.com/healthtechsecurity/news/366595645/Magellan-Health-Data-Breach-Victim-Tally-Reaches-365K-Patients",
      "https://www.dataguidance.com/news/usa-magellan-health-suffers-ransomware-attack",
      "https://www.classaction.org/news/magellan-health-hit-with-class-action-over-april-2020-ransomware-attack",
      "https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/"
    ],
    "confidence_notes": "High confidence. Multiple HHS OCR filings from Magellan and affiliated entities confirmed by HIPAA Journal tracking. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "ClassAction.org",
      "DataGuidance",
      "HIPAA Journal",
      "Magellan Health official notice",
      "TechTarget"
    ],
    "id": "INC-00088",
    "year": 2020,
    "lat": 33.4942,
    "lng": -111.9261,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Mercy Health (Ohio/Illinois) \u2014 2020 Insider Breach",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "St. Louis (Mercy Health parent)",
    "hq_county": "St. Louis",
    "discovery_date": "2020-10-07",
    "disclosure_date": "2020-12-01",
    "executive_summary": "Mercy Health, a health system serving patients in northern Illinois and southern Wisconsin, discovered on October 7, 2020 that an employee had improperly accessed patient medical records on multiple occasions without a legitimate work purpose. PHI of 11,187 individuals was accessed. Compromised data included names, addresses, DOBs, medical record numbers, treatment/clinical information, radiological images, and for a subset, health insurance numbers. A $1.8 million class action settlement was reached in June 2024. While classified as an insider breach, it is catalogued here as the employee deliberately accessed records over time.",
    "attack_type": "Insider Unauthorized Access",
    "attack_category": "Insider threat",
    "threat_actor_name": "Mercy Health employee (terminated)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 11187,
    "residents_affected_in_state": "IL and WI patients (Mercy Health northern IL / southern WI footprint)",
    "financial_impact": "$1.8 million class action settlement (June 2024)",
    "operational_impact": "No operational disruption; privacy violation",
    "remediation_disclosed": "Yes \u2014 employee terminated; access controls enhanced; patients notified December 2020; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/mercy-health-1-8-million-settlement-insider-breach/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/mercy-health-data-breach-1-8m-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, Top Class Actions settlement coverage.",
    "sources_used": [
      "HIPAA Journal",
      "Top Class Actions"
    ],
    "id": "INC-00089",
    "year": 2020,
    "lat": 38.627,
    "lng": -90.1994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Northwestern Medicine (Chicago area) \u2014 2020 Data Breach",
    "organization_type": "Nonprofit Academic Medical System",
    "organization_type_bucket": "Other healthcare entity",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2020-01-01",
    "disclosure_date": "2020-09-04",
    "executive_summary": "Northwestern Memorial Hospital notified approximately 56,000 patients and donors of a major data breach discovered early in 2020 in which their personal records were accessed without authorization. Details of the specific attack vector were not fully described in available sources. This is distinct from the Elekta breach affecting Northwestern Memorial Healthcare in 2021.",
    "attack_type": "Hacking / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 56000,
    "residents_affected_in_state": "Illinois (Chicago area) patients and donors",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient and donor data accessed; investigation launched",
    "remediation_disclosed": "Partial \u2014 notifications issued; details limited in available sources",
    "primary_source_url": "https://www.cbsnews.com/chicago/news/northwestern-memorial-hospital-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. CBS Chicago reporting; limited details available on attack vector.",
    "sources_used": [
      "CBS Chicago"
    ],
    "id": "INC-00090",
    "year": 2020,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Nuvance Health (NY/CT - email compromise)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Poughkeepsie",
    "hq_county": "Dutchess",
    "discovery_date": "2020-05-01",
    "disclosure_date": "2020-08-01",
    "executive_summary": "Nuvance Health, a health system serving New York's Hudson Valley and western Connecticut (operating Vassar Brothers Medical Center, Northern Dutchess Hospital, Sharon Hospital CT, Danbury Hospital CT, and others), reported a data security incident involving unauthorized access to employee email accounts. The breach exposed patient protected health information across its NY and CT facilities.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI at NY/CT facilities compromised via employee email accounts",
    "remediation_disclosed": "HHS OCR and patients notified; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2020; major NY/CT health system; limited press coverage; now part of Yale New Haven Health System",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00091",
    "year": 2020,
    "lat": 41.7065539,
    "lng": -73.9283672,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Overlake Medical Center and Clinics",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Bellevue",
    "hq_county": "King",
    "discovery_date": "2019-12-09",
    "disclosure_date": "2020-02-04",
    "executive_summary": "Overlake Medical Center in Bellevue, Washington detected a phishing attack on December 9, 2019, that had begun December 6. Multiple employee email accounts were compromised, potentially exposing the protected health information of approximately 109,000 patients. Compromised data included names, contact information, dates of birth, diagnoses, treatment information, and health insurance data. No Social Security numbers or financial data were exposed. A class-action settlement was proposed in 2021.",
    "attack_type": "Phishing / Email compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 109000,
    "residents_affected_in_state": "Majority WA-based (Bellevue/Eastside)",
    "financial_impact": "Settlement proposed; $148,590 immediate security spend + $168,000/year for 3 years committed",
    "operational_impact": "Employee email accounts compromised; PHI potentially accessible",
    "remediation_disclosed": "Multi-factor authentication implemented; email security enhanced; employee training; settlement proposed 2021",
    "primary_source_url": "https://www.hipaajournal.com/phi-of-109000-patients-potentially-compromised-in-washington-phishing-attack/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366595809/109K-Patient-Records-Impacted-in-Overlake-Medical-Phishing-Attack",
      "https://www.hipaajournal.com/overlake-hospital-medical-center-proposes-settlement-to-resolve-data-breach-case/"
    ],
    "confidence_notes": "HHS OCR confirmed; 109,000 notified but only 24,000 class members had PHI actually exposed",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget HealthTech Security"
    ],
    "id": "INC-00092",
    "year": 2020,
    "lat": 47.6101,
    "lng": -122.2015,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "PIH Health, Inc.",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Whittier",
    "hq_county": "Los Angeles",
    "discovery_date": "2019-06-11 to 2019-06-21 (phishing attack)",
    "disclosure_date": "2020-01-10",
    "executive_summary": "Phishing attack compromised 45 employee email accounts at PIH Health (initial reports indicated 145 accounts). Breach reported late - 7 months after discovery. OCR settlement followed.",
    "attack_type": "Hacking/IT Incident \u2014 Phishing / email credential compromise targeting 45 employee email accounts",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown (phishing attacker)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 189763,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$600,000 HIPAA settlement with OCR (April 2025); $9.76 million class action lawsuit settlement against Solara Medical Supplies (related company, separate incident)",
    "operational_impact": "No reported clinical operational disruption",
    "remediation_disclosed": "Corrective action plan (2-year OCR monitoring); risk analysis conducted; policies and procedures updated; breach notification compliance improved",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/pih-health-hipaa-penalty/",
      "https://www.paubox.com/blog/pih-health-pays-600000-settlement-after-phishing-attack"
    ],
    "confidence_notes": "OCR found multiple HIPAA violations including late breach notification (7 months vs. 60-day requirement), failure to limit PHI use, and inadequate risk analysis. PHI exposed: names, addresses, DOBs, driver's licenses, SSNs, diagnoses, lab results, medications, financial information.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00093",
    "year": 2020,
    "lat": 33.9792,
    "lng": -118.0328,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Pen Bay Medical Center (Maine Health affiliate)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "ME",
    "hq_city": "Rockport",
    "hq_county": "Knox",
    "discovery_date": "2020-07-01",
    "disclosure_date": "2020-10-01",
    "executive_summary": "Pen Bay Medical Center, a MaineHealth affiliate hospital serving the midcoast Maine region, reported a data security incident involving unauthorized access to patient health records. The breach affected patients receiving care in Knox and Waldo counties in Maine.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Midcoast Maine hospital patient PHI compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; ME MaineHealth affiliate; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00094",
    "year": 2020,
    "lat": 44.1875416,
    "lng": -69.0730466,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Regions Hospital / Gillette Children's (via Blackbaud \u2014 2020)",
    "organization_type": "Nonprofit Hospital System / Pediatric Specialty Care",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "St. Paul",
    "hq_county": "Ramsey",
    "discovery_date": "2020-07-16",
    "disclosure_date": "2020-09-15",
    "executive_summary": "Regions Hospital in St. Paul notified 52,795 patients affected by the Blackbaud donor database ransomware attack (Feb\u2013June 2020). Gillette Children's Specialty Healthcare notified 1,766 individuals. Both were part of the broader Minnesota healthcare Blackbaud breach cluster that also affected Children's Minnesota and Allina Health.",
    "attack_type": "Ransomware (Third-Party Vendor \u2014 Blackbaud)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Blackbaud breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 54561,
    "residents_affected_in_state": "Minnesota residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No clinical disruption; donor/patient database backup exposed",
    "remediation_disclosed": "Yes \u2014 Blackbaud paid ransom for deletion; notifications September 2020",
    "primary_source_url": "https://seclists.org/dataloss/2020/q3/217",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for victim counts. Reported in Star Tribune/seclists BreachExchange (Regions: 52,795; Gillette: 1,766).",
    "sources_used": [
      "Risk Based Security/Star Tribune via seclists"
    ],
    "id": "INC-00095",
    "year": 2020,
    "lat": 44.9537,
    "lng": -93.09,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Roper St. Francis Healthcare",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Charleston",
    "hq_county": "Charleston",
    "discovery_date": "2020-10-29",
    "disclosure_date": "2020-12-04",
    "executive_summary": "In late October 2020, Roper St. Francis Healthcare \u2014 a South Carolina health system operating four hospitals and more than 117 healthcare facilities \u2014 discovered that three employee email accounts had been compromised after employees responded to phishing emails. The email accounts were accessed between October 14 and October 29, 2020 and contained the protected health information of 89,761 patients, including names, medical record numbers, patient account numbers, dates of birth, and limited treatment and clinical information. Roper St. Francis had experienced prior breaches, including one involving Blackbaud in 2020. The company settled a class action lawsuit for $1.5 million in 2024.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 89761,
    "residents_affected_in_state": "SC: majority; exact SC count not separately disclosed",
    "financial_impact": "$1.5M class action settlement (2024, final approval May 2024).",
    "operational_impact": "Email accounts compromised for 15 days. Limited clinical data in email. No EHR or system-wide outage.",
    "remediation_disclosed": "Compromised accounts secured. Enhanced email security implemented. Credit monitoring offered. $1.5M class action settlement.",
    "primary_source_url": "https://www.hipaajournal.com/roper-st-francis-healthcare-settles-data-breach-lawsuit-for-1-5-million/",
    "secondary_source_urls": [
      "https://thelyonfirm.com/class-action/data-breach/roper-st-francis/",
      "https://www.rsfh.com/news/httpwwwrsfhcomhealth-professionals"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report confirms 89,761 affected. $1.5M settlement documented by HIPAA Journal with final approval date confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "The Lyon Firm",
      "Roper St. Francis official notice"
    ],
    "id": "INC-00096",
    "year": 2020,
    "lat": 32.7765,
    "lng": -79.9311,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Temple University Health System",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Philadelphia",
    "hq_county": "Philadelphia",
    "discovery_date": "2020-09-01",
    "disclosure_date": "2020-12-01",
    "executive_summary": "Temple University Health System, a major Philadelphia academic medical center, reported a data security incident involving unauthorized access to protected health information. The breach affected patients at Temple University Hospital and affiliated facilities. Temple is one of the largest academic medical centers in Pennsylvania.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI at academic medical center compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; major PA academic medical center; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00097",
    "year": 2020,
    "lat": 39.9526,
    "lng": -75.1652,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Texas Health Resources (Change Healthcare indirect impact / email breach 2020)",
    "organization_type": "Health System / Hospital Network",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Arlington",
    "hq_county": "Tarrant",
    "discovery_date": "2020-01-01",
    "disclosure_date": "2020-04-01",
    "executive_summary": "Texas Health Resources reported a data breach in 2020 involving unauthorized access to employee email accounts, exposing patient PHI. Texas Health is a major Dallas-Fort Worth health system. The breach was among the 128 TX hacking/IT incidents from 2020-2024 tracked by Texas Hospital Association. Specific affected count not separately confirmed in reviewed sources.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts accessed; patient PHI exposed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.tha.org/blog/addressing-the-surge-of-texas-data-breach-rates/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; Texas Hospital Association confirmed 128 TX hacking incidents 2020-2024; Texas Health Resources is major DFW system; specific breach details not fully confirmed in reviewed sources",
    "sources_used": [
      "Texas Hospital Association"
    ],
    "id": "INC-00098",
    "year": 2020,
    "lat": 32.7355816,
    "lng": -97.1071186,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Total Vision, PC",
    "organization_type": "Optometry Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "San Diego, CA",
    "hq_county": "San Diego County",
    "discovery_date": "2020-10-30",
    "disclosure_date": "2020-12-28",
    "executive_summary": "This incident involved your name, address, date of birth, social security number, and contact lens or eyeglass prescription. As a result, your personal information may have been potentially exposed to others. No other medical information or financial information was potentially exposed to the third party. This information was located on a server that was accessed by a third party. Upon learning of this incident, we promptly secured the server and then encrypted the information on the server. Our investigation is ongoing at this time. Please be assured that we are taking s",
    "attack_type": "Hacking / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals']",
    "primary_source_url": "https://oag.ca.gov/system/files/EXPERIAN_G0290_Total%20Vision_L01_SAS_1.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00099",
    "year": 2020,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Trinity Health (via Blackbaud ransomware \u2014 2020)",
    "organization_type": "Nonprofit Catholic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Livonia",
    "hq_county": "Wayne",
    "discovery_date": "2020-07-16",
    "disclosure_date": "2020-09-01",
    "executive_summary": "Blackbaud, a cloud software company providing donor database services to Trinity Health and many other nonprofits and hospitals, suffered a ransomware attack between February 7 and June 3, 2020. Blackbaud paid an undisclosed ransom for confirmation of data deletion. Trinity Health's donor database backup files were exposed, including donor and limited patient information. This was a multistate/multinational Blackbaud breach affecting hundreds of organizations globally.",
    "attack_type": "Ransomware (Third-Party Vendor)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown ransomware group (Blackbaud breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3,
    "residents_affected_in_state": "Multistate",
    "financial_impact": "Ransom paid by Blackbaud (amount undisclosed)",
    "operational_impact": "Donor database backup exposed; no impact to Trinity's clinical systems",
    "remediation_disclosed": "Yes \u2014 Blackbaud notified clients July 16, 2020; Trinity investigated and notified affected individuals",
    "primary_source_url": "https://oag.ca.gov/system/files/Trinity%20Breach.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for Blackbaud breach event. Trinity-specific patient count not separately reported.",
    "sources_used": [
      "California AG (Trinity breach notice)"
    ],
    "id": "INC-00100",
    "year": 2020,
    "lat": 42.36837,
    "lng": -83.3527097,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "US Fertility LLC",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MD",
    "hq_city": "Rockville",
    "hq_county": "Montgomery",
    "discovery_date": "2020-09-14",
    "disclosure_date": "2020-11-17",
    "executive_summary": "US Fertility, a Maryland-based network supporting fertility clinics nationwide, suffered a ransomware attack in which attackers gained access between August 12 and September 14, 2020, before deploying ransomware. The breach affected 878,550 individuals. Data exfiltrated included names, addresses, DOBs, MPI numbers, and some SSNs. A $5.75 million settlement was reached.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 878550,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$5.75 million settlement",
    "operational_impact": "878K patient records compromised; operational disruptions to 50+ clinics nationwide",
    "remediation_disclosed": "Law enforcement notified; third-party forensics; $5.75M settlement",
    "primary_source_url": "https://www.hipaajournal.com/u-s-fertility-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594092/US-Fertility-Reaches-575M-Data-Breach-Settlement"
    ],
    "confidence_notes": "OCR breach report; MD AG notice; $5.75M settlement; class action in US District Court of Maryland",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget Health IT Security"
    ],
    "id": "INC-00101",
    "year": 2020,
    "lat": 39.084,
    "lng": -77.1528,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Universal Health Services (UHS)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "King of Prussia",
    "hq_county": "Montgomery",
    "discovery_date": "2020-09-27",
    "disclosure_date": "2020-09-28",
    "executive_summary": "Universal Health Services, one of the largest hospital chains in the US with 400+ facilities, suffered a massive Ryuk ransomware attack beginning the weekend of September 26-27, 2020. Systems across facilities in multiple states were taken offline. Staff had to document patient care on paper for weeks. UHS reported $67 million in losses from the attack. No patient data was confirmed stolen.",
    "attack_type": "Ransomware (Ryuk)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Wizard Spider (Ryuk operators)",
    "attribution_status": "reported",
    "individuals_affected_reported": 0,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$67 million in losses (reported in UHS earnings)",
    "operational_impact": "400+ US facilities affected; systems offline nationwide; staff reverted to paper records for weeks",
    "remediation_disclosed": "Systems restored without paying ransom; FBI investigation; third-party forensics",
    "primary_source_url": "https://uhs.com/news/statement-from-universal-health-services/",
    "secondary_source_urls": [
      "https://www.mitnicksecurity.com/blog/an-overview-of-the-2020-uhs-ransomware-attack",
      "https://invenioit.com/security/ransomware-attacks-healthcare/"
    ],
    "confidence_notes": "UHS publicly confirmed; widely reported; SEC filing included financial impact; NJ facilities among those affected",
    "sources_used": [
      "UHS Press Release",
      "Mitnick Security",
      "Invenio IT"
    ],
    "id": "INC-00102",
    "year": 2020,
    "lat": 40.0947625,
    "lng": -75.3851334,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Universal Health Services, Inc.",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "King of Prussia",
    "hq_county": "Montgomery",
    "discovery_date": "2020-09-27",
    "disclosure_date": "2020-09-29",
    "executive_summary": "In the early hours of September 27, 2020, the Ryuk ransomware (attributed to threat group Wizard Spider) struck Universal Health Services, one of the largest for-profit hospital operators in the U.S. with approximately 400 facilities. IT systems across all ~250 U.S. hospital locations were taken offline within hours; staff reverted to paper documentation, EHR access was lost, and clinical workflows were severely degraded for weeks. UHS stated no patient or employee data was confirmed stolen, and no patient deaths were directly attributed in official disclosures; however, media reports cited care disruptions. UHS disclosed in its Q4 2020 10-K that the attack resulted in an estimated $67 million aggregate pre-tax impact, primarily from lost revenue and remediation costs.",
    "attack_type": "Ransomware (Ryuk / file encryption)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Wizard Spider (Ryuk operators)",
    "attribution_status": "reported",
    "individuals_affected_reported": 0,
    "residents_affected_in_state": "Not applicable (no patient data confirmed stolen)",
    "financial_impact": "$67 million estimated aggregate pre-tax impact disclosed in UHS 10-K/annual report for FY2020. Includes lost revenue and remediation costs. Insurance recovery partially offset losses.",
    "operational_impact": "~250 U.S. hospitals taken offline. EHR systems inaccessible. Staff reverted to paper documentation for weeks. Ambulance diversions at multiple sites. Lab systems disrupted. No confirmed patient deaths in official disclosures.",
    "remediation_disclosed": "Systems restored over approximately three weeks. Forensic investigation confirmed no patient/employee data accessed or exfiltrated (per UHS). Law enforcement notified.",
    "primary_source_url": "https://ir.uhsinc.com/sec-filings/annual-reports",
    "secondary_source_urls": [
      "https://www.bleepingcomputer.com/news/security/universal-health-services-lost-67-million-due-to-ryuk-ransomware-attack/",
      "https://www.healthcaredive.com/news/uhs-confirms-sunday-ransomware-attack-some-250-hospitals-still-affected/586048/",
      "https://cyote.inl.gov/content/uploads/24/2025/12/CyOTE-Case-Study_Ryuk_UHS.pdf"
    ],
    "confidence_notes": "High confidence on financials ($67M from SEC 10-K). Attack attribution to Ryuk/Wizard Spider is widely reported but not confirmed by UHS. No data theft confirmed \u2014 UHS stated no evidence of access.",
    "sources_used": [
      "UHS SEC filings (10-K FY2020)",
      "BleepingComputer",
      "Healthcare Dive",
      "INL CYOTE Case Study"
    ],
    "id": "INC-00103",
    "year": 2020,
    "lat": 40.0947625,
    "lng": -75.3851334,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "University of California, San Francisco (UCSF) \u2014 School of Medicine",
    "organization_type": "Academic medical center / research university (University of California system)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Francisco",
    "hq_county": "San Francisco County",
    "discovery_date": "2020-06-03",
    "disclosure_date": "2020-06-26",
    "executive_summary": "On June 1, 2020, NetWalker ransomware operators encrypted servers within UCSF's School of Medicine after gaining access via compromised VPN credentials. UCSF isolated affected servers on June 1 but encryption had already occurred. The data was critical to academic research (including COVID-19-related work), and because backups were insufficient, UCSF negotiated and paid a ransom of $1,140,895 (116.4 Bitcoin) on approximately June 15 in exchange for a decryption tool and return of exfiltrated data. Patient care delivery operations were not materially disrupted and UCSF stated patient medical records were not believed to have been exposed.",
    "attack_type": "Ransomware with data exfiltration (opportunistic)",
    "attack_category": "Ransomware",
    "threat_actor_name": "NetWalker (Mailto ransomware rebranded)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "NOT_SEPARATELY_DISCLOSED",
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'ransom_paid': 1140895, 'notes': '116.4 Bitcoin paid ~June 15, 2020. DOJ later charged Canadian national Sebastien Vachon-Desjardins as a NetWalker affiliate. No additional financial penalties publicly disclosed.'}",
    "operational_impact": "Limited to School of Medicine servers; core UCSF network and patient care not impacted. Research data encrypted. Decryption key received; systems restored June 16\u201320, 2020.",
    "remediation_disclosed": "FBI notified; systems isolated June 1; ransom paid ~June 15; decryption tool received and systems restored June 16\u201320. VPN credential exposure identified as root cause.",
    "primary_source_url": "https://www.hipaajournal.com/university-of-california-san-francisco-pays-1-14-million-ransom-to-resolve-netwalker-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.bbc.com/news/technology-53214783",
      "https://www.healthcareitnews.com/news/ucsf-pays-114-million-decrypt-files-after-ransomware-attack",
      "https://www.bleepingcomputer.com/news/security/netwalker-ransomware-continues-assault-on-us-colleges-hits-ucsf/",
      "https://www.justice.gov/archives/opa/pr/department-justice-launches-global-action-against-netwalker-ransomware"
    ],
    "confidence_notes": "Attack occurred June 1, 2020. NetWalker first appeared as Mailto in Oct 2019. DOJ seized ~$454,530 in crypto from NetWalker victims Jan 2021. No HIPAA breach notification found for patient PHI since UCSF stated patient records were not believed exposed. Breach primarily affected research data.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00104",
    "year": 2020,
    "lat": 37.7749,
    "lng": -122.4194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "University of Utah Health (Email phishing breaches 2019-2020)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "UT",
    "hq_city": "Salt Lake City",
    "hq_county": "Salt Lake",
    "discovery_date": "2020-01-01",
    "disclosure_date": "2020-06-01",
    "executive_summary": "University of Utah Health experienced two data breaches involving employee email account compromises: one via phishing emails and a second linked to malware on an employee's computer. Patient data including medical records and health plan information was exposed. Separately, in August 2023, University of Utah Health Plans reported a breach affecting 3,914 plan members via a MOVEit exploit at vendor TMG Health.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing / Email + Malware",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3914,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Affected patients notified; additional security controls implemented",
    "primary_source_url": "https://www.idtheftcenter.org/post/university-of-utah-health-data-breach-exposes-patient-health-information/",
    "secondary_source_urls": [
      "https://www.ksl.com/article/news/utah/health/data-breach-may-have-affected-almost-4000-university-of-utah-health-plan-members/50708165"
    ],
    "confidence_notes": "Moderate confidence; ITRC and KSL documented; exact numbers not confirmed publicly for phishing breaches",
    "sources_used": [
      "Identity Theft Resource Center, KSL.com"
    ],
    "id": "INC-00105",
    "year": 2020,
    "lat": 40.7608,
    "lng": -111.891,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "University of Vermont Health Network",
    "organization_type": "Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "VT",
    "hq_city": "Burlington",
    "hq_county": "Chittenden",
    "discovery_date": "2020-10-28",
    "disclosure_date": "2020-10-30",
    "executive_summary": "The University of Vermont Health Network was struck by a Ryuk ransomware attack on October 28, 2020, initiated via a phishing email. Attackers encrypted 1,300 servers and deployed malware on approximately 5,000 devices. The attack caused major disruptions lasting several weeks; Epic EHR was taken down and care was significantly affected across the six-hospital network. No patient data was confirmed stolen.",
    "attack_type": "Ransomware (Ryuk/TrickBot)",
    "attack_category": "Ransomware",
    "threat_actor_name": "UNC1878 (associated with Ryuk/TrickBot)",
    "attribution_status": "reported",
    "individuals_affected_reported": 0,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Estimated $63 million in recovery costs (reported by UVMHN)",
    "operational_impact": "1,300 servers encrypted; 5,000 devices compromised; Epic EHR offline for weeks; significant care disruptions across 6-hospital system",
    "remediation_disclosed": "FBI involved; systems rebuilt over weeks; restored from backups; no ransom confirmed paid",
    "primary_source_url": "https://legislature.vermont.gov/Documents/2022/WorkGroups/House%20Energy%20and%20Technology/Technology/Cybersecurity/W~Douglas%20Gentile~UVM%20Medical%20Center%20Cyber%20Attack~3-31-2022.pdf",
    "secondary_source_urls": [
      "https://westoahu.hawaii.edu/cyber/ics-cybersecurity/ics-weekly-summaries/ransomware-attack-on-the-university-of-vermont-health-network/",
      "https://insurica.com/blog/uvm-health-network-ransomware-attack/"
    ],
    "confidence_notes": "Documented in Vermont legislature testimony; widely reported; no breach of PHI confirmed",
    "sources_used": [
      "Vermont Legislature",
      "INSURICA",
      "Hawaii Pacific University Cyber Analysis"
    ],
    "id": "INC-00106",
    "year": 2020,
    "lat": 44.4759,
    "lng": -73.2121,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "VCU Health (via Community Memorial Hospital / Blackbaud)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Richmond",
    "hq_county": "Richmond City",
    "discovery_date": "2020-07-16",
    "disclosure_date": "2020-09-01",
    "executive_summary": "VCU Health's Community Memorial Hospital learned on July 16, 2020 of the global Blackbaud data security incident. Blackbaud, which provided data hosting services, was breached. A backup copy of files containing donor and community member data was stolen. Based on Blackbaud's ransom payment, the data was reportedly destroyed. Information was primarily demographic in nature (name, address); no SSNs or financial account information were stored by Blackbaud.",
    "attack_type": "Supply-Chain Ransomware (Business Associate - Blackbaud)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Blackbaud paid ransom; VCU Health costs not disclosed",
    "operational_impact": "Donor/community data stolen via Blackbaud; no identity theft risk per VCU assessment",
    "remediation_disclosed": "Blackbaud paid ransom; VCU Health advised no identity theft risk; individuals notified",
    "primary_source_url": "https://www.vcuhealth.org/community-memorial-hospital/community-resources/support-cmh/blackbaud-incident/",
    "secondary_source_urls": [],
    "confidence_notes": "VCU Health official website is primary source. Number of affected not disclosed.",
    "sources_used": [
      "VCU Health (official website)"
    ],
    "id": "INC-00107",
    "year": 2020,
    "lat": 37.5407,
    "lng": -77.436,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Valley Presbyterian Hospital",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Van Nuys, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2020-05-14",
    "disclosure_date": "2020-12-30",
    "executive_summary": "Blackbaud systems between May 14, 2020 and May 20, 2020. Blackbaud advised it reported the incident to law enforcement and worked with forensic investigators to determine the nature and scope of the incident. Following its investigation, Blackbaud notified its customers that an unknown actor may have accessed or acquired certain Blackbaud customer data. Blackbaud reported that the data was exfiltrated by the threat actor at some point before Blackbaud locked the threat actor out of the environment on May 20, 2020. Upon learning of the Blackbaud incident, Valley Presbyterian immediately commenc",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/VPH%20-%20CA%20Notice%20of%20Data%20Event.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00108",
    "year": 2020,
    "lat": 34.1866,
    "lng": -118.4487,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Virtua Health (South Jersey - email breach)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Marlton",
    "hq_county": "Burlington",
    "discovery_date": "2020-03-01",
    "disclosure_date": "2020-07-01",
    "executive_summary": "Virtua Health, a South Jersey health system operating multiple hospitals and outpatient facilities, reported an unauthorized access incident in 2020 involving employee email accounts. Patient PHI was potentially exposed including names, dates of birth, medical record numbers, and clinical information. Virtua operates Voorhees, Voorhees Pediatric, Marlton, Berlin, and Mount Holly hospitals in New Jersey.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "South Jersey multi-hospital patient PHI potentially compromised via email",
    "remediation_disclosed": "HHS OCR and patients notified; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2020; major NJ health system; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00109",
    "year": 2020,
    "lat": 39.9005585,
    "lng": -74.9338911,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wilmington Surgical Associates",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "NC",
    "hq_city": "Wilmington",
    "hq_county": "New Hanover",
    "discovery_date": "2020-10-01",
    "disclosure_date": "2020-12-28",
    "executive_summary": "Wilmington Surgical Associates in North Carolina suffered a Netwalker ransomware attack in October 2020. The Netwalker gang claimed to have stolen approximately 13GB of data prior to encrypting files and published some of it online. The breach affected 114,834 patients. Note: This organization is in NC, not the NE region.",
    "attack_type": "Ransomware (Netwalker)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Netwalker",
    "attribution_status": "claimed",
    "individuals_affected_reported": 114834,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "13GB patient data published online; 114K patients affected",
    "remediation_disclosed": "Law enforcement notified; class action filed",
    "primary_source_url": "https://www.hipaajournal.com/more-than-114000-patients-affected-by-wilmington-surgical-associates-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366595167/Patients-Sue-Wilmington-Surgical-For-Netwalker-Ransomware-Data-Leak"
    ],
    "confidence_notes": "NOTE: Organization in NC, not NE region. Including as reference; may be excluded from final NE dataset",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget"
    ],
    "id": "INC-00110",
    "year": 2020,
    "lat": 34.2352853,
    "lng": -77.9487284,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "20/20 Eye Care Network",
    "organization_type": "Health Plan (Vision Insurance / Eye Care Network)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "FL",
    "hq_city": "Plantation",
    "hq_county": "Broward",
    "discovery_date": "2021-01-11",
    "disclosure_date": "2021-04-23",
    "executive_summary": "20/20 Eye Care Network, a Florida-based vision care network providing insurance services to health plans and employers across multiple states, disclosed in April 2021 that a breach of its Amazon Web Services (AWS) S3 cloud storage environment had exposed the protected health information of 3,253,822 individuals. Attackers gained unauthorized access to the S3 buckets between January 11 and January 22, 2021 and may have downloaded or deleted member data. The compromised data included member names, addresses, dates of birth, Social Security numbers, member ID numbers, and health insurance information. This was a landmark case for cloud security exposure in healthcare, resulting in HHS OCR scrutiny of cloud access controls. A class action lawsuit was filed.",
    "attack_type": "Cloud Infrastructure Breach / AWS S3 Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3253822,
    "residents_affected_in_state": "FL NY PA and other states (multi-state vision network); exact state counts not separately disclosed",
    "financial_impact": "Class action lawsuits filed. Settlement amount not publicly confirmed. Remediation costs not disclosed.",
    "operational_impact": "Cloud-based member data deleted or downloaded. No clinical service disruption directly reported.",
    "remediation_disclosed": "AWS S3 access controls remediated. Third-party forensics. HHS OCR breach reported. Notification letters mailed. Credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/20-20-eye-care-network-data-breach/",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/2020-eye-care-network-breach-aws/599000/",
      "https://databreaches.net/2021/04/23/2020-eye-care-network-data-breach-affects-3-2-million-individuals/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report confirms 3,253,822. HIPAA Journal and DataBreaches.Net corroborate. AWS S3 exposure vector documented.",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare Dive",
      "DataBreaches.Net"
    ],
    "id": "INC-00111",
    "year": 2021,
    "lat": 26.1275862,
    "lng": -80.2331036,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "20/20 Eye Care Network (iCare Acquisitions)",
    "organization_type": "Health Plan (Vision/Hearing Care)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "FL",
    "hq_city": "Boca Raton",
    "hq_county": "Palm Beach",
    "discovery_date": "2021-01-01",
    "disclosure_date": "2021-05-28",
    "executive_summary": "20/20 Eye Care Network and 20/20 Hearing Care Network, FL-based health plan networks under iCare Acquisitions, experienced a cloud storage breach in January 2021. Attackers accessed AWS S3 storage buckets, downloaded the contents, and then deleted the data. PHI of 3,253,822 health plan members was potentially accessed. Notification was delayed more than 3 months. A $3 million class action settlement was reached.",
    "attack_type": "Cloud Storage Exposure / Insider Wrongdoing",
    "attack_category": "Insider threat",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4142440,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3 million class action settlement",
    "operational_impact": "Cloud storage data deleted by attackers; 3+ month notification delay",
    "remediation_disclosed": "AWS S3 buckets reviewed and secured; notifications mailed May 2021; $3M settlement",
    "primary_source_url": "https://www.hipaajournal.com/3-million-settlement-proposed-to-resolve-20-20-eye-care-network-data-breach-lawsuit/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/class-action-filed-against-20-20-eye-care-network-icare-health-solutions-over-jan-2021-data-breach",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/20-20-eye-care-network-hearing-care-network-data-breach-3m-class-action-settlement/"
    ],
    "confidence_notes": "HHS OCR lists 4,142,440 (FL entity). Maine AG filing provides breach details. Settlement confirmed by HIPAA Journal.",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "Top Class Actions"
    ],
    "id": "INC-00112",
    "year": 2021,
    "lat": 26.3683,
    "lng": -80.1289,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Alaska Department of Health and Social Services (DHSS)",
    "organization_type": "Government Healthcare Agency",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Juneau",
    "hq_county": "Juneau (Borough)",
    "discovery_date": "2021-05-02",
    "disclosure_date": "2021-09-16",
    "executive_summary": "A highly sophisticated nation-state cyberattack targeted the Alaska Department of Health and Social Services website in May 2021, exploiting a vulnerability to gain deeper network access. The attack potentially compromised personal and health information of any Alaskan who had interacted with DHSS \u2014 including Social Security numbers, dates of birth, addresses, driver's license numbers, Medicaid information, health information, and financial information. The state described it as 'any Alaskan could have been compromised.' Mandiant was engaged for incident response. CNN and multiple sources confirmed it was a nation-state actor. Services including vital records, background checks, behavioral health management, and vaccine data systems were taken offline.",
    "attack_type": "Nation-state cyberattack / Malware / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Nation-state actor (identity not publicly disclosed)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown (potentially all Alaskans who had interacted with DHSS)",
    "residents_affected_in_state": 730000,
    "financial_impact": "$215,000 for statewide credit monitoring",
    "operational_impact": "Multiple DHSS services offline for weeks/months; vital records, background checks, vaccine data, behavioral health systems all disrupted; systems rebuilt from ground up per Mandiant recommendation",
    "remediation_disclosed": "Systems rebuilt from ground up; Mandiant engaged; $215,000 credit monitoring offered to all Alaskans; FBI and CISA involved",
    "primary_source_url": "https://content.govdelivery.com/accounts/AKDHSS/bulletins/2f1ea13",
    "secondary_source_urls": [
      "https://alaskapublic.org/news/2021-09-17/cyberattackers-had-access-to-alaskans-private-health-information-state-says",
      "https://www.cnn.com/2021/09/20/politics/alaska-health-cyberattack",
      "https://www.bankinfosecurity.com/alaska-health-department-services-affected-by-malware-attack-a-16708",
      "https://www.governing.com/security/health-dept-cyber-attack-exposes-most-alaskans-personal-data"
    ],
    "confidence_notes": "Official DHSS breach notice; HIPAA and APIPA breach confirmed; nation-state characterization confirmed by state officials and CNN",
    "sources_used": [
      "Alaska DHSS official notice",
      "Alaska Public Media",
      "CNN",
      "BankInfoSecurity",
      "Governing"
    ],
    "id": "INC-00113",
    "year": 2021,
    "lat": 58.3019,
    "lng": -134.4197,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Arbour Hospital (HRI Behavioral Health)",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Jamaica Plain",
    "hq_county": "Suffolk",
    "discovery_date": "2021-01-01",
    "disclosure_date": "2021-04-01",
    "executive_summary": "Arbour Hospital, a behavioral health facility in Jamaica Plain, Massachusetts operated by HRI Behavioral Health / Universal Health Services, was subject to a $65,000 HIPAA settlement with HHS OCR in 2021 following a security incident. The settlement addressed failures in risk analysis, policies, and safeguards related to a cyber incident affecting behavioral health patient data.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$65,000 HHS OCR settlement (2021)",
    "operational_impact": "Behavioral health patient data compromised",
    "remediation_disclosed": "HHS OCR settlement with corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal OCR penalty table confirms $65K settlement 2021; limited detail publicly available",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00114",
    "year": 2021,
    "lat": 42.3116046,
    "lng": -71.1143838,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Atlantic Health System (NJ - network server breach)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Morristown",
    "hq_county": "Morris",
    "discovery_date": "2021-06-01",
    "disclosure_date": "2021-09-01",
    "executive_summary": "Atlantic Health System, a major New Jersey health system operating Morristown Medical Center, Overlook Medical Center, and other facilities, reported a data security incident involving unauthorized access to its network. Patient protected health information was potentially compromised. Atlantic Health serves over 2 million patients annually across northern and central New Jersey.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "NJ multi-hospital patient PHI potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified; security measures enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2021; major NJ health system with 2M+ annual patients; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00115",
    "year": 2021,
    "lat": 40.7970382,
    "lng": -74.4809868,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Barlow Respiratory Hospital",
    "organization_type": "Specialty Hospital",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2021-08-21",
    "disclosure_date": "2021-12-30",
    "executive_summary": "Barlow Respiratory Hospital (\u201cBarlow\u201d) is committed to protecting the security and privacy of our patient information. We are writing to notify you about an incident that may have involved some of your information. This notice explains the incident, measures we have taken in response, and additional steps you can take to protect your information. On November 30, 2021, we determined that your information may have been involved in an incident that disrupted the",
    "attack_type": "Hacking / Security Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Barlow%20-%20Califronia%20Notification.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00116",
    "year": 2021,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "BioPlus Specialty Pharmacy Services, LLC",
    "organization_type": "Healthcare Provider (Specialty Pharmacy)",
    "organization_type_bucket": "Pharmacy",
    "state": "FL",
    "hq_city": "Altamonte Springs",
    "hq_county": "Seminole",
    "discovery_date": "2021-11-11",
    "disclosure_date": "2021-12-10",
    "executive_summary": "Florida-based BioPlus Specialty Pharmacy suffered an unauthorized access incident between October 25 and November 11, 2021. Attackers accessed servers containing patient names, DOBs, SSNs, medical record numbers, claims and diagnosis information, and prescription details of up to 350,000 patients. BioPlus notified affected individuals within a month and offered credit monitoring. A settlement was proposed and received preliminary approval.",
    "attack_type": "Unauthorized Server Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 350000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Undisclosed settlement amount",
    "operational_impact": "PHI including SSNs and prescription details exposed",
    "remediation_disclosed": "Servers secured; notifications mailed December 10, 2021; credit monitoring offered; settlement proposed",
    "primary_source_url": "https://www.hipaajournal.com/bioplus-specialty-pharmacy-services-settlement/",
    "secondary_source_urls": [
      "https://www.justice4you.com/bioplus-data-breach/",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/bioplus-specialty-pharmacy-services-data-breach-class-action-settlement/",
      "https://oag.ca.gov/system/files/BioPlus-%20CA%20Sample.pdf"
    ],
    "confidence_notes": "Well-documented; multiple law firm investigations and settlement proceedings confirm details. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Arnold Law Firm",
      "California AG Breach Notification",
      "HIPAA Journal",
      "Top Class Actions"
    ],
    "id": "INC-00117",
    "year": 2021,
    "lat": 36.55185756742755,
    "lng": -118.43734362598389,
    "is_multistate": true,
    "hq_outside_state": "Altamonte Springs, Florida",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Bryan County Ambulance Authority (BCAA) \u2013 HIPAA Settlement 2024",
    "organization_type": "Emergency Medical Services",
    "organization_type_bucket": "Ambulance / EMS",
    "state": "OK",
    "hq_city": "Durant",
    "hq_county": "Bryan",
    "discovery_date": "2021-01-01",
    "disclosure_date": "2021-06-01",
    "executive_summary": "Bryan County Ambulance Authority experienced a HIPAA breach that led to a $90,000 OCR settlement in 2024. The HIPAA Journal 2024 breach report confirmed the BCAA settlement. Related to a breach reported from Bryan County OK EMS.",
    "attack_type": "Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14273,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$90,000 OCR settlement (2024)",
    "operational_impact": "EMS patient data compromised",
    "remediation_disclosed": "OCR settlement; corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/2024-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.saul.com/insights/alert/emergency-medical-service-provider-agrees-pay-90000-hipaa-settlement-following"
    ],
    "confidence_notes": "High confidence; $90K OCR settlement confirmed in HIPAA Journal 2024 annual report; 14,273 affected per SC058 OCR records; Bryan County OK EMS",
    "sources_used": [
      "HIPAA Journal 2024 Annual Report",
      "Saul Ewing law firm alert"
    ],
    "id": "INC-00118",
    "year": 2021,
    "lat": 33.9919761,
    "lng": -96.3776762,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "California Health & Wellness (Centene subsidiary)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Sacramento",
    "hq_county": "Sacramento",
    "discovery_date": "2021-01-20 to 2021-01-22 (Accellion FTA exploit)",
    "disclosure_date": "2021",
    "executive_summary": "California Health & Wellness, a Centene subsidiary, affected by Accellion FTA cyberattack. Names, addresses, DOBs, insurance IDs, and health information of 80,138 members stolen.",
    "attack_type": "Hacking/IT Incident \u2014 Supply chain attack via Accellion FTA zero-day exploitation",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 80138,
    "residents_affected_in_state": 80138,
    "financial_impact": "Part of broader Accellion litigation",
    "operational_impact": "No reported clinical disruption",
    "remediation_disclosed": "FTA discontinued; credit monitoring offered",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://compliancy-group.com/accellion-healthcare-data-breach-settlement/"
    ],
    "confidence_notes": "Part of broader Accellion FTA attack affecting 100+ organizations globally in Dec 2020 - Jan 2021.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00119",
    "year": 2021,
    "lat": 38.5816,
    "lng": -121.4944,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "California Physicians' Services d/b/a Blue Shield of California",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2021-01-20",
    "disclosure_date": "2021-12-13",
    "executive_summary": "On January 20, 2021, OneDigital, A Blue Shield broker and the broker for your employer group, detected unusual activity on its network systems. OneDigital determined that an unauthorized person may have improperly gained access to its systems through a ransomware attack. Although OneDigital was required to notify us of the incident within 24 hours, we learned about it on October 4, 2021. Immediately upon learning of the ransomware attack on OneDigital, Blue Shield began an investigation into the",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/CORRECTED%20EXPERIAN_H1193_Blue%20Shield%20of%20California%20%232_L01_SAS_1%20CORRECTED.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00120",
    "year": 2021,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Care New England Health System (RI)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "RI",
    "hq_city": "Providence",
    "hq_county": "Providence",
    "discovery_date": "2021-06-01",
    "disclosure_date": "2021-10-01",
    "executive_summary": "Care New England Health System, a Providence, Rhode Island health system operating Women & Infants Hospital, Butler Hospital, and Kent Hospital, reported a data security incident involving unauthorized access to patient health information. The breach affected patients across Care New England's facilities serving Rhode Island and southeastern New England.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "RI multi-hospital patient PHI potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2021; major RI health system; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00121",
    "year": 2021,
    "lat": 41.824,
    "lng": -71.4128,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Community Medical Centers, Inc.",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Stockton",
    "hq_county": "San Joaquin",
    "discovery_date": "2021-10 (unusual network activity detected)",
    "disclosure_date": "2021",
    "executive_summary": "Hacking incident at Community Medical Centers in Stockton requiring shutdown of IT network due to unusual network activity.",
    "attack_type": "Hacking/IT Incident \u2014 Unspecified hacking incident / network intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 656047,
    "residents_affected_in_state": "Not separately reported (all operations in CA Central Valley)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "IT network shutdown",
    "remediation_disclosed": "Not publicly disclosed in detail",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/largest-healthcare-data-breaches-of-2021/"
    ],
    "confidence_notes": "656,047 individuals affected per HHS OCR portal. Central Valley-based community health system.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00122",
    "year": 2021,
    "lat": 37.9577,
    "lng": -121.2908,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Conifer Health Solutions, LLC (Tenet Healthcare BA)",
    "organization_type": "BA/Vendor (Revenue Cycle Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Frisco",
    "hq_county": "Collin",
    "discovery_date": "2021-04-20",
    "disclosure_date": "2021-04-21",
    "executive_summary": "On April 20, 2021, Tenet Healthcare Corporation disclosed that its subsidiary Conifer Health Solutions had experienced a cybersecurity incident that impacted business at certain Tenet hospitals. The attack, described as an IT security incident, disrupted clinical and financial operations at Tenet facilities for several days. Tenet disclosed the incident in an 8-K filing with the SEC. While Tenet did not specifically confirm the attack as ransomware, the indicators \u2014 including immediate system isolation and restoration efforts \u2014 were consistent with a ransomware event. The financial impact was disclosed as approximately $100 million in lost revenues for Q2 2021 after accounting for expenses and recoveries. This was one of the first major healthcare systems to disclose a cyber incident via SEC 8-K.",
    "attack_type": "Ransomware / IT Security Incident (unconfirmed ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "TX CA FL and other Tenet states; individual PHI count not separately disclosed",
    "financial_impact": "~$100M in lost revenues Q2 2021 (net of expenses and recoveries; disclosed in Tenet SEC 10-Q). Additional remediation costs not separately itemized.",
    "operational_impact": "Clinical and financial operations disrupted at multiple Tenet hospitals. Patient care diversions at affected facilities. Business office functions at Conifer Health impacted nationwide.",
    "remediation_disclosed": "Systems isolated and restored over several days. FBI notified. Third-party cybersecurity experts engaged. SEC 8-K filed April 21, 2021. Tenet disclosed $100M impact in 10-Q.",
    "primary_source_url": "https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0000070858&type=8-K&dateb=&owner=include&count=40",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/tenet-healthcare-cyberattack-2021/599116/",
      "https://www.hipaajournal.com/tenet-healthcare-ransomware-attack/"
    ],
    "confidence_notes": "High confidence on operational and financial facts \u2014 SEC 8-K and 10-Q disclosures are primary. Ransomware not officially confirmed by Tenet but broadly characterized as such in coverage. PHI count not separately disclosed.",
    "sources_used": [
      "SEC EDGAR (Tenet 8-K/10-Q)",
      "Healthcare Dive",
      "HIPAA Journal"
    ],
    "id": "INC-00123",
    "year": 2021,
    "lat": 33.1507,
    "lng": -96.8236,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Dupage Medical Group (Illinois) \u2014 2021 Ransomware",
    "organization_type": "Physician Group Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "IL",
    "hq_city": "Downers Grove",
    "hq_county": "DuPage",
    "discovery_date": "2021-07-13",
    "disclosure_date": "2021-09-13",
    "executive_summary": "DuPage Medical Group (DMG), a large multispecialty physician group practice based in Downers Grove, Illinois (now known as DuPage Medical Group after its merger with Midwest Center for Women's Healthcare), reported a ransomware attack discovered on July 13, 2021. The attackers gained access to DMG's network and encrypted data. Patient PHI was potentially exposed. Approximately 655,384 individuals were affected. DMG is one of the largest physician-owned multispecialty medical groups in Illinois, serving patients across Chicagoland. Patients were notified in September 2021.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 655384,
    "residents_affected_in_state": "Illinois residents \u2014 primarily DuPage Cook Will and Kane counties",
    "financial_impact": "$3 million class action settlement (2022)",
    "operational_impact": "Network encrypted; patient data potentially exposed; operations disrupted during recovery",
    "remediation_disclosed": "Yes \u2014 investigation conducted, patients notified September 2021, security improvements implemented",
    "primary_source_url": "https://www.hipaajournal.com/600000-dupage-medical-group-patients-notified-about-phi-breach/",
    "secondary_source_urls": [
      "https://www.dulyhealthandcare.com/news/dupage-medical-group-informs-patients-of-data-security-incident-and-offers-support",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/dupage-medical-group-data-breach-3m-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal documented this breach. HHS OCR confirms 655,384 individuals.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00124",
    "year": 2021,
    "lat": 41.7936822,
    "lng": -88.0102281,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Einstein Healthcare Network (now Jefferson Health)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Philadelphia",
    "hq_county": "Philadelphia",
    "discovery_date": "2021-01-01",
    "disclosure_date": "2021-04-01",
    "executive_summary": "Einstein Healthcare Network, a Philadelphia-based health system that merged with Jefferson Health in 2021, reported a data security incident involving unauthorized access to employee email accounts. The breach exposed protected health information of patients at Einstein Medical Centers in Philadelphia, Montgomery, and Elkins Park. Einstein serves a large urban patient population in the Northeast.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Philadelphia patient PHI compromised via email accounts",
    "remediation_disclosed": "HHS OCR and patients notified; email security improved",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; major PA health system; now part of Jefferson Health; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00125",
    "year": 2021,
    "lat": 39.9526,
    "lng": -75.1652,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Eskenazi Health",
    "organization_type": "Safety-Net Public Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2021-08-04",
    "disclosure_date": "2021-10-01",
    "executive_summary": "Sophisticated threat actors (identified by some as Vice Society ransomware) first accessed Eskenazi Health's network on or about May 19, 2021, and disabled security systems to remain undetected. On August 4, 2021, ransomware was deployed, forcing the hospital network offline including EHR. Ambulances were diverted. Data exfiltrated was posted to the dark web. Despite initial statements suggesting no data exfiltration, subsequent investigation confirmed theft of PHI for 1,515,918 individuals including names, SSNs, diagnoses, face photos, and credit card information. Eskenazi recovered encrypted data from backups and did not pay the ransom. A $2.5 million class action settlement was reached in 2025 covering ~160,000 individuals whose data appeared on the dark web.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Vice Society (attributed by cybersecurity researchers)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1515918,
    "residents_affected_in_state": "Primarily Indiana residents",
    "financial_impact": "$2.5 million class action settlement (2025); ransom not paid; significant recovery costs",
    "operational_impact": "EHR offline; ambulance diversions; network taken offline; operations impacted for weeks",
    "remediation_disclosed": "Yes \u2014 data recovered from backups; systems restored; law enforcement notified; patient notifications November 2021",
    "primary_source_url": "https://www.hipaajournal.com/eskenazi-health-2-5-million-class-action-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.eskenazihealth.edu/news/update-on-eskenazi-health-cyber-incident",
      "https://www.wfyi.org/health/2021-08-24/eskenazi-hospital-data-taken-in-ransomware-hack"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal (1.5M), Eskenazi public notices, WFYI reporting, settlement filings.",
    "sources_used": [
      "HIPAA Journal",
      "Eskenazi Health",
      "WFYI",
      "SC Media"
    ],
    "id": "INC-00126",
    "year": 2021,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Eskenazi Health (Health & Hospital Corporation of Marion County)",
    "organization_type": "Hospital / Health System (Public)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2021-08-04",
    "disclosure_date": "2021-08-24",
    "executive_summary": "Eskenazi Health, a public hospital division of Marion County's Health & Hospital Corporation, discovered a ransomware attack on August 4, 2021, though the initial intrusion occurred May 19, 2021 \u2014 with threat actors remaining undetected for over two months after disabling security protections. Eskenazi took its network offline immediately on August 4, diverted ambulances, and did not pay the ransom. Data was stolen and posted on a dark web site (attributed to Vice Society by online reports). A total of 1,515,918 individuals were affected per HHS OCR, though the class action settlement covers approximately 160,000 individuals whose data was confirmed published on the dark web. Compromised data included SSNs, medical record numbers, diagnoses, prescriptions, face photographs, and credit card information. A $2.5 million settlement was reached.",
    "attack_type": "Ransomware / Data Theft / Dark Web Publication",
    "attack_category": "Ransomware",
    "threat_actor_name": "Vice Society (reported by online sources; not confirmed by Eskenazi)",
    "attribution_status": "reported",
    "individuals_affected_reported": 1515918,
    "residents_affected_in_state": "Primarily Indiana; not broken out further",
    "financial_impact": "$2.5 million class action settlement (2025). No ransom paid. Forensic and legal costs additional.",
    "operational_impact": "Network taken offline August 4. Ambulances diverted. EHR inaccessible. Staff on downtime procedures. Threat actor had 2+ months undetected dwell time.",
    "remediation_disclosed": "Network taken offline and rebuilt. FBI notified. No ransom paid. Notifications November 2021. Credit monitoring and identity protection offered (3 years + $1M insurance policy). Settlement fund established.",
    "primary_source_url": "https://www.eskenazihealth.edu/news/update-on-eskenazi-health-cyber-incident",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/eskenazi-health-2-5-million-class-action-data-breach-settlement/",
      "https://www.wfyi.org/health/2021-08-24/eskenazi-hospital-data-taken-in-ransomware-hack",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/2-5m-eskenazi-health-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. Official Eskenazi notice published. HHS OCR: 1,515,918. Vice Society attribution from online sources only; Eskenazi did not confirm. $2.5M settlement from court records.",
    "sources_used": [
      "Eskenazi Health official notice",
      "HIPAA Journal",
      "WFYI",
      "Top Class Actions"
    ],
    "id": "INC-00127",
    "year": 2021,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Florida Blue (Blue Cross Blue Shield of Florida)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "FL",
    "hq_city": "Jacksonville",
    "hq_county": "Duval",
    "discovery_date": "2021-07-01",
    "disclosure_date": "2021-07-01",
    "executive_summary": "Florida Blue disclosed in July 2021 that a brute force password attack on its member portal compromised the personal information of over 30,000 members. Attackers used a large database of user credentials obtained from other sources to access Florida Blue member accounts. Data potentially exposed included names, DOBs, addresses, SSNs, medical records, lab results, diagnoses, medications, insurance information, and dates of service.",
    "attack_type": "Brute Force / Credential Stuffing Attack",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 30000,
    "residents_affected_in_state": 30000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member portal accounts accessed by unauthorized parties",
    "remediation_disclosed": "Affected accounts flagged; law firm investigation ongoing as of January 2022",
    "primary_source_url": "https://classlawdc.com/2022/01/21/data-breach-investigation-of-leaked-florida-blue-health-insurance-information/",
    "secondary_source_urls": [],
    "confidence_notes": "Reported by law firm investigating breach. Exact HHS OCR figure not independently confirmed at this figure; treat individuals_affected as approximate.",
    "sources_used": [
      "Migliaccio & Rathod LLP"
    ],
    "id": "INC-00128",
    "year": 2021,
    "lat": 30.3322,
    "lng": -81.6557,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Florida Healthy Kids Corporation",
    "organization_type": "Health Plan (Medicaid - CHIP)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "FL",
    "hq_city": "Tallahassee",
    "hq_county": "Leon",
    "discovery_date": "2020-12-09",
    "disclosure_date": "2021-02-01",
    "executive_summary": "Florida Healthy Kids Corporation (FL's CHIP program) was notified by its web hosting vendor, Jelly Bean Communications Design, on December 9, 2020 that unauthorized access had occurred to its online application platform. Jelly Bean had failed to patch multiple website vulnerabilities since November 2013\u2014a seven-year lapse. Hackers manipulated applicant addresses and may have accessed names, DOBs, SSNs, financial data, and insurance details for up to 3.5 million individuals. Jelly Bean settled False Claims Act allegations for $293,771.",
    "attack_type": "Supply-Chain/Vendor Exploit (Unpatched Web Application Vulnerabilities)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3500000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Jelly Bean Communications settled False Claims Act for $293,771",
    "operational_impact": "Online application platform taken offline; thousands of applicant addresses modified",
    "remediation_disclosed": "Platform taken offline; alternative hosting sought; HHS OCR notified; breach reported February 2021",
    "primary_source_url": "https://www.hipaajournal.com/failure-to-patch-results-in-7-year-breach-of-florida-medicaid-applicants-phi/",
    "secondary_source_urls": [
      "https://www.scworld.com/news/feds-fine-florida-childrens-health-insurance-site-2020-hack"
    ],
    "confidence_notes": "HHS OCR lists 3,500,000 affected. DOJ False Claims Act action corroborates details.",
    "sources_used": [
      "HIPAA Journal",
      "SC Media"
    ],
    "id": "INC-00129",
    "year": 2021,
    "lat": 30.4383,
    "lng": -84.2807,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Forefront Dermatology",
    "organization_type": "Multistate Dermatology Practice (HQ Wisconsin)",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "WI",
    "hq_city": "Green Bay",
    "hq_county": "Brown",
    "discovery_date": "2021-06-04",
    "disclosure_date": "2021-07-06",
    "executive_summary": "The Cuba ransomware gang attacked Forefront Dermatology in late May 2021 (breach window May 28 \u2013 June 4, 2021), gaining unauthorized network access, exfiltrating data, and encrypting files before detection on June 4. Approximately 2.4 million patients and employees across 21 states had sensitive data compromised including names, SSNs, dates of birth, health insurance information, and medical records. Cuba dumped stolen data on its dark web leak site. Plaintiffs alleged 'incredibly simplistic passwords' enabled the attack. A $3.75 million class action settlement was reached in 2022.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Cuba Ransomware",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2400000,
    "residents_affected_in_state": 21,
    "financial_impact": "$3.75 million settlement; up to $10,000 per class member for documented losses",
    "operational_impact": "Partial network offline; patient data widely exposed; reputational damage",
    "remediation_disclosed": "Yes \u2014 network segments secured; policies and security practices reviewed; settlement includes security enhancements",
    "primary_source_url": "https://www.hipaajournal.com/forefront-dermatology-proposes-3-75-million-settlement-to-resolve-ransomware-lawsuit/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/forefront-dermatology-data-breach-3-75m-class-action-settlement/",
      "https://www.lawcommentary.com/articles/forefront-dermatology-to-pay-nearly-4-million-following-2021-data-breach"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, court filings, confirmed Cuba attribution via dark web post.",
    "sources_used": [
      "HIPAA Journal",
      "Top Class Actions",
      "Law Commentary"
    ],
    "id": "INC-00130",
    "year": 2021,
    "lat": 44.5133,
    "lng": -88.0133,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Forefront Dermatology, S.C.",
    "organization_type": "Medical Group / IPA",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "WI",
    "hq_city": "Racine",
    "hq_county": "Racine",
    "discovery_date": "2021-06-04",
    "disclosure_date": "2021-07-14",
    "executive_summary": "Forefront Dermatology, a Wisconsin-based multi-state dermatology group with locations in 21 states and DC, discovered on June 4, 2021, that unauthorized parties had accessed its IT network between May 28 and June 4, 2021. The attack was a ransomware incident affecting approximately 2,413,553 patients and employees across all locations. Compromised data included patient names, addresses, dates of birth, account numbers, health insurance plan member IDs, medical record numbers, provider names, and medical/clinical treatment information. No Social Security numbers or financial account information were confirmed compromised. A $3.75 million class action settlement was reached.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2413553,
    "residents_affected_in_state": 21,
    "financial_impact": "$3.75 million class action settlement. Ransom payment status not disclosed.",
    "operational_impact": "IT systems compromised for 7 days. Patient and employee data accessed. Clinical operations continued at dermatology practices.",
    "remediation_disclosed": "IT systems secured. Forensic investigation conducted. HHS OCR breach report filed. Notification letters sent to 2.4M individuals. Credit monitoring offered. $3.75M settlement.",
    "primary_source_url": "https://www.forefrontdermatology.com/data-security-incident-notice/",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/forefront-dermatology-reports-breach-24m-patient-records",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/forefront-dermatology-data-breach-3-75m-class-action-settlement/",
      "https://www.hipaaguide.net/data-breach-affects-up-to-2-4-million-forefront-dermatology-patients/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal: 2,413,553. Official notice published. Settlement amount confirmed by court records.",
    "sources_used": [
      "Forefront Dermatology official notice",
      "Healthcare IT News",
      "Top Class Actions",
      "HIPAA Guide"
    ],
    "id": "INC-00131",
    "year": 2021,
    "lat": 42.7313756,
    "lng": -87.7834769,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Hackley Community Care (Michigan)",
    "organization_type": "Federally Qualified Health Center",
    "organization_type_bucket": "FQHC / Community health",
    "state": "MI",
    "hq_city": "Muskegon",
    "hq_county": "Muskegon",
    "discovery_date": "2020-09-07",
    "disclosure_date": "2021-02-01",
    "executive_summary": "Hackley Community Care, a Federally Qualified Health Center in Muskegon, Michigan, reported that a phishing email was sent to staff in September 2020. One employee clicked a malicious link and entered credentials that were captured by the attacker, who then remotely accessed the employee's email account between September 7\u201324, 2020. Investigation confirmed only one email account was compromised and no EHR access was gained. 2,644 patients were affected. For most, the exposure was limited to names and addresses; some patients had more sensitive data exposed and were offered complimentary credit monitoring.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2644,
    "residents_affected_in_state": "Primarily Muskegon County Michigan residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Limited to single email account; no EHR access; minor patient data exposure",
    "remediation_disclosed": "Yes \u2014 account secured, forensic investigation, credit monitoring for high-risk patients, additional security measures implemented",
    "primary_source_url": "https://www.hipaajournal.com/nebraska-medicine-notifies-219000-patients-about-september-2020-malware-attack/",
    "secondary_source_urls": [
      "https://www.dataguidance.com/news/usa-hcc-announces-data-breach-affecting-2644-patients"
    ],
    "confidence_notes": "Medium confidence. HIPAA Journal article mentions Hackley Community Care as a secondary item. DataGuidance confirmed 2,644 patients.",
    "sources_used": [
      "HIPAA Journal",
      "DataGuidance"
    ],
    "id": "INC-00132",
    "year": 2021,
    "lat": 43.2341813,
    "lng": -86.2483921,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Health Net",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2021-09-12",
    "disclosure_date": "2021-12-22",
    "executive_summary": "On Oct. 27, 2021, TTEC informed Health Net that some of our member information was involved in a cyber incident. TTEC had the incident between March 4, 2021 and Sept. 12, 2021. During that time, an unauthorized actor viewed or downloaded our data files stored on TTEC\u2019s systems. Upon learning of the cyber incident, TTEC instantly took measures to contain the incident. They began an investigation. They engaged cyber security firms with experience in these matters. Law enforcement was notified, and TTEC worked to support its investigation. The forensic investigation is now complete. Your informat",
    "attack_type": "Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Law enforcement notified', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/Health%20Net%20-%20TTEC%20Notification%20Letter.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00133",
    "year": 2021,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Health Net Community Solutions, Inc.",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Woodland Hills",
    "hq_county": "Los Angeles",
    "discovery_date": "2021-01-20 to 2021-01-22 (Accellion FTA exploit)",
    "disclosure_date": "2021-03-24",
    "executive_summary": "Health Net Community Solutions was affected by a cyberattack on Accellion's File Transfer Appliance (FTA) product. Unauthorized actors exploited zero-day vulnerabilities to steal data.",
    "attack_type": "Hacking/IT Incident \u2014 Supply chain attack via third-party file transfer software (Accellion FTA zero-day exploitation); data extortion without encryption",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P) ransomware group (associated with FIN11/TA505)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 686556,
    "residents_affected_in_state": "Not separately reported (CA Medi-Cal members primarily affected)",
    "financial_impact": "$10 million class action settlement (Health Net Defendants nationwide); Accellion paid $8.1M settlement",
    "operational_impact": "Accellion FTA service subsequently discontinued (April 30, 2021)",
    "remediation_disclosed": "Discontinued use of Accellion FTA; Accellion fixed vulnerabilities; credit monitoring offered",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/more-than-1-2-million-health-net-members-affected-by-accellion-cyberattack/"
    ],
    "confidence_notes": "Part of broader Accellion FTA attack affecting 100+ organizations globally. Health Net reported three separate entities totaling 1,236,902 individuals: Health Net Community Solutions (686,556), Health Net of California (523,709), and Health Net Life Insurance (26,637).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00134",
    "year": 2021,
    "lat": 34.1684,
    "lng": -118.6059,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Health Net of California, Inc.",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Woodland Hills",
    "hq_county": "Los Angeles",
    "discovery_date": "2021-01-20 to 2021-01-22 (Accellion FTA exploit)",
    "disclosure_date": "2021-03-24",
    "executive_summary": "Health Net of California affected by same Accellion FTA zero-day cyberattack. Names, addresses, dates of birth, insurance ID numbers, and health information stolen.",
    "attack_type": "Hacking/IT Incident \u2014 Supply chain attack via Accellion FTA zero-day; data extortion",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "reported",
    "individuals_affected_reported": 523709,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of $10M Health Net class action settlement",
    "operational_impact": "Accellion FTA discontinued post-breach",
    "remediation_disclosed": "Same as Health Net Community Solutions - FTA discontinued; credit monitoring offered",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/more-than-1-2-million-health-net-members-affected-by-accellion-cyberattack/",
      "https://oag.ca.gov/system/files/Health%20Net%20of%20California%20-%20Accellion%20Breach%20Notice%20Letter.pdf"
    ],
    "confidence_notes": "Separate OCR filing for same Accellion incident as Health Net Community Solutions. Part of broader coordinated attack. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00135",
    "year": 2021,
    "lat": 34.1684,
    "lng": -118.6059,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Howard University College of Dentistry",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "DC",
    "hq_city": "Washington",
    "hq_county": "District of Columbia",
    "discovery_date": "2021-09-03",
    "disclosure_date": "2021-12-10",
    "executive_summary": "Howard University College of Dentistry in Washington, DC discovered a ransomware attack on September 3, 2021. Unauthorized individuals gained access to the network and deployed ransomware. Up to 80,915 patients had their PHI potentially compromised including dental records and treatment information.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 80915,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems encrypted; dental records compromised; 80K+ patients affected",
    "remediation_disclosed": "Systems restored; law enforcement notified; HHS OCR breach filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/ransomware-attack-affects-81000-howard-university-college-of-dentistry-patients/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach report; HIPAA Journal reporting",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00136",
    "year": 2021,
    "lat": 38.9072,
    "lng": -77.0369,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Humana Inc",
    "organization_type": "Health Plan / Insurer (Multistate)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Louisville, KY (multistate)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2021-08-25",
    "disclosure_date": "2021-12-06",
    "executive_summary": "Team Alvarez Insurance Services (\u201cTeam Alvarez\u201d) was recently the victim of a ransomware attack beginning on August 25, 2021. On August 25, 2021, upon discovery of the incident, Team Alvarez initiated a review of the incident and engaged legal counsel. As a result of the attack, several of Team Alvarez\u2019 servers were encrypted and some of your personal information contained on insurance enrollment forms may have been accessed by an unauthorized individual. Information Affected The information tha",
    "attack_type": "Ransomware / Third-Party Vendor Breach",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Alvarez%20member%20notification_Nov2021-Reviewed%20-%20381152.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00137",
    "year": 2021,
    "lat": 35.487866270723856,
    "lng": -120.64576095996841,
    "is_multistate": true,
    "hq_outside_state": "Louisville",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Intermountain Healthcare",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "UT",
    "hq_city": "Salt Lake City",
    "hq_county": "Salt Lake",
    "discovery_date": "2021-05-17",
    "disclosure_date": "2021-07-19",
    "executive_summary": "Intermountain Healthcare was affected by a cyberattack on its business associate Elekta, a cancer treatment software provider. Four specialty oncology clinics in southern Nevada (Intermountain-affiliated) were impacted. Patient data including names and scanned image files (potentially including medical imaging, intake forms, Social Security numbers, dates of birth, demographic information, and insurance cards) may have been accessible to unauthorized individuals between April 6 and April 20, 2021. Total number of affected Intermountain patients was not publicly disclosed.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (Elekta attacker)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Some cancer treatment procedures affected at four Nevada specialty clinics; Utah/Idaho facilities not impacted",
    "remediation_disclosed": "Elekta migrated to new cloud system; Intermountain reviewed vendor security policies",
    "primary_source_url": "https://www.healthcareitnews.com/news/intermountain-healthcare-patient-data-breached-security-incident",
    "secondary_source_urls": [
      "https://www.auntminnie.com/imaging-informatics/enterprise-imaging/pacs-vna/article/15628853/intermountain-facilities-affected-by-elekta-data-breach"
    ],
    "confidence_notes": "Moderate confidence; number of patients not disclosed; incident confirmed by Intermountain spokesperson",
    "sources_used": [
      "Healthcare IT News, AuntMinnie"
    ],
    "id": "INC-00138",
    "year": 2021,
    "lat": 40.7608,
    "lng": -111.891,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Johnson Memorial Health",
    "organization_type": "Community Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Franklin",
    "hq_county": "Johnson",
    "discovery_date": "2021-10-01",
    "disclosure_date": "2021-10-07",
    "executive_summary": "Hive ransomware group attacked Johnson Memorial Health on October 1, 2021. Hackers gained network access at 10:31 PM and deployed ransomware at 10:33 PM \u2014 just 2 minutes later. The hospital's IT department detected the anomaly at 10:40 PM and shut down the network by 10:45 PM. A $3 million Bitcoin ransom demand was refused. Ambulances were diverted; staff reverted to pen-and-paper operations. Recovery took nearly 6 months to reach near-normal operations. The revenue cycle was not fully recovered for years; cyber insurance claim remained unpaid nearly 2 years later. Annual insurance premium increased 60%.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Hive ransomware",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Indiana (Johnson County and surrounding counties)",
    "financial_impact": "$3M ransom demanded (not paid); months of billing revenue lost; cyber insurance claim unpaid for 2+ years; 60% premium increase",
    "operational_impact": "Ransomware encrypted network; ambulance diversions; pen-and-paper operations for weeks; unable to bill insurance/Medicare/Medicaid for months; near-6-month recovery",
    "remediation_disclosed": "Yes \u2014 network rebuilt; law enforcement engaged; no ransom paid; recovery ongoing",
    "primary_source_url": "https://www.hipaajournal.com/ransomware-deployed-2-minutes-after-hackers-gained-access-to-johnson-memorial-healths-network/",
    "secondary_source_urls": [
      "https://www.npr.org/sections/health-shots/2023/05/08/1172569347/cyberattacks-on-health-care-are-increasing-inside-one-hospitals-fight-to-recover",
      "https://kffhealthnews.org/news/article/what-one-hospitals-slow-recovery-from-a-cyberattack-means-for-patients/",
      "https://ipmnewsroom.org/a-hospital-went-dark-after-it-was-hacked-its-still-reeling-two-years-later/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, NPR Side Effects Public Media, KFF Health News in-depth investigation. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Entrepreneur",
      "HHS OCR",
      "HIPAA Journal",
      "Illinois Newsroom/IPM News",
      "KFF Health News",
      "NPR/Side Effects Public Media"
    ],
    "id": "INC-00139",
    "year": 2021,
    "lat": 39.4149034,
    "lng": -85.0563234,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "La Clinica de La Raza, Inc. (La Clinica)",
    "organization_type": "Federally Qualified Health Center (FQHC)",
    "organization_type_bucket": "FQHC / Community health",
    "state": "CA",
    "hq_city": "Oakland, CA",
    "hq_county": "Alameda County",
    "discovery_date": "2021-01-12",
    "disclosure_date": "2021-03-29",
    "executive_summary": "On January 28, 2021, La Clinica became aware that malware had been deployed on certain La Clinica systems which store information, including personal information, for the organization. Upon learning of the incident, La Clinica immediately took steps to stop access to these systems, including permanently disconnecting the affected systems from other La Clinica systems and its overall network. La Clinica also began an immediate investigation of the incident with the support of a third-party forensics company. On February 26, 2021, La Clinica\u2019s investigation determined that the malware was deploy",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Law enforcement notified', 'Forensic investigation conducted', 'Additional security measures implemented']",
    "primary_source_url": "https://oag.ca.gov/system/files/La%20Clinica%20Adult%20and%20Minor%20English%20and%20Spanish%20Patient%20Privacy%20Notification%20Sample%20Proof.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00140",
    "year": 2021,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Lab Logistics",
    "organization_type": "Clinical Laboratory",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "CA",
    "hq_city": "Unknown",
    "hq_county": "Unknown",
    "discovery_date": "2021-07-12",
    "disclosure_date": "2021-11-09",
    "executive_summary": "We recently discovered unauthorized access to our network occurred on or around July 12, 2021.",
    "attack_type": "Hacking / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals']",
    "primary_source_url": "https://oag.ca.gov/system/files/Lab%20Logistics%20LLC%20-%20L01%20%5Bredacted%5D%20%289946513x7AB84%29.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00141",
    "year": 2021,
    "lat": 36.81861440609833,
    "lng": -118.81768000708252,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Lake Region Healthcare",
    "organization_type": "Regional Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Fergus Falls",
    "hq_county": "Otter Tail",
    "discovery_date": "2020-12-22",
    "disclosure_date": "2021-01-07",
    "executive_summary": "Lake Region Healthcare was hit with a ransomware attack first detected December 22, 2020, affecting locations in Fergus Falls, Battle Lake, Ashby, and Barnesville, Minnesota. EHR downtime procedures were immediately implemented. The attack prompted contact with federal and local law enforcement. Third-party security specialists were engaged. No data exfiltration was confirmed at the time of initial reporting. The health system had previously implemented downtime protocols which enabled continued patient care.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Ryuk ransomware suspected given timing of broader Ryuk campaign)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Minnesota residents (west-central region)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR downtime at multiple locations; patient care appointments impacted; some services operated on alternative systems",
    "remediation_disclosed": "Yes \u2014 third-party forensics engaged; systems restored; law enforcement notified",
    "primary_source_url": "https://www.hipaajournal.com/lake-region-healthcare-recovering-from-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366595425/Minnesotas-Lake-Region-Healthcare-Recovering-From-Ransomware-Attack"
    ],
    "confidence_notes": "Moderate confidence. HIPAA Journal and TechTarget reporting; no HHS OCR breach portal entry identified with patient count.",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget/HealthITSecurity"
    ],
    "id": "INC-00142",
    "year": 2021,
    "lat": 46.283015,
    "lng": -96.077558,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Lifespan Corporation (RI - email breach)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "RI",
    "hq_city": "Providence",
    "hq_county": "Providence",
    "discovery_date": "2020-02-01",
    "disclosure_date": "2021-05-01",
    "executive_summary": "Lifespan Corporation, Rhode Island's largest health system operating Rhode Island Hospital, Miriam Hospital, Newport Hospital, and Bradley Hospital, paid a $1,040,000 HIPAA settlement in 2021 following a phishing attack in 2017 that compromised email accounts. The settlement, while related to a 2017 incident, was resolved within the 2019-2026 scope. A separate 2020 incident also occurred involving email account compromise. The 2017 incident exposed PHI of 20,431 individuals.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 20431,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$1,040,000 HHS OCR HIPAA settlement (2021)",
    "operational_impact": "RI hospital network email accounts compromised; PHI of 20,431 individuals exposed",
    "remediation_disclosed": "HHS OCR settlement with corrective action plan; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR settlement well documented; RI largest health system; settlement within scope period; underlying incident 2017/2020",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00143",
    "year": 2021,
    "lat": 41.824,
    "lng": -71.4128,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Lincare Holdings Inc.",
    "organization_type": "Home Health / Respiratory Care (Multistate)",
    "organization_type_bucket": "Home health / Long-term care",
    "state": "CA",
    "hq_city": "Clearwater, FL (multistate)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2021-09-10",
    "disclosure_date": "2021-11-24",
    "executive_summary": "Lincare took immediate action after learning of the incident to secure its network and launched an investigation, including working with outside cybersecurity experts to determine the source of the activity and potential impact on Lincare\u2019s network. The investigation confirmed that certain systems may have first been accessed on September 10, 2021. The unauthorized access was blocked by September 29, 2021. A comprehensive review of all potentially impacted data has commenced and remains ongoing.",
    "attack_type": "Hacking / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Lincare%20-%20Sample%20Notification.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00144",
    "year": 2021,
    "lat": 35.39078697532596,
    "lng": -119.61696294901284,
    "is_multistate": true,
    "hq_outside_state": "Clearwater",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Memorial Hermann Health System (MedData breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2020-12-01",
    "disclosure_date": "2021-03-31",
    "executive_summary": "Memorial Hermann Health System notified patients of a breach involving MedData, a revenue management vendor. A former MedData employee had saved patient files to personal folders on a public-facing website sometime before September 2019, and these files were discoverable via web scraping. In December 2020, Memorial Hermann was notified that patient data was accessible. The breach exposed names, addresses, dates of birth, SSNs, diagnoses, claim information, and health insurance details. The number of affected patients was not publicly disclosed.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate Insider / Unauthorized Disclosure",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Former MedData employee (insider)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 6260,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "MedData implemented additional security controls; blocked file sharing websites; updated data policies; law enforcement informed; credit monitoring offered",
    "primary_source_url": "https://abc13.com/post/memorial-hermann-hospital-data-breach-meddata-meddate-social-security-patient-information/5374994/",
    "secondary_source_urls": [
      "https://www.click2houston.com/news/local/2022/02/08/over-6000-memorial-hermann-patients-information-leaked-in-contractors-data-breach-vendor-says/"
    ],
    "confidence_notes": "Moderate confidence; two separate MedData/Advent Health breach notices found; exact total number unclear",
    "sources_used": [
      "ABC13 Houston, Click2Houston/KPRC 2"
    ],
    "id": "INC-00145",
    "year": 2021,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Metro Presort, Inc. (Oregon Healthcare Clients)",
    "organization_type": "Business Associate (Print/Mail Vendor) \u2014 Healthcare clients include Oregon Heart Center and Salem Clinic",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2019-05-15",
    "disclosure_date": "2021-01-01",
    "executive_summary": "Metro Presort, a print and mail services vendor serving multiple Oregon healthcare clients, suffered a RYUK ransomware attack on May 6\u201315, 2019. The breach compromised protected health information of 38,387 individuals nationally. After initial investigation concluded the data had not been accessed, a reinvestigation in 2020 determined PHI may have been compromised, leading to delayed notifications starting January 2021. Affected Oregon healthcare clients included Oregon Heart Center (3,172 patients) and Salem Clinic (20,928 patients).",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "RYUK ransomware operators",
    "attribution_status": "unknown",
    "individuals_affected_reported": 38387,
    "residents_affected_in_state": 24100,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Extended notification delay due to reinvestigation; healthcare client patient data exposed",
    "remediation_disclosed": "Reinvestigation conducted; individual notifications sent Jan 2021; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/reinvestigation-of-2019-metro-presort-ransomware-attack-reveals-phi-may-have-been-compromised/",
    "secondary_source_urls": [
      "https://oregonheartcenter.com/metro-presort-data-breach-info/"
    ],
    "confidence_notes": "HHS OCR breach portal filing (38,387 individuals); HIPAA Journal reporting on reinvestigation; Oregon Heart Center primary notice published",
    "sources_used": [
      "HIPAA Journal",
      "Oregon Heart Center patient notice",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00146",
    "year": 2021,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MultiCare Health System / Woodcreek Provider Services (via Netgain Technology)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Tacoma",
    "hq_county": "Pierce",
    "discovery_date": "2020-12-03",
    "disclosure_date": "2021-03-09",
    "executive_summary": "Netgain Technology, an IT vendor serving Woodcreek Provider Services (a MultiCare-affiliated medical practice management company), was hit by ransomware between November 23 and December 3, 2020. Attackers gained access to an archive server containing scanned clinical and financial records. More than 207,000 patients and employees of Woodcreek and MultiCare pediatric clinics were affected. A ransom was paid and the data was reportedly returned. Compromised data included names, addresses, Social Security numbers, medical records, bank account numbers, and insurance information.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ransomware operator)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 207000,
    "residents_affected_in_state": "Majority WA-based (Puget Sound pediatric clinics)",
    "financial_impact": "Ransom paid (amount undisclosed)",
    "operational_impact": "Archive server with clinical and financial records compromised; primary EMR unaffected",
    "remediation_disclosed": "Ransom paid; data reportedly returned; security policies revised; notifications sent",
    "primary_source_url": "https://www.hipaajournal.com/210000-multicare-health-system-woodcreek-healthcare-patients-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.kiro7.com/news/south-sound-news/data-breach-exposes-information-more-than-200000-multicare-staff-patients/BNKK6ZIIRZHTXAKG5BDJ6LIQLY/",
      "https://www.securedata.com/blog/multicare-data-breach-exposes-patient-records"
    ],
    "confidence_notes": "Well documented; reported to WA AG and HHS OCR; 207,000+ figure confirmed by HIPAA Journal",
    "sources_used": [
      "HIPAA Journal",
      "KIRO7 News",
      "Secure Data"
    ],
    "id": "INC-00147",
    "year": 2021,
    "lat": 47.2529,
    "lng": -122.4443,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "NEC Networks, LLC d/b/a CaptureRx",
    "organization_type": "Business Associate (Pharmacy Technology)",
    "organization_type_bucket": "Pharmacy",
    "state": "TX",
    "hq_city": "San Antonio",
    "hq_county": "Bexar",
    "discovery_date": "2021-02-19",
    "disclosure_date": "2021-05-05",
    "executive_summary": "CaptureRx, a San Antonio-based pharmacy technology company, suffered a ransomware attack on February 19, 2021. The attack resulted in unauthorized access and acquisition of protected health information for approximately 2.4 million patients of its healthcare provider clients across the US. Files containing PHI were accessed and stolen, affecting numerous hospitals and health systems that used CaptureRx services.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2420000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4.75M class action settlement (2022)",
    "operational_impact": "Disrupted pharmacy operations for client organizations",
    "remediation_disclosed": "Systems restored via backups; forensic investigation completed; notifications sent",
    "primary_source_url": "https://www.hipaajournal.com/capturerx-ransomware-attack-affects-multiple-healthcare-provider-clients/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/class-action-lawsuit-filed-over-february-2021-capturerx-data-breach",
      "https://www.hipaajournal.com/capturerx-proposes-4-75-million-settlement-to-end-data-breach-litigation/"
    ],
    "confidence_notes": "High confidence; OCR confirms TX state; HHS portal listed 1,656,569 initially, later revised upward to ~2.4M with client reports",
    "sources_used": [
      "HIPAA Journal, ClassAction.org"
    ],
    "id": "INC-00148",
    "year": 2021,
    "lat": 29.4241,
    "lng": -98.4936,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Nebraska Medicine / University of Nebraska Medical Center",
    "organization_type": "Academic Medical Center / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NE",
    "hq_city": "Omaha",
    "hq_county": "Douglas",
    "discovery_date": "2020-09-20",
    "disclosure_date": "2021-02-05",
    "executive_summary": "Nebraska Medicine, the clinical partner of the University of Nebraska Medical Center in Omaha, suffered a malware/ransomware attack between August 27\u2013September 20, 2020. An unauthorized party installed malware on the shared Nebraska Medicine/UNMC computer network, gaining access and exfiltrating patient data before deploying ransomware. Approximately 219,000 individuals were affected. Data exposed included names, addresses, dates of birth, medical record numbers, health insurance information, physician notes, laboratory results, imaging, diagnoses, treatment information, prescriptions, and \u2014 for some \u2014 Social Security numbers and driver's license numbers. A limited number of patients from Faith Regional Health Services, Great Plains Health, and Mary Lanning Healthcare (whose information was in the Nebraska Medicine/UNMC network) were also affected. A class action settlement was reached in 2021.",
    "attack_type": "Malware / Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 219000,
    "residents_affected_in_state": "Primarily Nebraska residents; some from surrounding states",
    "financial_impact": "Class action settlement approved 2021 \u2014 up to $300 per class member for ~126,000 notified individuals",
    "operational_impact": "Patient appointments postponed; staff charted by hand; access to patient portal and EHR disrupted; operations impacted for ~24 days",
    "remediation_disclosed": "Yes \u2014 malware removed, systems restored, incident response protocols activated, law enforcement notified, credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/nebraska-medicine-notifies-219000-patients-about-september-2020-malware-attack/",
    "secondary_source_urls": [
      "https://www.infosecurity-magazine.com/news/nebraska-medicine-data-breach/",
      "https://www.bankinfosecurity.com/nebraska-medicine-settlement-a-16834"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report, HIPAA Journal, InfoSecurity Magazine, BankInfoSecurity.",
    "sources_used": [
      "HIPAA Journal",
      "InfoSecurity Magazine",
      "BankInfoSecurity",
      "HHS OCR"
    ],
    "id": "INC-00149",
    "year": 2021,
    "lat": 41.2565,
    "lng": -95.9345,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Netgain Technology, LLC (Healthcare Sector Impact)",
    "organization_type": "BA/Vendor (IT Managed Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MN",
    "hq_city": "Eden Prairie",
    "hq_county": "Hennepin",
    "discovery_date": "2020-12-01",
    "disclosure_date": "2021-01-13",
    "executive_summary": "In late 2020, Netgain Technology, a Minnesota-based managed IT services provider serving healthcare clients, experienced a ransomware attack that affected multiple healthcare customers including County of Cook (Cook County Health, IL), Carle Foundation Hospital, and numerous community health centers and FQHCs. Netgain paid the ransom and worked to recover customer data. The breach exposed patient data across dozens of healthcare organizations that had entrusted their IT infrastructure to Netgain. The incident highlighted the systemic risk of healthcare organizations relying on third-party IT managed service providers. Affected healthcare organizations included a consortium of Federally Qualified Health Centers (FQHCs), making this a landmark case for community health center cybersecurity risk.",
    "attack_type": "Ransomware / Third-Party IT MSP Compromise",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1700000,
    "residents_affected_in_state": "MN IL and other states; exact counts vary by client organization",
    "financial_impact": "Ransom paid by Netgain. Individual client remediation costs not aggregated publicly. Class action lawsuits filed against Netgain.",
    "operational_impact": "Multiple healthcare organizations' IT systems disrupted. EHR access interrupted for FQHC clients. Cook County Health operations impacted. Patient care disruptions across multiple facilities.",
    "remediation_disclosed": "Ransom paid. Client systems restored. Notifications mailed by affected healthcare clients. HHS OCR breach notifications filed by multiple clients separately.",
    "primary_source_url": "https://www.hipaajournal.com/netgain-technology-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/netgain-ransomware-healthcare/595000/",
      "https://databreaches.net/category/breach-incidents/netgain/"
    ],
    "confidence_notes": "Moderate-High confidence. Netgain ransomware confirmed by multiple healthcare client breach notices. Exact aggregate affected count estimated from client reports; no single Netgain HHS OCR filing found. Individual client counts vary.",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare Dive",
      "DataBreaches.Net"
    ],
    "id": "INC-00150",
    "year": 2021,
    "lat": 44.8546856,
    "lng": -93.470786,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "New England Life Care (ME home health)",
    "organization_type": "Healthcare Provider (Home Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Bangor",
    "hq_county": "Penobscot",
    "discovery_date": "2021-08-01",
    "disclosure_date": "2021-11-01",
    "executive_summary": "New England Life Care, a Maine-based home infusion therapy and specialty pharmacy company, reported a data security incident involving unauthorized access to patient health and financial information. The breach affected patients receiving home infusion services across northern New England.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Home infusion patient data compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; Maine home health specialty pharmacy; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00151",
    "year": 2021,
    "lat": 44.8016,
    "lng": -68.7712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Newberry County Memorial Hospital (Ryuk Ransomware) \u2014 SC",
    "organization_type": "Healthcare Provider / Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Newberry",
    "hq_county": "Newberry",
    "discovery_date": "2021-02-21",
    "disclosure_date": "2021-03-01",
    "executive_summary": "Newberry County Memorial Hospital in South Carolina was hit by Ryuk ransomware on February 21, 2021 at 0200. IT staff locked down all systems by 0315. According to hospital administration, no patient or employee confidential information was compromised. Hospital recovered through backups and manual procedures. This is a notable SC healthcare ransomware event.",
    "attack_type": "Ransomware (Ryuk)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Ryuk",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 0,
    "residents_affected_in_state": 0,
    "financial_impact": "Operational disruption costs; no ransom reported paid",
    "operational_impact": "All hospital systems locked down; manual operations; no patient data confirmed compromised",
    "remediation_disclosed": "Systems locked down within 75 minutes; backups used for recovery; hospital staff shifted to manual procedures",
    "primary_source_url": "https://www.masc.sc/sites/default/files/uploads/affiliated-associations/ransomware-mtasc-9-25-web.pdf",
    "secondary_source_urls": [
      "https://www.facebook.com/hacknoticefeed/posts/fyi-sc-newberry-county-memorial-hospital-experienced-ransomware-attack-last-mont/290612342617803/"
    ],
    "confidence_notes": "Medium confidence \u2014 MASC presentation references the incident; Facebook Hacknotice feed reported it. Hospital claimed no data compromise. Including as operational ransomware incident.",
    "sources_used": [
      "Municipal Association of South Carolina (MASC) Presentation",
      "HackNotice"
    ],
    "id": "INC-00152",
    "year": 2021,
    "lat": 34.3266879,
    "lng": -81.5830086,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Northern California Medical Associates, Inc.",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "Santa Rosa, CA",
    "hq_county": "Sonoma County",
    "discovery_date": "2021-02-19",
    "disclosure_date": "2021-05-03",
    "executive_summary": "Upon detection of the activity, we shut down portions of our network, reset passwords, and commenced an investigation that included working with computer forensic specialists to determine the nature and scope of the event. During the course of the investigation, we learned that unauthorized access to the NCMA network began on February 19, 2021 and culminated in unauthorized encryption of certain NCMA servers and workstations on March 3, 2021. On or about March 29, 2021, we confirmed that certain",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/NCMA%20-%20Substitute%20Notice%20of%20Data%20Event.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00153",
    "year": 2021,
    "lat": 38.4404,
    "lng": -122.7141,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Northwestern Medicine (Lurie Children's 2020 Netgain / Allina Apple Valley connection)",
    "organization_type": "Nonprofit Academic Medical System",
    "organization_type_bucket": "Other healthcare entity",
    "state": "MN",
    "hq_city": "Minneapolis (Apple Valley Clinic \u2014 Allina Health)",
    "hq_county": "Dakota",
    "discovery_date": "2020-12-02",
    "disclosure_date": "2021-03-01",
    "executive_summary": "Apple Valley Clinic, part of Allina Health in Minnesota, reported a data breach affecting at least 157,939 patients due to a ransomware attack on Netgain Technology LLC, its cloud and technology service vendor. Netgain experienced a ransomware attack in November 2020. On December 2, 2020, Netgain informed affected clients including Apple Valley Clinic. Compromised data included names, DOBs, SSNs, bank account information, patient billing information, and patient symptoms and diagnoses.",
    "attack_type": "Ransomware (Third-Party Vendor \u2014 cloud/IT service provider)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown ransomware group (Netgain breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 157939,
    "residents_affected_in_state": "Minnesota residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Netgain cloud services disrupted; Apple Valley Clinic/Allina data compromised",
    "remediation_disclosed": "Yes \u2014 Netgain contained attack; patients notified; Apple Valley Clinic issued breach notices",
    "primary_source_url": "https://caseygerry.com/blog/allina-health-apple-valley-clinic-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. CaseyGerry attorneys (class action); HIPAA Journal confirmed count.",
    "sources_used": [
      "CaseyGerry Trial Lawyers"
    ],
    "id": "INC-00154",
    "year": 2021,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Northwestern Memorial Healthcare / Elekta breach",
    "organization_type": "Nonprofit Academic Medical System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2021-04-20",
    "disclosure_date": "2021-07-06",
    "executive_summary": "Elekta, Inc. \u2014 a radiation therapy and radiosurgery equipment provider \u2014 suffered a ransomware attack between April 2 and April 20, 2021. The attack breached Elekta's cloud-based data storage, exposing PHI of patients at numerous hospital clients. Northwestern Memorial Healthcare (Chicago area, 9 hospitals) was the largest single victim, with 1.4 million patient records (including 201,197 oncology patients) exposed. Overall, 3.1 million individuals across multiple health systems had data compromised. Genetic information was among the types exposed for Illinois patients, triggering GIPA claims. An $8.9 million joint Elekta/NMH settlement was reached in December 2024.",
    "attack_type": "Ransomware (Third-Party Vendor)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown ransomware group (Elekta breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1400000,
    "residents_affected_in_state": 1400000,
    "financial_impact": "$8.9 million settlement (December 2024); up to $5,000 per class member; up to $1,000 pro-rata cash; additional $1,000 for Illinois GIPA subclass",
    "operational_impact": "Elekta's cloud storage breached; radiation therapy clinical data exposed; genetic information compromised",
    "remediation_disclosed": "Yes \u2014 Elekta contained breach; NMH notified patients; settlement includes enhanced security measures",
    "primary_source_url": "https://www.hipaajournal.com/8-9-million-data-breach-settlement-elekta-northwestern-memorial-healthcare/",
    "secondary_source_urls": [
      "https://hipaatimes.com/8.9m-settlement-reached-in-elekta-and-nmh-data-breach-affect",
      "https://www.techtarget.com/healthtechsecurity/news/366595205/Northwestern-Memorial-HealthCare-Latest-Victim-of-Elektas-PHI-Data-Breach"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, HIPAA Times/Paubox, TechTarget/HealthTech Security.",
    "sources_used": [
      "HIPAA Journal",
      "HIPAA Times/Paubox",
      "TechTarget"
    ],
    "id": "INC-00155",
    "year": 2021,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Oklahoma State University \u2013 Center for Health Sciences (OSU-CHS)",
    "organization_type": "Academic Medical Center / Teaching Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Tulsa",
    "hq_county": "Tulsa",
    "discovery_date": "2018-01-05",
    "disclosure_date": "2021-01-05",
    "executive_summary": "OSU-CHS suffered unauthorized server access November 7, 2017 to January 5, 2018, exposing PHI of 279,865 patients. OCR imposed $875,000 settlement in 2022 for HIPAA Security Rule violations. Included because OCR enforcement was finalized 2022.",
    "attack_type": "Hacking / Server Access",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 279865,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$875,000 OCR settlement (2022)",
    "operational_impact": "Server containing patient PHI compromised",
    "remediation_disclosed": "OCR settlement; corrective action plan implemented",
    "primary_source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/osu-center-for-health-sciences/index.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthcare-data-breach-statistics/"
    ],
    "confidence_notes": "High confidence; OCR published $875K settlement 2022; breach 2017-2018 but enforcement 2022; HIPAA Journal confirmed",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00156",
    "year": 2021,
    "lat": 36.154,
    "lng": -95.9928,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "One Community Health",
    "organization_type": "Community Health Center",
    "organization_type_bucket": "FQHC / Community health",
    "state": "CA",
    "hq_city": "Sacramento, CA",
    "hq_county": "Sacramento County",
    "discovery_date": "2021-04-19",
    "disclosure_date": "2021-11-22",
    "executive_summary": "As part of our investigation, we worked very closely with cybersecurity professionals to quickly isolate the affected systems and identify the nature of the attack. Based on our comprehensive investigation and document review, which concluded on October 6, 2021, we discovered that your Social Security number and one or more of the following were removed from our network in connection with this incident: full name, date of bi",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/One%20Community%20Health%20-%20Notice%20Letter%20-%20SSN%20Patient%20%28Redacted%29%20%289972368x7AB84%29.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00157",
    "year": 2021,
    "lat": 38.5816,
    "lng": -121.4944,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Orlando Family Physicians, LLC (OFP)",
    "organization_type": "Healthcare Provider (Multi-Specialty Physician Group)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Orlando",
    "hq_county": "Orange",
    "discovery_date": "2021-04-15",
    "disclosure_date": "2021-07-20",
    "executive_summary": "On April 15, 2021, an attacker gained access to an OFP employee email account via phishing, then accessed three additional employee emails. By May 21, OFP determined the attacker likely accessed patient PII, though the attack appeared designed to commit financial fraud. 447,426 patients were notified. Exposed data varied by individual and could include names, demographics, diagnoses, prescriptions, Medicare beneficiary numbers, SSNs, and passports.",
    "attack_type": "Phishing / Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 447426,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action settlement (closed; settlement amount not separately confirmed)",
    "operational_impact": "4 employee email accounts compromised; potential financial fraud attempted",
    "remediation_disclosed": "Affected accounts terminated; third-party forensics; security measures enhanced; staff retrained",
    "primary_source_url": "https://www.scworld.com/analysis/nearly-450k-patients-impacted-by-orlando-family-physicians-phishing-attack",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/orlando-family-physicians-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "HHS OCR lists 447,426 affected. SC Media and Top Class Actions corroborate.",
    "sources_used": [
      "SC Media",
      "Top Class Actions"
    ],
    "id": "INC-00158",
    "year": 2021,
    "lat": 28.5383,
    "lng": -81.3792,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Personal Touch Holding Corp.",
    "organization_type": "Healthcare Provider (Home Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Lake Success",
    "hq_county": "Nassau",
    "discovery_date": "2021-01-27",
    "disclosure_date": "2021-07-22",
    "executive_summary": "Personal Touch Holding Corp., a New York-based home health care company, suffered a ransomware attack in January 2021 initiated via a phishing email containing a malicious Excel file. The attack compromised the protected health information and personal data of approximately 753,107 patients and employees. The New York Attorney General secured a $350,000 settlement in October 2023, finding that Personal Touch had poor security practices and inadequate HIPAA training.",
    "attack_type": "Ransomware (phishing initial vector)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 753107,
    "residents_affected_in_state": 316845,
    "financial_impact": "$350,000 NY AG settlement (2023); class action settlement pending",
    "operational_impact": "Home health patient and employee records compromised; PHI and SSNs exposed",
    "remediation_disclosed": "Outside cybersecurity experts engaged; law enforcement notified; NY AG settlement with corrective action plan",
    "primary_source_url": "https://ag.ny.gov/press-release/2023/attorney-general-james-secures-350000-long-island-home-health-care-company",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/personal-touch-holding-corp-class-action-data-breach-settlement/",
      "https://blog.cloudticity.com/personal-touch-settles-privacy-lawsuit-ransomware-attack"
    ],
    "confidence_notes": "NY AG press release confirms 316,845 NY residents; HHS OCR breach report shows 753,107 total; widely reported",
    "sources_used": [
      "NY AG",
      "HIPAA Journal",
      "Cloudticity"
    ],
    "id": "INC-00159",
    "year": 2021,
    "lat": 40.7706572,
    "lng": -73.7176312,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Practicefirst Medical Management Solutions (PBS Medcode Corp.)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "Buffalo",
    "hq_county": "Erie",
    "discovery_date": "2020-12-25",
    "disclosure_date": "2021-07-02",
    "executive_summary": "Professional Business Systems Inc., doing business as Practicefirst Medical Management Solutions and PBS Medcode Corp., a New York medical billing and practice management company, suffered an attempted ransomware attack in December 2020. Before deploying ransomware, attackers exfiltrated files containing protected health information and personal data of 1,210,688 patients and employees of its healthcare provider clients. Compromised data included names, SSNs, diagnoses, financial information, and employee credentials.",
    "attack_type": "Ransomware with prior data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1210688,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI and employee credentials of 1.2M+ individuals exfiltrated; multiple healthcare provider clients affected",
    "remediation_disclosed": "HHS OCR notified; affected individuals notified; law enforcement engaged",
    "primary_source_url": "https://www.prnewswire.com/news-releases/practicefirst-notifies-affected-individuals-of-data-incident-301324866.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/largest-healthcare-data-breaches-of-2021/"
    ],
    "confidence_notes": "HHS OCR breach report confirms 1,210,688; PR Newswire official notification; included in HIPAA Journal 2021 largest breaches list",
    "sources_used": [
      "PR Newswire",
      "HIPAA Journal"
    ],
    "id": "INC-00160",
    "year": 2021,
    "lat": 42.8864,
    "lng": -78.8784,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Professional Business Systems, Inc. d/b/a Practicefirst Medical Management Solutions and PBS Medcode Corp.",
    "organization_type": "BA / Vendor (Medical Management / Billing)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "Amherst",
    "hq_county": "Erie",
    "discovery_date": "2020-12-25",
    "disclosure_date": "2021-07-02",
    "executive_summary": "Practicefirst Medical Management Solutions, a Buffalo-area medical management and billing company, suffered a ransomware attack beginning November 25, 2020, exploiting a critical firewall vulnerability that had been unpatched since January 2019. The attacker exfiltrated approximately 79,000 files containing PHI and personal information of 1.2 million individuals (428,000 New Yorkers) before deploying ransomware on December 25, 2020. Practicefirst paid the ransom on January 9, 2021, and obtained an attestation that the exfiltrated data had been destroyed. The New York Attorney General fined Practicefirst $550,000 for patch management failures and HIPAA violations in May 2023. Patient notifications were not completed until July 2021, more than 7 months after the breach.",
    "attack_type": "Ransomware / Data Exfiltration (firewall exploit via unpatched vulnerability)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1200000,
    "residents_affected_in_state": 428000,
    "financial_impact": "Ransom paid January 9, 2021 (amount not disclosed). $550,000 NY AG penalty (May 2023). Legal costs from class action and regulatory actions.",
    "operational_impact": "Medical billing and management services disrupted. EHR access disrupted for 114 client practices. No direct patient care disruption.",
    "remediation_disclosed": "Firewall patched (February 25, 2021, ~3 months after breach). Ransom paid with data destruction attestation. NY AG settlement with enhanced security requirements including encryption, MFA, pen testing, vulnerability scans. Individual notifications July 2021.",
    "primary_source_url": "https://www.prnewswire.com/news-releases/practicefirst-notifies-affected-individuals-of-data-incident-301324866.html",
    "secondary_source_urls": [
      "https://ag.ny.gov/sites/default/files/settlements-agreements/Practicefirst%20AOD.pdf",
      "https://www.hipaajournal.com/ny-ag-fines-practicefirst-550000-for-patch-management-failures/",
      "https://www.scworld.com/news/practicefirst-pays-new-york-550k-after-patching-failure-leads-to-2020-breach"
    ],
    "confidence_notes": "High confidence. NY AG AOD (Assurance of Discontinuance) is primary document detailing all facts. Ransom payment confirmed in NY AG investigation findings.",
    "sources_used": [
      "Practicefirst PR Newswire notice",
      "NY AG AOD document",
      "HIPAA Journal",
      "SC Media"
    ],
    "id": "INC-00161",
    "year": 2021,
    "lat": 42.9783924,
    "lng": -78.7997616,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Renown Health",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NV",
    "hq_city": "Reno",
    "hq_county": "Washoe",
    "discovery_date": "2021-05-17",
    "disclosure_date": "2021-07-01",
    "executive_summary": "Renown Health was affected by a cyberattack on its business associate Elekta, a cancer treatment software provider. The incident impacted four specialty oncology clinics in southern Nevada. Patient data including names, Social Security numbers, addresses, dates of birth, diagnoses, medical treatment information, and scanned image files were potentially exposed between April 6 and April 20, 2021. 65,181 Renown patients were affected.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (Elekta attacker)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 65181,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Some cancer treatment procedures impacted; Elekta system shut down for affected clinics",
    "remediation_disclosed": "Elekta migrated data to new-generation cloud system; notifications mailed; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/northwestern-memorial-healthcare-and-renown-health-affected-by-elekta-cyberattack/",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/intermountain-healthcare-patient-data-breached-security-incident",
      "https://www.2news.com/elekta-system-shut-down-for-renown-patients-after-data-breach-in-april/article_e2d603de-eff7-52ea-a861-2ea583a10d8f.html"
    ],
    "confidence_notes": "High confidence; 65,181 confirmed by HIPAA Journal; part of broader Elekta breach affecting 42+ health systems",
    "sources_used": [
      "HIPAA Journal, Healthcare IT News, 2 News (Reno)"
    ],
    "id": "INC-00162",
    "year": 2021,
    "lat": 39.5296,
    "lng": -119.8138,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "ReproSource Fertility Diagnostics, Inc.",
    "organization_type": "Fertility Diagnostics Lab",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "CA",
    "hq_city": "Marlborough, MA (multistate)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2021-08-08",
    "disclosure_date": "2021-10-08",
    "executive_summary": "On August 8, 2021, an unauthorized party accessed the ReproSource network. We discovered ransomware on the morning of August 10, and in less than an hour we severed all network connection activity and contained the incident. We immediately launched a comprehensive investigation to determine the cause and scope of the incident. We retained leading cybersecurity experts to assist with our investigation, confirmed containment of the ransomware, and quickly and securely recovered operations. Additio",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 350000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Quest%20Diagnostics%20Adult%20CM%201yr%2010.6.21%20r6prf.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00163",
    "year": 2021,
    "lat": 36.88594601292007,
    "lng": -119.82083324926225,
    "is_multistate": true,
    "hq_outside_state": "Marlborough",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "SMP Health (St. Margaret's Health \u2014 Spring Valley and Peru, IL)",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Spring Valley",
    "hq_county": "Bureau",
    "discovery_date": "2021-02-01",
    "disclosure_date": "2021-02-01",
    "executive_summary": "St. Margaret's Health (operated by SMP Health), a rural Catholic hospital in Spring Valley, Illinois, suffered a ransomware attack in February 2021 that halted its ability to submit insurance claims, Medicare, and Medicaid reimbursements for months, sending the already financially struggling 120-year-old institution into a financial spiral. The attack, combined with pandemic-related losses and staff shortages, proved fatal: St. Margaret's Health permanently closed both its Spring Valley (44-bed) and Peru (49-bed) hospitals on June 16, 2023 \u2014 believed to be the first U.S. hospital closure publicly attributed in part to a ransomware attack. This is a landmark incident for the sector even though individual PHI counts were not separately disclosed.",
    "attack_type": "Ransomware (billing/claims systems encryption)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "IL; not separately reported",
    "financial_impact": "Not separately disclosed. Attack-caused claims submission failure for months led to financial collapse contributing to hospital closure. OSF Healthcare acquired Peru campus assets.",
    "operational_impact": "Claims submission and billing systems offline for months. Financial collapse. Both hospital locations permanently closed June 16, 2023. Community left without local emergency room and obstetrics services.",
    "remediation_disclosed": "IT systems restored eventually but financial damage was permanent. OSF Healthcare acquired Peru campus. Spring Valley location permanently shuttered.",
    "primary_source_url": "https://www.nbcnews.com/tech/security/illinois-hospital-links-closure-ransomware-attack-rcna85983",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/ransomware-attack-key-factor-in-decision-to-close-rural-illinois-hospital/",
      "https://www.healthcarefinancenews.com/news/cyberattack-partly-blame-st-margarets-health-closing-all-operations",
      "https://www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-attack-partially-to-blame-for-120-year-old-hospital-closure"
    ],
    "confidence_notes": "High confidence on closure link to ransomware. Hospital VP confirmed billing/claims disruption for months in NBC News interview. PHI breach count not separately reported.",
    "sources_used": [
      "NBC News",
      "HIPAA Journal",
      "Healthcare Finance News",
      "BitDefender",
      "Healthcare Finance News"
    ],
    "id": "INC-00164",
    "year": 2021,
    "lat": 41.3275353,
    "lng": -89.1998078,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Saint Alphonsus Health System",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ID",
    "hq_city": "Boise",
    "hq_county": "Ada",
    "discovery_date": "2021-01-01",
    "disclosure_date": "2021-03-04",
    "executive_summary": "Saint Alphonsus Health System (Trinity Health subsidiary, Idaho/Oregon) reported a phishing attack that compromised an employee email account. The breach exposed protected health information of 134,906 patients. Compromised data included patient names, addresses, telephone numbers, dates of birth, email addresses, medical record numbers, treatment information, and billing information; some Social Security numbers may also have been exposed.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 134906,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Notifications sent; credit monitoring offered; Trinity Health committed to protecting PHI",
    "primary_source_url": "https://www.hipaajournal.com/phishing-attack-saint-alphonsus-health-saint-agnes-medical-center/",
    "secondary_source_urls": [
      "https://www.prnewswire.com/news-releases/saint-alphonsus-health-system-responds-to-an-email-security-incident-301240741.html"
    ],
    "confidence_notes": "High confidence; HHS OCR confirmed 134,906; PR Newswire official announcement verified",
    "sources_used": [
      "HIPAA Journal, PR Newswire (Saint Alphonsus official release)"
    ],
    "id": "INC-00165",
    "year": 2021,
    "lat": 43.615,
    "lng": -116.2023,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Salem Clinic, P.C.",
    "organization_type": "Healthcare Provider (Multi-Specialty Clinic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Salem",
    "hq_county": "Marion",
    "discovery_date": "2019-05-15",
    "disclosure_date": "2021-01-01",
    "executive_summary": "Salem Clinic, a large multi-specialty medical clinic in Salem, Oregon, was among the healthcare clients impacted by the Metro Presort RYUK ransomware attack of May 2019. Approximately 20,928 patients of Salem Clinic had their protected health information exposed when Metro Presort's systems were compromised. Notifications were delayed until January 2021 following a reinvestigation that determined PHI had likely been accessible to the ransomware operators.",
    "attack_type": "Ransomware (third-party vendor incident)",
    "attack_category": "Ransomware",
    "threat_actor_name": "RYUK ransomware operators",
    "attribution_status": "unknown",
    "individuals_affected_reported": 20928,
    "residents_affected_in_state": 20928,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI exposed at third-party vendor; delayed notification to patients",
    "remediation_disclosed": "Individual notifications sent; credit monitoring offered (as part of Metro Presort response)",
    "primary_source_url": "https://oregonheartcenter.com/metro-presort-data-breach-info/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/reinvestigation-of-2019-metro-presort-ransomware-attack-reveals-phi-may-have-been-compromised/"
    ],
    "confidence_notes": "Salem Clinic affected party confirmed via Oregon Heart Center breach notice (both Metro Presort clients); Salem Clinic patient count separately reported to HHS OCR",
    "sources_used": [
      "Oregon Heart Center patient notice",
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00166",
    "year": 2021,
    "lat": 44.9429,
    "lng": -123.0351,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sanford Health \u2014 2021 Cyber Incident",
    "organization_type": "Rural Health System (46 hospitals, 224 clinics)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2021-08-04",
    "disclosure_date": "2021-08-05",
    "executive_summary": "Sanford Health, one of the largest rural health systems in the US (serving 250,000+ sq miles across the Midwest), experienced a cybersecurity incident on August 4, 2021 concurrent with the Eskenazi Health attack. Sanford CEO Bill Gassen issued a statement about 'aggressive measures to contain the impact.' Third-party IT security was engaged and federal law enforcement notified. The investigation found no evidence of data compromise, patient, employee, financial, or other data affected. The nature of the attack (whether ransomware or not) was not confirmed publicly.",
    "attack_type": "Cyber Incident (nature unconfirmed; possible ransomware attempt)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "claimed",
    "individuals_affected_reported": "No data compromise confirmed",
    "residents_affected_in_state": "No patient data confirmed compromised",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network disruption; third-party IT security engaged; investigation launched; no confirmed EHR downtime reported",
    "remediation_disclosed": "Yes \u2014 contained; federal law enforcement notified; investigation cleared of data compromise",
    "primary_source_url": "https://www.scworld.com/analysis/sanford-health-eskenazi-health-recovering-from-cyberattacks-in-ehr-downtime",
    "secondary_source_urls": [
      "https://news.sanfordhealth.org/news-release/vendor-for-sanford-health-announces-data-security-event/"
    ],
    "confidence_notes": "Moderate confidence. SC World reporting; Sanford CEO statement. No confirmed data breach; 'cyber incident' designation appropriate.",
    "sources_used": [
      "SC World",
      "Sanford Health News"
    ],
    "id": "INC-00167",
    "year": 2021,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Schneck Medical Center",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Seymour",
    "hq_county": "Jackson",
    "discovery_date": "2021-09-29",
    "disclosure_date": "2021-09-29",
    "executive_summary": "Schneck Medical Center suffered a ransomware attack on or around September 29, 2021, exploiting critical security vulnerabilities identified in a December 2020 risk analysis that the hospital failed to remediate. PHI of 89,707 Indiana residents was exposed including names, addresses, DOBs, SSNs, driver's licenses, financial account information, payment card information, diagnoses, and health insurance information. The hospital failed to issue individual patient notifications until May 13, 2022 \u2014 226 days after discovery. Indiana AG sued and reached a $250,000 settlement in September 2023. A $1.3 million class action settlement was also reached.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 89707,
    "residents_affected_in_state": 89707,
    "financial_impact": "$250,000 Indiana AG settlement penalty; $1.3 million class action settlement",
    "operational_impact": "Significant network disruption; data exfiltrated; operations impacted; recovery took months",
    "remediation_disclosed": "Yes \u2014 information security program mandated within 90 days; incident response plan implemented; staff training required",
    "primary_source_url": "https://www.hipaajournal.com/schneck-medical-center-settles-hipaa-lawsuit-with-indiana-ag/",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/indiana-schneck-medical-center-data-breach-settlement/693256/",
      "https://news.bloomberglaw.com/privacy-and-data-security/indiana-sues-schneck-medical-center-over-2021-data-breach"
    ],
    "confidence_notes": "High confidence. Indiana AG lawsuit, HIPAA Journal, Healthcare Dive, Bloomberg Law.",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare Dive",
      "Bloomberg Law"
    ],
    "id": "INC-00168",
    "year": 2021,
    "lat": 38.9592201,
    "lng": -85.8902547,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Scripps Health",
    "organization_type": "Nonprofit integrated health system (5 acute-care hospitals, 19 outpatient facilities)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Diego",
    "hq_county": "San Diego County",
    "discovery_date": "2021-05-01",
    "disclosure_date": "2021-05-05",
    "executive_summary": "On May 1, 2021, Scripps Health detected a ransomware attack that crippled its internal computer systems for nearly a month. The attack forced the health system to redirect ambulances from four hospitals, cancel scheduled appointments, and revert to paper-based patient charting. Hackers exfiltrated files containing PHI of approximately 147,267 patients (confirmed breach notice number), though class-action filings placed the total at risk at 1.2 million. The financial impact was $112.7 million in lost revenue and incremental costs, making it one of the costliest healthcare ransomware incidents ever recorded.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 147267,
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'litigation_settlement': 3570000, 'operational_losses': 91600000, 'incremental_costs': 21100000, 'total_disclosed': 112700000, 'insurance_recovery_expected': 14100000, 'notes': '$3.57M class-action settlement (prelim approved); $112.7M total losses per financial filing'}",
    "operational_impact": "EHR offline ~28 days; ambulance diversion from Encinitas, La Jolla, San Diego, and Chula Vista hospitals; trauma diversions from Scripps Mercy and Scripps Memorial La Jolla; elective surgery cancellations; staff on paper charting for ~1 month; regional ED overcrowding at adjacent hospitals; My Scripps patient portal inaccessible. Systems restored by May 26, 2021.",
    "remediation_disclosed": "Investigation with federal law enforcement (FBI); enhanced information security and monitoring capabilities; credit monitoring offered to affected patients; systems fully restored May 26, 2021.",
    "primary_source_url": "https://www.hipaajournal.com/scripps-health-ransomware-attack-cost-113-million/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/scripps-health-reached-settlement-addressing-breach-12-million-patients-data",
      "https://www.bankinfosecurity.com/scripps-health-a-17288",
      "https://www.hipaajournal.com/scripps-health-3-5m-settlement-ransomware/",
      "https://www.fiercehealthcare.com/health-tech/scripps-ransomware-post-mortem-shows-cybersecurity-regional-problem",
      "https://www.hipaajournal.com/scripps-health-ransomware-attack/",
      "https://pmc.ncbi.nlm.nih.gov/articles/PMC10167570/",
      "https://oag.ca.gov/system/files/Scripps%20Health-%20Sample%20Notice.pdf",
      "https://www.hipaajournal.com/147000-patients-affected-by-scripps-health-ransomware-attack/",
      "https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2804585",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
      "https://www.hipaajournal.com/scripps-health-ransomware-attack-cost-113-million/",
      "https://www.compliance.com/resources/3-5-million-settlement-by-scripps-health-for-ransomware-attack-compromising-patient-information/",
      "https://www.scripps.org/news_items/4498-notice-of-potential-data-security-event"
    ],
    "confidence_notes": "Attack occurred April 29, 2021 (data exfiltration); detected/confirmed May 1. OCR-reported PHI breach: 147,267. Class actions allege 1.2 million at risk. Backup servers in Arizona also encrypted. Settlement as of Jan 2023; court approved amounts include min $100/class member, up to $7,500 for identity theft victims. | JAMA study confirmed measurable impact on adjacent San Diego County hospital EDs during the 4-week attack period. OCR filed 147,267 individuals in initial report; settlement covers 1.2 million at-risk patients. Attack demonstrated cascade effects on regional health system capacity. | Cross-referenced across multiple authoritative sources. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BankInfoSecurity (ISMG)",
      "California AG Breach Notification",
      "Compliance.com",
      "FierceHealthcare",
      "HHS OCR Breach Portal",
      "HIPAA Journal",
      "Organization notice / News / SEC",
      "Scripps Health official notice"
    ],
    "id": "INC-00169",
    "year": 2021,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sea Mar Community Health Centers",
    "organization_type": "Healthcare Provider (Federally Qualified Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2021-06-24",
    "disclosure_date": "2021-10-01",
    "executive_summary": "Hackers from the Marketo threat group infiltrated Sea Mar Community Health Centers' network between December 2020 and March 2021, exfiltrating approximately 3 TB of sensitive patient data covering 688,000 individuals. Files were subsequently posted for sale on the Marketo dark web leak site in June 2021, and additional data appeared on the Snatch Team leak site in early 2022. Sea Mar delayed notification for approximately 10 months after the initial intrusion. A $4.4 million class-action settlement was later upheld by the Washington Court of Appeals.",
    "attack_type": "Data exfiltration / Hacking",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Marketo (extortion group); possible Snatch Team secondary disclosure",
    "attribution_status": "claimed",
    "individuals_affected_reported": 688000,
    "residents_affected_in_state": "Not separately reported (majority WA-based)",
    "financial_impact": "$4.4 million class-action settlement",
    "operational_impact": "Patient data sold on dark web marketplaces; prolonged exposure window",
    "remediation_disclosed": "Identity theft protection offered; security improvements implemented; $4.4M settlement",
    "primary_source_url": "https://www.hipaajournal.com/sea-mar-community-health-centers-facing-class-action-lawsuit-over-688000-record-data-breach/",
    "secondary_source_urls": [
      "https://databreaches.net/2022/02/19/sea-mar-community-health-centers-hit-with-class-action-2021-data-breach/",
      "https://www.hbsslaw.com/cases/sea-mar-community-health-centers-data-breach",
      "https://www.techtarget.com/healthtechsecurity/news/366594854/Seattle-Health-Center-Discovers-Additional-Data-Stolen-During-June-Breach",
      "https://oag.ca.gov/system/files/Sea%20Mar%20Sample%20Notice.pdf"
    ],
    "confidence_notes": "Well-documented; HHS OCR breach portal filing confirmed 688,000 individuals; settlement finalized and upheld by appeals court | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification",
      "DataBreaches.net",
      "HIPAA Journal",
      "Hagens Berman (class action)",
      "TechTarget Health"
    ],
    "id": "INC-00170",
    "year": 2021,
    "lat": 35.452296774324125,
    "lng": -119.39559280043174,
    "is_multistate": true,
    "hq_outside_state": "Seattle",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Smile Brands, Inc.",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Irvine",
    "hq_county": "Orange",
    "discovery_date": "2021-04-24 (attack discovered)",
    "disclosure_date": "06/24/2021 (amended multiple times)",
    "executive_summary": "Ransomware attack on Smile Brands, a provider of support services for dental offices. Initial report listed 1,200 individuals, later amended to 199,683, then to final count of 2,592,494.",
    "attack_type": "Hacking/IT Incident \u2014 Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2592494,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuits filed; settlement amounts not confirmed in sources",
    "operational_impact": "Access to parts of system disrupted",
    "remediation_disclosed": "Access promptly terminated; law enforcement notified; 12-month credit monitoring offered (including $1M identity theft insurance)",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/up-to-2592494-individuals-affected-by-smile-brands-ransomware-attack/",
      "https://www.scworld.com/analysis/breach-update-shows-2-6m-individuals-affected-by-smile-brands-data-theft"
    ],
    "confidence_notes": "Breach report amended significantly from initial 1,200 to 2.59 million. PHI included names, addresses, phone, DOBs, SSNs, financial info, gov't IDs, and health information.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00171",
    "year": 2021,
    "lat": 33.6846,
    "lng": -117.8265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "St. Margaret's Health (Spring Valley and Peru, IL)",
    "organization_type": "Rural Community Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Spring Valley",
    "hq_county": "Bureau",
    "discovery_date": "2021-02-01",
    "disclosure_date": "2021-03-01",
    "executive_summary": "A ransomware attack in February 2021 struck St. Margaret's Hospital in Spring Valley, Illinois, preventing the hospital from submitting claims to insurers, Medicare, and Medicaid for months. This financial catastrophe, compounded by COVID-19 staffing shortages and pre-existing financial pressures, proved insurmountable. Despite an 18+ month recovery effort, St. Margaret's Health permanently closed all five facilities (2 hospitals, 3 clinics) on June 16, 2023 \u2014 one of the first U.S. hospital closures directly attributed in part to a ransomware attack.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Illinois (Spring Valley and Peru communities)",
    "financial_impact": "Millions in lost insurance, Medicare, and Medicaid reimbursements during claims submission blackout; contributed to closure",
    "operational_impact": "Claims submission offline for months; severe financial spiral; contributed to permanent closure of 2 hospitals and 3 clinics June 16, 2023",
    "remediation_disclosed": "Partial \u2014 attack contained but recovery failed; facilities permanently closed",
    "primary_source_url": "https://www.hipaajournal.com/ransomware-attack-key-factor-in-decision-to-close-rural-illinois-hospital/",
    "secondary_source_urls": [
      "https://www.cbsnews.com/chicago/news/st-maragrets-health-central-illinois-hospital-closing/",
      "https://www.cyberdefensemagazine.com/lessons-learned-cyberattack-shutters-five-illinois-healthcare-facilities/"
    ],
    "confidence_notes": "High confidence. Extensive media coverage, HIPAA Journal, CBS News Chicago, Cyber Defense Magazine.",
    "sources_used": [
      "HIPAA Journal",
      "CBS News Chicago",
      "Cyber Defense Magazine"
    ],
    "id": "INC-00172",
    "year": 2021,
    "lat": 41.3275353,
    "lng": -89.1998078,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Stanford Health Care / Stanford Medicine (Accellion FTA Breach)",
    "organization_type": "Academic medical center (Stanford University affiliated); includes Stanford Health Care, Stanford Medicine Children's Health, Stanford Medicine Partners",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Stanford (Palo Alto area)",
    "hq_county": "Santa Clara County",
    "discovery_date": "2021-03-29",
    "disclosure_date": "2021-04-02",
    "executive_summary": "In early 2021, Stanford University School of Medicine disclosed that it was among hundreds of organizations globally breached through a zero-day vulnerability in Accellion's legacy File Transfer Appliance (FTA). The breach, part of a coordinated attack by the Cl0p group linked to FIN11, exposed data stored on Accellion FTA servers used by Stanford Medicine. The breach led to forensic investigation and notification of affected individuals, though the number of affected individuals was not publicly disclosed by Stanford. A separate 2023 Brightline/MOVEit-related incident also affected Stanford group health plan members.",
    "attack_type": "Third-party vendor zero-day exploitation (Accellion FTA)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "FIN11 / Cl0p (linked to Accellion FTA campaign)",
    "attribution_status": "reported",
    "individuals_affected_reported": "NOT_PUBLICLY_DISCLOSED",
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'notes': 'No financial penalties or settlements publicly disclosed for the Stanford Accellion incident specifically.'}",
    "operational_impact": "No reported patient care disruption. Data exfiltration from FTA server.",
    "remediation_disclosed": "Accellion FTA servers identified and affected data analyzed with cyber-forensics firm. Law enforcement notified. Identity theft protection offered to employees. Affected individuals notified.",
    "primary_source_url": "https://med.stanford.edu/connected/announcements/cybersecurity-incident-2021.html",
    "secondary_source_urls": [
      "https://news.stanford.edu/stories/2023/04/information-data-security-incident-involving-health-benefits-vendor",
      "https://news.stanford.edu/stories/2023/05/frequently-asked-questions-regarding-brightline-data-security-incident"
    ],
    "confidence_notes": "Stanford also affected by 2023 Akira ransomware attack on its Department of Public Safety (27,000 individuals; Sept 27, 2023; not a hospital system breach but included SSNs and some medical data). Stanford Medicine's Brightline/Forta breach (March 2023) via MOVEit-adjacent GoAnywhere affected unknown number of health plan members' demographic data.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00173",
    "year": 2021,
    "lat": 37.4275,
    "lng": -122.1697,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sutter Buttes Imaging Medical Group, Inc.",
    "organization_type": "Medical Imaging / Radiology Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "Yuba City, CA",
    "hq_county": "Sutter County",
    "discovery_date": "2019-07-01",
    "disclosure_date": "2021-02-09",
    "executive_summary": "Dear <<first_name>> <<middle_name>> <<last_name>> <<suffix>>: We write to inform you of a potential breach of some of your personal information held by Sutter Buttes Imaging Medical Group (\u201cSBI\u201d) for diagnostic imaging services performed at Sutter Buttes Imaging Center, 945 Shasta Street, Yuba City, CA. In December 2020, we learned that third party IT hardware utilized by SBI demonstrated vulnerabilities which allowed unauthorized penetration for a period of time between July 2019 and December 2020. After thorough",
    "attack_type": "Hacking / Security Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Sutter%20Buttes%20Imaging%20Ad%20r4prf.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00174",
    "year": 2021,
    "lat": 39.1404,
    "lng": -121.6169,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Total Health Care (Maryland / DC area - email breach)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MD",
    "hq_city": "Rockville",
    "hq_county": "Montgomery",
    "discovery_date": "2021-05-01",
    "disclosure_date": "2021-08-01",
    "executive_summary": "Total Health Care, a Maryland-based health plan serving the DC metropolitan area, reported a data security incident involving unauthorized access to employee email accounts containing member health insurance and protected health information. The breach affected health plan members in Maryland and the greater DC area.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member PHI and insurance data compromised via email",
    "remediation_disclosed": "HHS OCR and members notified; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; MD health plan; DC-area service area; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00175",
    "year": 2021,
    "lat": 39.084,
    "lng": -77.1528,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "TriHealth (via Bricker & Eckler law firm ransomware \u2014 2021)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Cincinnati",
    "hq_county": "Hamilton",
    "discovery_date": "2021-02-05",
    "disclosure_date": "2021-04-02",
    "executive_summary": "Bricker & Eckler LLP, a Columbus, Ohio law firm representing TriHealth, suffered a ransomware attack on its email server in late January 2021. Bricker notified TriHealth on February 5, 2021 that TriHealth data was included in the attack. PHI of a select group of TriHealth employees and patients was stolen, including names, addresses, medical information, driver's license numbers, and approximately 1,700 Social Security numbers out of 430,185 total affected nationwide. Law enforcement was engaged; no evidence of misuse found.",
    "attack_type": "Ransomware (Third-Party Vendor \u2014 law firm)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown ransomware group",
    "attribution_status": "unknown",
    "individuals_affected_reported": 430185,
    "residents_affected_in_state": "Ohio (Cincinnati area) patients and employees",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "TriHealth's own systems not breached; law firm's email server compromised",
    "remediation_disclosed": "Yes \u2014 Bricker implemented additional security; federal law enforcement investigation; 12 months identity theft protection offered",
    "primary_source_url": "https://www.trihealth.com/news/trihealth-confirms-third-party-data-breach",
    "secondary_source_urls": [
      "https://thelyonfirm.com/class-action/data-breach/trihealth/"
    ],
    "confidence_notes": "High confidence. TriHealth official press release; The Lyon Firm class action details.",
    "sources_used": [
      "TriHealth.com",
      "The Lyon Firm"
    ],
    "id": "INC-00176",
    "year": 2021,
    "lat": 39.1031,
    "lng": -84.512,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Trinity Health (via Accellion FTA breach)",
    "organization_type": "Nonprofit Catholic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Livonia",
    "hq_county": "Wayne",
    "discovery_date": "2021-01-29",
    "disclosure_date": "2021-03-01",
    "executive_summary": "Trinity Health learned on January 29, 2021 that attackers had exploited a zero-day vulnerability in the Accellion File Transfer Appliance (FTA), a secure email/file exchange platform. Attackers downloaded files containing names, contact details, DOBs, medical record numbers, laboratory information, medications, claims data, SSNs, and limited financial information. California residents were notified as the breach affected patients across Trinity's 92-hospital, 22-state network. A class action settlement was reached in 2025.",
    "attack_type": "Zero-Day Vulnerability Exploitation (Accellion FTA)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "CLOP/Cl0p (global Accellion FTA campaign)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately reported for Trinity alone",
    "residents_affected_in_state": "Multistate; MI-headquartered; nationwide patient population",
    "financial_impact": "Settlement amount not publicly disclosed in available sources",
    "operational_impact": "Accellion FTA system compromised; Trinity's core systems not breached; patient notification required",
    "remediation_disclosed": "Yes \u2014 Accellion FTA decommissioned; patients notified; credit monitoring and identity protection offered",
    "primary_source_url": "https://hipaatimes.com/trinity-health-settles-litigation-linked-to-2021-accellion-fta-data-breach",
    "secondary_source_urls": [
      "https://oag.ca.gov/system/files/Trinity%20Breach.pdf"
    ],
    "confidence_notes": "High confidence. Paubox/HIPAA Times, California AG Trinity breach notice.",
    "sources_used": [
      "HIPAA Times/Paubox",
      "California AG"
    ],
    "id": "INC-00177",
    "year": 2021,
    "lat": 42.36837,
    "lng": -83.3527097,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "UC San Diego Health",
    "organization_type": "Academic medical center / health system (University of California)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Diego",
    "hq_county": "San Diego County",
    "discovery_date": "2021-03-12",
    "disclosure_date": "2021-07-27",
    "executive_summary": "Between December 2, 2020, and April 8, 2021, unauthorized actors accessed employee email accounts at UC San Diego Health via credential phishing. Suspicious activity was detected March 12, 2021, and access was terminated April 8, 2021; however, PHI breach was not confirmed until May 25, 2021. The breach exposed a broad range of patient, student, and employee data, including SSNs, financial account numbers, lab results, diagnoses, and treatment information. The Regents of the University of California agreed to a $2.95 million settlement in 2025.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": "NOT_DISCLOSED_PUBLICLY",
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'litigation_settlement': 2950000, 'notes': '$2.95M class-action settlement (Tsvetanova v. Regents of UC, 2025)'}",
    "operational_impact": "No operational disruption to patient care reported. Email accounts accessed without care-delivery impact.",
    "remediation_disclosed": "Compromised accounts secured April 8, 2021; enhanced security controls; phishing prevention training; FBI notified; cybersecurity experts engaged. Individual notifications mailed by September 9, 2021.",
    "primary_source_url": "https://health.ucsd.edu/news/press-releases/2024-03-08-uc-san-diego-health-notifies-patients-of-phishing-event/",
    "secondary_source_urls": [
      "https://www.govtech.com/security/uc-san-diego-health-hack-may-have-exposed-patient-info",
      "https://www.classaction.org/news/data-breach-uc-san-diego-health-hit-with-class-action-over-alleged-four-month-phishing-attack",
      "https://www.claimdepot.com/settlements/ucsdh-health-data-breach-settlement",
      "https://www.kpbs.org/news/health/2021/07/27/uc-san-diego-health-announces-data-breach",
      "https://oag.ca.gov/system/files/UCSDH%20Sample%20Individual%20Notification.pdf",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf"
    ],
    "confidence_notes": "Breach period: Dec 2, 2020 \u2013 Apr 8, 2021. Total individuals affected never publicly disclosed by UCSD. Separate 2024 phishing event (Jan 9\u201322, 2024) affected 1,642 individuals in lung transplant and rheumatology departments (official UCSD press release: https://health.ucsd.edu/news/press-releases/2024-03-08-uc-san-diego-health-notifies-patients-of-phishing-event/). Settlement deadline July 31, 2025. | Breach affected patients, students, and employees. PHI included names, SSNs, DOBs, medical records, claims, government ID, payment info, usernames/passwords. Approximately 500,000 affected (estimate based on settlement and reporting). | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification",
      "HHS OCR Breach Portal",
      "Organization notice / News / SEC"
    ],
    "id": "INC-00178",
    "year": 2021,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "United Health Centers of San Joaquin Valley",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Fresno",
    "hq_county": "Fresno",
    "discovery_date": "2021-08 (ransomware attack)",
    "disclosure_date": "2021 (reported per CA AG requirement)",
    "executive_summary": "Ransomware attack by Vice Society on United Health Centers, operating nearly two dozen clinics in Fresno, Kings and Tulare counties. PHI of patients publicly dumped on dark web.",
    "attack_type": "Hacking/IT Incident \u2014 Ransomware with data exfiltration and public data dump on dark web",
    "attack_category": "Ransomware",
    "threat_actor_name": "Vice Society ransomware group",
    "attribution_status": "claimed",
    "individuals_affected_reported": 97000,
    "residents_affected_in_state": "Central Valley CA residents (Kings Tulare Fresno counties)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Entire computer network shutdown; systems eventually restored to 'full functionality'",
    "remediation_disclosed": "Third-party forensic specialists engaged; reported to CA AG and state regulators; systems restored; law enforcement notified",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.govtech.com/security/hackers-strike-fresno-calif-health-care-network"
    ],
    "confidence_notes": "BleepingComputer and DataBreaches.net first reported the attack. PHI dumped publicly included billing records, prescription refill forms, patient rosters with 5,000+ entries. Vice Society subsequently known for targeting public school districts and healthcare providers.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00179",
    "year": 2021,
    "lat": 36.7378,
    "lng": -119.7871,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "University of New Mexico Health (UNM Health)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NM",
    "hq_city": "Albuquerque",
    "hq_county": "Bernalillo",
    "discovery_date": "2021-06-04",
    "disclosure_date": "2021-08-01",
    "executive_summary": "An unauthorized third party gained access to UNM Health's network on May 2, 2021 and potentially accessed or obtained files from the UNM Hospital, UNM Medical Group, and UNM Sandoval Regional Medical Center. The breach was not discovered until June 4, over a month after initial intrusion. The attacker may have accessed names, addresses, dates of birth, medical record numbers, health insurance information, Social Security numbers, and clinical information for 637,252 patients.",
    "attack_type": "Hacking/IT Incident \u2013 Network intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 637252,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR system not impacted; targeted network file servers",
    "remediation_disclosed": "Enhanced system security; staff education; credit monitoring offered to SSN-affected individuals",
    "primary_source_url": "https://www.techtarget.com/healthtechsecurity/news/366595087/More-Than-600K-Patients-Impacted-by-UNM-Health-Data-Breach",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/more-600k-patients-affected-unm-health-hack",
      "https://www.idstrong.com/sentinel/unm-health-data-breach/"
    ],
    "confidence_notes": "High confidence; OCR breach portal confirmed 637,252 affected; multiple sources consistent",
    "sources_used": [
      "TechTarget, Healthcare IT News, Identity Theft Resource Center, IDStrong"
    ],
    "id": "INC-00180",
    "year": 2021,
    "lat": 35.0844,
    "lng": -106.6504,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Wake Forest Baptist Health-Lexington Medical Center (via Healthgrades)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Lexington",
    "hq_county": "Davidson",
    "discovery_date": "2021-01-29",
    "disclosure_date": "2021-03-26",
    "executive_summary": "Wake Forest Baptist Health-Lexington Medical Center was notified on January 29, 2021 by its former vendor Healthgrades that an unauthorized individual accessed an archived Healthgrades server between October 16\u201328, 2020. The server contained LMC patient backup files from 2010\u20132011 including names, addresses, SSNs, medical records, dates of service, diagnoses, and insurance info. No current LMC systems were affected.",
    "attack_type": "Vendor/Business Associate Breach (Unauthorized Server Access)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Archived patient data from 2010\u20132011 exposed via former vendor",
    "remediation_disclosed": "LMC confirmed no ongoing data sharing with Healthgrades; law enforcement notified; notifications mailed March 26, 2021",
    "primary_source_url": "https://www.wakehealth.edu/locations/hospitals/lexington-medical-center/notice-of-a-vendor-data-privacy-incident",
    "secondary_source_urls": [
      "https://www.govtech.com/security/Vendor-Breach-Raises-Alarms-for-a-North-Carolina-Health-System.html"
    ],
    "confidence_notes": "Wake Forest Baptist official notice is primary source. GovTech provides additional context.",
    "sources_used": [
      "Wake Forest Baptist Health (official website)",
      "GovTech"
    ],
    "id": "INC-00181",
    "year": 2021,
    "lat": 35.8240265,
    "lng": -80.2533838,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "WellStar Health System \u2014 Phishing 2021",
    "organization_type": "Healthcare Provider / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Marietta",
    "hq_county": "Cobb",
    "discovery_date": "2021-08-01",
    "disclosure_date": "2021-11-01",
    "executive_summary": "WellStar Health System in Georgia reported a phishing-related data breach in 2021 in which employee email accounts were compromised. The breach exposed patient PHI. This is separate from the tracking pixel lawsuit (ID #69) and represents a direct phishing breach incident reported to HHS OCR.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; patient PHI potentially accessed",
    "remediation_disclosed": "Affected accounts secured; patients notified; security measures enhanced",
    "primary_source_url": "https://www.scworld.com/brief/data-breach-at-ga-health-system-confirmed",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence \u2014 SC World reporting; limited details publicly available.",
    "sources_used": [
      "SC World"
    ],
    "id": "INC-00182",
    "year": 2021,
    "lat": 33.9526,
    "lng": -84.5499,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Wolfe Eye Clinic",
    "organization_type": "Eye Care Clinic Network",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "IA",
    "hq_city": "West Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2021-02-08",
    "disclosure_date": "2021-06-25",
    "executive_summary": "Wolfe Eye Clinic, a large network of eye care clinics serving patients across Iowa, was targeted in a ransomware attack on February 8, 2021. Attackers encrypted files and demanded ransom; the clinic declined to pay and recovered files via backup systems. However, an investigation completed June 8, 2021 confirmed that files containing PHI of approximately 500,000 current and former patients had been exfiltrated. Compromised data included names, addresses, dates of birth, Social Security numbers, and protected medical and health information. The Iowa AG was notified June 29, 2021. This is among the largest Iowa healthcare breaches on record.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 500000,
    "residents_affected_in_state": 500000,
    "financial_impact": "Not publicly disclosed; class action lawsuits filed",
    "operational_impact": "Systems encrypted and temporarily unavailable; backup recovery deployed; ransom not paid",
    "remediation_disclosed": "Yes \u2014 backup recovery, network secured, forensic investigation, Iowa AG notified, credit monitoring offered",
    "primary_source_url": "https://www.iowaattorneygeneral.gov/media/cms/6292021_Wolfe_Clinic_P_F247F781F97CC.pdf",
    "secondary_source_urls": [
      "https://thelyonfirm.com/class-action/data-breach/wolfe-eye-clinic/",
      "https://www.paubox.com/blog/ransomware-attack-wolfe-eye-clinic",
      "https://www.scworld.com/news/actors-steal-data-of-500k-patients-during-eye-clinic-ransomware-attack"
    ],
    "confidence_notes": "High confidence. Iowa AG breach notice (primary source), SC World, The Lyon Firm, Paubox.",
    "sources_used": [
      "Iowa AG",
      "The Lyon Firm",
      "Paubox",
      "SC World"
    ],
    "id": "INC-00183",
    "year": 2021,
    "lat": 41.5644476,
    "lng": -93.7594059,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wyoming Department of Health",
    "organization_type": "Government Agency (State Public Health)",
    "organization_type_bucket": "Other healthcare entity",
    "state": "WY",
    "hq_city": "Cheyenne",
    "hq_county": "Laramie",
    "discovery_date": "2021-03-10",
    "disclosure_date": "2021-04-27",
    "executive_summary": "The Wyoming Department of Health disclosed that a workforce member inappropriately uploaded 53 files containing COVID-19 and influenza test result data, and one file of breath alcohol test results, to public and private GitHub repositories. The exposure affected approximately 164,021 Wyoming residents (about 25% of the state's population) beginning as early as November 5, 2020. Data became publicly accessible on GitHub as early as January 8, 2021. The exposed data did not include SSNs, financial, or insurance information, but did include names, patient IDs, addresses, dates of birth, and test results.",
    "attack_type": "Unauthorized Access/Disclosure \u2013 Insider Accidental Exposure",
    "attack_category": "Insider threat",
    "threat_actor_name": "N/A (insider error)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 164021,
    "residents_affected_in_state": 164021,
    "financial_impact": "Not publicly disclosed; fraud reports surfaced from opportunistic callers",
    "operational_impact": "Files removed from GitHub; corrective action taken",
    "remediation_disclosed": "Files removed; GitHub destroyed dangling data; internal OPSC investigation completed; corrective actions taken",
    "primary_source_url": "https://health.wyo.gov/exposure-of-laboratory-test-result-data-described/",
    "secondary_source_urls": [
      "https://health.wyo.gov/fraud-reports-surface-related-to-wdh-information-breach/"
    ],
    "confidence_notes": "High confidence; Wyoming DOH official website; AHA/H-ISAC documented; HHS OCR may classify as unauthorized disclosure not hacking",
    "sources_used": [
      "Wyoming Department of Health official website"
    ],
    "id": "INC-00184",
    "year": 2021,
    "lat": 41.14,
    "lng": -104.8202,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Adaptive Health Integrations",
    "organization_type": "Healthcare Software and Billing Services",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "ND",
    "hq_city": "Williston",
    "hq_county": "Williams",
    "discovery_date": "2021-10-17",
    "disclosure_date": "2022-04-20",
    "executive_summary": "Adaptive Health Integrations (AHI), a Williston, North Dakota-based healthcare software and billing company, discovered on or around October 17, 2021, that an unauthorized individual had gained access to its systems. AHI's investigation concluded February 23, 2022. The breach affected 510,574 individuals whose PHI may have been accessed, including names, dates of birth, contact information, and Social Security numbers. The company notified affected patients in April 2022, approximately six months after the incident. HHS OCR reported this as the second-largest North Dakota healthcare breach on record at the time. Class action litigation was filed.",
    "attack_type": "Unauthorized Network Access / Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 510574,
    "residents_affected_in_state": "North Dakota residents \u2014 exact count not separately reported",
    "financial_impact": "Not publicly disclosed; class action litigation filed",
    "operational_impact": "Patient billing and software services potentially disrupted",
    "remediation_disclosed": "Yes \u2014 threat contained, forensic investigation conducted, notifications sent April 2022",
    "primary_source_url": "https://www.hipaajournal.com/adaptive-health-integrations-data-breach-affects-more-than-510000-individuals/",
    "secondary_source_urls": [
      "https://compliancy-group.com/adaptive-health-integrations-breach/",
      "https://classlawdc.com/2022/04/19/adaptive-health-integrations-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal (510,574), HIPAA Journal, Compliancy Group.",
    "sources_used": [
      "HIPAA Journal",
      "Compliancy Group",
      "M&R Law",
      "HHS OCR"
    ],
    "id": "INC-00185",
    "year": 2022,
    "lat": 48.1465457,
    "lng": -103.621814,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Advocate Aurora Health",
    "organization_type": "Nonprofit Health System (IL/WI)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Downers Grove",
    "hq_county": "DuPage",
    "discovery_date": "2022-10-14",
    "disclosure_date": "2022-10-20",
    "executive_summary": "Advocate Aurora Health discovered that tracking technologies (Meta Pixel, Google Analytics, and SDKs) embedded in its MyChart patient portal, LiveWell app, and scheduling website had transmitted patient health information to Facebook, Google, and other third parties without patient consent since at least October 2017. Notifications were sent to approximately 3 million individuals. A $12.225 million class action settlement was reached in 2023, with final approval granted July 2024. This was among the first and largest healthcare tracking pixel disclosures in the country.",
    "attack_type": "Unauthorized Tracking Technology Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Unknown third parties (Meta/Facebook, Google \u2014 recipients of data)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3000000,
    "residents_affected_in_state": 2500000,
    "financial_impact": "$12.225 million settlement; each claimant eligible for up to $50",
    "operational_impact": "No operational disruption; privacy/regulatory impact; HHS OCR notified",
    "remediation_disclosed": "Yes \u2014 tracking technologies removed from all websites, MyChart portal, and LiveWell app",
    "primary_source_url": "https://www.hipaajournal.com/advocate-aurora-health-settles-pixel-lawsuit-for-12-25-million/",
    "secondary_source_urls": [
      "https://abc7chicago.com/post/advocate-aurora-health-data-breach-tracking-technology-2022/12352343/",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/advocate-aurora-health-pixel-tracking-12-2m-class-action-settlement/",
      "https://healthitsecurity.com/news/advocate-aurora-health-reports-3m-patient-data-breach-due-to-tracking-pixels",
      "https://www.beckershospitalreview.com/cybersecurity/advocate-aurora-health-up-to-3m-patients-may-have-had-data-shared-via-web-tracking-tools.html",
      "https://www.hipaajournal.com/advocate-aurora-health-tracking-pixel-breach/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report, court settlement documents, major media coverage. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "ABC7 Chicago",
      "Becker's Hospital Review",
      "HIPAA Journal",
      "Health IT Security",
      "Top Class Actions"
    ],
    "id": "INC-00186",
    "year": 2022,
    "lat": 41.7936822,
    "lng": -88.0102281,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Alabama Eye & Cataract (Eye Care Leaders) \u2014 Alabama",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Birmingham",
    "hq_county": "Jefferson",
    "discovery_date": "2022-03-01",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Alabama Eye & Cataract was among the eye care providers affected by the Eye Care Leaders ransomware attack (December 2021). The breach affected 26,000 individuals. Patient data including names, dates of birth, SSNs, medical record numbers, and health/insurance information was exposed through ECL's compromised EMR system.",
    "attack_type": "Ransomware (Supply-Chain via Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 26000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient EMR records compromised; PHI potentially exposed",
    "remediation_disclosed": "ECL took down compromised systems; covered entities notified patients",
    "primary_source_url": "https://www.hipaajournal.com/june-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal June 2022 breach report, HHS OCR data.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00187",
    "year": 2022,
    "lat": 33.5186,
    "lng": -86.8104,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Alameda Health System",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Oakland",
    "hq_county": "Alameda",
    "discovery_date": "2020-05 to 2022-03 (prolonged unauthorized email access)",
    "disclosure_date": "05/2022",
    "executive_summary": "Unauthorized access to employee email accounts at Alameda Health System, Oakland's public healthcare system. The breach spanned nearly two years before discovery.",
    "attack_type": "Hacking/IT Incident \u2014 Unauthorized access to employee email accounts (phishing/credential compromise)",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 90000,
    "residents_affected_in_state": "Not separately reported (all operations in Alameda County)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No reported clinical operational disruption",
    "remediation_disclosed": "Investigation launched; breach notifications sent June 2022; California AG notified",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/data-breaches-reported-by-alameda-health-system-aon-and-capsule-pharmacy/",
      "https://www.medicalrecords.com/hospital_breaches/alameda-health-system"
    ],
    "confidence_notes": "Breach occurred over extended period May 2020 to March 2022, per reporting. Oakland-based public integrated health system serving Alameda County.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00188",
    "year": 2022,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Aloha Laser Vision, LLC (via Eye Care Leaders)",
    "organization_type": "Healthcare Provider (Ophthalmology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "Honolulu",
    "discovery_date": "2021-12-04",
    "disclosure_date": "2022-06-30",
    "executive_summary": "Aloha Laser Vision in Hawaii was one of at least 41 eye care providers affected by a ransomware attack on Eye Care Leaders, an EHR vendor. Hackers deleted databases and configuration files from Eye Care Leaders' myCare Identity solution on or around December 4, 2021. 43,263 Aloha Laser Vision patients were affected. Hawaii DCCA recorded 39,087 Hawaii residents impacted. Compromised data included patient names, dates of birth, medical record numbers, health insurance information, and Social Security numbers.",
    "attack_type": "Ransomware (via business associate)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware operator)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 43263,
    "residents_affected_in_state": 39087,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR databases and configuration files deleted",
    "remediation_disclosed": "Not publicly disclosed by Aloha Laser Vision specifically",
    "primary_source_url": "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
    "secondary_source_urls": [
      "https://cca.hawaii.gov/ocp/notices/security-breach/",
      "https://www.dataguidance.com/news/usa-aloha-laser-vision-notifies-ocr-data-security"
    ],
    "confidence_notes": "Hawaii DCCA confirmed 39,087 HI residents; HHS OCR confirmed 43,263 total individuals",
    "sources_used": [
      "HIPAA Journal",
      "Hawaii DCCA",
      "DataGuidance"
    ],
    "id": "INC-00189",
    "year": 2022,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Aloha Nursing Rehab Centre",
    "organization_type": "Healthcare Provider (Skilled Nursing Facility)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Kaneohe",
    "hq_county": "Honolulu",
    "discovery_date": "2022-07-08",
    "disclosure_date": "2022-12-28",
    "executive_summary": "Aloha Nursing Rehab Centre discovered on December 28, 2022, that on July 8, 2022, an unauthorized party had accessed one or more files on its network containing confidential patient information. Compromised data included names, dates of birth, Social Security numbers, financial account information, driver's license or state ID numbers, medical record numbers, patient account numbers, health information, and health insurance information for 20,216 individuals. Hawaii DCCA recorded 12,096 Hawaii residents impacted.",
    "attack_type": "Hacking / Unauthorized network access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 20216,
    "residents_affected_in_state": 12096,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI and financial data exposed",
    "remediation_disclosed": "Notifications sent; cybersecurity investigation conducted",
    "primary_source_url": "https://www.jdsupra.com/legalnews/aloha-nursing-rehab-centre-reports-2022-3681534/",
    "secondary_source_urls": [
      "https://cca.hawaii.gov/ocp/notices/security-breach/"
    ],
    "confidence_notes": "HHS OCR filed February 24, 2023; Hawaii DCCA confirmed 12,096 HI residents",
    "sources_used": [
      "JD Supra",
      "Hawaii DCCA"
    ],
    "id": "INC-00190",
    "year": 2022,
    "lat": 21.4055,
    "lng": -157.7960716,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Anne Arundel Medical Center / Luminis Health (MD)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Annapolis",
    "hq_county": "Anne Arundel",
    "discovery_date": "2021-09-01",
    "disclosure_date": "2022-01-01",
    "executive_summary": "Anne Arundel Medical Center (now part of Luminis Health), an Annapolis, Maryland health system, reported a data security incident in 2021 involving unauthorized access to patient health information. The breach affected patients receiving care at AAMC and its affiliated facilities in Anne Arundel County, Maryland.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Maryland multi-hospital patient PHI potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified; security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2021; major MD health system; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00191",
    "year": 2022,
    "lat": 38.9784,
    "lng": -76.4922,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Augusta University Medical Center \u2014 Email Breach 2022",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Augusta",
    "hq_county": "Richmond",
    "discovery_date": "2022-03-01",
    "disclosure_date": "2022-06-14",
    "executive_summary": "Augusta University Medical Center reported a data security incident to the South Carolina Attorney General in June 2022 affecting 11,181 SC residents (in addition to GA residents). This is distinct from the major 2017/2018 phishing incidents. The June 2022 incident involved unauthorized access to email accounts or network systems containing patient PHI.",
    "attack_type": "Unauthorized Access / Email Compromise",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11181,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI potentially accessed",
    "remediation_disclosed": "SC AG notified June 2022",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing. Incident in 2022, reported to SC AG June 14, 2022. Note: 11,181 SC residents, total individuals may be higher.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00192",
    "year": 2022,
    "lat": 33.4735,
    "lng": -82.0105,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Avem Health Partners",
    "organization_type": "Business Associate (Administrative and Technology Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2022-09-09",
    "disclosure_date": "2022-12-14",
    "executive_summary": "Avem Health Partners, an Oklahoma City-based provider of administrative and technology services to healthcare organizations, experienced a third-party data breach at its vendor 365 Data Centers. On May 14, 2022, unauthorized actors accessed information on 365 Data Centers' servers (which suffered a ransomware attack that shut down their entire cloud network). Avem was notified by 365 Data Centers on September 9, 2022. A review completed October 6, 2022 confirmed that 271,303 individuals' protected health information was exposed. Avem notified affected individuals in December 2022. A $1.45 million class action settlement was reached in 2024.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack via Third-Party Vendor (365 Data Centers)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 271303,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$1,450,000 class action settlement (2024); up to $7,000 per class member for out-of-pocket losses; 3 years identity theft protection",
    "operational_impact": "365 Data Centers' entire cloud network shut down; Avem services to healthcare organizations disrupted",
    "remediation_disclosed": "Vendor relationships evaluated; notifications sent December 2022; credit monitoring offered; AG breach notice filed",
    "primary_source_url": "https://www.hipaajournal.com/avem-health-partners-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594196/Third-Party-Data-Breach-Impacts-271K-at-Oklahoma-Healthcare-Administrative-Tech-Services-Company",
      "https://www.paubox.com/blog/avem-health-partners-experienced-a-third-party-breach",
      "https://www.jdsupra.com/legalnews/avem-health-partners-files-notice-of-3638798/"
    ],
    "confidence_notes": "HHS OCR confirmed 271,303 affected; $1.45M settlement confirmed by HIPAA Journal; listed in HIPAA Journal December 2022 monthly breach report",
    "sources_used": [
      "HIPAA Journal, TechTarget, Paubox, JD Supra"
    ],
    "id": "INC-00193",
    "year": 2022,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Avera Health / MCG Health breach",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2022-03-25",
    "disclosure_date": "2022-06-13",
    "executive_summary": "MCG Health, LLC, a vendor providing patient care guidelines to Avera McKennan Hospital & University Health Center, determined on March 25, 2022 that an unauthorized party had previously obtained patient information. Approximately 900 Avera McKennan patients were personally notified. Compromised data included names, SSNs, medical codes, postal addresses, telephone numbers, email addresses, DOBs, and gender. MCG began sending notices June 10, 2022.",
    "attack_type": "Third-Party Vendor Breach (unauthorized access)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 900,
    "residents_affected_in_state": 900,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal; Avera's own systems not breached",
    "remediation_disclosed": "Yes \u2014 MCG notified Avera; patients notified; credit monitoring offered",
    "primary_source_url": "https://www.avera.org/news-media/news/2022/mcg-data-security-issue/",
    "secondary_source_urls": [
      "https://siouxfalls.business/avera-impacted-by-data-security-issue/"
    ],
    "confidence_notes": "High confidence. Avera official press release, Sioux Falls Business reporting.",
    "sources_used": [
      "Avera Health",
      "SiouxFalls.Business"
    ],
    "id": "INC-00194",
    "year": 2022,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "BJC HealthCare \u2014 2022 Physician Email Breach",
    "organization_type": "Nonprofit Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "St. Louis",
    "hq_county": "St. Louis",
    "discovery_date": "2022-03-28",
    "disclosure_date": "2022-05-01",
    "executive_summary": "In March 2022, unauthorized parties accessed email accounts of resident physicians and other medical personnel at 12 BJC hospitals between March 4 and March 28, 2022. PHI of patients was potentially exposed. BJC reported the breach to HHS OCR in May 2022 as initially affecting 500 individuals (placeholder). The final affected count was not publicly confirmed in available sources.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 500,
    "residents_affected_in_state": "Primarily Missouri residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal \u2014 email accounts only compromised",
    "remediation_disclosed": "Yes \u2014 accounts secured; investigation initiated",
    "primary_source_url": "https://www.hipaajournal.com/bjc-healthcare-settles-data-breach-lawsuit-stemming-from-2020-phishing-attack/",
    "secondary_source_urls": [
      "https://www.torhoermanlaw.com/bjc-healthcare-security-breach-class-action-lawsuit/"
    ],
    "confidence_notes": "Moderate confidence. HHS OCR filing noted in HIPAA Journal; victim count not finalized.",
    "sources_used": [
      "HIPAA Journal",
      "TorHoerman Law"
    ],
    "id": "INC-00195",
    "year": 2022,
    "lat": 38.627,
    "lng": -90.1994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Baptist Medical Center / Resolute Health Hospital",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "San Antonio / New Braunfels",
    "hq_county": "Bexar County / Comal",
    "discovery_date": "2022-04-20",
    "disclosure_date": "2022-06-15",
    "executive_summary": "Baptist Medical Center in San Antonio and Resolute Health Hospital in New Braunfels discovered malicious code had been installed on their computer networks. An unauthorized third party gained access to systems between March 31 and April 24, 2022, accessing and removing data. The breach affected 1,608,549 (Baptist) and 54,239 (Resolute) individuals. Compromised data included names, dates of birth, addresses, Social Security numbers, health insurance information, medical record numbers, diagnosis and treatment information, and billing data.",
    "attack_type": "Hacking/IT Incident \u2013 Malware / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1662788,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "User access to IT applications suspended; extensive cybersecurity protocols executed",
    "remediation_disclosed": "Forensic investigation launched; law enforcement notified; security capabilities enhanced; systems hardened",
    "primary_source_url": "https://www.ksat.com/news/local/2022/06/16/baptist-medical-center-resolute-health-hospital-report-cybersecurity-breach-involving-patient-information/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/texas-tech-university-health-sciences-center-ransomware-data-breach/",
      "https://www.bankinfosecurity.com/malware-breach-affects-12-million-medical-center-patients-a-19466"
    ],
    "confidence_notes": "High confidence; OCR lists Baptist Medical Center TX at 1,608,549; Resolute reported separately at 54,239",
    "sources_used": [
      "KSAT San Antonio, HIPAA Journal, BankInfoSecurity/ISMG"
    ],
    "id": "INC-00196",
    "year": 2022,
    "lat": 29.4241,
    "lng": -98.4936,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Broward Health",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Fort Lauderdale",
    "hq_county": "Broward",
    "discovery_date": "2021-10-15",
    "disclosure_date": "2022-01-01",
    "executive_summary": "Broward Health (30+ facilities in Broward County, FL) reported a major breach when a hacker gained access via a third-party medical provider's account on October 15, 2021. The attacker exfiltrated data including names, addresses, DOBs, SSNs, financial info, medical history, and insurance data. The breach affected 1,357,879 individuals (Maine AG) / 1,351,431 (HHS OCR). Notifications were issued January 1, 2022.",
    "attack_type": "Unauthorized Access via Third-Party Credentials",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1357879,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Data exfiltrated; notifications mailed nearly 3 months post-discovery",
    "remediation_disclosed": "Third-party access revoked; forensic investigation; notifications mailed January 1, 2022",
    "primary_source_url": "https://www.hipaajournal.com/broward-health-notifies-over-1-3-million-individuals-about-october-2021-data-breach/",
    "secondary_source_urls": [
      "https://natlawreview.com/article/broward-health-data-breach-affects-13-million-individuals",
      "https://www.kgglaw.com/class-action-lawsuits/broward-health-data-breach-class-action-lawsuit/"
    ],
    "confidence_notes": "Highly reliable; Maine AG and HHS OCR both confirm. Notification date confirmed by National Law Review.",
    "sources_used": [
      "HIPAA Journal",
      "National Law Review",
      "KGG Law"
    ],
    "id": "INC-00197",
    "year": 2022,
    "lat": 26.1224,
    "lng": -80.1373,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Bryan County Ambulance Authority (BCAA)",
    "organization_type": "Healthcare Provider (Emergency Medical Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Durant",
    "hq_county": "Bryan",
    "discovery_date": "2022-05-01",
    "disclosure_date": "2022-05-01",
    "executive_summary": "Bryan County Ambulance Authority (BCAA), a governmental EMS provider in Oklahoma, suffered a ransomware attack that encrypted files containing PHI of 14,273 patients. The breach was reported to HHS in May 2022. OCR investigation found BCAA failed to conduct adequate risk analysis. In November 2024, BCAA agreed to pay $90,000 in OCR's first ransomware enforcement action under its new Risk Analysis Initiative, along with a 3-year corrective action plan.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14273,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$90,000 HIPAA OCR settlement (November 2024)",
    "operational_impact": "Files encrypted; patient data at risk",
    "remediation_disclosed": "Systems secured; $90,000 penalty; 3-year corrective action plan including risk analysis, risk management, updated policies, and HIPAA training",
    "primary_source_url": "https://www.saul.com/insights/alert/emergency-medical-service-provider-agrees-pay-90000-hipaa-settlement-following",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; HHS OCR official action; Saul Ewing law firm documented",
    "sources_used": [
      "Saul Ewing LLP"
    ],
    "id": "INC-00198",
    "year": 2022,
    "lat": 33.9919761,
    "lng": -96.3776762,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "CHI Health (Nebraska / CommonSpirit subsidiary) \u2014 Separate 2022 Breach Component",
    "organization_type": "Nonprofit Hospital System (CommonSpirit/Catholic Health Initiatives subsidiary)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NE",
    "hq_city": "Omaha",
    "hq_county": "Douglas",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2022-12-15",
    "executive_summary": "CHI Health, the Nebraska-based hospital system and subsidiary of CommonSpirit Health (formerly Catholic Health Initiatives), was specifically identified as affected by the October 2022 CommonSpirit ransomware attack. The confirmed impacted CHI Health Nebraska facilities included CHI Health Lakeside (Omaha), CHI Health Midlands (Papillion), CHI Health Plainview, CHI Health Creighton University Medical Center \u2013 Bergan Mercy (Omaha), Lasting Hope Recovery Center (Omaha), CHI Health Immanuel (Omaha), CHI Health Schuyler, CHI Health Good Samaritan (Kearney), CHI Health Richard Young Behavioral Health (Kearney), CHI Health Nebraska Heart (Lincoln), CHI Health St. Elizabeth (Lincoln), CHI Health St. Francis (Grand Island), CHI Health St. Mary's (Nebraska City), and The Physician Network. CHI Health at Home Nebraska locations were also impacted. This entry represents the Nebraska-specific component of the broader CommonSpirit breach (MW-092).",
    "attack_type": "Ransomware (CommonSpirit parent system attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Nebraska residents \u2014 subset of CommonSpirit total",
    "financial_impact": "Part of CommonSpirit's $160M total loss",
    "operational_impact": "14 Nebraska facilities and CHI Health at Home affected; EHR outage, appointment delays, paper record fallback",
    "remediation_disclosed": "Yes \u2014 systems restored over 5+ weeks; see CommonSpirit disclosure (MW-092)",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and"
    ],
    "confidence_notes": "High confidence. CommonSpirit April 2023 update lists all 14 Nebraska CHI Health facilities as affected. Nebraska-specific subset.",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare",
      "CommonSpirit official statements"
    ],
    "id": "INC-00199",
    "year": 2022,
    "lat": 41.2565,
    "lng": -95.9345,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CHRISTUS Spohn Health System Corporation",
    "organization_type": "Healthcare Provider (Catholic Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Corpus Christi",
    "hq_county": "Nueces",
    "discovery_date": "2022-04-01",
    "disclosure_date": "2022-07-01",
    "executive_summary": "CHRISTUS Spohn Health System Corporation experienced a ransomware attack attributed to the AvosLocker group. The attack resulted in theft of protected health information, with AvosLocker posting samples of allegedly stolen patient data to its dark web leak site. The breach affected 15,062 individuals and exposed patient PHI. CHRISTUS filed the breach report with HHS on July 1, 2022.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "AvosLocker",
    "attribution_status": "claimed",
    "individuals_affected_reported": 15062,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed in detail",
    "primary_source_url": "https://www.jdsupra.com/legalnews/christus-spohn-health-system-2513343/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/avoslocker-claims-credit-for-christus-health-ransomware-attack/"
    ],
    "confidence_notes": "High confidence; HHS OCR breach filing confirmed; JD Supra and HIPAA Journal both documented",
    "sources_used": [
      "JD Supra, HIPAA Journal"
    ],
    "id": "INC-00200",
    "year": 2022,
    "lat": 27.8006,
    "lng": -97.3964,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Capitol Region Education Council (CREC)",
    "organization_type": "Healthcare Provider (School Health Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "Hartford",
    "hq_county": "Hartford",
    "discovery_date": "2022-08-01",
    "disclosure_date": "2022-11-01",
    "executive_summary": "Capitol Region Education Council (CREC) in Hartford, Connecticut, a regional educational services agency that also provides school health services, reported a data security incident involving unauthorized access to health and personal information of students and employees. The breach exposed protected health information maintained in CREC's school health records systems.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Student and employee health information compromised",
    "remediation_disclosed": "HHS OCR and individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2022; CT school health services covered entity; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00201",
    "year": 2022,
    "lat": 41.7658,
    "lng": -72.6734,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Cardiovascular Consultants, Ltd.",
    "organization_type": "Medical Group / Cardiology Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2022-05-06",
    "disclosure_date": "2022-07-08",
    "executive_summary": "Cardiovascular Consultants, Ltd., a Phoenix, Arizona-based cardiology specialty practice, disclosed in July 2022 a ransomware attack that occurred May 6\u201319, 2022. The RansomHouse threat group claimed responsibility and listed approximately 1.19 million patient records on its leak site. Cardiovascular Consultants reported 484,000 individuals to HHS OCR. Compromised data included names, Social Security numbers, dates of birth, medical and health information, financial information, and insurance information. This breach was notable for the sophistication of the cardiology-specific patient data targeted and was one of the larger specialty cardiology practice breaches on record.",
    "attack_type": "Ransomware / Data Exfiltration / Double Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "RansomHouse",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 484000,
    "residents_affected_in_state": "AZ: majority (Phoenix-based specialty practice)",
    "financial_impact": "Class action lawsuits filed. Settlement not publicly disclosed. Ransom payment status: Not publicly confirmed.",
    "operational_impact": "Cardiology practice operations disrupted for approximately 13 days. Patient records and sensitive cardiovascular health data exfiltrated.",
    "remediation_disclosed": "Third-party forensics. HHS OCR breach reported. Notification letters mailed. Credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/cardiovascular-consultants-data-breach/",
    "secondary_source_urls": [
      "https://www.databreaches.net/ransomhouse-claims-responsibility-for-cardiovascular-consultants-breach/",
      "https://healthitsecurity.com/news/cardiovascular-consultants-breach"
    ],
    "confidence_notes": "Moderate-high confidence. HHS OCR breach report confirms 484,000. RansomHouse claimed on dark web leak site. Discrepancy between 1.19M (RansomHouse claim) and 484K (HHS OCR filing) typical of ransomware group overclaiming.",
    "sources_used": [
      "HIPAA Journal",
      "DataBreaches.Net",
      "Health IT Security"
    ],
    "id": "INC-00202",
    "year": 2022,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CareFirst Administrators",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MD",
    "hq_city": "Baltimore",
    "hq_county": "Baltimore City",
    "discovery_date": "2022-10-01",
    "disclosure_date": "2022-11-15",
    "executive_summary": "CareFirst Administrators, a Maryland-based health plan administrator, was affected by a phishing attack on a business associate in November 2022. Approximately 14,538 individuals had their PHI potentially compromised. The attack targeted a business associate's email systems.",
    "attack_type": "Phishing attack on business associate",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14538,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "14K+ health plan member records potentially compromised via BA",
    "remediation_disclosed": "HHS OCR breach report filed; members notified",
    "primary_source_url": "https://www.hipaajournal.com/november-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal November 2022 report",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00203",
    "year": 2022,
    "lat": 39.2904,
    "lng": -76.6122,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Carolina Eyecare Physicians (Eye Care Leaders)",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Mount Pleasant",
    "hq_county": "Charleston",
    "discovery_date": "2021-12-08",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Carolina Eyecare Physicians, LLC in South Carolina was affected by the Eye Care Leaders (ECL) ransomware attack of December 2021. The breach resulted in exposure of patient data from ECL's myCare Integrity EMR system. Carolina Eyecare Physicians reported 68,739 affected individuals to HHS OCR.",
    "attack_type": "Ransomware (Supply-Chain via Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 68739,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient EMR data exposed; PHI potentially acquired",
    "remediation_disclosed": "ECL took down compromised systems; patient notification letters sent",
    "primary_source_url": "https://www.hipaajournal.com/june-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal June 2022 breach report, HHS OCR portal data.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00204",
    "year": 2022,
    "lat": 32.7940651,
    "lng": -79.8625851,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Charleston Area Medical Center (CAMC) \u2014 2022",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WV",
    "hq_city": "Charleston",
    "hq_county": "Kanawha",
    "discovery_date": "2022-01-10",
    "disclosure_date": "2022-04-01",
    "executive_summary": "Charleston Area Medical Center (CAMC) in Charleston, West Virginia disclosed a phishing attack in which employee email accounts were compromised on January 10-11, 2022. The forensic investigation suggested the attacker aimed to collect employee login credentials rather than access patient data, but data theft could not be ruled out. Approximately 54,000 patients were affected.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 54000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; patient PHI potentially accessed",
    "remediation_disclosed": "Affected accounts immediately secured; cybersecurity forensics firm engaged; investigation completed March 16, 2022",
    "primary_source_url": "https://www.hipaajournal.com/data-breaches-reported-by-wv-and-co-healthcare-providers-and-nj-medical-billing-administrator/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 HIPAA Journal April 2022 reporting. Approximate affected count of 54,000 from contemporaneous news reports.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00205",
    "year": 2022,
    "lat": 38.3498,
    "lng": -81.6326,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Charlotte Radiology",
    "organization_type": "Healthcare Provider (Radiology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Charlotte",
    "hq_county": "Mecklenburg",
    "discovery_date": "2021-12-01",
    "disclosure_date": "2022-10-01",
    "executive_summary": "Charlotte Radiology experienced a cyberattack in December 2021 where hackers breached its computer systems and accessed patient information. The breach was investigated by a law firm in October 2022. Specific number of affected individuals and breach details were not fully disclosed in available public sources.",
    "attack_type": "Network Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient information potentially accessed",
    "remediation_disclosed": "Investigation launched; law firm investigation noted October 2022",
    "primary_source_url": "https://classlawdc.com/2022/10/12/mr-investigates-charlotte-radiology-data-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/"
    ],
    "confidence_notes": "Law firm investigation reported. Also separately affected by Nuance/MOVEit breach in 2023. December 2021 incident from law firm report; Nuance 2023 breach documented separately.",
    "sources_used": [
      "Migliaccio & Rathod LLP",
      "HIPAA Journal"
    ],
    "id": "INC-00206",
    "year": 2022,
    "lat": 35.2271,
    "lng": -80.8431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Christie Business Holdings Company / Christie Clinic (IL)",
    "organization_type": "Multi-Specialty Physician Group Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "IL",
    "hq_city": "Champaign",
    "hq_county": "Champaign",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2022-03-24",
    "executive_summary": "Christie Clinic (Christie Business Holdings Company, P.C.), a large multi-specialty physician-owned medical practice in Champaign, Illinois, discovered in January 2022 that an unauthorized third party had gained access to a single administrative email account between July 14\u2013August 19, 2021. The breach purpose appeared to be interception of a business transaction between the clinic and a third-party vendor. The compromised email account contained PHI and PII for 502,869 individuals, including names, addresses, Social Security numbers, medical information, and health insurance information. No access to the EHR, patient portal, or network was identified beyond the single email account.",
    "attack_type": "Business Email Compromise / Unauthorized Email Access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 502869,
    "residents_affected_in_state": "Primarily Illinois residents (central/eastern Illinois service area)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Single email account compromised; limited to data exposure of current and past patients",
    "remediation_disclosed": "Yes \u2014 account secured, federal law enforcement notified, additional security measures implemented, credit monitoring offered",
    "primary_source_url": "https://www.bankinfosecurity.com/illinois-clinic-says-nearly-503000-affected-in-email-breach-a-18893",
    "secondary_source_urls": [
      "https://www.justice4you.com/christie-clinic-data-breach/",
      "https://thelyonfirm.com/class-action/data-breach/christie-clinic/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal (502,869 individuals), BankInfoSecurity, class action filings.",
    "sources_used": [
      "BankInfoSecurity",
      "HHS OCR",
      "Arnold Law Firm",
      "The Lyon Firm"
    ],
    "id": "INC-00207",
    "year": 2022,
    "lat": 40.1164841,
    "lng": -88.2430932,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Coastal Carolina Community Health Center",
    "organization_type": "Healthcare Provider / FQHC",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Conway",
    "hq_county": "Horry",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Coastal Carolina Community Health Center, a Federally Qualified Health Center in South Carolina, reported a network intrusion affecting patient PHI. The incident was reported to HHS OCR.",
    "attack_type": "Network Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI potentially accessed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence \u2014 SC Consumer Affairs listing reference only; limited details.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00208",
    "year": 2022,
    "lat": 33.8360035,
    "lng": -79.0478143,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "CommonSpirit Health",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2022-10-05",
    "executive_summary": "CommonSpirit Health, the second-largest nonprofit health system in the U.S. (142+ hospitals, 21 states), detected a ransomware attack on October 2, 2022, with unauthorized access confirmed between September 16 and October 3. Initial notifications in December 2022 covered Franciscan Health patients in Washington state; subsequent investigations expanded the breach to 164 facilities across 21 states by April 2023. Data compromised included names, addresses, phone numbers, dates of birth, medical record numbers, diagnoses, treatment info, health insurance, and for a small subset Social Security numbers. CommonSpirit disclosed expected costs of approximately $150 million from business interruptions and response. The OCR breach report lists 623,774 individuals, though the actual total across all 164 facilities is substantially higher.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": 21,
    "financial_impact": "Estimated ~$150 million from business interruptions and response costs (disclosed in February 2023 financial update). Class action lawsuits filed.",
    "operational_impact": "IT systems disrupted across 142+ hospitals. EHR offline at multiple facilities for weeks. Staff reverted to paper documentation. Patient care delays reported.",
    "remediation_disclosed": "Third-party forensic investigators engaged. Notifications sent in waves (Dec 2022, Feb 2023, Apr 2023) as investigation expanded. Credit monitoring offered. Upgraded security posture.",
    "primary_source_url": "https://www.commonspirit.org/newsroom/news/cybersecurity-incident",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/more-than-623000-patients-affected-by-commonspirit-health-ransomware-attack/",
      "https://techcrunch.com/2022/12/09/commonspirit-health-ransomware-attack-exposed-patient-data/",
      "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/"
    ],
    "confidence_notes": "High confidence on attack timeline and scope. OCR breach figure of 623,774 is a minimum; final count from all 164 facilities may be substantially higher. Threat actor unknown.",
    "sources_used": [
      "CommonSpirit Health official newsroom",
      "HIPAA Journal",
      "TechCrunch",
      "Healthcare Facilities Today"
    ],
    "id": "INC-00209",
    "year": 2022,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CommonSpirit Health (CHI Baylor St. Luke's / CHI St. Joseph TX Hospitals)",
    "organization_type": "Healthcare Provider (Nonprofit Hospital System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Chicago (IL HQ) / Multiple TX locations",
    "hq_county": "Multiple TX counties",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2022-12-01",
    "executive_summary": "CommonSpirit Health suffered a major ransomware attack between September 16 and October 3, 2022, affecting 164 facilities across the US including multiple Texas hospitals: CHI Baylor St. Luke's, CHI St. Luke's Health (multiple Houston area hospitals), CHI St. Joseph Health (Bryan/College Station), and CHI St. Luke's Memorial system. The attack encrypted files, caused EHR downtime, and led to ambulance diversions. Patient data from file servers was stolen, including names, addresses, birth dates, phone numbers, medical record numbers, and in some cases Social Security numbers. Texas was among the states whose facilities were explicitly listed as affected.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Not separately reported (Texas portion of nationwide figure)",
    "financial_impact": "$150M+ in losses reported in Q1 2023 SEC filings",
    "operational_impact": "EHR downtime nationwide; ambulance diversions; elective procedures canceled; Texas facilities experienced month-long system disruptions",
    "remediation_disclosed": "Systems rebuilt; affected patients notified in multiple waves (Dec 2022, Feb 2023, Apr 2023); OCR investigation ongoing",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/commonspirit-health-reports-150-million-loss-due-to-ransomware-attack/",
      "https://www.paubox.com/blog/commonspirit-health-ransomware-attack-update"
    ],
    "confidence_notes": "High confidence; OCR confirmed 623,774 affected total; multiple TX hospitals explicitly listed in April 2023 update",
    "sources_used": [
      "HIPAA Journal, Paubox, PhoenixNAP"
    ],
    "id": "INC-00210",
    "year": 2022,
    "lat": 35.2173269,
    "lng": -101.7922122,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "CommonSpirit Health (Midwest facilities \u2014 CHI Health NE, CHI Saint Joseph MN, CHI St. Alexius ND, CHI Mercy Iowa, MercyOne Iowa)",
    "organization_type": "Nonprofit Hospital System (Catholic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NE",
    "hq_city": "Chicago (IL); significant Midwest footprint: Omaha NE, Minneapolis MN, Bismarck ND, Des Moines IA",
    "hq_county": "Cook County (IL HQ); multiple Midwest counties",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2022-12-01",
    "executive_summary": "CommonSpirit Health, the second-largest nonprofit hospital system in the US, was hit by a ransomware attack first detected October 2, 2022. Investigation revealed unauthorized access from September 16\u2013October 3, 2022. Systems were taken offline across 140+ hospitals in 21 states, causing EHR outages, appointment cancellations, and ambulance diversions. Ultimately 623,774 individuals were confirmed affected, with 164 facilities impacted. In the Midwest, affected facilities included CHI Health Nebraska (14 facilities), CHI Saint Joseph Health Minnesota (6 facilities), CHI St. Alexius North Dakota (13 facilities), CHI Mercy Iowa locations, and MercyOne Iowa affiliates. Financial impact: $160 million in losses reported. Midwest facilities experienced multi-week downtime.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "claimed",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Nebraska North Dakota Minnesota Iowa residents affected \u2014 not separately quantified by state",
    "financial_impact": "$160 million total organizational loss (CommonSpirit disclosed); class action lawsuits filed",
    "operational_impact": "Multi-week EHR outage across 140 hospitals; ambulance diversions; delayed procedures; staff reverting to paper records",
    "remediation_disclosed": "Yes \u2014 systems restored over 5+ weeks; FBI and cybersecurity firms engaged; CHI Health at Home services also affected",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and",
      "https://www.cshub.com/attacks/news/commonspirit-health-reports-that-ransomware-attack-cost-160-million"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal (623,774), HIPAA Journal, CommonSpirit official disclosures. Midwest facilities confirmed in April 2023 update.",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare",
      "CS Hub",
      "CommonSpirit official statements"
    ],
    "id": "INC-00211",
    "year": 2022,
    "geocode_note": "Exact city not resolved; placed at NE state centroid.",
    "lat": 41.05116341093632,
    "lng": -98.58192181204926,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "CommonSpirit Health (including Dignity Health CA hospitals)",
    "organization_type": "Nonprofit Catholic health system \u2014 second-largest in US (formed 2019 from Catholic Health Initiatives + Dignity Health merger)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Chicago, IL (national); San Francisco, CA (Dignity Health)",
    "hq_county": "NOT_APPLICABLE (multi-state; Dignity Health CA in San Francisco County)",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2022-10-05",
    "executive_summary": "CommonSpirit Health detected a ransomware attack on October 2, 2022, that disrupted EHR systems, patient portals, and IT infrastructure across over 100 facilities in 13 states. Unauthorized access occurred September 16 \u2013 October 3, 2022, with the threat actor exfiltrating files containing PHI of 623,774+ individuals from two file servers. California's Dignity Health facilities reported minimal direct impact during the incident, but by April 2023 CommonSpirit confirmed 164 facilities were affected, including Dignity Health and Centura Health sites. Total incident cost was $160 million.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'total_disclosed': 160000000, 'notes': '$160M total incident cost per CommonSpirit financial filings; $150M initial estimate'}",
    "operational_impact": "EHR and patient portal outages lasting weeks at affected facilities; ambulance rerouting at some locations (notably MercyOne Des Moines); elective surgery cancellations; staff reverted to paper charting. Dignity Health CA facilities reported 'minimal impact' in official Nov 2022 update.",
    "remediation_disclosed": "Law enforcement notified; leading cybersecurity specialists engaged; forensic investigation completed Feb 21, 2023. Affected individuals notified from December 2022 through April 2023. Corrective security measures implemented.",
    "primary_source_url": "https://www.commonspirit.org/news-articles/commonspirit-update",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and",
      "https://www.healthcaredive.com/news/commonspirit-health-ransomware-cyberattack/634011/",
      "https://www.cshub.com/attacks/news/commonspirit-health-reports-that-ransomware-attack-cost-160-million"
    ],
    "confidence_notes": "OCR breach filing: Dec 1, 2022 (623,774 individuals). Dignity Health is a CA-headquartered subsidiary. The April 2023 update listed no California Dignity Health hospitals specifically among the 164 affected; however Centura Health (associated/former facility) was included. CommonSpirit HQ is Chicago; Dignity Health CA HQ is San Francisco.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00212",
    "year": 2022,
    "lat": 37.16059966721677,
    "lng": -118.07477317262898,
    "is_multistate": true,
    "hq_outside_state": "Chicago",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "CommonSpirit Health / CHI St. Joseph Children's Health (PA)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Lancaster",
    "hq_county": "Lancaster",
    "discovery_date": "2022-10-03",
    "disclosure_date": "2022-12-01",
    "executive_summary": "CommonSpirit Health, the second-largest US nonprofit hospital system, suffered a ransomware attack from September 16 to October 3, 2022, affecting 164 facilities across 13 states. CHI St. Joseph Children's Health in Lancaster, PA was among the affected facilities. Total confirmed affected individuals reached 623,774. The attack cost CommonSpirit approximately $150 million.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Not separately reported for PA",
    "financial_impact": "$150 million total impact (CommonSpirit reported)",
    "operational_impact": "164 hospitals and care sites affected; EHR and IT systems taken offline; care disruptions across 13 states",
    "remediation_disclosed": "FBI notified; third-party cybersecurity; systems restored over weeks; class action filed",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and"
    ],
    "confidence_notes": "CommonSpirit confirmed; OCR breach report; PA facility (CHI St. Joseph Children's Health Lancaster) listed in affected facilities",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare"
    ],
    "id": "INC-00213",
    "year": 2022,
    "lat": 40.0379,
    "lng": -76.3055,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CommonSpirit Health / Virginia Mason Franciscan Health",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Tacoma",
    "hq_county": "Pierce",
    "discovery_date": "2022-10-03",
    "disclosure_date": "2022-12-01",
    "executive_summary": "CommonSpirit Health, the Chicago-based parent of Virginia Mason Franciscan Health (VMFH), suffered a ransomware attack in which unauthorized access occurred from September 16 to October 3, 2022. VMFH operates 10 hospitals in the Puget Sound area. Patient data including names, addresses, phone numbers, dates of birth, and internal hospital IDs were exposed. Electronic health record and MyChart patient portal systems were taken offline for approximately two weeks, causing appointment cancellations and care disruptions. CommonSpirit estimated total losses of approximately $160 million across its 140-hospital network.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Not separately reported (VMFH serves Puget Sound region)",
    "financial_impact": "~$160 million total losses reported by CommonSpirit system-wide",
    "operational_impact": "EHR and MyChart offline ~2 weeks; appointment cancellations at multiple WA hospitals including St. Joseph, St. Michael, St. Clare, St. Francis, and others",
    "remediation_disclosed": "Systems restored with enhanced monitoring; law enforcement notified; breach notifications sent",
    "primary_source_url": "https://www.seattletimes.com/seattle-news/health/patient-data-leaked-in-last-months-cyberattack-on-virginia-mason-franciscan-health/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594537/CommonSpirit-Ransomware-Attack-Impacted-Patient-Data-at-Virginia-Mason-Franciscan-Health"
    ],
    "confidence_notes": "HHS OCR breach portal listed CommonSpirit (IL-HQ) as 623,774; WA-specific patient count not disaggregated; well-corroborated by Seattle Times and HealthTech Security reporting",
    "sources_used": [
      "Seattle Times",
      "TechTarget HealthTech Security",
      "HIPAA Journal"
    ],
    "id": "INC-00214",
    "year": 2022,
    "lat": 47.2529,
    "lng": -122.4443,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Community Health Network (Indiana) \u2014 2022 Tracking Pixel",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2022-11-18",
    "disclosure_date": "2022-11-18",
    "executive_summary": "Community Health Network (CHN) of Indiana reported to HHS OCR on November 18, 2022 an unauthorized access/disclosure breach affecting 1.5 million individuals related to the use of website tracking code (tracking pixels) that transmitted patient information to third parties without patient consent. This was one of the largest pixel-tracking breach disclosures in the healthcare sector.",
    "attack_type": "Unauthorized Tracking Technology Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable \u2014 third-party ad platforms as data recipients",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1500000,
    "residents_affected_in_state": 1500000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No clinical disruption; HHS OCR investigation; privacy compliance impact",
    "remediation_disclosed": "Yes \u2014 tracking code removed; HHS OCR notified",
    "primary_source_url": "https://www.bankinfosecurity.com/community-health-network-breach-a-20569",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HHS OCR breach portal report; BankInfoSecurity reporting.",
    "sources_used": [
      "BankInfoSecurity"
    ],
    "id": "INC-00215",
    "year": 2022,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Comstar LLC",
    "organization_type": "Business Associate (Ambulance Billing)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MA",
    "hq_city": "North Billerica",
    "hq_county": "Middlesex",
    "discovery_date": "2022-03-01",
    "disclosure_date": "2022-09-01",
    "executive_summary": "Comstar LLC, a Massachusetts-based ambulance billing and coding company, suffered a ransomware attack in March 2022 in which an unauthorized actor accessed, encrypted, and held for ransom files and servers. The breach exposed the Social Security numbers, driver's license numbers, financial account numbers, and medical assessment information of approximately 349,255 individuals\u2014326,426 Massachusetts residents and 22,829 Connecticut residents. A $515,000 multi-state settlement with the MA and CT Attorneys General was reached in January 2026.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 349255,
    "residents_affected_in_state": 326426,
    "financial_impact": "$515,000 MA/CT AG settlement (2026); $415,000 to MA, $100,000 to CT",
    "operational_impact": "Ambulance billing records for ~349,000 patients exposed; SSNs, financial data, and medical assessment data stolen",
    "remediation_disclosed": "MA and CT AG settlement; phishing protection, MFA, intrusion detection, and annual security assessments mandated",
    "primary_source_url": "https://www.govtech.com/security/ambulance-company-to-pay-two-states-515k-over-data-breach",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthcare-data-breach-statistics/"
    ],
    "confidence_notes": "GovTech reports CT AG Tong confirms exact figures; MA/CT AG press releases confirm settlement; well documented",
    "sources_used": [
      "GovTech",
      "CT AG",
      "MA AG"
    ],
    "id": "INC-00216",
    "year": 2022,
    "lat": 42.5852621,
    "lng": -71.2877645,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Conifer Revenue Cycle Solutions, LLC",
    "organization_type": "Business Associate (Revenue Cycle Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Frisco",
    "hq_county": "Collin",
    "discovery_date": "2022-01-20",
    "disclosure_date": "2022-08-12",
    "executive_summary": "Conifer Revenue Cycle Solutions, LLC (a Tenet Healthcare subsidiary providing revenue cycle management to healthcare providers) discovered unauthorized access to a Microsoft Office 365-hosted business email account on April 14, 2022, with the unauthorized access having occurred on January 20, 2022. A detailed review from June 13 to August 3, 2022 confirmed that personal and protected health information of 134,948 individuals was contained in the compromised email account. The incident affected patients at five healthcare organizations that used Conifer's services. A class action lawsuit was filed against Conifer and Tenet Healthcare.",
    "attack_type": "Hacking/IT Incident \u2013 Microsoft 365 Business Email Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 134948,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuit filed; settlement amount not publicly disclosed",
    "operational_impact": "Limited to compromised email account; internal network and systems not affected",
    "remediation_disclosed": "Enhanced email security; bolstered safeguards; notifications sent",
    "primary_source_url": "https://www.hipaajournal.com/august-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.healthcareittoday.com/2022/08/17/conifer-health-solutions-security-incident-impacts-patients-at-5-healthcare-organizations/",
      "https://www.classaction.org/news/conifer-tenet-failed-to-prevent-january-2022-data-breach-class-action-claims"
    ],
    "confidence_notes": "HHS OCR confirmed 134,948 affected; listed in HIPAA Journal August 2022 Monthly Report; class action filed",
    "sources_used": [
      "HIPAA Journal August 2022 Monthly Report, Healthcare IT Today, ClassAction.org"
    ],
    "id": "INC-00217",
    "year": 2022,
    "lat": 33.1507,
    "lng": -96.8236,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Connexin Software (Office Practicum)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "PA",
    "hq_city": "Ambler",
    "hq_county": "Montgomery",
    "discovery_date": "2022-08-26",
    "disclosure_date": "2022-11-14",
    "executive_summary": "Connexin Software (operating as Office Practicum), a Pennsylvania-based EHR and billing provider for pediatric practices, suffered a data breach in August 2022 when unauthorized parties accessed an offline dataset used for data conversion and troubleshooting. The breach affected 2,216,365 patients across hundreds of pediatric practices nationwide. Data compromised included names, SSNs, DOBs, health insurance information, and medical records. A $4 million settlement was reached.",
    "attack_type": "Hacking/IT Incident (unauthorized access to offline data)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2216365,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4 million settlement",
    "operational_impact": "PHI of 2.2M+ pediatric patients exposed across hundreds of practices nationwide",
    "remediation_disclosed": "Law enforcement notified; affected practices notified; credit monitoring; $4M settlement",
    "primary_source_url": "https://www.hipaajournal.com/november-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.ahdootwolfson.com/blog/connexin-software-a-k-a-office-practicum-suffered-a-data-breach-impacting-2-2-million-people-class-action-investigation/",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/connexin-software-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "OCR breach report; $4M settlement; class action in Eastern District of PA",
    "sources_used": [
      "HIPAA Journal",
      "Ahdoot & Wolfson",
      "Top Class Actions"
    ],
    "id": "INC-00218",
    "year": 2022,
    "lat": 40.1545535,
    "lng": -75.2215651,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Connexin Software, Inc.",
    "organization_type": "BA/Vendor (Pediatric EHR / Practice Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "PA",
    "hq_city": "Philadelphia",
    "hq_county": "Philadelphia",
    "discovery_date": "2022-08-26",
    "disclosure_date": "2022-10-22",
    "executive_summary": "In August 2022, Connexin Software, a Philadelphia-based electronic health record (EHR) and practice management vendor serving approximately 119 pediatric specialty practices nationwide, experienced a ransomware attack affecting an offline database used for data storage and analysis. The offline dataset contained patient records from practices that had previously used Connexin's software, meaning some affected patients no longer had active relationships with the practices. Connexin reported the breach to HHS OCR on December 28, 2022 as affecting 2,216,365 individuals \u2014 predominantly minors. Compromised data included names, dates of birth, addresses, Social Security numbers, insurance information, diagnoses, and clinical records. This remains one of the largest known breaches specifically affecting the pediatric patient population.",
    "attack_type": "Ransomware / Data Exfiltration (offline database)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2216365,
    "residents_affected_in_state": 119,
    "financial_impact": "Class action lawsuits filed across multiple jurisdictions. Settlement not publicly announced as of research date.",
    "operational_impact": "119 pediatric practices' historical patient data compromised. Predominantly minor patient population. Offline backup database targeted \u2014 primary EHR systems may not have been directly impacted.",
    "remediation_disclosed": "Third-party forensics. Law enforcement notified. HHS OCR breach reported December 2022. Notification letters mailed to 2.2M individuals. Credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/connexin-software-data-breach/",
    "secondary_source_urls": [
      "https://www.bleepingcomputer.com/news/security/connexin-software-breach-exposes-data-of-119-pediatric-practices/",
      "https://healthitsecurity.com/news/connexin-software-breach-affects-2-2m-patients"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report confirms 2,216,365 as of December 2022 filing. HIPAA Journal and BleepingComputer corroborate pediatric scope and offline database vector. Note: ID 68 was incorrectly labeled; this ID 69 is the correct Connexin entry.",
    "sources_used": [
      "HIPAA Journal",
      "BleepingComputer",
      "Health IT Security"
    ],
    "id": "INC-00219",
    "year": 2022,
    "lat": 39.9526,
    "lng": -75.1652,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Danbury Psychiatric Consultants",
    "organization_type": "Healthcare Provider (Psychiatry)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "Danbury",
    "hq_county": "Fairfield",
    "discovery_date": "2021-06-01",
    "disclosure_date": "2022-01-01",
    "executive_summary": "Danbury Psychiatric Consultants in Danbury, Connecticut, was subject to a $3,500 HHS OCR HIPAA settlement in 2022 stemming from a cybersecurity incident involving impermissible PHI disclosure. The practice provides psychiatric care to patients in western Connecticut.",
    "attack_type": "Hacking/IT Incident (unauthorized access/disclosure)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3,500 HHS OCR settlement (2022)",
    "operational_impact": "Psychiatric patient PHI impermissibly disclosed",
    "remediation_disclosed": "HHS OCR settlement with corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2022 OCR penalties table confirms $3.5K settlement; CT psychiatric practice",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00220",
    "year": 2022,
    "lat": 41.394817,
    "lng": -73.4540111,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Erie County Medical Center Corporation",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Buffalo",
    "hq_county": "Erie",
    "discovery_date": "2021-09-01",
    "disclosure_date": "2022-01-01",
    "executive_summary": "Erie County Medical Center Corporation (ECMCC) in Buffalo, New York was subject to a $50,000 HHS OCR HIPAA settlement in 2022. ECMCC previously suffered a significant ransomware attack in April 2017 (SamSam ransomware, 6,000 computers affected) and has continued to face cybersecurity-related enforcement. The 2022 settlement addressed HIPAA compliance deficiencies related to data security.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$50,000 HHS OCR settlement (2022)",
    "operational_impact": "Patient data security deficiencies identified",
    "remediation_disclosed": "HHS OCR HIPAA settlement with corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2022 OCR penalties table confirms $50K settlement; notable NY public hospital; prior 2017 SamSam attack documented separately",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00221",
    "year": 2022,
    "lat": 42.8864,
    "lng": -78.8784,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Eye Care Leaders (Iowa / Midwest eye care providers)",
    "organization_type": "EHR Software Vendor (Business Associate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Durham NC (serves Midwest providers including Iowa Wolfe Clinic, Wisconsin ophthalmology practices)",
    "hq_county": "Durham County NC",
    "discovery_date": "2021-12-04",
    "disclosure_date": "2022-05-24",
    "executive_summary": "Eye Care Leaders (ECL), an EHR and patient management software provider serving ophthalmology practices nationwide, was breached in December 2021 in a ransomware attack that destroyed databases and configuration files. At least 41 Iowa, Wisconsin, Michigan, Illinois, Indiana, Ohio, and Minnesota eye care providers had patient data compromised. Total affected patients across all providers exceeded 3.65 million nationwide. Iowa Wolfe Clinic (see MW-097) reported 542,776 patients affected. Multiple other Midwest eye care providers also reported sub-breaches. A $4.07 million class action settlement was reached in 2024. This entry documents the ECL breach itself as a multi-state Midwest business associate breach.",
    "attack_type": "Ransomware / Database Destruction",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3649470,
    "residents_affected_in_state": "Iowa Wisconsin Michigan Illinois Indiana Ohio Minnesota eye care patients (significant Midwest exposure)",
    "financial_impact": "$4.07 million class action settlement (2024); $2.61M for patients, $1.46M for physicians",
    "operational_impact": "Practice management and EHR systems destroyed/unavailable for 41+ providers nationwide; major disruption to eye care practices",
    "remediation_disclosed": "Yes \u2014 ECL rebuilt systems; providers notified; patients individually notified 2022; settlement 2024",
    "primary_source_url": "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/eye-care-leaders-ecl-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal confirmed 3,649,470 total; Iowa Wolfe Clinic is 542,776; multiple Midwest providers affected. $4.07M settlement confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "Top Class Actions",
      "HHS OCR"
    ],
    "id": "INC-00222",
    "year": 2022,
    "lat": 35.9495488,
    "lng": -78.9263775,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Eye Care Leaders (NE ophthalmology clients)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Durham",
    "hq_county": "Durham",
    "discovery_date": "2021-12-04",
    "disclosure_date": "2022-03-01",
    "executive_summary": "Eye Care Leaders, a provider of electronic health record systems to eye care providers, suffered a cyberattack in December 2021 that affected at least 41 eye care providers nationally and exposed the data of approximately 3.65 million patients. Multiple Northeast eye care practices were among the affected clients. The company destroyed its myCare Integrity environment on December 4-5, 2021 in response to the incident.",
    "attack_type": "Hacking/IT Incident (cloud EHR environment attack)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3650000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; multiple class action lawsuits filed",
    "operational_impact": "41+ eye care providers' patient records compromised; cloud EHR environment destroyed; significant disruption to NE ophthalmology practices",
    "remediation_disclosed": "Cloud environment taken offline; provider clients notified; HHS OCR notified",
    "primary_source_url": "https://www.hipaajournal.com/2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2022 breach report confirms 3.65M patients across 41+ providers; NE clients documented; included for NE-affiliate coverage",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00223",
    "year": 2022,
    "lat": 35.994,
    "lng": -78.8986,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Eye Care Leaders, LLC",
    "organization_type": "BA / Vendor (EHR for Eye Care)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Durham",
    "hq_county": "Durham",
    "discovery_date": "2021-12-04",
    "disclosure_date": "2022-03-01",
    "executive_summary": "Eye Care Leaders (ECL), a Durham-based vendor providing electronic health records and practice management software to 9,000+ ophthalmologists and optometrists nationwide, suffered a ransomware attack on December 4, 2021, in which hackers accessed its cloud-based myCare Integrity solution and deleted databases and system configuration files. At least 41 eye care providers confirmed their patient data was compromised, with total affected individuals across all reporting entities reaching 3,649,470. The largest single impact was at Texas Tech University Health Science Center (1.29M patients). A class action settlement of $4.07 million was reached in 2024 ($2.61M for patients; $1.46M for physicians/clinics).",
    "attack_type": "Ransomware / Database Deletion / Data Exfiltration (data theft not confirmed but could not be ruled out)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3649470,
    "residents_affected_in_state": 1290000,
    "financial_impact": "$4.07 million class action settlement (final approval June 2024). No ransom payment confirmed. ECL also faced separate revenue cycle management claims.",
    "operational_impact": "EHR system downtime for at least a week for some providers. Databases deleted requiring restoration. Eye care practices unable to access patient records during outage.",
    "remediation_disclosed": "Unauthorized access terminated within 24 hours. Forensic investigation conducted through April 2022. Client notifications began March 1, 2022. Credit monitoring offered by affected providers. Settlement fund established.",
    "primary_source_url": "https://www.eyecareleaders.com/data-security-incident-notice/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
      "https://www.bankinfosecurity.com/cloud-based-ehr-vendor-hack-affects-eye-care-practices-a-19066",
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/eye-care-leaders-ecl-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. 41 affected providers listed with individual counts confirmed by multiple OCR reports and Maine AG filings. Total 3,649,470 from HIPAA Journal tracking table.",
    "sources_used": [
      "Eye Care Leaders official notice",
      "HIPAA Journal",
      "BankInfoSecurity",
      "Compliancy Group",
      "Top Class Actions"
    ],
    "id": "INC-00224",
    "year": 2022,
    "lat": 35.994,
    "lng": -78.8986,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "First Choice Community Health Care, Inc.",
    "organization_type": "Healthcare Provider (Community Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NM",
    "hq_city": "Albuquerque",
    "hq_county": "Bernalillo",
    "discovery_date": "2022-03-27",
    "disclosure_date": "2022-08-01",
    "executive_summary": "First Choice Community Healthcare, Inc., a community health system operating nine facilities across three New Mexico counties, discovered suspicious activity in its computer systems on March 27, 2022. An independent cybersecurity investigation confirmed that an unauthorized party accessed and may have acquired files containing protected health information. The review, completed June 3, 2022, identified 101,541 potentially affected individuals. Data compromised included names, Social Security numbers, First Choice patient ID numbers, diagnosis and clinical treatment information, medications, dates of service, health insurance information, medical record numbers, patient account numbers, dates of birth, and provider information.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Hacking",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 101541,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Engaged independent cybersecurity firm; notifications sent August 1, 2022; toll-free call center established; credit monitoring offered",
    "primary_source_url": "https://www.prnewswire.com/news-releases/first-choice-provides-notice-following-data-security-incident-301596950.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/august-2022-healthcare-data-breach-report/",
      "https://www.jdsupra.com/legalnews/first-choice-community-healthcare-inc-6860484/"
    ],
    "confidence_notes": "HHS OCR confirmed 101,541 affected; listed in HIPAA Journal August 2022 Monthly Report; PR Newswire official notice available",
    "sources_used": [
      "PR Newswire, HIPAA Journal August 2022 Monthly Report, JD Supra"
    ],
    "id": "INC-00225",
    "year": 2022,
    "lat": 35.0844,
    "lng": -106.6504,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Fred Hutchinson Cancer Center / Seattle Cancer Care Alliance (email breach)",
    "organization_type": "Healthcare Provider (Cancer Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2022-03-26",
    "disclosure_date": "2022-06-08",
    "executive_summary": "Fred Hutchinson Cancer Center (formerly Seattle Cancer Care Alliance) disclosed that an unauthorized third party accessed a single employee email account between March 25 and March 26, 2022. The compromised account contained protected health information and personal information of some patients, including names, addresses, Social Security numbers, driver's license numbers, financial account information, medical information, and health insurance information. Fred Hutch immediately terminated the unauthorized access and retained a forensic security firm. No indication of identity theft or fraud was identified. This is a separate and earlier incident from the November 2023 Hunters International ransomware attack (WA-002).",
    "attack_type": "Phishing / Unauthorized email access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately reported (small number \u2014 single employee email account)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Single employee email account compromised; patient notifications sent",
    "remediation_disclosed": "Account secured; forensic investigation conducted; law enforcement and regulators notified; patient notification letters sent",
    "primary_source_url": "https://www.fredhutch.org/en/news/releases/2022/06/notice-of-a-data-security-incident-involving-seattle-cancer-care.html",
    "secondary_source_urls": [
      "https://www.fredhutch.org/en/news/releases/2022/10/notice-of-a-data-security-incident.html"
    ],
    "confidence_notes": "High confidence: official Fred Hutch notice published; separate from 2023 ransomware attack; individual count not disclosed as breach may have been below HHS notification threshold or was filed under a smaller count",
    "sources_used": [
      "Fred Hutch official notice (June 2022)",
      "Fred Hutch official notice (October 2022)"
    ],
    "id": "INC-00226",
    "year": 2022,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Gateway Rehabilitation Center",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Aliquippa",
    "hq_county": "Beaver",
    "discovery_date": "2022-06-13",
    "disclosure_date": "2022-11-18",
    "executive_summary": "Gateway Rehabilitation Center, a Pennsylvania drug rehabilitation and addiction treatment provider, discovered a cyberattack (attributed to BlackByte ransomware) on June 13, 2022. Approximately 130,000 patients had their PII and PHI compromised, including SSNs, financial information, and medical records. BlackByte published leaked data on its dark web site by July 8, 2022. Gateway waited 5 months to notify patients. A $775K settlement received preliminary approval.",
    "attack_type": "Ransomware (BlackByte)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackByte",
    "attribution_status": "reported",
    "individuals_affected_reported": 130000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$775,000 settlement (preliminary approval)",
    "operational_impact": "130K patients' records exposed; data published on dark web",
    "remediation_disclosed": "Law enforcement notified; credit monitoring offered; $775K settlement",
    "primary_source_url": "https://databreaches.net/2022/11/19/gateway-rehab-issues-notice-about-june-ransomware-incident/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/gateway-rehabilitation-center-facing-class-action-over-2022-data-breach-impacting-130k-patients",
      "https://shublawyers.com/current-cases/gateway-rehab-data-breach-preliminary-approval-of-775k-settlement-granted-in-class-action/"
    ],
    "confidence_notes": "DataBreaches.Net reporting with screenshots; OCR breach report; class action; $775K settlement",
    "sources_used": [
      "DataBreaches.Net",
      "ClassAction.org",
      "Shub Johns & Holbrook"
    ],
    "id": "INC-00227",
    "year": 2022,
    "lat": 40.6102386,
    "lng": -80.267726,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Health Alliance Hospital (Kingston, NY) - Network Server Hacking Nov 2022",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Kingston",
    "hq_county": "Ulster",
    "discovery_date": "2022-10-01",
    "disclosure_date": "2022-11-15",
    "executive_summary": "New York-Presbyterian Healthcare system (which includes Health Alliance Hospital in Kingston) reported a network server hacking incident in November 2022 affecting 12,000 individuals. This is separate from the 2023 cyberattack on HealthAlliance. Patient PHI on network servers was compromised.",
    "attack_type": "Hacking/IT Incident (network server)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 12000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network server compromised; 12K patient records exposed",
    "remediation_disclosed": "HHS OCR breach report filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/november-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal November 2022 report",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00228",
    "year": 2022,
    "lat": 41.9287812,
    "lng": -74.0023825,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Highmark Inc. (PA/DE health plan members)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "PA",
    "hq_city": "Pittsburgh",
    "hq_county": "Allegheny",
    "discovery_date": "2021-12-10",
    "disclosure_date": "2022-05-06",
    "executive_summary": "Highmark Inc., Pennsylvania's largest health insurer serving Pennsylvania, West Virginia, Delaware, and New York, reported a data security incident involving unauthorized access to member health plan data through a third-party vendor. The breach affected members across multiple Northeast states. Highmark confirmed the incident was limited to data held by the vendor and did not directly penetrate Highmark's own systems.",
    "attack_type": "Hacking/IT Incident (third-party vendor)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member data compromised via vendor; PA, WV, DE, NY members affected",
    "remediation_disclosed": "HHS OCR and members notified; vendor security reviewed",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; PA-based major insurer; NE states confirmed service area; note separate entry in existing dataset marks Highmark with more detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00229",
    "year": 2022,
    "lat": 40.4406,
    "lng": -79.9959,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Infinity Rehab / Avamere Health Services",
    "organization_type": "Healthcare Provider (Rehabilitation & Senior Care Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Wilsonville",
    "hq_county": "Clackamas County (OR headquarters; WA patients affected)",
    "discovery_date": "2022-03-17",
    "disclosure_date": "2022-07-28",
    "executive_summary": "Avamere Health Services and its subsidiary Infinity Rehab suffered unauthorized network access between January 19 and March 17, 2022. The breach affected 197,730 patients at Avamere and 183,254 at Infinity Rehab (total 380,984 individuals nationally). Washington state partner MultiCare specifically notified 18,615 Washington patients whose data was held by Infinity Rehab. Compromised information included names, SSNs, dates of birth, medical records, financial account information, and treatment data.",
    "attack_type": "Unauthorized network access / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 380984,
    "residents_affected_in_state": 18615,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "380,984 patients across multiple states notified; WA patients at MultiCare facilities included",
    "remediation_disclosed": "Forensic investigation; individual notifications; credit monitoring offered",
    "primary_source_url": "https://databreaches.net/2022/07/28/infinity-rehab-and-avamere-health-services-notify-380984-patients-about-breach-at-avamere/",
    "secondary_source_urls": [
      "https://www.thenewstribune.com/news/local/article264390016.html",
      "https://www.hipaajournal.com/avamere-health-services-infinity-rehab-data-breach/"
    ],
    "confidence_notes": "HHS OCR breach portal confirmed 380,984 total; WA patient count (18,615) confirmed via MultiCare partner notification; DataBreaches.net reporting",
    "sources_used": [
      "DataBreaches.net",
      "The News Tribune (Tacoma)",
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00230",
    "year": 2022,
    "geocode_note": "Exact city not resolved; placed at WA state centroid.",
    "lat": 47.72186110236136,
    "lng": -121.85997106711814,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Injured Workers Pharmacy",
    "organization_type": "Healthcare Provider (Pharmacy)",
    "organization_type_bucket": "Pharmacy",
    "state": "MA",
    "hq_city": "Andover",
    "hq_county": "Essex",
    "discovery_date": "2021-11-01",
    "disclosure_date": "2022-02-03",
    "executive_summary": "Injured Workers Pharmacy, an Andover, Massachusetts specialty pharmacy serving workers' compensation patients, reported a cyber incident to the Vermont Attorney General in February 2022. The breach involved unauthorized access to patient medication and personal information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Specialty pharmacy patient records compromised",
    "remediation_disclosed": "Vermont AG notified; patients notified",
    "primary_source_url": "https://ago.vermont.gov/blog/2022/02/03/",
    "secondary_source_urls": [],
    "confidence_notes": "Vermont AG breach notice database; limited detail available publicly",
    "sources_used": [
      "Vermont AG"
    ],
    "id": "INC-00231",
    "year": 2022,
    "lat": 42.65717,
    "lng": -71.1408776,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Kaiser Foundation Health Plan of Washington",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Renton",
    "hq_county": "King",
    "discovery_date": "2022-04-05",
    "disclosure_date": "2022-06-03",
    "executive_summary": "Kaiser Foundation Health Plan of Washington discovered on April 5, 2022, that an unauthorized party had gained access to an employee's email account. The compromised account contained names, dates of service, medical record numbers, and laboratory test result information for 69,589 members. The unauthorized access was terminated within hours of discovery. The incident was reported to HHS OCR and notifications were sent to affected members.",
    "attack_type": "Email compromise / Unauthorized access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 69589,
    "residents_affected_in_state": "Majority WA-based members",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unauthorized access to member PHI in employee email",
    "remediation_disclosed": "Access terminated within hours; FBI notified; notifications sent",
    "primary_source_url": "https://www.techtarget.com/healthtechsecurity/news/366594773/Kaiser-Permanente-Discloses-Data-Breach-at-WA-Health-Plan-69K-Impacted",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR confirmed; TechTarget HealthTech Security reported June 2022",
    "sources_used": [
      "TechTarget HealthTech Security",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00232",
    "year": 2022,
    "lat": 47.4829,
    "lng": -122.2171,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kaiser Foundation Health Plan, Inc., Southern California",
    "organization_type": "Health Plan / Integrated Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Oakland, CA",
    "hq_county": "Alameda County",
    "discovery_date": "2022-05-20",
    "disclosure_date": "2022-07-15",
    "executive_summary": "On May 20, 2022, Kaiser Permanente discovered that an unknown individual broke into a locked storage area at the Kaiser Permanente Los Angeles Medical Center earlier that same day and stole a Kaiser Permanente iPad. The password to access the iPad was stolen along with the device. The iPad was used at a Kaiser Permanente COVID-19 testing site by employees and contained photos of COVID-19 lab specimen labels (there were no photos of any individual patients). While we do not have any specific evidence that your information was accessed and/or viewed by the unknown individual, you were among indi",
    "attack_type": "Phishing / Email Attack",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Multiple incidents (see individual notices)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/LAMC%20iPad%20Breach_Member%20Notification%20Letter_FINAL%20ADULT%20%281%29.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/kaiser-foundation-health-plan-data-breach/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00233",
    "year": 2022,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Keck Medicine of USC",
    "organization_type": "Academic medical center (University of Southern California; Keck Hospital + Norris Cancer Hospital + outpatient clinics)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles County",
    "discovery_date": "2022-09-30",
    "disclosure_date": "2022-12-15",
    "executive_summary": "On September 30, 2022, Keck Medicine of USC discovered unauthorized access to a provider's email account. An investigation determined the account was accessed without authorization, and a review of its contents (completed November 22, 2022) confirmed the presence of patient PHI including names, addresses, SSNs, lab results, medical diagnoses, and health insurance information. Notification letters were sent December 15, 2022. The number of affected individuals was not publicly disclosed in available sources.",
    "attack_type": "Email account compromise (likely phishing)",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": "NOT_PUBLICLY_DISCLOSED",
    "residents_affected_in_state": "Predominantly CA given USC patient base",
    "financial_impact": "{'notes': 'No financial penalties or settlements publicly disclosed for this incident.'}",
    "operational_impact": "Limited to single provider email account. No clinical disruption reported.",
    "remediation_disclosed": "Account secured; independent forensic investigation; provider assigned additional security awareness training; additional technical controls implemented. Toll-free hotline 1-833-814-1789 established.",
    "primary_source_url": "https://www.keckmedicine.org/wp-content/uploads/2022/12/Keck-Medicine-of-USC-Notice-of-Data-Incident.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/ransomware-attack-announced-by-keck-medical-center-of-usc-3605/",
      "https://www.keckmedicine.org/wp-content/uploads/2022/12/Keck-Medicine-of-USC-Notice-of-Data-Incident.pdf",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf"
    ],
    "confidence_notes": "Keck also suffered a 2016 ransomware attack (Aug 1, 2016; Keck Hospital and Norris Hospital servers encrypted; 16,000 patients affected; no ransom paid; data recovered from backups) \u2014 the 2022 email compromise is the more recent in-scope incident. The 2016 incident is outside the 2018\u20132025 scope but noted for historical context. | PHI potentially involved: name, address, DOB, SSN, patient ID, lab results, provider info, medical diagnosis/treatment, health insurance info. Access limited to single provider email account. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HHS OCR Breach Portal",
      "Organization notice / News / SEC"
    ],
    "id": "INC-00234",
    "year": 2022,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Kernersville Eye Surgeons (Eye Care Leaders)",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Kernersville",
    "hq_county": "Forsyth",
    "discovery_date": "2021-12-08",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Kernersville Eye Surgeons was one of the North Carolina eye care practices affected by the Eye Care Leaders (ECL) ransomware attack of December 2021. The breach affected 13,412 patients, exposing PHI from ECL's myCare Integrity EMR system.",
    "attack_type": "Ransomware (Supply-Chain via Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13412,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient EMR data exposed",
    "remediation_disclosed": "ECL took down compromised systems; patient notification letters sent",
    "primary_source_url": "https://www.hipaajournal.com/june-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 HIPAA Journal June 2022 breach report, HHS OCR data.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00235",
    "year": 2022,
    "lat": 36.1198589,
    "lng": -80.0736533,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Kevin Wolf DPM (Goldsboro Podiatry) \u2014 NC",
    "organization_type": "Healthcare Provider / Podiatry Practice",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Goldsboro",
    "hq_county": "Wayne",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Goldsboro Podiatry (Kevin Wolf, DPM) in North Carolina reported a network hacking incident to HHS OCR in June 2022, affecting 30,669 individuals. The breach involved unauthorized access to network server systems containing patient PHI.",
    "attack_type": "Network Server Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 30669,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network server containing patient PHI accessed by unauthorized individuals",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/june-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence \u2014 HIPAA Journal June 2022 breach report with HHS OCR data; limited additional reporting available.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00236",
    "year": 2022,
    "lat": 35.3848841,
    "lng": -77.9927651,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Keystone Health (Chambersburg PA)",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Chambersburg",
    "hq_county": "Franklin",
    "discovery_date": "2022-08-19",
    "disclosure_date": "2022-10-14",
    "executive_summary": "Keystone Health, a Federally Qualified Health Center in Chambersburg, Pennsylvania, reported a cyberattack on August 19, 2022 in which unauthorized actors accessed its computer systems. The breach affected approximately 235,237 patients, with compromised data including names, SSNs, dates of birth, clinical treatment information, and health insurance details.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 235237,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Community health center patient records compromised; SSNs and clinical data exposed",
    "remediation_disclosed": "Third-party forensics engaged; law enforcement notified; HHS OCR notified; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; PA FQHC; 235,237 confirmed; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00237",
    "year": 2022,
    "lat": 39.9375112,
    "lng": -77.6612586,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Logan Health Medical Center",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MT",
    "hq_city": "Kalispell",
    "hq_county": "Flathead",
    "discovery_date": "2021-11-22",
    "disclosure_date": "2022-02-24",
    "executive_summary": "Logan Health Medical Center (formerly Kalispell Regional Healthcare), a regional hospital system in northwest Montana, detected suspicious activity on its systems November 22, 2021, including evidence of unauthorized access to a single file server containing patient information. The intrusion occurred November 18, 2021. Investigation confirmed on January 5, 2022, that certain files had been accessed. 213,543 individuals were affected (174,761 Montanans). Compromised data included names, addresses, medical record numbers, SSNs, dates of birth, phone numbers, email addresses, insurance claim information, diagnoses, and treating physician data. Electronic medical records were not compromised. A $4.3 million class action settlement was reached.",
    "attack_type": "Hacking / Unauthorized File Server Access",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 213543,
    "residents_affected_in_state": 174761,
    "financial_impact": "$4.3 million class action settlement (January 2023). Previous breach (2019 phishing, 130K patients) settled for $4.2M. Combined breach settlements exceed $8.5M.",
    "operational_impact": "Single file server compromised. Electronic medical records unaffected. Patient care continued normally.",
    "remediation_disclosed": "File server isolated. Third-party forensic investigators retained. Additional security measures implemented. Notification letters and credit monitoring offered. $4.3M settlement.",
    "primary_source_url": "https://loganhealth.org/notice-of-data-security-incident/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/logan-health-medical-center-cyberattack-affects-more-than-213000-patients/",
      "https://flatheadbeacon.com/2022/03/08/logan-health-notifies-patients-of-data-breach-that-affected-thousands-of-montanans/",
      "https://www.techtarget.com/healthtechsecurity/news/366594480/Logan-Health-Reaches-43M-Settlement-Following-Healthcare-Data-Breach-Lawsuit",
      "https://topclassactions.com/lawsuit-settlements/privacy/data-breach/logan-health-data-breach-4-3m-class-action-settlement/",
      "https://law.justia.com/cases/montana/supreme-court/2024/da-23-0215.html",
      "https://www.scworld.com/analysis/logan-health-agrees-to-4-3m-settlement-after-2021-health-data-breach"
    ],
    "confidence_notes": "High confidence. Maine AG filing confirmed 213,543 affected. Montana-specific count (174,761) from Flathead Beacon. $4.3M settlement confirmed. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Flathead Beacon",
      "HIPAA Journal",
      "Logan Health official notice",
      "SC Media, Top Class Actions, Justia (Montana Supreme Court)",
      "TechTarget"
    ],
    "id": "INC-00238",
    "year": 2022,
    "lat": 48.1958,
    "lng": -114.3127,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Lowell General Hospital (Mass General Brigham affiliate)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Lowell",
    "hq_county": "Middlesex",
    "discovery_date": "2022-04-01",
    "disclosure_date": "2022-07-01",
    "executive_summary": "Lowell General Hospital, a community hospital in Lowell, Massachusetts and affiliate of Mass General Brigham (formerly Partners HealthCare), reported a data security incident involving unauthorized access to patient health information. The breach affected patients receiving care at Lowell General's main campus and Saints campus facilities.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Community hospital patient PHI compromised",
    "remediation_disclosed": "HHS OCR and patients notified; security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2022; MA community hospital; Mass General Brigham affiliation confirmed; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00239",
    "year": 2022,
    "lat": 42.6334,
    "lng": -71.3162,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Lubbock Heart & Surgical Hospital",
    "organization_type": "Healthcare Provider (Specialty Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Lubbock",
    "hq_county": "Lubbock",
    "discovery_date": "2022-07-12",
    "disclosure_date": "2022-09-09",
    "executive_summary": "Lubbock Heart & Surgical Hospital experienced a hacking incident between July 11 and July 12, 2022 in which an unauthorized party accessed its systems and attempted to copy files. The hospital took immediate action to block access and secure systems. 122,605 patients were affected. Compromised data may have included PHI stored in accessed files.",
    "attack_type": "Hacking/IT Incident \u2013 Unauthorized Access / Data Exfiltration Attempt",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 122605,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems taken offline; immediate containment actions taken",
    "remediation_disclosed": "Systems secured; forensic investigation; notifications sent",
    "primary_source_url": "https://www.classaction.org/media/lubbock-heart-surgical-hospital-data-breach-notice.pdf",
    "secondary_source_urls": [
      "https://lubbocklights.com/umc-paid-ransom-with-insurance-data-was-restored-not-sold-on-dark-web/"
    ],
    "confidence_notes": "High confidence; HHS OCR breach report confirmed 122,605; data breach notice available",
    "sources_used": [
      "ClassAction.org (breach notice PDF), Lubbock Lights"
    ],
    "id": "INC-00240",
    "year": 2022,
    "lat": 33.5779,
    "lng": -101.8552,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MCG Health (Washington) \u2014 separate VMMC phishing incident",
    "organization_type": "Healthcare Provider (Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2022-01-03",
    "disclosure_date": "2022-03-01",
    "executive_summary": "Virginia Mason Medical Center (VMMC, distinct from VMFH) notified patients of a phishing attack on staff email accounts between December 21, 2021 and January 3, 2022, that affected approximately 3,000 individuals. The FBI was also notified. VMMC implemented blocks to the phishing domain and provided additional employee education. (Note: This is a separate incident from the CommonSpirit/VMFH 2022 ransomware.)",
    "attack_type": "Phishing / Email compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3000,
    "residents_affected_in_state": "WA-based VMMC patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; PHI potentially accessed",
    "remediation_disclosed": "Phishing domain blocked; employee education enhanced; FBI notified",
    "primary_source_url": "https://www.techtarget.com/healthtechsecurity/news/366594773/Kaiser-Permanente-Discloses-Data-Breach-at-WA-Health-Plan-69K-Impacted",
    "secondary_source_urls": [],
    "confidence_notes": "Mentioned as a separate March 2022 notification within TechTarget Kaiser article; VMMC incident confirmed",
    "sources_used": [
      "TechTarget HealthTech Security"
    ],
    "id": "INC-00241",
    "year": 2022,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MCG Health, LLC",
    "organization_type": "Business Associate (Health IT / Patient Care Guidelines)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2022-03-25",
    "disclosure_date": "2022-06-10",
    "executive_summary": "Seattle-based MCG Health, a Hearst Health subsidiary providing patient care guidelines to health plans and providers, suffered a targeted cyberattack around February 25\u201326, 2020, but did not discover the breach until March 25, 2022\u2014more than two years later. The attackers exfiltrated data on approximately 793,283\u20131.1 million patients of at least 10 MCG healthcare clients. Compromised data included names, Social Security numbers, medical codes, addresses, phone numbers, email addresses, dates of birth, and gender. An $8.8 million class-action settlement was reached in 2024.",
    "attack_type": "Targeted data theft / Hacking",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 793283,
    "residents_affected_in_state": "Not separately reported (multi-state clients affected)",
    "financial_impact": "$8.8 million class-action settlement (final approval October 2024)",
    "operational_impact": "PHI and PII of patients at 10+ health system clients exposed; breach undetected for 2 years",
    "remediation_disclosed": "Enhanced intrusion detection and monitoring deployed; $8.8M settlement; 3 years credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/mcg-health-class-action-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.bankinfosecurity.com/software-maker-mcg-health-settles-data-breach-suit-for-88m-a-25851",
      "https://news.bloomberglaw.com/privacy-and-data-security/mcg-health-to-pay-8-8-million-to-settle-suit-over-2022-breach"
    ],
    "confidence_notes": "HHS OCR portal listed 793,283; Maine AG notification listed ~1.1M. Breach occurred Feb 2020 but discovered March 2022; reported as 2022 breach.",
    "sources_used": [
      "HIPAA Journal",
      "Bank Info Security",
      "Bloomberg Law"
    ],
    "id": "INC-00242",
    "year": 2022,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MMA Operations (Wisconsin) \u2014 Health Data Breach",
    "organization_type": "Healthcare Business Services",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WI",
    "hq_city": "Unknown \u2014 Wisconsin-based",
    "hq_county": "Unknown",
    "discovery_date": "2022-06-30",
    "disclosure_date": "2022-09-01",
    "executive_summary": "MMA Operations, a Wisconsin-based healthcare business services company, reported a data breach to the Wisconsin DATCP on September 1, 2022, with an incident date of on or before June 30, 2022. Data accessed included names, Social Security numbers, driver's license numbers, financial account information, credit card numbers, medical information, passport numbers, and email addresses with associated passwords and security questions. This was among the most data-type-diverse healthcare data breaches documented in the Wisconsin DATCP archive for 2022.",
    "attack_type": "Hacking/IT Incident (type not specified beyond data types involved)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown \u2014 not publicly quantified",
    "residents_affected_in_state": "Wisconsin residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Partial \u2014 Wisconsin DATCP notified September 2022",
    "primary_source_url": "https://datcp.wi.gov/Pages/Programs_Services/DataBreachArchive.aspx",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. Wisconsin DATCP official breach archive.",
    "sources_used": [
      "Wisconsin DATCP"
    ],
    "id": "INC-00243",
    "year": 2022,
    "geocode_note": "Exact city not resolved; placed at WI state centroid.",
    "lat": 44.29750463202714,
    "lng": -89.75074984119225,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "MUSC Health Alliance",
    "organization_type": "Healthcare Provider / Academic Medical Center Affiliate",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Charleston",
    "hq_county": "Charleston",
    "discovery_date": "2022-03-01",
    "disclosure_date": "2022-06-07",
    "executive_summary": "MUSC Health Alliance reported a data security incident to the South Carolina Attorney General in June 2022, affecting 3,685 SC residents. The Medical University of South Carolina's affiliated health network experienced an unauthorized access incident exposing patient PHI.",
    "attack_type": "Unauthorized Access / Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3685,
    "residents_affected_in_state": 3685,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI exposed",
    "remediation_disclosed": "SC AG notified June 2022",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing with MUSC Health Alliance named.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00244",
    "year": 2022,
    "lat": 32.7765,
    "lng": -79.9311,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Main Line Health (PA - email account breach)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Radnor",
    "hq_county": "Delaware",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2022-04-01",
    "executive_summary": "Main Line Health, a Philadelphia suburban health system operating Lankenau Medical Center, Bryn Mawr Hospital, Paoli Hospital, and Riddle Hospital, reported a data security incident involving unauthorized access to employee email accounts. Patient protected health information was potentially exposed at this major Delaware County, Pennsylvania health system.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Philadelphia suburban patient PHI potentially compromised via email accounts",
    "remediation_disclosed": "HHS OCR and patients notified; email security controls enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; major PA health system; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00245",
    "year": 2022,
    "lat": 40.0448619,
    "lng": -75.3594728,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "McCoy Vision Center (Eye Care Leaders) \u2014 Alabama",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Dothan",
    "hq_county": "Houston",
    "discovery_date": "2022-03-01",
    "disclosure_date": "2022-06-01",
    "executive_summary": "McCoy Vision Center in Alabama was affected by the Eye Care Leaders (ECL) ransomware attack on December 4, 2021. ECL's myCare Integrity EMR system was compromised, deleting records and exposing patient data including names, dates of birth, SSNs, medical record numbers, and health insurance information. McCoy Vision Center reported 33,930 affected individuals.",
    "attack_type": "Ransomware (Supply-Chain via Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 33930,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient EMR records deleted/encrypted via vendor ECL system; PHI exposed",
    "remediation_disclosed": "ECL took down compromised systems; covered entities notified patients; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
    "secondary_source_urls": [
      "https://classlawdc.com/2022/06/21/eye-care-leaders-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal OCR portal data, June 2022 breach report.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal",
      "Migliaccio & Rathod LLP"
    ],
    "id": "INC-00246",
    "year": 2022,
    "lat": 31.2237285,
    "lng": -85.3934375,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "McKenzie Health System (McKenzie Memorial Hospital) \u2014 2022 Ransomware",
    "organization_type": "Critical Access Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Sandusky",
    "hq_county": "Sanilac",
    "discovery_date": "2022-03-11",
    "disclosure_date": "2022-04-01",
    "executive_summary": "McKenzie Health System, a critical access hospital in rural Sandusky, Michigan, discovered on or about March 11, 2022 that its computer and information systems were under attack from an unknown threat actor. The attack had begun approximately 24 hours prior and was likely initiated through a phishing email. Attackers demanded a seven-figure ransom; McKenzie declined to pay and restored systems using backups to 12 hours prior to the attack. HHS OCR ultimately recorded 51,040 individuals affected, with PHI including names, addresses, dates of birth, Social Security and driver's license numbers, claims information, diagnoses, medications, medical record numbers, patient account numbers, and health insurance information. McKenzie suffered a second breach in 2025 (see MW-100).",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 51040,
    "residents_affected_in_state": "Michigan residents primarily",
    "financial_impact": "Not publicly disclosed; ransom not paid; cybersecurity insurance engaged",
    "operational_impact": "All IT systems taken offline; hospital operated without computer access during recovery; backup recovery restored systems to ~12 hours pre-attack",
    "remediation_disclosed": "Yes \u2014 systems restored, law enforcement notified, improved firewalls, patient credit monitoring offered, OCR technical assistance received",
    "primary_source_url": "https://www.ruralhealthinfo.org/toolkits/emergency-preparedness/case-studies/equipment-infrastructure-failures/mckenzie-health-system",
    "secondary_source_urls": [
      "https://databreaches.net/2025/07/28/two-data-breaches-in-three-years-mckenzie-health/"
    ],
    "confidence_notes": "High confidence. Rural Health Information Hub case study (primary), HHS OCR (51,040 affected), DataBreaches.Net.",
    "sources_used": [
      "Rural Health Info",
      "HHS OCR",
      "DataBreaches.Net"
    ],
    "id": "INC-00247",
    "year": 2022,
    "lat": 43.420299,
    "lng": -82.829657,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "MedStar Mobile Healthcare",
    "organization_type": "Emergency Medical Services (Multistate)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Fort Worth, TX (multistate)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2022-10-19",
    "disclosure_date": "2022-12-19",
    "executive_summary": "WHAT HAPPENED An unauthorized third party gained access to a restricted location in MedStar\u2019s computer network that contained a number of files, including those with personal health information. We have not been able to confirm that those files were actually accessed by the third party, and therefore cannot say that any of your information in those files was accessed. Nevertheless, in an abundance of caution and out of respect for those individuals we have served, we are providing this notice to alert you to the potential that your information was impacted by this incident.",
    "attack_type": "Cyberattack (unspecified)",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Law enforcement notified', 'Additional security measures implemented']",
    "primary_source_url": "https://oag.ca.gov/system/files/MedStar%20Template%20Notice.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00248",
    "year": 2022,
    "lat": 38.20706531677876,
    "lng": -120.77815195814674,
    "is_multistate": true,
    "hq_outside_state": "Fort Worth",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "MelroseWakefield Healthcare",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Melrose",
    "hq_county": "Middlesex",
    "discovery_date": "2021-09-01",
    "disclosure_date": "2022-01-01",
    "executive_summary": "MelroseWakefield Healthcare, a Massachusetts health system now part of Tufts Medicine, was subject to a $55,000 HHS OCR HIPAA right-of-access settlement in 2022. The settlement arose from a complaint related to a cyber incident where patient access to medical records was delayed. The organization provides hospital and outpatient services to communities north of Boston.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$55,000 HHS OCR settlement (2022)",
    "operational_impact": "Patient record access disrupted; data security incident",
    "remediation_disclosed": "HHS OCR HIPAA settlement with corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2022 OCR penalties table confirms $55K settlement; Massachusetts health system",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00249",
    "year": 2022,
    "lat": 42.4564323,
    "lng": -71.064182,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Memorial Hermann Health System (Advent Health Partners breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2021-09-01",
    "disclosure_date": "2022-02-08",
    "executive_summary": "Advent Health Partners, a contracted vendor providing Medicaid eligibility, workers' compensation, and billing services to Memorial Hermann, experienced a security incident in September 2021 involving suspicious activity on employee email accounts. Investigation found approximately 6,260 Memorial Hermann patients may have had PHI accessed, including names, dates of birth, SSNs, driver's license numbers, financial information, health insurance information, and treatment information.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate Email Compromise",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 6260,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Additional security controls implemented; credit monitoring offered; law enforcement informed",
    "primary_source_url": "https://www.click2houston.com/news/local/2022/02/08/over-6000-memorial-hermann-patients-information-leaked-in-contractors-data-breach-vendor-says/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; KPRC 2 Houston documented; smaller incident",
    "sources_used": [
      "Click2Houston/KPRC 2"
    ],
    "id": "INC-00250",
    "year": 2022,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Methodist Craig Ranch Surgical Center",
    "organization_type": "Healthcare Provider (Surgical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "McKinney",
    "hq_county": "Collin",
    "discovery_date": "2022-07-07",
    "disclosure_date": "2022-08-03",
    "executive_summary": "Methodist Craig Ranch Surgical Center was affected by the same hacking and data theft incident that struck Methodist McKinney Hospital (the Karakurt group attack between May 20 and July 7, 2022). The breach compromised the protected health information of 15,157 patients of the surgical center. Data compromised included names, addresses, Social Security numbers, dates of birth, medical history, diagnosis, treatment, medical record numbers, and health insurance information. This incident was reported separately to HHS OCR from the Methodist McKinney incident.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Hacking and Data Theft",
    "attack_category": "Ransomware",
    "threat_actor_name": "Karakurt",
    "attribution_status": "claimed",
    "individuals_affected_reported": 15157,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of $985,000 combined class action settlement with Methodist McKinney Hospital",
    "operational_impact": "Not separately disclosed from Methodist McKinney incident",
    "remediation_disclosed": "Notifications sent; credit monitoring offered; additional security measures implemented",
    "primary_source_url": "https://www.hipaajournal.com/august-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/phi-exposed-methodist-mckinny-hospital-columbia-river-mental-health-services/"
    ],
    "confidence_notes": "HHS OCR confirmed 15,157 affected at this entity separately from 110,244 at Methodist McKinney Hospital; same attack vector",
    "sources_used": [
      "HIPAA Journal August 2022 Monthly Report, HIPAA Journal breach notification report"
    ],
    "id": "INC-00251",
    "year": 2022,
    "lat": 33.1976496,
    "lng": -96.6154471,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Methodist McKinney Hospital",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "McKinney",
    "hq_county": "Collin",
    "discovery_date": "2022-07-07",
    "disclosure_date": "2022-08-03",
    "executive_summary": "Methodist McKinney Hospital suffered a hacking and data theft incident in which unauthorized actors accessed its network server between May 20 and July 7, 2022. The Karakurt ransomware group claimed responsibility and alleged exfiltration of 367 GB of data. The breach affected 110,244 patients of Methodist McKinney Hospital, with related notification also sent for 15,157 patients of Methodist Craig Ranch Surgical Center. Data compromised included names, addresses, Social Security numbers, dates of birth, medical history, diagnosis, treatment, medical record numbers, and health insurance information. A class action settlement of $985,000 was reached.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Hacking and Data Theft",
    "attack_category": "Ransomware",
    "threat_actor_name": "Karakurt",
    "attribution_status": "claimed",
    "individuals_affected_reported": 110244,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$985,000 class action settlement (Methodist McKinney Hospital, Methodist Hospitals of Dallas, and MedHealth combined)",
    "operational_impact": "Network disruption; systems compromised",
    "remediation_disclosed": "Engaged cybersecurity firm; notified affected patients; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/phi-exposed-methodist-mckinny-hospital-columbia-river-mental-health-services/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/methodist-mckinney-hospital-announces-8569787/",
      "https://www.hipaajournal.com/august-2022-healthcare-data-breach-report/",
      "https://www.claimdepot.com/settlements/mmh-data-settlement"
    ],
    "confidence_notes": "HHS OCR confirmed 110,244 affected; Karakurt claimed responsibility on dark web leak site; $985K settlement confirmed",
    "sources_used": [
      "HIPAA Journal, JD Supra, HIPAA Journal August 2022 Monthly Report, Claim Depot"
    ],
    "id": "INC-00252",
    "year": 2022,
    "lat": 33.1976496,
    "lng": -96.6154471,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Metropolitan Area EMS Authority (dba MedStar Mobile Healthcare)",
    "organization_type": "Healthcare Provider (Emergency Medical Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Fort Worth",
    "hq_county": "Tarrant",
    "discovery_date": "2022-10-20",
    "disclosure_date": "2022-12-19",
    "executive_summary": "Metropolitan Area EMS Authority, operating as MedStar Mobile Healthcare (a Fort Worth, TX-based emergency and non-emergency ambulance service), discovered unauthorized network activity on October 20, 2022. Forensic investigation revealed that hackers had accessed parts of its network where patient data was stored, compromising the protected health information of 612,000 individuals. Data exposed included names, contact information, dates of birth, and limited medical information. A class action lawsuit (Kaether v. Metropolitan Area EMS Authority d/b/a MedStar Mobile Healthcare) was filed, and a settlement was proposed offering up to $3,000 per class member for documented losses.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 612000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action settlement proposed; up to $3,000 per class member for documented losses; 12 months credit monitoring included",
    "operational_impact": "Network access compromised; ambulance service operational continuity details not publicly disclosed",
    "remediation_disclosed": "Third-party cybersecurity specialists engaged; notifications mailed December 19, 2022; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/medstar-mobile-health-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/2022-healthcare-data-breach-report/",
      "https://www.calhipaa.com/december-2022-healthcare-data-breach-report/"
    ],
    "confidence_notes": "HHS OCR confirmed 612,000 affected; listed in HIPAA Journal 2022 Annual Report; class action settlement proposed",
    "sources_used": [
      "HIPAA Journal, CalHIPAA December 2022 Healthcare Data Breach Report, HIPAA Journal 2022 Annual Report"
    ],
    "id": "INC-00253",
    "year": 2022,
    "lat": 32.7555,
    "lng": -97.3308,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Morley Companies Inc.",
    "organization_type": "Business Process Outsourcing / Healthcare Services Vendor",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MI",
    "hq_city": "Saginaw",
    "hq_county": "Saginaw",
    "discovery_date": "2021-08-01",
    "disclosure_date": "2022-02-01",
    "executive_summary": "Morley Companies Inc., a Saginaw, Michigan-based business process outsourcing company providing services to Fortune 500 and Global 100 healthcare clients, discovered on August 1, 2021 that data on its systems had become unavailable due to a ransomware attack. Investigation determined the attack began July 20, 2021. Morley discovered additional data had been compromised on January 26, 2022. The breach affected 521,046 individuals, including current and former employees and clients, with PHI including names, addresses, Social Security numbers, dates of birth, medical diagnostic and treatment information, and health insurance information. Notification letters were not sent until February 1, 2022, approximately six months after discovery.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 521046,
    "residents_affected_in_state": "Michigan residents \u2014 exact count not separately reported",
    "financial_impact": "Not publicly disclosed; class action litigation filed",
    "operational_impact": "Data became unavailable; business process disruptions for Fortune 500 healthcare clients",
    "remediation_disclosed": "Yes \u2014 network secured, forensic investigation, notifications sent February 2022, security improvements implemented",
    "primary_source_url": "https://compliancy-group.com/morley-companies-ransomware-hack/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/morley-companies-facing-class-action-over-august-2021-data-breach",
      "https://www.justice4you.com/morley-companies-inc-data-breach/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, multiple news sources, class action documentation.",
    "sources_used": [
      "Compliancy Group",
      "ClassAction.org",
      "Arnold Law Firm",
      "HHS OCR"
    ],
    "id": "INC-00254",
    "year": 2022,
    "lat": 43.4200387,
    "lng": -83.9490365,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Morley Companies, Inc. \u2014 California Healthcare BA Impact",
    "organization_type": "Business process outsourcing provider (business associate to healthcare organizations including Fortune 500 health plans)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Saginaw, MI (non-CA HQ; included due to significant CA healthcare impact)",
    "hq_county": "NOT_APPLICABLE (Michigan-headquartered; CA residents specifically eligible for $75 CCPA payment)",
    "discovery_date": "2021-08-01",
    "disclosure_date": "2022-02-01",
    "executive_summary": "On August 1, 2021, Morley Companies discovered its data had become unavailable due to ransomware malware, which had been present since at least July 20, 2021. Morley, which provides business process outsourcing to dozens of health plans and healthcare companies, suffered exfiltration of names, SSNs, DOBs, addresses, client identification numbers, medical diagnostic and treatment information, and health insurance information of 521,046+ individuals. The breach affected patients of multiple healthcare clients, including CA residents. A $4.3 million class-action settlement was reached in 2022.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 521046,
    "residents_affected_in_state": 75,
    "financial_impact": "{'litigation_settlement': 4300000, 'notes': '$4.3M class-action settlement (2022); up to $2,500 reimbursement for out-of-pocket expenses; CA residents receive $75 CCPA payment; 3 years free credit monitoring.'}",
    "operational_impact": "Data unavailable to Morley and its clients from August 1, 2021; restoration timeline not disclosed.",
    "remediation_disclosed": "Network secured; cybersecurity experts engaged; additional data confirmed potentially compromised January 26, 2022; breach notifications mailed February 1, 2022; law enforcement notified.",
    "primary_source_url": "https://www.hipaajournal.com/class-action-data-breach-lawsuit-settled-by-morley-companies/",
    "secondary_source_urls": [
      "https://compliancy-group.com/morley-companies-ransomware-hack/",
      "https://www.techtarget.com/healthtechsecurity/news/366594510/Avalon-Healthcare-Morley-Companies-Reach-Healthcare-Data-Breach-Settlements",
      "https://www.scworld.com/analysis/morley-reaches-4-3m-settlement-after-hacking-incident-leads-to-data-theft-for-694k"
    ],
    "confidence_notes": "Morley is Michigan-headquartered but included per task instructions as a BA affecting California healthcare clients. 5-month delay from attack detection (Aug 2021) to public notification (Feb 2022). Total impacted including non-healthcare clients: ~694,000 across all settlement notices.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00255",
    "year": 2022,
    "lat": 35.64970588344894,
    "lng": -120.24818310617896,
    "is_multistate": true,
    "hq_outside_state": "Saginaw",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "MultiCare Health System / Kaye-Smith (vendor ransomware)",
    "organization_type": "Healthcare Provider (Hospital System) / Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "WA",
    "hq_city": "Tacoma",
    "hq_county": "Pierce",
    "discovery_date": "2022-06-15",
    "disclosure_date": "2022-10-15",
    "executive_summary": "Kaye-Smith, a business associate vendor providing print and mail services, suffered a ransomware attack that affected approximately 119,000 patients across multiple healthcare clients, including MultiCare Health System in Washington. The breach exposed patient names, Social Security numbers, addresses, dates of birth, health plan information, and clinical data. MultiCare notified affected patients in October 2022. This is a separate incident from the 2020 Netgain/Woodcreek breach (WA-004). The Kaye-Smith attack specifically targeted a vendor's print and mail fulfillment systems.",
    "attack_type": "Ransomware (at vendor)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 119000,
    "residents_affected_in_state": "Primarily WA-based MultiCare patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Print and mail vendor systems encrypted; patient notification materials disrupted; PHI exposed",
    "remediation_disclosed": "Kaye-Smith systems restored; MultiCare issued patient notifications; security review conducted",
    "primary_source_url": "https://www.hipaajournal.com/multicare-health-system-kaye-smith-data-breach-119000/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence: HIPAA Journal reporting; HHS OCR filing confirmed; separate incident from WA-004 Netgain/Woodcreek breach",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00256",
    "year": 2022,
    "lat": 47.2529,
    "lng": -122.4443,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Mystic Valley Elder Services",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Malden",
    "hq_county": "Middlesex",
    "discovery_date": "2022-04-01",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Mystic Valley Elder Services, a Malden, Massachusetts-based elder care services organization, experienced a cyberattack in 2022 that exposed client data. The organization agreed to pay $520,000 to settle a consolidated class action lawsuit stemming from the incident.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$520,000 settlement",
    "operational_impact": "Elder services client data compromised",
    "remediation_disclosed": "$520K settlement; security improvements",
    "primary_source_url": "https://www.hipaajournal.com/category/hipaa-breach-news/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal settlement reporting; limited detail available",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00257",
    "year": 2022,
    "lat": 42.4268484,
    "lng": -71.0683741,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Nationwide Optometry, P.C.",
    "organization_type": "Optometry Group (Multistate)",
    "organization_type_bucket": "Vision / Eye care",
    "state": "CA",
    "hq_city": "New York, NY (multistate)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2021-04-20",
    "disclosure_date": "2022-11-30",
    "executive_summary": "U.S Vision has represented to us that on May 12, 2021, U.S. Vision became aware of suspicious activity involving its computer network. U.S. Vision launched an investigation into the nature and scope of the incident with the assistance of cybersecurity specialists. Through its investigation, U.S. Vision learned that an unauthorized individual accessed its network intermittently between April 20, 2021 and May 17, 2021, and that files containing your information may have been viewed and/or taken by the unauthorized individual. U.S. Vision informed us of this incident on May 12, 2021, but was unab",
    "attack_type": "Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals']",
    "primary_source_url": "https://oag.ca.gov/system/files/2022-10-28%20%E2%80%93%20CA%20Individual%20Notice%20Templates_2.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00258",
    "year": 2022,
    "lat": 37.0096088458525,
    "lng": -119.72785857604767,
    "is_multistate": true,
    "hq_outside_state": "New York",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Novant Health \u2013 Meta Pixel Breach",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Winston-Salem",
    "hq_county": "Forsyth",
    "discovery_date": "2022-06-17",
    "disclosure_date": "2022-08-25",
    "executive_summary": "Novant Health (15 hospitals, NC) discovered on June 17, 2022 that a Meta Pixel improperly configured on its MyChart portal had been transmitting PHI to Meta/Facebook. The pixel was placed to support COVID-19 outreach advertising. Data potentially disclosed included names, email addresses, phone numbers, IP addresses, emergency contact info, appointment types, dates, physician names, and in some cases SSNs. 1,362,296 individuals were affected. A $6.6M class action settlement was reached in 2024.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (Meta Pixel misconfiguration)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1362296,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$6.6 million class action settlement (2024)",
    "operational_impact": "PHI of 1.36M patients transmitted to Meta/Facebook without authorization",
    "remediation_disclosed": "Pixel removed; $6.6M settlement; HHS OCR notification",
    "primary_source_url": "https://www.hipaajournal.com/novant-health-pixel-privacy-breach-settlement/",
    "secondary_source_urls": [
      "https://www.justice4you.com/novant-health-data-breach/",
      "https://blackcloak.io/streaming-media-platform-plex-and-novant-health-experience-data-breaches/"
    ],
    "confidence_notes": "HHS OCR lists 1,362,296. First healthcare provider to report pixel-related HIPAA violation. Settlement confirmed by HIPAA Journal.",
    "sources_used": [
      "HIPAA Journal",
      "Arnold Law Firm",
      "BlackCloak"
    ],
    "id": "INC-00259",
    "year": 2022,
    "lat": 36.0999,
    "lng": -80.2442,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "OU Health (Ciox third-party breach)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2021-07-02",
    "disclosure_date": "2022-01-18",
    "executive_summary": "OU Health was notified by former third-party vendor Ciox Health of a data breach involving unauthorized access to a Ciox employee's email account between June 24 and July 2, 2021. 509 OU Health patients were potentially affected. Compromised data included patient names, dates of birth, provider names, and dates of service (no financial or SSNs).",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate Email Compromise",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 509,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal",
    "remediation_disclosed": "Notifications sent; assistance line established (855-618-3107)",
    "primary_source_url": "https://www.ouhealth.com/blog/2022/january/ciox-security-breach-impacts-approximately-500-o/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; official OU Health website notice",
    "sources_used": [
      "OU Health official website"
    ],
    "id": "INC-00260",
    "year": 2022,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "OakBend Medical Center",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Richmond",
    "hq_county": "Fort Bend",
    "discovery_date": "2022-09-01",
    "disclosure_date": "2022-09-16",
    "executive_summary": "OakBend Medical Center suffered a ransomware attack on September 1, 2022. The Daixin Team claimed responsibility and stated they exfiltrated approximately 3.5 GB of data including over 1 million records containing patient and employee PHI and PII (SSNs, medical information). The attack took systems offline for weeks including voicemail and email. The breach was eventually reported to HHS as affecting up to 500,000 patients.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware + Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Daixin Team",
    "attribution_status": "claimed",
    "individuals_affected_reported": 500000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR and communication systems taken offline for weeks; voicemail down; FBI, Microsoft, Dell cybersecurity experts engaged",
    "remediation_disclosed": "Systems rebuilt; FBI engaged; Microsoft and Dell assisted with recovery; IRP activated",
    "primary_source_url": "https://databreaches.net/2022/09/11/oakbend-medical-center-hit-by-ransomware-daixin-team-claims-responsibility/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/oakbend-medical-center-suffers-ransomware-attack/",
      "https://www.halock.com/texas-hospital-disrupted-by-ransomware-attack/"
    ],
    "confidence_notes": "High confidence; Daixin Team confirmed responsibility; OCR report confirmed ~500,000",
    "sources_used": [
      "DataBreaches.net, HIPAA Journal, HALOCK"
    ],
    "id": "INC-00261",
    "year": 2022,
    "lat": 29.5821811,
    "lng": -95.7607832,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "OneTouchPoint Inc.",
    "organization_type": "Healthcare Printing and Mailing Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "WI",
    "hq_city": "Hartland",
    "hq_county": "Waukesha",
    "discovery_date": "2022-04-28",
    "disclosure_date": "2022-06-03",
    "executive_summary": "OneTouchPoint Inc., a Hartland, Wisconsin-based healthcare printing and mailing company serving healthcare organizations nationwide, discovered on April 28, 2022 that files on its systems were encrypted by ransomware. Investigation revealed the compromise began April 27, 2022. Data potentially accessed included patient names, member ID numbers, health assessment information, diagnoses, medications, Social Security numbers, and other PHI. OneTouchPoint served dozens of healthcare clients, with the total affected individual count growing from an initial 1.1 million to 2,651,396 as investigations revealed the full scope. This was one of the largest healthcare data breaches of 2022.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4112892,
    "residents_affected_in_state": "Wisconsin residents \u2014 exact count not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Disrupted printing/mailing services for dozens of healthcare plan clients; affected benefits communications",
    "remediation_disclosed": "Yes \u2014 systems secured, investigation conducted, notifications sent to healthcare clients and individuals",
    "primary_source_url": "https://www.hipaajournal.com/onetouchpoint-ransomware-victim-count-increases-to-2-65-million/",
    "secondary_source_urls": [
      "https://www.medicalrecords.com/hospital_breaches/onetouchpoint-inc",
      "https://classlawdc.com/2022/08/04/onetouchpoint-inc-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, HIPAA Journal, multiple class action documentation. HHS OCR reports 4,112,892 affected.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR",
      "MedicalRecords.com",
      "Class action filings"
    ],
    "id": "INC-00262",
    "year": 2022,
    "lat": 43.105008,
    "lng": -88.3420398,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Partnership HealthPlan of California",
    "organization_type": "Health Plan (Medi-Cal Managed Care)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Redding, CA",
    "hq_county": "Shasta County",
    "discovery_date": "2022-03-19",
    "disclosure_date": "2022-05-18",
    "executive_summary": "PHC immediately began an investigation with the assistance of cybersecurity specialists. We have evidence that an unauthorized party accessed or took certain information from PHC\u2019s network on or about March 19, 2022.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Hive",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 854913,
    "residents_affected_in_state": 854913,
    "financial_impact": "Not publicly disclosed; class action lawsuits filed",
    "operational_impact": "IT systems offline; claim processing disrupted for North/Central CA members",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/Partnership%20HealthPlan%20of%20California%20-%20Sample%20notice.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/partnership-healthplan-of-california-hive-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/hive-ransomware-claims-cyberattack-on-partnership-healthplan-of-california/",
      "https://www.hipaajournal.com/over-850000-individuals-affected-by-partnership-healthplan-of-california-cyberattack/",
      "https://www.scworld.com/analysis/after-hive-cyberattack-partnership-healthplan-confirms-data-theft-affecting-855k",
      "https://www.govtech.com/security/hackers-claim-responsibility-for-california-ransomware-attack",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf"
    ],
    "confidence_notes": "PHC serves 618,000+ Medi-Cal members in Sonoma, Del Norte, Humboldt, Lake, Lassen, Marin, Mendocino, Modoc, Napa, Shasta, Siskiyou, Solano, Trinity, and Yolo counties. FBI investigated Hive until law enforcement operation took down Hive infrastructure in Jan 2023. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00263",
    "year": 2022,
    "lat": 40.5865,
    "lng": -122.3917,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Philadelphia FIGHT Community Health Centers",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Philadelphia",
    "hq_county": "Philadelphia",
    "discovery_date": "2022-06-01",
    "disclosure_date": "2022-09-01",
    "executive_summary": "Philadelphia FIGHT Community Health Centers, a Philadelphia federally qualified health center specializing in HIV/AIDS care and primary care for underserved populations, reported a data security incident. The breach involved unauthorized access to sensitive patient health records including HIV status and treatment information, raising significant patient privacy concerns.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "HIV/AIDS patient data at high risk; sensitive clinical information potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified; security measures reviewed",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; Philadelphia HIV-specialty FQHC; sensitivity of HIV data noted; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00264",
    "year": 2022,
    "lat": 39.9526,
    "lng": -75.1652,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Practice Resources LLC",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "Syracuse",
    "hq_county": "Onondaga",
    "discovery_date": "2022-04-12",
    "disclosure_date": "2022-08-23",
    "executive_summary": "Practice Resources LLC, a Syracuse-based medical billing and practice management company, suffered a ransomware attack on April 12, 2022, affecting 28 healthcare organization clients. The breach compromised health plan numbers, dates of treatment, addresses, and medical record numbers for 942,138 individuals. Practice Resources agreed to a $1.5 million settlement to resolve resulting litigation.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 942138,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$1.5 million settlement",
    "operational_impact": "Data of 942K patients across 28 healthcare organizations exposed",
    "remediation_disclosed": "Cybersecurity enhancements implemented; $1.5M settlement",
    "primary_source_url": "https://www.hipaajournal.com/practice-resources-class-action-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594681/NY-Billing-Company-Suffers-Ransomware-Attack-942K-Impacted"
    ],
    "confidence_notes": "OCR breach report; CA AG notice filed; $1.5M settlement filed in NDNY",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget Health IT Security"
    ],
    "id": "INC-00265",
    "year": 2022,
    "lat": 43.0481,
    "lng": -76.1474,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Professional Finance Company Inc. (PFC) \u2014 Midwest healthcare clients",
    "organization_type": "Medical Debt Collections Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CO",
    "hq_city": "Greeley CO (serves Midwest healthcare clients)",
    "hq_county": "Weld County CO",
    "discovery_date": "2022-02-26",
    "disclosure_date": "2022-05-05",
    "executive_summary": "Professional Finance Company Inc. (PFC), a Greeley, Colorado-based medical debt collections company, experienced a ransomware attack on February 26, 2022. PFC served 657 healthcare provider clients across the country, including numerous Midwest healthcare organizations. The breach affected 1,918,941 individuals. The ransomware encrypted PFC's systems, and data was potentially stolen. Multiple Ohio, Indiana, Illinois, Michigan, Minnesota, Missouri, Wisconsin, and Iowa healthcare organizations had their patients' debt collection data exposed through PFC. This entry documents Midwest healthcare organizations' exposure through this multi-state vendor breach.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1918941,
    "residents_affected_in_state": "Multiple Midwest states \u2014 exact state breakdown not publicly available",
    "financial_impact": "Class action lawsuits filed; not separately quantified",
    "operational_impact": "Debt collections operations disrupted; 657 healthcare clients notified; patient data exposed across multiple states",
    "remediation_disclosed": "Yes \u2014 law enforcement notified; systems secured; 657 healthcare clients notified; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal 2022 annual report confirms PFC breach (657 clients, 1,918,941 individuals). HHS OCR confirmed. Midwest clients are subset of total.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00266",
    "year": 2022,
    "lat": 40.4443593,
    "lng": -104.691286,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Professional Finance Company, Inc.",
    "organization_type": "Business Associate (Medical Debt Collections)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CO",
    "hq_city": "Greeley",
    "hq_county": "Weld",
    "discovery_date": "2022-02-26",
    "disclosure_date": "2022-05-05",
    "executive_summary": "Professional Finance Company, Inc., a Greeley, CO-based debt collection company serving healthcare clients, suffered a ransomware attack on February 26, 2022. While the attack was blocked, not before unauthorized access and data theft occurred. The breach affected 1,918,941 individuals whose debt collection information was held by PFC on behalf of healthcare provider clients.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1918941,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$2.5M class action settlement (2025)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Client notifications sent; class action settled",
    "primary_source_url": "https://www.hipaajournal.com/professional-finance-company-settlement-data-breach-lawsuit/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/2-5m-professional-finance-co-data-breach-class-action-settlement-2/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 1,918,941; settlement documentation available",
    "sources_used": [
      "HIPAA Journal, Top Class Actions"
    ],
    "id": "INC-00267",
    "year": 2022,
    "lat": 40.4233142,
    "lng": -104.7091322,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Rosenfeld VanWirt PC (LVHN-affiliated)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "PA",
    "hq_city": "Allentown",
    "hq_county": "Lehigh",
    "discovery_date": "2022-11-01",
    "disclosure_date": "2022-12-01",
    "executive_summary": "Rosenfeld VanWirt PC, a Pennsylvania business associate affiliated with the Lehigh Valley Health Network, reported a hacking incident in November 2022 that affected 18,719 individuals. This incident was part of the broader hacking wave affecting multiple LVHN-affiliated entities in November 2022.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 18719,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "18K+ individuals' data compromised via LVHN-affiliated BA",
    "remediation_disclosed": "HHS OCR breach filed",
    "primary_source_url": "https://www.hipaajournal.com/november-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal November 2022; noted as LVHN affiliate in HIPAA Journal reporting",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00268",
    "year": 2022,
    "lat": 40.6084,
    "lng": -75.4902,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Rush University System for Health",
    "organization_type": "Academic Medical Center / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2022-09-01",
    "disclosure_date": "2022-09-30",
    "executive_summary": "Rush University Medical Center was targeted in a class action lawsuit filed September 30, 2022 alleging that it used tracking technologies (Meta Pixel, Google Analytics, and Bidtellect) on its website and patient portal to transmit patient health information to third parties without consent. The lawsuit alleged violations of the Electronic Communications Privacy Act (ECPA) and other laws. An Illinois federal court later narrowed but did not dismiss the lawsuit. This was among the early healthcare pixel tracking cases in Illinois.",
    "attack_type": "Unauthorized Tracking Technology Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable \u2014 Meta, Google, Bidtellect as data recipients",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Illinois patients using Rush website/portal",
    "financial_impact": "Litigation ongoing; settlement amount not determined in available sources",
    "operational_impact": "No clinical disruption; privacy/HIPAA compliance impact",
    "remediation_disclosed": "Not publicly confirmed in available sources",
    "primary_source_url": "https://www.classaction.org/media/kurowski-et-al-v-rush-system-for-health.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/advocate-aurora-health-settles-pixel-lawsuit-for-12-25-million/"
    ],
    "confidence_notes": "Moderate confidence. Class action complaint filed; court narrowed but continued case. Breach not on HHS OCR portal as hacking incident.",
    "sources_used": [
      "ClassAction.org (court filing)",
      "HIPAA Journal (contextual)"
    ],
    "id": "INC-00269",
    "year": 2022,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "San Gorgonio Memorial Hospital",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Banning, CA (Riverside County)",
    "hq_county": "Riverside County",
    "discovery_date": "2022-10-29",
    "disclosure_date": "2022-12-07",
    "executive_summary": "We also began an investigation with the assistance of a third-party forensic firm. The investigation determined that an unauthorized party gained access to our network between October 29, 2022 and November 10, 2022 and, during that time, copied some of the documents on our system. On November 14, 2022, we learned that some of those documents contained patient information.",
    "attack_type": "Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Forensic investigation conducted', 'Additional security measures implemented']",
    "primary_source_url": "https://oag.ca.gov/system/files/SGMH%20-%20California%20Notification.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00270",
    "year": 2022,
    "lat": 33.9255,
    "lng": -116.8763,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Shields Health Care Group",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MA",
    "hq_city": "Quincy",
    "hq_county": "Norfolk",
    "discovery_date": "2022-03-28",
    "disclosure_date": "2022-07-25",
    "executive_summary": "Shields Health Care Group, a Massachusetts-based provider of MRI, PET, and radiation therapy services to 50+ partner facilities across New England, suffered a hacking incident between March 7-21, 2022. Attackers exfiltrated data including names, SSNs, DOBs, insurance information, and treatment details from more than 2.38 million patients. A $15.35 million class action settlement was reached in 2025.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2380483,
    "residents_affected_in_state": 60,
    "financial_impact": "$15.35 million settlement (2025)",
    "operational_impact": "2.38M patient records from 50+ New England healthcare facilities exfiltrated",
    "remediation_disclosed": "Notification to 50+ partner facilities; credit monitoring offered; law enforcement notified; $15.35M settlement",
    "primary_source_url": "https://www.hipaajournal.com/shields-health-care-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366624966/Shields-Health-Care-Group-settles-breach-lawsuit-for-1535M",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/15-35m-shields-health-group-data-breach-settlement/",
      "https://www.hipaajournal.com/2-million-patients-affected-by-shields-health-care-group-cyberattack/",
      "https://www.bitdefender.com/en-us/blog/hotforsecurity/2-million-patient-records-compromised-in-largest-healthcare-breach-of-2022-so-far",
      "https://www.cbsnews.com/boston/news/shields-health-care-group-data-breach-cyber-attack-massachusetts/",
      "https://www.shieldshealthcare.net/shields-data-breach-notice/"
    ],
    "confidence_notes": "OCR breach report; Maine AG notice; $15.35M settlement | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BitDefender",
      "CBS Boston",
      "HIPAA Journal",
      "Shields Health Care Group official notice",
      "TechTarget",
      "Top Class Actions"
    ],
    "id": "INC-00271",
    "year": 2022,
    "lat": 42.2529,
    "lng": -71.0023,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sight Partners Physicians, P.C. (via Eye Care Leaders)",
    "organization_type": "Healthcare Provider (Ophthalmology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2021-12-04",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Sight Partners Physicians in Washington was one of at least 41 eye care providers nationwide affected by a ransomware attack on Eye Care Leaders, an EHR vendor serving ophthalmology practices. Hackers gained access to Eye Care Leaders' myCare Identity system on or around December 4, 2021, and deleted databases and configuration files. Sight Partners' patients had data exposed including names, dates of birth, medical record numbers, health insurance information, and Social Security numbers for 86,101 individuals.",
    "attack_type": "Ransomware (via business associate)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware operator)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 86101,
    "residents_affected_in_state": "Majority WA-based",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR databases and configuration files deleted by attackers",
    "remediation_disclosed": "Not publicly disclosed by Sight Partners specifically",
    "primary_source_url": "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR confirmed 86,101 individuals; Sight Partners listed in Eye Care Leaders breach report",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00272",
    "year": 2022,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "SightCare, Inc. (Nationwide Vision / Nationwide Sightcare)",
    "organization_type": "Health Plan (Vision Care)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "AZ",
    "hq_city": "Scottsdale",
    "hq_county": "Maricopa",
    "discovery_date": "2021-09-01",
    "disclosure_date": "2022-10-28",
    "executive_summary": "SightCare, Inc., operating as Nationwide Vision / Nationwide Sightcare, experienced a data breach affecting 637,999 plan members through a hack at USV Optical, Inc., a U.S. Vision subsidiary that provided certain administrative services. The breach exposed names, addresses, dates of birth, insurance information, and potentially Social Security numbers. A class action was filed in November 2022 (Torres v. U.S. Vision), and a $3.45 million settlement was reached to resolve claims from the 637,999 Sightcare members and 73,073 U.S. Vision members.",
    "attack_type": "Hacking/IT Incident \u2013 Third-Party Business Associate Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 637999,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3,450,000 class action settlement (combined for Sightcare and U.S. Vision members)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Notifications sent; credit monitoring offered; settlement fund established",
    "primary_source_url": "https://www.hipaajournal.com/3-4m-settlement-resolves-claims-against-nationwide-vision-sightcare-over-2021-data-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/2022-healthcare-data-breach-report/",
      "https://www.claimdepot.com/settlements/nationwide-sightcare-3345000-data-breach-settlement"
    ],
    "confidence_notes": "HHS OCR confirmed 637,999 affected; listed in HIPAA Journal 2022 Annual Report; $3.45M settlement confirmed",
    "sources_used": [
      "HIPAA Journal, HIPAA Journal 2022 Annual Report, Claim Depot"
    ],
    "id": "INC-00273",
    "year": 2022,
    "lat": 33.4942,
    "lng": -111.9261,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Southwest Health Center",
    "organization_type": "Community Health Center / Rural Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WI",
    "hq_city": "Platteville",
    "hq_county": "Grant",
    "discovery_date": "2022-01-11",
    "disclosure_date": "2022-07-05",
    "executive_summary": "Southwest Health Center, a community health center and critical access hospital in Platteville, Wisconsin, experienced a cyber incident on January 11, 2022. The breach was publicly disclosed July 5, 2022, with the Wisconsin DATCP breach archive listing the incident. Data accessed included names, dates of birth, Social Security numbers, financial account numbers, medical information, and health insurance information. No additional details on the attack type or total affected individuals were publicly disclosed in available sources.",
    "attack_type": "Hacking/IT Incident (type not specified in public notice)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown \u2014 not publicly specified",
    "residents_affected_in_state": "Wisconsin residents (Grant County area)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Partial \u2014 Wisconsin DATCP notified July 2022",
    "primary_source_url": "https://datcp.wi.gov/Pages/Programs_Services/DataBreachArchive.aspx",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. Wisconsin DATCP official breach archive is primary source; limited additional details available.",
    "sources_used": [
      "Wisconsin DATCP"
    ],
    "id": "INC-00274",
    "year": 2022,
    "lat": 42.7342942,
    "lng": -90.4784451,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "St. Luke's Health (CommonSpirit Texas \u2013 Adelanto vendor breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2022-09-01",
    "disclosure_date": "2022-11-03",
    "executive_summary": "St. Luke's Health (Texas-based, part of CommonSpirit Health) notified 16,906 patients that a vendor, Adelanto Healthcare Ventures (AHCV), had its two employee email accounts compromised on November 5, 2021. AHCV initially found no PHI exposure, but a September 2022 re-review confirmed St. Luke's patient data was present. Compromised information included names, addresses, DOBs, SSNs, Medicaid numbers, medical record numbers, and limited clinical information. This breach is separate from CommonSpirit's October 2022 ransomware attack.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate Email Compromise",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 16906,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "AHCV implemented additional security controls; no data misuse found",
    "primary_source_url": "https://www.techtarget.com/healthtechsecurity/news/366593981/St-Lukes-Health-Suffers-Third-Party-Data-Breach-Unrelated-to-CommonSpirit-Attack",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/st-lukes-health-reports-third-party-data-breach/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 16,906; TechTarget confirmed separate from CommonSpirit attack",
    "sources_used": [
      "TechTarget, HIPAA Journal"
    ],
    "id": "INC-00275",
    "year": 2022,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "St. Luke's Health System (Kaye-Smith vendor breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "ID",
    "hq_city": "Boise",
    "hq_county": "Ada",
    "discovery_date": "2022-07-06",
    "disclosure_date": "2022-08-10",
    "executive_summary": "St. Luke's Health System in Idaho reported that Kaye-Smith, a vendor handling statement processing and billing services, experienced a data breach in May 2022. The breach was discovered by St. Luke's on July 6. 31,573 St. Luke's patients had their records potentially exposed. No St. Luke's networks were directly affected.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 31573,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No St. Luke's network impact; vendor affected",
    "remediation_disclosed": "Patient notifications sent; Kaye-Smith security review",
    "primary_source_url": "https://www.boisestate.edu/cybersecurity/2022/08/10/st-lukes-vendor-experiences-data-breach-thousands-of-idaho-patients-may-be-affected/",
    "secondary_source_urls": [
      "https://www.forbin.com/blog/post/monthly-breach-deets-saint-luke-s-health-system-data-breach"
    ],
    "confidence_notes": "High confidence; Boise State cybersecurity news documented; St. Luke's spokesperson confirmed 31,573",
    "sources_used": [
      "Boise State University Cybersecurity News, VGM Forbin"
    ],
    "id": "INC-00276",
    "year": 2022,
    "lat": 43.615,
    "lng": -116.2023,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Stanley Street Treatment and Resources (SSTAR)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Fall River",
    "hq_county": "Bristol",
    "discovery_date": "2022-10-01",
    "disclosure_date": "2022-11-11",
    "executive_summary": "Stanley Street Treatment and Resources (SSTAR), a substance use disorder treatment provider in Fall River, Massachusetts, experienced a hacking incident with data theft confirmed affecting 45,785 individuals. Network servers were compromised and patient data was exfiltrated. SSTAR notified affected individuals in November 2022.",
    "attack_type": "Hacking/IT Incident (data theft from network server)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 45785,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network server compromised; patient data exfiltrated",
    "remediation_disclosed": "HHS OCR breach report filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/november-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/stanley-street-treatment-and-resources-9169420/"
    ],
    "confidence_notes": "OCR breach report; JD Supra reporting on notification letters",
    "sources_used": [
      "HIPAA Journal",
      "JD Supra"
    ],
    "id": "INC-00277",
    "year": 2022,
    "lat": 41.7010642,
    "lng": -71.1546367,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Stokes Regional Eye Centers (Eye Care Leaders)",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Orangeburg",
    "hq_county": "Orangeburg",
    "discovery_date": "2021-12-08",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Stokes Regional Eye Centers in South Carolina was affected by the Eye Care Leaders (ECL) ransomware attack. ECL's myCare Integrity system was compromised on December 4, 2021, deleting and exposing patient records. Stokes reported 266,170 affected individuals to HHS OCR \u2014 the largest single-entity impact of the ECL breach. SC Consumer Affairs shows 1,327 SC residents in the listing.",
    "attack_type": "Ransomware (Supply-Chain via Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 266170,
    "residents_affected_in_state": 1327,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient EMR data from ECL myCare Integrity system exposed; PHI including SSNs, DOBs, medical record numbers potentially acquired",
    "remediation_disclosed": "ECL took down compromised systems; patient notification letters sent; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
    "secondary_source_urls": [
      "https://dojmt.gov/wp-content/uploads/Consumer-notification-letter-143.pdf",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal, Montana DOJ notification letter, SC Consumer Affairs listing.",
    "sources_used": [
      "HIPAA Journal",
      "Montana DOJ Notification Letter",
      "SC Consumer Affairs Breach Portal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00278",
    "year": 2022,
    "lat": 33.4054944,
    "lng": -80.778429,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Summit Eye Associates (Eye Care Leaders) \u2014 Tennessee",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Knoxville",
    "hq_county": "Knox",
    "discovery_date": "2021-12-08",
    "disclosure_date": "2022-06-01",
    "executive_summary": "Summit Eye Associates in Tennessee was affected by the Eye Care Leaders (ECL) ransomware attack of December 2021. The breach impacted 53,818 patients whose data was stored in ECL's myCare Integrity EMR system. Patient PHI including names, DOBs, SSNs, medical record numbers, and health insurance information was potentially exposed.",
    "attack_type": "Ransomware (Supply-Chain via Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (Eye Care Leaders ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 53818,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient EMR data exposed; PHI potentially acquired",
    "remediation_disclosed": "ECL took down compromised systems; patient notification letters sent",
    "primary_source_url": "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 HIPAA Journal list of ECL breach victims with affected count.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00279",
    "year": 2022,
    "lat": 35.9606,
    "lng": -83.9207,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Texas Tech University Health Sciences Center (Lubbock)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Lubbock",
    "hq_county": "Lubbock",
    "discovery_date": "2022-03-30",
    "disclosure_date": "2022-06-07",
    "executive_summary": "Texas Tech University Health Sciences Center reported that its electronic medical record vendor, Eye Care Leaders, suffered a data breach. The breach compromised protected health information for 1,290,104 TTUHSC patients. No evidence of data exfiltration was found from the TTUHSC-related records, though system data was destroyed in the attack on Eye Care Leaders' platform.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate Breach (Eye Care Leaders EMR vendor)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1290104,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EMR access disrupted",
    "remediation_disclosed": "Notifications sent; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/almost-1-3-million-patients-of-texas-tech-university-health-sciences-center-affected-by-eye-care-leaders-data-breach/",
    "secondary_source_urls": [
      "https://lubbocklights.com/umc-paid-ransom-with-insurance-data-was-restored-not-sold-on-dark-web/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 1,290,104 from June 2022 report; separate from 2024 Interlock attack",
    "sources_used": [
      "HIPAA Journal, Lubbock Lights"
    ],
    "id": "INC-00280",
    "year": 2022,
    "lat": 33.5779,
    "lng": -101.8552,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "The Elizabeth Hospice",
    "organization_type": "Hospice Organization",
    "organization_type_bucket": "Home health / Long-term care",
    "state": "CA",
    "hq_city": "Escondido, CA",
    "hq_county": "San Diego County",
    "discovery_date": "Unknown",
    "disclosure_date": "2022-12-14",
    "executive_summary": "On October 21, 2022, TEH learned that one its now former employees was forwarding emails fromher business emailaccount to her personalemailaccount while employed with the organization. TEH immediately begananinternalreview ofthe employee's business emailaccount, and determined onNovember 14, 2022, that the following information may have been exposed as a result of this incident: first name, last name, date of admission, date ofdischarge, patient account number, and basic healthinformation. Please note that your Social Security number and financial account information were not involved in this",
    "attack_type": "Cyber Incident (unspecified)",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/TEH%20-%20Ex.%20A.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00281",
    "year": 2022,
    "lat": 33.1192,
    "lng": -117.0864,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "United Health Centers of the San Joaquin Valley",
    "organization_type": "Federally Qualified Health Center (FQHC) nonprofit; operates 20+ community health centers in Fresno, Kings, and Tulare counties",
    "organization_type_bucket": "FQHC / Community health",
    "state": "CA",
    "hq_city": "Fresno",
    "hq_county": "Fresno County",
    "discovery_date": "2021-09-22",
    "disclosure_date": "2022-08-12",
    "executive_summary": "Between August 24 and 28, 2021, the Vice Society ransomware group attacked United Health Centers of the San Joaquin Valley, a community FQHC serving low-income patients across California's Central Valley. The attackers exfiltrated patient data including names, Social Security numbers, and medical record numbers, then published the stolen files on their dark web leak site. UHC did not notify the California Attorney General until August 12, 2022 \u2014 nearly a year after the incident \u2014 prompting a class-action lawsuit alleging unreasonable delay. The reported HHS count of 500 individuals is a placeholder; actual impacted patient count was described as 'thousands.'",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Vice Society",
    "attribution_status": "claimed",
    "individuals_affected_reported": 500,
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'litigation_settlement': 'UNDISCLOSED_AMOUNT', 'notes': 'Class-action settled (Avetisyan v. United Health Centers of San Joaquin Valley, Fresno County Superior Court No. 22-CEG-285); claimants eligible for up to $500 non-economic losses and up to $2,500 economic losses; 3-year credit monitoring offered'}",
    "operational_impact": "Full network shutdown; all computer systems shut down; organization described the event only as an 'encryption event' publicly; patient data published freely on dark web for months before notification",
    "remediation_disclosed": "Network secured; third-party cybersecurity specialists engaged; comprehensive review completed April 11, 2022; 12-month Experian identity theft/credit monitoring offered to affected individuals",
    "primary_source_url": "https://oag.ca.gov/system/files/UHC%20Breach%20Notification%20Letter.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/vice-society-ransomware-gang-attacks-united-health-centers-of-san-joaquin-valley/",
      "https://www.hipaajournal.com/united-health-centers-of-san-joaquin-valley-notifies-patients-about-august-2021-ransomware-attack/",
      "https://www.hipaajournal.com/united-health-centers-of-the-san-joaquin-valley-proposes-settlement-to-resolve-data-breach-lawsuit/",
      "https://databreaches.net/2021/09/25/united-health-centers-of-san-joaquin-valley-remains-publicly-silent-after-ransomware-attack/",
      "https://www.techtarget.com/healthtechsecurity/news/366594582/United-Health-Centers-of-the-San-Joaquin-Valley-Reaches-Proposed-Data-Breach-Settlement"
    ],
    "confidence_notes": "Vice Society is a prolific ransomware group that frequently targets healthcare and education. CA AG notification delayed nearly 12 months post-incident despite CA law requiring 15-day notification \u2014 a key compliance failure highlighted in litigation. HHS OCR placeholder count of 500 does not reflect true scope. Settlement finalized approx. Feb 2023 per hearing schedule.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00282",
    "year": 2022,
    "lat": 36.7378,
    "lng": -119.7871,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "University of Chicago Medicine (pixel tracking lawsuit)",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2022-09-01",
    "executive_summary": "University of Chicago Medical Center (UCMC) was sued in federal court for alleged violations of the Electronic Communications Privacy Act (ECPA) related to its use of pixel tracking technology on its website. Plaintiff alleged UCMC's pixels transmitted patient information \u2014 including website visits related to medical providers, conditions, and treatments \u2014 to third parties without consent. An Illinois federal court narrowed the lawsuit in October 2025, dismissing some claims but allowing others to proceed, while striking class allegations due to UCMC's terms of service class-action waiver.",
    "attack_type": "Unauthorized Tracking Technology Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable \u2014 third-party advertising networks as data recipients",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Illinois patients",
    "financial_impact": "Litigation ongoing; damages not determined",
    "operational_impact": "No clinical disruption",
    "remediation_disclosed": "Not publicly confirmed",
    "primary_source_url": "https://www.insideclassactions.com/2025/10/10/illinois-court-narrows-lawsuit-over-medical-centers-use-of-pixel-technology-and-strikes-class-claims/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. Inside Class Actions legal reporting; court case confirmed ongoing.",
    "sources_used": [
      "Inside Class Actions"
    ],
    "id": "INC-00283",
    "year": 2022,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Upstate Carolina Radiology",
    "organization_type": "Healthcare Provider / Radiology Practice",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Spartanburg",
    "hq_county": "Spartanburg",
    "discovery_date": "2022-06-01",
    "disclosure_date": "2022-09-09",
    "executive_summary": "Upstate Carolina Radiology, P.A. reported a data security incident to the South Carolina Attorney General in September 2022 affecting 1,327 SC residents. The incident involved unauthorized access to patient radiology records and PHI.",
    "attack_type": "Unauthorized Access / Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1327,
    "residents_affected_in_state": 1327,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient radiology records and PHI potentially accessed",
    "remediation_disclosed": "Not publicly disclosed; SC AG notified September 2022",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing. Limited details on nature of attack beyond SC AG filing.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00284",
    "year": 2022,
    "lat": 34.9498007,
    "lng": -81.9320157,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Valley Baptist Medical Center \u2013 Harlingen",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Harlingen",
    "hq_county": "Cameron",
    "discovery_date": "2022-04-12",
    "disclosure_date": "2022-08-01",
    "executive_summary": "Valley Baptist Medical Center \u2013 Harlingen and its Brownsville campus patients were affected by a ransomware attack on Practice Resources, LLC (a New York-based business associate providing billing/collection services), which suffered a ransomware attack on April 12, 2022. The breach compromised the personal and protected health information of 11,137 Valley Baptist patients. Data exposed included demographic details, health insurance details, and medical record information; for some patients, Social Security numbers were included.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack via Business Associate",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11137,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Impact limited to billing services; patient care not reported as disrupted",
    "remediation_disclosed": "Notifications sent; enhanced security measures per Practice Resources remediation",
    "primary_source_url": "https://www.hipaajournal.com/august-2022-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.calhipaa.com/phi-exposed-due-to-breaches-at-practice-resources-and-valley-baptist-medical-center/",
      "https://www.scworld.com/analysis/134k-common-ground-plan-members-added-to-vendors-ransomware-fallout"
    ],
    "confidence_notes": "HHS OCR confirmed 11,137 affected; listed in HIPAA Journal August 2022 Monthly Report; linked to Practice Resources LLC ransomware attack",
    "sources_used": [
      "HIPAA Journal August 2022 Monthly Report, CalHIPAA, SC World"
    ],
    "id": "INC-00285",
    "year": 2022,
    "lat": 26.1907543,
    "lng": -97.6960599,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "WakeMed Health & Hospitals \u2013 Meta Pixel Breach",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Raleigh",
    "hq_county": "Wake",
    "discovery_date": "2022-05-01",
    "disclosure_date": "2022-10-14",
    "executive_summary": "WakeMed (970-bed Raleigh health system) used Meta Pixel on its website and MyChart portal from March 2018 to May 2022. The pixel transmitted patient data to Meta/Facebook, including email addresses, phone numbers, IP addresses, emergency contacts, allergy and medication information, COVID vaccine status, and appointment details. ~495,000 patients were notified. NC AG launched an investigation.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (Meta Pixel misconfiguration)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 495000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; NC AG investigation launched",
    "operational_impact": "4+ years of unauthorized PHI transmission to Meta/Facebook",
    "remediation_disclosed": "Pixel disabled May 2022; notifications sent October 2022",
    "primary_source_url": "https://www.hipaajournal.com/wakemed-meta-pixel-privacy-breach/",
    "secondary_source_urls": [
      "https://www.wakemed.org/about-us/news-and-media/wakemed-news-releases/wakemed-notifies-patients-of-potential-data-privacy-incident",
      "https://www.classaction.org/news/data-breach-wakemed-shared-patient-portal-info-with-facebook-for-over-four-years-class-action-claims"
    ],
    "confidence_notes": "WakeMed official notification is a primary source. HIPAA Journal and class action corroborate.",
    "sources_used": [
      "HIPAA Journal",
      "WakeMed (official)",
      "ClassAction.org"
    ],
    "id": "INC-00286",
    "year": 2022,
    "lat": 35.7796,
    "lng": -78.6382,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "WakeMed Health and Hospitals (DC area patients - tracking pixel)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Raleigh",
    "hq_county": "Wake",
    "discovery_date": "2022-04-01",
    "disclosure_date": "2022-10-17",
    "executive_summary": "WakeMed Health and Hospitals reported a Meta Pixel tracking technology breach affecting approximately 495,949 individuals. While headquartered in North Carolina, WakeMed serves patients from the DC and Maryland areas. The breach involved unauthorized transmission of patient appointment scheduling and portal activity to Meta through tracking pixels embedded in patient-facing web pages.",
    "attack_type": "Tracking pixel / third-party technology impermissible disclosure",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not applicable",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 495949,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuits filed; regulatory inquiry",
    "operational_impact": "Patient portal and scheduling data transmitted to Meta without authorization",
    "remediation_disclosed": "Pixels removed; HHS OCR notified; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Lower confidence for NE relevance; included for DC/MD patient coverage; well documented nationally",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00287",
    "year": 2022,
    "lat": 35.7796,
    "lng": -78.6382,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "WellStar Health System",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Marietta",
    "hq_county": "Cobb",
    "discovery_date": "2022-02-07",
    "disclosure_date": "2022-04-08",
    "executive_summary": "Marietta, GA-based WellStar Health System (11 hospitals, Atlanta metro area) disclosed a breach in which a phishing attack compromised two employee email accounts between December 6, 2021 and January 3, 2022. PHI including names, medical record numbers, WellStar account numbers, and laboratory test descriptions/results was exposed. Financial data and SSNs were not affected. Notifications mailed April 8, 2022.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Two employee email accounts compromised; limited PHI exposed",
    "remediation_disclosed": "Accounts disabled; mandatory password resets; additional cybersecurity professionals engaged; notifications mailed April 8, 2022",
    "primary_source_url": "https://www.scworld.com/brief/data-breach-at-ga-health-system-confirmed",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/data-breach-alert-wellstar-health-system-4248891/"
    ],
    "confidence_notes": "SC Media and JD Supra corroborate. Number of affected individuals not publicly reported.",
    "sources_used": [
      "SC Media",
      "JD Supra"
    ],
    "id": "INC-00288",
    "year": 2022,
    "lat": 33.9526,
    "lng": -84.5499,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Westchester Medical Center Health Network - behavioral health (HealthAlliance related)",
    "organization_type": "Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NY",
    "hq_city": "Valhalla",
    "hq_county": "Westchester",
    "discovery_date": "2021-11-01",
    "disclosure_date": "2022-01-31",
    "executive_summary": "The Westchester Medical Center Health Network (WMCHealth) reported a data security incident in late 2021 involving unauthorized access to employee email accounts containing protected health information. The breach affected patients of WMCHealth facilities in the Hudson Valley region of New York. WMCHealth is the parent organization of HealthAlliance Hospital, which separately suffered a major ransomware attack in October 2023.",
    "attack_type": "Phishing/Email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Hudson Valley patient PHI compromised via employee email accounts",
    "remediation_disclosed": "HHS OCR and patients notified; email security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2021-2022; WMCHealth confirmed NY health system; note this is separate from the October 2023 HealthAlliance ransomware attack already in dataset",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00289",
    "year": 2022,
    "lat": 41.075213,
    "lng": -73.7750061,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Westerly Hospital (RI - network breach)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "RI",
    "hq_city": "Westerly",
    "hq_county": "Washington",
    "discovery_date": "2022-09-01",
    "disclosure_date": "2022-12-01",
    "executive_summary": "Westerly Hospital, a Rhode Island community hospital and part of the Yale New Haven Health System, reported a data security incident involving unauthorized access to its network. Patient protected health information was potentially compromised at this southern Rhode Island community hospital.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "RI community hospital patient PHI potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; RI Yale New Haven Health affiliate; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00290",
    "year": 2022,
    "lat": 41.3775996,
    "lng": -71.8272911,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wolfe Clinic PC (via Eye Care Leaders EHR breach)",
    "organization_type": "Eye Care Clinic",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "IA",
    "hq_city": "Marshalltown",
    "hq_county": "Marshall",
    "discovery_date": "2021-12-01",
    "disclosure_date": "2022-09-27",
    "executive_summary": "Wolfe Clinic PC (distinct from Wolfe Eye Clinic), an Iowa-based eye care practice, was among the healthcare providers affected by the December 2021 ransomware attack on Eye Care Leaders, an EHR and patient management software provider. Eye Care Leaders' platform was breached in early December 2021, affecting at least 41 eye care providers and exposing data of approximately 3.65 million patients total. Wolfe Clinic PC reported the breach to HHS OCR, affecting 542,776 individuals with PHI including names, dates of birth, addresses, Social Security numbers, financial data, medical record numbers, and health insurance information.",
    "attack_type": "Third-Party EHR Vendor Ransomware (Eye Care Leaders)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 542776,
    "residents_affected_in_state": "Iowa residents \u2014 exact count not separately reported",
    "financial_impact": "Eye Care Leaders $4.07M class action settlement (2024)",
    "operational_impact": "Practice management system unavailable during ECL outage; data exposed",
    "remediation_disclosed": "Yes \u2014 Eye Care Leaders rebuilt systems; individual notifications sent 2022",
    "primary_source_url": "https://www.hipaajournal.com/cyberattacks-reported-by-wolfe-clinic-reiter-affiliated-companies-serv-behavioral-health-system/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/closed-settlements/eye-care-leaders-ecl-data-breach-class-action-settlement/",
      "https://www.hipaajournal.com/eye-care-leaders-impacts-millions-of-patients/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal (542,776), HIPAA Journal, class action documentation.",
    "sources_used": [
      "HIPAA Journal",
      "Top Class Actions",
      "HHS OCR"
    ],
    "id": "INC-00291",
    "year": 2022,
    "lat": 42.048881,
    "lng": -92.9122672,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wood River Health",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "RI",
    "hq_city": "Hope Valley",
    "hq_county": "Washington",
    "discovery_date": "2022-06-01",
    "disclosure_date": "2022-09-01",
    "executive_summary": "Wood River Health, a federally qualified health center in Hope Valley, Rhode Island, reported a data security incident involving unauthorized access to patient health information. The breach affected community health center patients in southern Rhode Island.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Community health center patient data potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; RI FQHC; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00292",
    "year": 2022,
    "lat": 41.5098682,
    "lng": -71.7196508,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wright & Filippis LLC",
    "organization_type": "Prosthetics, Orthotics & Accessibility Solutions Provider",
    "organization_type_bucket": "Healthcare provider (other)",
    "state": "MI",
    "hq_city": "Sterling Heights",
    "hq_county": "Macomb",
    "discovery_date": "2022-01-28",
    "disclosure_date": "2022-11-18",
    "executive_summary": "Wright & Filippis, a Michigan-based prosthetics and orthotics provider, suffered a ransomware attack between January 26\u201328, 2022. Security software detected the attack but was unable to prevent file encryption. A forensic investigation confirmed that attackers accessed parts of the network containing PHI for 877,584 individuals, including names, dates of birth, Social Security numbers, financial account numbers, and health insurance information. Notifications were not sent until November 18, 2022, nearly 10 months after the incident. A $2.9 million class action settlement was proposed in October 2023.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 877584,
    "residents_affected_in_state": "Michigan residents \u2014 exact count not separately reported",
    "financial_impact": "$2.9 million class action settlement (proposed 2023)",
    "operational_impact": "File encryption disrupted operations; delayed notifications to patients",
    "remediation_disclosed": "Yes \u2014 investigation concluded, notifications sent November 2022, security improvements implemented",
    "primary_source_url": "https://www.hipaajournal.com/wright-filippis-proposes-2-9-million-class-action-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/wright-filippis-files-notice-of-data-3499228/",
      "https://www.classaction.org/news/wright-and-filippis-failed-to-prevent-2022-data-breach-that-impacted-over-877k-patients-class-action-alleges"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report, HIPAA Journal, class action documentation.",
    "sources_used": [
      "HIPAA Journal",
      "JD Supra",
      "ClassAction.org",
      "HHS OCR"
    ],
    "id": "INC-00293",
    "year": 2022,
    "lat": 42.5803122,
    "lng": -83.0302033,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Your Patient Advisor by Captify Health",
    "organization_type": "Healthcare Organization",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Unknown",
    "hq_county": "Unknown",
    "discovery_date": "2019-05-26",
    "disclosure_date": "2022-12-22",
    "executive_summary": "After a lengthy and extensive investigation, our experts discovered that our website was compromised and some of your information may have been exposed. That investigation concluded on October 13, 2022. We worked diligently to obtain updated contact information to complete notification to potentially impacted individuals.",
    "attack_type": "Hacking / Security Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Law enforcement notified', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/Your%20Patient%20Advisor%20-%20Sample%20Notice.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00294",
    "year": 2022,
    "lat": 37.14541246310275,
    "lng": -119.75719957617571,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Yuma Regional Medical Center",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AZ",
    "hq_city": "Yuma",
    "hq_county": "Yuma",
    "discovery_date": "2022-04-25",
    "disclosure_date": "2022-06-12",
    "executive_summary": "Yuma Regional Medical Center detected a ransomware attack on April 25, 2022. Investigation confirmed unauthorized access to its network between April 21 and April 25, 2022, during which attackers exfiltrated a subset of files prior to encryption. 737,448 current and former patients were notified. Compromised data included names, Social Security numbers, health insurance information, and limited medical information. The electronic medical record system was not affected.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 737448,
    "residents_affected_in_state": "Yuma County residents and seasonal workers",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems taken offline; backup procedures activated; most scheduled services continued with some delays",
    "remediation_disclosed": "Law enforcement notified; third-party forensics engaged; security improvements implemented; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/700000-patients-affected-by-yuma-regional-medical-center-ransomware-attack/",
    "secondary_source_urls": [
      "https://therecord.media/arizona-hospital-says-ssns-of-700000-people-leaked-during-april-ransomware-attack",
      "https://www.bankinfosecurity.com/medical-center-ransomware-attack-affects-700000-a-19337"
    ],
    "confidence_notes": "High confidence; OCR confirmed 737,448; The Record and BankInfoSecurity both documented",
    "sources_used": [
      "HIPAA Journal, The Record, BankInfoSecurity"
    ],
    "id": "INC-00295",
    "year": 2022,
    "lat": 32.6927,
    "lng": -114.6277,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "23andMe, Inc.",
    "organization_type": "Direct-to-consumer genetic testing and health analytics company (CA-headquartered; healthcare-adjacent)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "South San Francisco",
    "hq_county": "San Mateo County",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-10-06",
    "executive_summary": "In October 2023, 23andMe disclosed that credential stuffing attacks compromised approximately 14,000 customer accounts (0.1% of its ~14 million users). Through 23andMe's DNA Relatives and family tree features, these compromised accounts exposed profile data of approximately 6.9 million users, including ancestry information, health-predisposition data, and for some users, geographic location, birth year, and ethnicity data. The breach was particularly sensitive due to the nature of genetic data. 23andMe filed for bankruptcy in March 2025, raising concerns about the disposition of genetic data assets. The UK ICO fined 23andMe \u00a32.31 million in June 2025.",
    "attack_type": "Credential stuffing (no internal system breach; exploited DNA Relatives feature design)",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "NOT_PUBLICLY_IDENTIFIED",
    "attribution_status": "reported",
    "individuals_affected_reported": 6900000,
    "residents_affected_in_state": "CA is primary HQ state; CA GIPA and CCPA apply; CA AG issued consumer alert upon bankruptcy",
    "financial_impact": "{'estimated_incident_cost': 2000000, 'uk_ico_fine': 2310000, 'notes': '23andMe estimated $1\u20132M internal response costs. UK ICO fine \u00a32.31M (June 2025). Company filed Chapter 11 bankruptcy March 23, 2025. Acquisition by TTAM Research Institute for $305M (with data protection commitments).'}",
    "operational_impact": "No patient care disruption (consumer genetics company). 23andMe subsequently mandated 2FA for all users. Company declared bankruptcy March 2025 in part due to breach fallout and market decline.",
    "remediation_disclosed": "2FA mandatory for all users post-breach. SEC Form 8-K filed. Settlement discussions ongoing pre-bankruptcy. CA AG Rob Bonta issued consumer alert urging data deletion (March 2025).",
    "primary_source_url": "https://blog.23andme.com/articles/addressing-data-security-concerns",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/6-9-million-23andme-users-affected-by-data-breach/",
      "https://www.bbc.com/news/articles/c4grggw4n56o",
      "https://www.fiercehealthcare.com/regulatory/23andme-bankruptcy-sparks-genetic-data-privacy-concerns-its-15m-customers",
      "https://www.bsk.com/news-events-videos/nearly-7-million-consumers-impacted-by-23andme-data-breach",
      "https://arxiv.org/abs/2502.04303"
    ],
    "confidence_notes": "CAVEAT: 23andMe is not a HIPAA covered entity or business associate; its data is governed by consumer privacy laws (CCPA, CA Genetic Information Privacy Act), not HIPAA. Included per task instructions as CA-headquartered healthcare-adjacent genetic health company. The breach targeted specific ethnic groups (Ashkenazi Jewish, Chinese ancestry users). Data is not subject to HIPAA but is sensitive genetic health data. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "23andMe official blog",
      "Bond Schoeneck & King",
      "HIPAA Journal",
      "Organization notice / News / SEC",
      "arXiv academic paper"
    ],
    "id": "INC-00296",
    "year": 2023,
    "lat": 37.6547,
    "lng": -122.4077,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Acuity International (healthcare staffing - NE clients)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "VA",
    "hq_city": "Reston",
    "hq_county": "Fairfax",
    "discovery_date": "2022-11-01",
    "disclosure_date": "2023-01-01",
    "executive_summary": "Acuity International, a healthcare staffing and managed care company with clients in multiple Northeast states, reported a data security incident involving unauthorized access to employee and client healthcare data. The breach affected individuals associated with Acuity's healthcare staffing operations in the Northeast region.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare staffing employee and client data potentially compromised",
    "remediation_disclosed": "HHS OCR and individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; VA HQ but NE healthcare clients served; lower confidence for NE specificity",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00297",
    "year": 2023,
    "lat": 38.953282,
    "lng": -77.3464516,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Adventist HealthCare (MD/DC area)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Gaithersburg",
    "hq_county": "Montgomery",
    "discovery_date": "2023-07-01",
    "disclosure_date": "2023-10-01",
    "executive_summary": "Adventist HealthCare, a Maryland health system operating Shady Grove Medical Center, White Oak Medical Center, and Hackettstown Medical Center (NJ), reported a data security incident in 2023 involving unauthorized access to patient health information. The breach affected patients in Montgomery County and the greater DC/Maryland region.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "MD/DC area multi-hospital patient data potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2023; MD/DC area health system with NJ campus; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00298",
    "year": 2023,
    "lat": 39.1399187,
    "lng": -77.1929215,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Allina Health (via Navvis breach \u2014 2023)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2023-07-25",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Allina Health was among the affected clients of Navvis & Company (a healthcare management company) that suffered a ransomware attack July 12\u201325, 2023. Allina Health patient data was part of the 2.8 million individuals affected in the Navvis breach. This is distinct from the SSM Health Navvis entry (MW-016), as Allina is a separately identified victim. (Note: The HIPAA Journal Navvis settlement article names Allina Health explicitly as one of the affected plans.)",
    "attack_type": "Ransomware (Third-Party Vendor \u2014 Navvis)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown ransomware group",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2800000,
    "residents_affected_in_state": "Minnesota patients",
    "financial_impact": "Covered under Navvis/SSM $6.5M settlement",
    "operational_impact": "Allina's own systems not directly breached; Navvis's systems compromised",
    "remediation_disclosed": "Yes \u2014 Navvis notified patients on rolling basis; 12 months credit monitoring",
    "primary_source_url": "https://www.hipaajournal.com/navvis-ssm-health-data-breach-settlement/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal explicitly lists Allina Health as Navvis breach victim.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00299",
    "year": 2023,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Allways Health Partners (MA health plan - MOVEit/GoAnywhere)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MA",
    "hq_city": "Somerville",
    "hq_county": "Middlesex",
    "discovery_date": "2023-05-01",
    "disclosure_date": "2023-08-01",
    "executive_summary": "Allways Health Partners, a Massachusetts-based nonprofit health plan (subsidiary of Mass General Brigham), reported a data security incident related to a vendor's use of GoAnywhere MFT file transfer software compromised by the Clop ransomware group. Member health plan data including names, member IDs, and health information was potentially exposed.",
    "attack_type": "GoAnywhere MFT vulnerability exploit (supply chain)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P)",
    "attribution_status": "reported",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "MA health plan member data exposed via vendor GoAnywhere exploit",
    "remediation_disclosed": "Members notified; vendor remediation performed; HHS OCR notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2023; MGB health plan affiliate; Clop GoAnywhere campaign well documented; moderate confidence",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00300",
    "year": 2023,
    "lat": 42.3875968,
    "lng": -71.0994968,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Apria Healthcare LLC",
    "organization_type": "Home Healthcare Equipment and Services Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2021-10-10",
    "disclosure_date": "2023-05-22",
    "executive_summary": "Indianapolis-based Apria Healthcare LLC, a home medical equipment provider, suffered two separate hacking incidents: the first between April 5\u2013May 7, 2019, and a second between August 27\u2013October 10, 2021. Both were disclosed together in May 2023, approximately 629 days after the second breach was discovered. The FBI notified Apria on September 1, 2021 that an unauthorized third party was likely accessing their systems. The breaches exposed the PHI and PII of up to 1,869,598 individuals, including names, Social Security numbers, financial data, medical histories, and health insurance information. At least 42,000 Hoosiers were affected. Apria agreed to a $6.4 million class action settlement. The Indiana AG filed a separate enforcement lawsuit.",
    "attack_type": "Hacking / Network Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1869598,
    "residents_affected_in_state": 42000,
    "financial_impact": "$6.4 million class action settlement (2025); Indiana AG enforcement action pending",
    "operational_impact": "CEO and employee email accounts accessed; PHI and financial data exposed; delayed notification increased harm potential",
    "remediation_disclosed": "Yes \u2014 FBI engaged, investigation with forensic experts, security improvements implemented",
    "primary_source_url": "https://www.hipaajournal.com/apria-healthcare-data-breach-settlement/",
    "secondary_source_urls": [
      "https://events.in.gov/event/attorney_general_todd_rokita_continues_fight_for_patient_privacy_files_suit_against_apria_healthcare",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/6-37m-apria-healthcare-data-breach-class-action-settlement/",
      "https://www.bleepingcomputer.com/news/security/apria-healthcare-discloses-breach-of-187m-patient-records/",
      "https://healthitsecurity.com/news/apria-healthcare-breach-nearly-2m-patients",
      "https://www.hipaajournal.com/apria-healthcare-data-breach/",
      "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, HIPAA Journal, Indiana AG official announcement, class action documentation. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BleepingComputer",
      "Delaware AG database",
      "HHS OCR",
      "HIPAA Journal",
      "Health IT Security",
      "Indiana AG",
      "Top Class Actions"
    ],
    "id": "INC-00301",
    "year": 2023,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Apria Healthcare \u2014 Southeast patients",
    "organization_type": "Healthcare Provider / Home Medical Equipment",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Indianapolis",
    "hq_county": "Marion County (IN-based)",
    "discovery_date": "2021-09-01",
    "disclosure_date": "2023-05-22",
    "executive_summary": "Apria Healthcare disclosed two hacking incidents affecting approximately 1,869,598 individuals. The first breach occurred April 5 \u2013 May 7, 2019; the second August 27 \u2013 October 10, 2021. Apria operates extensively throughout Florida and the Southeast. Exposed data included personal, medical, health insurance, and financial information, including Social Security numbers. Apria agreed to a $6.4M class action settlement. Florida and SE patients were among the affected population.",
    "attack_type": "Network Hacking (two separate incidents)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1869598,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$6.4M class action settlement; Indiana AG litigation pending",
    "operational_impact": "Patient personal, medical, insurance, and financial data potentially viewed or obtained over two multi-week access windows",
    "remediation_disclosed": "$6.4M settlement; security improvements; credit monitoring",
    "primary_source_url": "https://www.hipaajournal.com/apria-healthcare-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.classaction.org/apria-data-breach-lawsuit"
    ],
    "confidence_notes": "Medium confidence for SE-specific impact \u2014 Apria operates major FL/SE operations per annual reports; national breach with major SE patient base. HQ is Indiana but significant FL/SE provider.",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "Kessler Topaz"
    ],
    "id": "INC-00302",
    "year": 2023,
    "lat": 27.8110773,
    "lng": -82.6034056,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Ardent Health Services / Lovelace Health System (New Mexico)",
    "organization_type": "Health System / Hospital Network",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NM",
    "hq_city": "Albuquerque",
    "hq_county": "Bernalillo",
    "discovery_date": "2023-11-23",
    "disclosure_date": "2023-11-24",
    "executive_summary": "Ardent Health Services, parent of Lovelace Health System in New Mexico, suffered a ransomware attack on November 23, 2023 (Thanksgiving). Lovelace facilities in Albuquerque diverted ambulances and rescheduled non-emergent procedures. EHR and clinical systems taken offline. 30+ hospitals affected across multiple states.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Ambulances diverted; elective procedures cancelled; EHR offline at NM Lovelace facilities",
    "remediation_disclosed": "Systems gradually restored; law enforcement notified",
    "primary_source_url": "https://www.hipaajournal.com/ardent-health-services-ransomware-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; HIPAA Journal confirmed Ardent Thanksgiving 2023 ransomware; Lovelace Health System is Ardent's NM subsidiary; NM-specific patient count not separately disclosed",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00303",
    "year": 2023,
    "lat": 35.0844,
    "lng": -106.6504,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Arietis Health, LLC",
    "organization_type": "Business Associate (Revenue Cycle Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Fort Myers",
    "hq_county": "Lee",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-10-02",
    "executive_summary": "Fort Myers-based Arietis Health, a revenue cycle management company, confirmed it was affected by the Clop group's mass exploitation of Progress Software's MOVEit Transfer zero-day vulnerability on May 31, 2023. Attackers accessed its MOVEit server on May 31, 2023 and acquired files containing PHI of patients at NorthStar Anesthesia and other clients. The breach affected 1,975,066 individuals. Arietis settled the MDL class action for $2.8 million.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1975066,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$2.8 million MDL class action settlement",
    "operational_impact": "MOVEit Transfer taken offline; PHI acquired by attackers",
    "remediation_disclosed": "Systems secured; investigation launched; notifications mailed October 2023",
    "primary_source_url": "https://www.jdsupra.com/legalnews/arietis-health-llc-announces-moveit-2472384/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/arietis-health-progress-software-hit-with-class-action-over-may-2023-moveit-data-breach",
      "https://www.cohenmilstein.com/medical-tech-co-exits-moveit-hack-mdl-for-2-8m/"
    ],
    "confidence_notes": "HHS OCR lists 1,975,066 affected. Clop MOVEit attribution well-established. Settlement confirmed by Cohen Milstein.",
    "sources_used": [
      "JD Supra",
      "ClassAction.org",
      "Cohen Milstein"
    ],
    "id": "INC-00304",
    "year": 2023,
    "lat": 26.640628,
    "lng": -81.8723084,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Asante (EHR unauthorized access by physician)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OR",
    "hq_city": "Medford",
    "hq_county": "Jackson",
    "discovery_date": "2023-01-01",
    "disclosure_date": "2023-03-08",
    "executive_summary": "Asante, an Oregon health system with three hospitals and 30+ primary care facilities, discovered that a physician (Dr. Paul Hoffman) had improperly accessed 8,834 patient records over approximately nine years (June 2014 through January 2023) without a valid clinical need. Hoffman had access to Asante's EHR system to treat his own patients at Asante facilities but accessed records of patients unrelated to his care. No evidence of malicious intent was found. Asante terminated Hoffman's EHR access and reported to the Oregon Medical Board.",
    "attack_type": "Insider threat / EHR snooping",
    "attack_category": "Insider threat",
    "threat_actor_name": "Internal (non-employee physician with system access)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 8834,
    "residents_affected_in_state": "OR-based Asante patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "9 years of unauthorized medical record access",
    "remediation_disclosed": "Physician access revoked; reported to Oregon Medical Board; EHR monitoring enhanced",
    "primary_source_url": "https://www.hipaajournal.com/asante-discovers-9-years-of-unauthorized-medical-record-access-by-a-physician/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594425/Oregon-Health-System-Uncovers-9-Year-HIPAA-Violation-by-Physician"
    ],
    "confidence_notes": "Confirmed by HHS OCR breach portal; physician identified by name in public court filings",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget HealthTech Security"
    ],
    "id": "INC-00305",
    "year": 2023,
    "lat": 42.3265,
    "lng": -122.8756,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Asuris Northwest Health / Regence BlueShield (Welltok MOVEit)",
    "organization_type": "Health Plan (Health Insurance)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Spokane",
    "hq_county": "Spokane",
    "discovery_date": "2023-07-26",
    "disclosure_date": "2023-11-17",
    "executive_summary": "Asuris Northwest Health and its affiliate Regence BlueShield of Washington (both operated by Regence) were among at least 165 healthcare clients affected by the Welltok MOVEit Transfer breach of May 2023. The Clop ransomware group exploited CVE-2023-34362 in Progress Software's MOVEit Transfer tool on May 30, 2023, gaining access to Welltok's server containing health plan member data. Asuris Northwest Health serves eastern Washington; Regence BlueShield serves western Washington. Compromised data included member names, dates of birth, addresses, health information, and for some individuals, Social Security numbers and Medicare/Medicaid IDs. Welltok's total breach affected 14.76 million individuals across 165+ clients.",
    "attack_type": "SQL injection exploit / Data exfiltration (MOVEit zero-day)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 14760000,
    "residents_affected_in_state": "Not separately reported for WA",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member data exposed; names, DOBs, addresses, health information, SSNs (some), Medicare/Medicaid IDs (some) compromised",
    "remediation_disclosed": "MOVEit server decommissioned; notifications sent Nov 2023; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/welltok-data-breach/",
    "secondary_source_urls": [
      "https://www.medicalrecords.com/hospital_breaches/regence-bluecross-blueshield-of-oregon",
      "https://techcrunch.com/2023/11/20/hackers-accessed-sensitive-health-data-of-welltok-patients/"
    ],
    "confidence_notes": "Asuris Northwest Health and Regence BlueShield confirmed as Welltok clients per HIPAA Journal reporting; total for these specific plans not separately disclosed; part of HHS OCR filing by Welltok (14,762,475 total)",
    "sources_used": [
      "HIPAA Journal",
      "TechCrunch",
      "MedicalRecords.com",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00306",
    "year": 2023,
    "lat": 47.6588,
    "lng": -117.426,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Atlantic General Hospital",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Berlin",
    "hq_county": "Worcester",
    "discovery_date": "2023-01-29",
    "disclosure_date": "2023-03-24",
    "executive_summary": "Atlantic General Hospital discovered a ransomware attack on January 29, 2023, when files were encrypted. Attackers had access to the network from January 20-29, 2023. The breach ultimately affected 136,981 individuals with compromised data including names, DOBs, SSNs, driver's license numbers, health insurance information, and financial data. The hospital agreed to a $2.25 million settlement.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 136981,
    "residents_affected_in_state": 6219,
    "financial_impact": "$2.25 million settlement (2024)",
    "operational_impact": "Hospital services disrupted for several days; walk-in lab and outpatient imaging closed",
    "remediation_disclosed": "Systems restored; law enforcement notified; $2.25M settlement",
    "primary_source_url": "https://www.hipaajournal.com/atlantic-general-hospital-settles-data-breach-lawsuit-for-2-25-million/",
    "secondary_source_urls": [
      "https://www.wmdt.com/2023/01/atlantic-general-hospital-experiences-ransomware-event/",
      "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/"
    ],
    "confidence_notes": "Hospital confirmed; DE AG filing; OCR breach report; $2.25M settlement preliminary approval",
    "sources_used": [
      "HIPAA Journal",
      "WMDT/47ABC",
      "Delaware AG"
    ],
    "id": "INC-00307",
    "year": 2023,
    "lat": 38.324505,
    "lng": -75.2188589,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Atrium Health (Maryland / Mid-Atlantic - tracking pixel breach)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Charlotte",
    "hq_county": "Unknown",
    "discovery_date": "2022-07-01",
    "disclosure_date": "2023-01-05",
    "executive_summary": "Atrium Health, which operates healthcare facilities including in Maryland and the Mid-Atlantic region, reported a tracking pixel data breach affecting approximately 994,000 individuals. Like other major health systems in 2022-2023, Atrium used Meta Pixel and other third-party tracking technologies on its patient portal and website, inadvertently transmitting patient health information to Meta (Facebook) and Google. The breach was among the wave of pixel-related healthcare breaches following OCR guidance in December 2022.",
    "attack_type": "Tracking pixel / third-party technology impermissible disclosure",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not applicable (third-party pixel technology)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 994000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Multiple class action lawsuits; regulatory scrutiny",
    "operational_impact": "Patient scheduling, portal, and website interactions transmitted to Meta/Google without authorization",
    "remediation_disclosed": "Pixels removed; HHS OCR notified; patients notified; lawsuits filed",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate - MD operations confirmed; breach well documented nationally; pixel breach category consistent with 2022-2023 wave",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00308",
    "year": 2023,
    "lat": 38.4773235,
    "lng": -76.7848553,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Avera Health (via DMS Health Technologies breach \u2014 2023)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2023-09-07",
    "disclosure_date": "2023-09-15",
    "executive_summary": "Avera Health was informed by DMS Health Technologies, its mobile heart screening imaging vendor, of a data security incident between March 27 and April 24, 2023 (same DMS breach affecting Sanford Health, per MW-042). The same 21,211-patient Sanford notification includes SD, ND, MN, and IA patients; Avera notified its own affected patients separately. This entry captures Avera's independent notification of DMS breach-affected patients.",
    "attack_type": "Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately quantified for Avera (part of broader DMS breach)",
    "residents_affected_in_state": "South Dakota patients primarily",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Avera's own systems not breached; imaging vendor's data compromised",
    "remediation_disclosed": "Yes \u2014 DMS notified patients; Kroll identity monitoring offered",
    "primary_source_url": "https://drgnews.com/2023/09/07/avera-notified-of-data-breech-of-dms-health-technologies/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. DRGNews reporting; consistent with Sanford Health's DMS breach confirmation.",
    "sources_used": [
      "DRGNews"
    ],
    "id": "INC-00309",
    "year": 2023,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Bellin Health (Wisconsin)",
    "organization_type": "Regional Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WI",
    "hq_city": "Green Bay",
    "hq_county": "Brown",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Bellin Health, a Green Bay, Wisconsin-based regional hospital and health system, reported a hacking incident to HHS OCR in December 2023 affecting 20,790 individuals. The incident was listed in the HIPAA Journal December 2023 healthcare data breach report. Patient PHI was compromised. Bellin Health serves northeastern Wisconsin and the Upper Peninsula of Michigan. Specific details about the attack vector and operational impact were not further disclosed in available public sources.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 20790,
    "residents_affected_in_state": "Wisconsin residents \u2014 primarily northeastern Wisconsin/Brown County area",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not fully disclosed",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal December 2023 report citing HHS OCR. 20,790 individuals confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00310",
    "year": 2023,
    "lat": 44.5133,
    "lng": -88.0133,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CHI LakeWood Health / CHI St. Francis / CHI St. Joseph's (Minnesota \u2014 CommonSpirit 2022)",
    "organization_type": "Nonprofit Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Baudette / Breckenridge / Park Rapids",
    "hq_county": "Lake of the Woods County / Wilkin County / Hubbard",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-04-06",
    "executive_summary": "CommonSpirit Health's Minnesota facilities were confirmed affected by the October 2022 ransomware attack, including CHI LakeWood Health (Baudette), CHI St. Francis Health (Breckenridge), CHI St. Joseph's Health (Park Rapids), CHI St. Gabriel's Health (Little Falls), CHI St. Francis Home (Breckenridge), CHI Health at Home Minnesota locations, and CHI St. Joseph's Hospice. These critical access hospitals and health centers in rural Minnesota experienced EHR outages and service disruptions as part of the broader CommonSpirit breach. This represents the Minnesota-specific component of MW-092.",
    "attack_type": "Ransomware (CommonSpirit parent system attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Minnesota rural communities \u2014 Baudette Breckenridge Park Rapids Little Falls areas",
    "financial_impact": "Part of CommonSpirit $160M total loss",
    "operational_impact": "Rural Minnesota critical access hospitals impacted; EHR downtime, appointment delays",
    "remediation_disclosed": "Yes \u2014 systems restored; see CommonSpirit (MW-092)",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. CommonSpirit April 2023 update lists 6 Minnesota CHI facilities. MN-specific subset of MW-092.",
    "sources_used": [
      "HIPAA Journal",
      "CommonSpirit official statement (April 2023)"
    ],
    "id": "INC-00311",
    "year": 2023,
    "lat": 48.7124408,
    "lng": -94.600171,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "CHI St. Alexius Health (North Dakota \u2014 CommonSpirit 2022 Ransomware Component)",
    "organization_type": "Nonprofit Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ND",
    "hq_city": "Bismarck",
    "hq_county": "Burleigh",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-04-06",
    "executive_summary": "CHI St. Alexius Health, CommonSpirit Health's North Dakota hospital system, was confirmed as affected by the October 2022 CommonSpirit ransomware attack in the April 2023 disclosure. North Dakota facilities confirmed affected included CHI St. Alexius Medical Center (Bismarck), CHI St. Alexius Health Carrington & Foster County Medical Center, CHI Lisbon Health, CHI St. Alexius Health Devils Lake & Clinics, CHI Mercy Health Valley City, CHI St. Alexius Health Williston, CHI Oakes Hospital & Clinics, CHI St. Alexius Health Turtle Lake, CHI St. Alexius Health Garrison & Clinics, CHI St. Alexius Health Dickinson & Clinics, CHI Health at Home Fargo, CHI Friendship Fargo, and all CHI St. Alexius Physician Clinics. This represents the largest North Dakota hospital system impacted by the CommonSpirit breach.",
    "attack_type": "Ransomware (CommonSpirit parent system attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": 13,
    "financial_impact": "Part of CommonSpirit $160M total loss",
    "operational_impact": "13+ North Dakota facilities impacted; EHR outage, appointment delays, paper fallback operations",
    "remediation_disclosed": "Yes \u2014 systems restored; see CommonSpirit disclosure (MW-092)",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and"
    ],
    "confidence_notes": "High confidence. CommonSpirit April 2023 update lists 13 North Dakota CHI St. Alexius facilities. ND-specific subset of MW-092.",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare",
      "CommonSpirit official statement (April 2023)"
    ],
    "id": "INC-00312",
    "year": 2023,
    "lat": 46.8083,
    "lng": -100.7837,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Capital Health",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Trenton",
    "hq_county": "Mercer",
    "discovery_date": "2023-11-11",
    "disclosure_date": "2023-11-28",
    "executive_summary": "Capital Health's computer network was taken offline by a cyberattack between November 11-26, 2023. LockBit claimed responsibility on January 7, 2024, stating it had stolen over 10 million files from the health system. The breach exposed patient and employee names, addresses, SSNs, dates of birth, email addresses, and potentially clinical information. Capital Health agreed to a $4.5 million settlement in 2026.",
    "attack_type": "Ransomware (LockBit)",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4.5 million settlement (2026)",
    "operational_impact": "Two-week network outage (Nov 11-26, 2023); multiple facilities affected across NJ and PA",
    "remediation_disclosed": "Systems restored; forensic investigation; law enforcement notified; $4.5M settlement",
    "primary_source_url": "https://www.capitalhealth.org/information-technology-security-incident",
    "secondary_source_urls": [
      "https://www.nj.com/healthfit/2026/02/nj-health-system-agrees-to-pay-45m-in-data-breach-settlement.html",
      "https://nj1015.com/nj-cyberattack-settlement/"
    ],
    "confidence_notes": "Capital Health confirmed; LockBit claimed; settlement filed in federal court",
    "sources_used": [
      "Capital Health official notice",
      "NJ.com",
      "NJ 101.5"
    ],
    "id": "INC-00313",
    "year": 2023,
    "lat": 40.2206,
    "lng": -74.7597,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Capital Health Regional Medical Center / Capital Health Medical Center (2023 LockBit - NJ/PA)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Pennington",
    "hq_county": "Mercer",
    "discovery_date": "2023-11-11",
    "disclosure_date": "2023-11-28",
    "executive_summary": "This is the same incident as Capital Health (entry #6) but specifically notes that Capital Health's Regional Medical Center in Trenton NJ and Capital Health Medical Center in Hopewell, NJ were both affected by the LockBit attack. PA facilities were also affected. LockBit claimed 10 million files stolen including patient and employee records with PII and clinical data.",
    "attack_type": "Ransomware (LockBit)",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4.5 million settlement (2026)",
    "operational_impact": "Two NJ hospitals offline Nov 11-26, 2023; staff on downtime procedures",
    "remediation_disclosed": "Systems restored; $4.5M settlement",
    "primary_source_url": "https://www.capitalhealth.org/information-technology-security-incident",
    "secondary_source_urls": [
      "https://nj1015.com/nj-cyberattack-settlement/"
    ],
    "confidence_notes": "Duplicate entry noting specific NJ hospital facilities; see Capital Health entry #6 for full details",
    "sources_used": [
      "Capital Health official notice",
      "NJ 101.5"
    ],
    "id": "INC-00314",
    "year": 2023,
    "lat": 40.3281213,
    "lng": -74.7909992,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Capital Health System, Inc.",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Trenton",
    "hq_county": "Mercer",
    "discovery_date": "2023-11-27",
    "disclosure_date": "2023-11-28",
    "executive_summary": "Capital Health, a New Jersey hospital system operating hospitals in Trenton and Hopewell, suffered a ransomware attack that caused a two-week network outage from November 11-26, 2023. The investigation confirmed unauthorized access to its systems November 11-26. On January 7, 2024, the LockBit ransomware group claimed responsibility, asserting it had stolen more than 10 million files including patient medical data. LockBit threatened to publish the data within 48 hours unless paid a ransom. Capital Health's official notice lists names, addresses, SSNs, dates of birth, email addresses, phone numbers, and potentially clinical information as compromised. A class action settlement of $4.5 million was agreed.",
    "attack_type": "Ransomware / Double Extortion / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit",
    "attribution_status": "claimed",
    "individuals_affected_reported": 10000000,
    "residents_affected_in_state": "NJ: state-specific count not separately reported",
    "financial_impact": "$4.5 million class action settlement. Ransom payment status not confirmed.",
    "operational_impact": "Network outage November 11-26, 2023 (two weeks). Hospital operations disrupted. No confirmed patient care deaths.",
    "remediation_disclosed": "Systems restored after two-week outage. Law enforcement notified. Official notice posted November 28, 2023 on Capital Health website. Settlement fund established.",
    "primary_source_url": "https://www.capitalhealth.org/information-technology-security-incident",
    "secondary_source_urls": [
      "https://www.securityweek.com/ransomware-gang-claims-attack-on-capital-health/",
      "https://nj1015.com/nj-cyberattack-settlement/",
      "https://6abc.com/post/capital-health-cybersecurity-outage-network-nj-news/14118250/"
    ],
    "confidence_notes": "High confidence on operational facts. LockBit claim posted January 7, 2024. Final individual count not confirmed per official notice. $4.5M settlement from court records.",
    "sources_used": [
      "Capital Health official security notice",
      "SecurityWeek",
      "NJ1015",
      "6ABC"
    ],
    "id": "INC-00315",
    "year": 2023,
    "lat": 40.2206,
    "lng": -74.7597,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Cardiovascular Associates (Alabama)",
    "organization_type": "Healthcare Provider / Cardiology Practice",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Birmingham",
    "hq_county": "Jefferson",
    "discovery_date": "2022-12-05",
    "disclosure_date": "2023-02-03",
    "executive_summary": "Cardiovascular Associates in Alabama detected a network hacking incident on December 5, 2022. Forensic investigation confirmed hackers had access for approximately one week (November 28 \u2013 December 5, 2022) and exfiltrated files containing PHI and PII of 441,640 individuals. A class action lawsuit was filed alleging negligence in cybersecurity practices.",
    "attack_type": "Network Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 441640,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuit filed; settlement amount not yet confirmed",
    "operational_impact": "Patient PHI and PII exfiltrated including names, addresses, SSNs, driver's license numbers, health and insurance information",
    "remediation_disclosed": "Third-party forensic firm engaged; law enforcement notified; security improvements implemented",
    "primary_source_url": "https://www.hipaajournal.com/class-action-lawsuit-filed-against-cardiovascular-associates-over-441k-record-data-breach/",
    "secondary_source_urls": [
      "https://www.turkestrauss.com/2023/03/22/cardiovascular-associates-data-breach-investigation-2/"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal reporting, HHS OCR breach portal, class action lawsuit filings.",
    "sources_used": [
      "HIPAA Journal",
      "Turke & Strauss LLP",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00316",
    "year": 2023,
    "lat": 33.5186,
    "lng": -86.8104,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Cardiovascular Consultants Ltd.",
    "organization_type": "Healthcare Provider (Cardiology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2023-09-29",
    "disclosure_date": "2023-12-02",
    "executive_summary": "Cardiovascular Consultants Ltd., an Arizona cardiology practice with offices in Phoenix, Scottsdale, and Glendale, identified suspicious activity in its systems on September 29, 2023. Forensic investigation confirmed unauthorized access beginning September 27, 2023, with hackers exfiltrating patient files before deploying ransomware to encrypt the network. The breach affected 484,000 individuals. Exposed data included names, addresses, dates of birth, emergency contact information, Social Security numbers, driver's license numbers, insurance policy information, diagnosis and treatment details, and billing records. A class action was filed in December 2023, and a $3.85 million settlement was reached in 2026.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack with Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 484000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3,850,000 class action settlement (2026); pro rata cash payments estimated ~$75/class member",
    "operational_impact": "Network encrypted by ransomware; systems disrupted",
    "remediation_disclosed": "Third-party cybersecurity firm engaged; additional security measures implemented; 24 months credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/cardiovascular-consultants-data-breach/",
    "secondary_source_urls": [
      "https://www.calhipaa.com/cardiovascular-consultants-agrees-to-3-85m-settlement-of-data-breach-lawsuit/"
    ],
    "confidence_notes": "HHS OCR confirmed 484,000 affected; HIPAA Journal breach notice; $3.85M settlement confirmed in 2026",
    "sources_used": [
      "HIPAA Journal, CalHIPAA/calhipaa.com"
    ],
    "id": "INC-00317",
    "year": 2023,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Care N' Care Insurance Company (Texas health plan \u2013 MOVEit)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "TX",
    "hq_city": "Fort Worth",
    "hq_county": "Tarrant",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Care N' Care Insurance Company, a Texas Medicare Advantage health plan, was affected by a MOVEit Transfer data theft attack via TMG Health Inc. 33,032 individuals were affected. The breach was part of the broader Clop group's MOVEit exploitation.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day (via TMG Health BA)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 33032,
    "residents_affected_in_state": "Texas Medicare Advantage members",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; OCR July 2023 breach report listed this entity specifically",
    "sources_used": [
      "HIPAA Journal July 2023 Breach Report"
    ],
    "id": "INC-00318",
    "year": 2023,
    "lat": 32.7555,
    "lng": -97.3308,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CareSource Management Group Co.",
    "organization_type": "Health Plan (Medicaid/Medicare Managed Care)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OH",
    "hq_city": "Dayton",
    "hq_county": "Montgomery",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-06-27",
    "executive_summary": "CareSource, one of the largest Medicaid managed care organizations in the United States operating across multiple states, confirmed on June 27, 2023, that the Cl0p ransomware group's MOVEit Transfer zero-day exploitation (CVE-2023-34362) in May 2023 had affected its members. CareSource serves Medicaid and Medicare populations across Ohio, Indiana, Kentucky, West Virginia, Georgia, and other states. The breach compromised the protected health information of 3,180,537 individuals, including names, addresses, dates of birth, genders, Social Security numbers, health plan information, medications, allergies, and health conditions. CareSource notified affected individuals on August 24, 2023, and offered two years of complimentary credit monitoring. Multiple class action lawsuits were filed.",
    "attack_type": "Supply Chain / MOVEit Zero-Day SQL Injection (CVE-2023-34362) / Data Theft",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 3180537,
    "residents_affected_in_state": 744000,
    "financial_impact": "Multiple class action lawsuits filed. Settlement not yet disclosed. Credit monitoring costs for 3.18M individuals.",
    "operational_impact": "Pure data theft. No system encryption. CareSource managed Medicaid and Medicare data including highly sensitive population health information.",
    "remediation_disclosed": "MOVEit application patched/decommissioned. Third-party forensics. HHS OCR breach reported. Notifications mailed August 24, 2023. Two years of credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/caresource-facing-multiple-class-action-lawsuits-over-moveit-data-breach/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/caresource-hit-with-class-action-after-member-info-was-exposed-during-moveit-data-breach",
      "https://www.wfyi.org/health/2023-09-01/a-data-breach-exposed-private-health-information-of-more-than-200000-medicaid-clients-in-indiana",
      "https://thelyonfirm.com/blog/caresource-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report filed. Indiana FSSA publicly confirmed Medicaid member counts. HIPAA Journal and ClassAction.org corroborate.",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "WFYI Public Media (Indiana)",
      "The Lyon Firm"
    ],
    "id": "INC-00319",
    "year": 2023,
    "lat": 39.7589,
    "lng": -84.1916,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CaroMont Health (via ESO Solutions)",
    "organization_type": "Healthcare Provider / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Gastonia",
    "hq_county": "Gaston",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "CaroMont Health, a Gastonia, NC hospital system, was named as an entity affected by the ESO Solutions ransomware attack of September 2023. Patient data stored in ESO's software systems was potentially exposed. This is a separate event from any prior CaroMont incidents.",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient EMS records exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 12, 2023; 24-month Kroll identity monitoring offered",
    "primary_source_url": "https://www.jdsupra.com/legalnews/eso-solutions-data-breach-update-eso-6676886/",
    "secondary_source_urls": [
      "https://heimdalsecurity.com/blog/major-data-breach-at-eso-solutions-affects-2-7-million-patients/"
    ],
    "confidence_notes": "High confidence \u2014 JD Supra ESO breach update and Heimdal Security named CaroMont Health as ESO client.",
    "sources_used": [
      "JD Supra",
      "Heimdal Security"
    ],
    "id": "INC-00320",
    "year": 2023,
    "lat": 35.2622654,
    "lng": -81.1838186,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Catawba Valley Medical Center",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Hickory",
    "hq_county": "Catawba",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Hickory, NC-based Catawba Valley Medical Center was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Patient data was potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00321",
    "year": 2023,
    "lat": 35.7333312,
    "lng": -81.3442915,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Cerebral Inc. (tracking pixel breach - DE registration)",
    "organization_type": "Healthcare Provider (Telehealth)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "DE",
    "hq_city": "San Luis Obispo",
    "hq_county": "San Luis Obispo",
    "discovery_date": "2023-01-15",
    "disclosure_date": "2023-03-06",
    "executive_summary": "Cerebral Inc., a telehealth mental health company registered as a business associate in Delaware, disclosed that tracking pixels on its website transmitted sensitive mental health and substance use disorder PHI of 3,179,835 individuals to third parties including Meta, Google, TikTok, and others without authorization. This was among the largest tracking-pixel related HIPAA breaches disclosed. NE residents were among those affected.",
    "attack_type": "Tracking pixel / unauthorized disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 3179835,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; FTC investigation",
    "operational_impact": "3.18M individuals' sensitive mental health PHI transmitted to tech companies",
    "remediation_disclosed": "Pixels removed; HHS OCR breach filed; FTC investigation; FTC settlement $7M (2024)",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal; registered in DE per OCR filing; FTC $7M settlement 2024",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00322",
    "year": 2023,
    "lat": 35.2827525,
    "lng": -120.659615,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Cerebral, Inc.",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "San Francisco",
    "hq_county": "San Francisco  (CA operations)",
    "discovery_date": "Not specified (tracking technology active period)",
    "disclosure_date": "03/2023",
    "executive_summary": "Cerebral (mental health telehealth company) impermissibly disclosed patient data to third parties including Google, Meta, Snapchat via tracking pixels on its platforms. FTC settlement resulted.",
    "attack_type": "Unauthorized Access/Disclosure \u2014 Tracking pixel/analytics code impermissible disclosure; FTC Act violation",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3179835,
    "residents_affected_in_state": "Not separately reported (significant CA user base)",
    "financial_impact": "$7.1 million FTC settlement ($10M CMP, $8M suspended; $5.1M refunds to customers)",
    "operational_impact": "No clinical operational disruption",
    "remediation_disclosed": "Tracking technologies removed; FTC corrective order",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
      "https://www.malwarebytes.com/blog/news/2024/04/mental-health-company-cerebral-failed-to-protect-sensitive-personal-data-must-pay-7-million",
      "https://www.cnn.com/2023/03/10/politics/cerebral-mental-health-privacy-data-exposure",
      "https://medcitynews.com/2023/03/cerebral-admits-that-it-wrongly-shared-data-of-3-1m-users/",
      "https://www.hipaajournal.com/cerebral-impermissible-disclosure-pixel-3170000/"
    ],
    "confidence_notes": "Cerebral is incorporated in DE but headquartered in San Francisco with CA operations. Ranked #40 largest healthcare breach of all time. Significant CA user base for telehealth mental health services. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "CNN",
      "HHS OCR Breach Portal",
      "HIPAA Journal",
      "Malwarebytes / FTC announcement",
      "MedCity News"
    ],
    "id": "INC-00323",
    "year": 2023,
    "lat": 37.7749,
    "lng": -122.4194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Chattanooga Heart Institute (Memorial Heart Institute, LLC)",
    "organization_type": "Healthcare Provider (Cardiovascular Care Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Chattanooga",
    "hq_county": "Hamilton",
    "discovery_date": "2023-04-17",
    "disclosure_date": "2023-07-01",
    "executive_summary": "The Chattanooga Heart Institute detected a cyberattack on April 17, 2023. Investigation determined the Karakurt ransomware group accessed the network between March 8 and March 16, 2023 and exfiltrated files. 545,491 individuals were affected per HHS OCR. Data included names, addresses, emails, phones, DOBs, driver's licenses, SSNs, account info, health insurance, diagnosis details, lab results, medications, and financial information. A $3.75M class action settlement was reached.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Karakurt",
    "attribution_status": "claimed",
    "individuals_affected_reported": 545491,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3.75 million class action settlement (preliminary approval 2026)",
    "operational_impact": "170,450+ records stolen in July 2023 HHS report; full scope 545,491",
    "remediation_disclosed": "Investigation launched; HHS OCR notified; $3.75M settlement",
    "primary_source_url": "https://www.classaction.org/news/3.75m-chattanooga-heart-institute-settlement-ends-class-action-lawsuit-over-2023-cyberattack",
    "secondary_source_urls": [
      "https://www.calhipaa.com/chattanooga-heart-institute-agrees-to-3-75m-settlement-to-resolve-its-data-breach-lawsuit/",
      "https://chattanoogaheartsettlement.com"
    ],
    "confidence_notes": "HHS OCR listed 170,450 in July 2023 report; updated to 545,491. $3.75M settlement well-documented.",
    "sources_used": [
      "ClassAction.org",
      "HIPAA E-Tool (CalHIPAA)",
      "Settlement Website"
    ],
    "id": "INC-00324",
    "year": 2023,
    "lat": 35.0456,
    "lng": -85.3097,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Cheyenne Radiology Group & MRI",
    "organization_type": "Healthcare Provider (Outpatient Radiology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WY",
    "hq_city": "Cheyenne",
    "hq_county": "Laramie",
    "discovery_date": "2022-12-12",
    "disclosure_date": "2023-07-27",
    "executive_summary": "Cheyenne Radiology Group & MRI, a 70-year-old radiology practice in Wyoming, suffered a cyberattack detected on December 12, 2022. The practice immediately halted the breach and engaged third-party forensic experts to determine if patient information was affected. Patient notification was issued in July 2023, and credit monitoring services were offered to those affected.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Wyoming patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Breach immediately stopped upon detection; third-party forensic expert hired; credit monitoring offered",
    "primary_source_url": "https://radiologybusiness.com/topics/health-it/enterprise-imaging/70-year-old-radiology-practice-suffers-cyberattack",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; Radiology Business documented; details limited",
    "sources_used": [
      "Radiology Business"
    ],
    "id": "INC-00325",
    "year": 2023,
    "lat": 41.14,
    "lng": -104.8202,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Chippewa County Human Services",
    "organization_type": "County Government / Public Health",
    "organization_type_bucket": "Other healthcare entity",
    "state": "WI",
    "hq_city": "Chippewa Falls",
    "hq_county": "Chippewa",
    "discovery_date": "2023-02-28",
    "disclosure_date": "2023-04-05",
    "executive_summary": "Chippewa County Human Services in Chippewa Falls, Wisconsin experienced a data breach on February 28, 2023. Disclosed on April 5, 2023, the breach affected county social services clients. Data accessed included medical history numbers, client names, prescription information, and progress notes for Chippewa County Human Services clients. Approximately 842 individuals were affected. This incident is documented in the Wisconsin DATCP breach archive.",
    "attack_type": "Hacking/IT Incident (type not specified in public notice)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 842,
    "residents_affected_in_state": 842,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Client medical and prescription data compromised",
    "remediation_disclosed": "Partial \u2014 DATCP notified April 2023",
    "primary_source_url": "https://datcp.wi.gov/Pages/Programs_Services/DataBreachArchive.aspx",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. Wisconsin DATCP official breach archive. Limited additional details.",
    "sources_used": [
      "Wisconsin DATCP"
    ],
    "id": "INC-00326",
    "year": 2023,
    "lat": 44.9371325,
    "lng": -91.3932118,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Clay County Social Services (Minnesota) \u2014 Ransomware",
    "organization_type": "County Government / Social Services",
    "organization_type_bucket": "Other healthcare entity",
    "state": "MN",
    "hq_city": "Moorhead",
    "hq_county": "Clay",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Clay County Social Services in Moorhead, Minnesota reported a ransomware attack with data theft confirmed to HHS OCR in December 2023, affecting 22,005 individuals. The incident is documented in the HIPAA Journal December 2023 healthcare data breach report. As a county social services agency, Clay County Social Services handles sensitive health and welfare information for Minnesota residents. The attack involved ransomware encryption with confirmed data theft, indicating a double-extortion attack.",
    "attack_type": "Ransomware / Data Theft",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 22005,
    "residents_affected_in_state": 22005,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Social services operations disrupted; sensitive health and welfare data compromised",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified December 2023; patients/clients notified",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal December 2023 report citing HHS OCR. 22,005 individuals confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00327",
    "year": 2023,
    "lat": 46.8739081,
    "lng": -96.7538674,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Codman Square Health Center",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Boston",
    "hq_county": "Suffolk",
    "discovery_date": "2022-11-28",
    "disclosure_date": "2023-03-01",
    "executive_summary": "Codman Square Health Center, a federally qualified health center in Dorchester, Massachusetts, discovered a ransomware attack on November 28, 2022. Attackers accessed and exfiltrated files containing patient information between November 23-27, 2022. The breach affected 10,161 patients whose names, addresses, and PHI were compromised.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 10161,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network compromised; patient files exfiltrated",
    "remediation_disclosed": "Third-party cybersecurity specialists; HHS OCR breach filed; affected individuals notified",
    "primary_source_url": "https://www.jdsupra.com/legalnews/codman-square-health-center-reports-1915772/",
    "secondary_source_urls": [
      "https://data.metrowestdailynews.com/health-care-data-breaches/codman-square-health-center-ma-10161-20230301-hacking-network/"
    ],
    "confidence_notes": "OCR breach report; JD Supra reporting; Codman website notice",
    "sources_used": [
      "JD Supra",
      "Metro West Daily News"
    ],
    "id": "INC-00328",
    "year": 2023,
    "lat": 42.3601,
    "lng": -71.0589,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Colorado Department of Health Care Policy & Financing",
    "organization_type": "Government Agency (State Medicaid Program)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2023-06-13",
    "disclosure_date": "2023-08-11",
    "executive_summary": "The Colorado Department of Health Care Policy & Financing (HCPF) was affected by the global MOVEit zero-day exploit through its business associate IBM, which used MOVEit for file transfers. The breach, confirmed on June 13, 2023, exposed the protected health information and personally identifiable information of Health First Colorado (Medicaid) and CHP+ members, applicants, and providers. Initial notification disclosed approximately 4 million affected; updated count confirmed 4,662,668 individuals.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day Exploitation (via IBM as BA)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4662668,
    "residents_affected_in_state": "Primarily Colorado Medicaid/CHP+ members",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No HCPF systems directly impacted; IBM's MOVEit server affected",
    "remediation_disclosed": "Multiple notification waves (August 2023, October 2023, February 2024); credit monitoring offered; IBM's MOVEit patched",
    "primary_source_url": "https://www.hipaajournal.com/colorado-department-health-care-policy-financing-breach/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/colorado-department-of-health-care-7038352/",
      "https://www.reddit.com/r/Denver/comments/15sf0k9/hcpf_ibm_data_breach_how_worried_should_i_be/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 4,091,794 (later updated to 4,662,668 per AG notification); well-documented",
    "sources_used": [
      "HIPAA Journal, JD Supra, Reddit Denver"
    ],
    "id": "INC-00329",
    "year": 2023,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CommonSpirit Health \u2013 CHI St. Vincent Health (Arkansas facilities)",
    "organization_type": "Health System / Hospital Network",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Little Rock",
    "hq_county": "Pulaski",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-04-06",
    "executive_summary": "CHI St. Vincent hospitals in Arkansas (Little Rock, North Sherwood, Hot Springs, Morrilton) and associated medical groups were explicitly listed in CommonSpirit Health's October 2022 ransomware attack affecting 164 facilities. Six Arkansas locations named. Part of the 623,774-individual breach.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$160 million CommonSpirit system-wide",
    "operational_impact": "EHR systems offline; care disruptions at AR facilities",
    "remediation_disclosed": "Systems restored; law enforcement notified; patient notifications issued",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and"
    ],
    "confidence_notes": "High confidence; CHI St. Vincent AR explicitly listed in CommonSpirit April 2023 164-facility update; FierceHealthcare confirmed 6 AR locations",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare"
    ],
    "id": "INC-00330",
    "year": 2023,
    "lat": 34.7465,
    "lng": -92.2896,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CommonSpirit Health \u2013 Centura Health System (Colorado facilities)",
    "organization_type": "Health System / Hospital Network",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CO",
    "hq_city": "Englewood",
    "hq_county": "Arapahoe",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-04-06",
    "executive_summary": "Centura Health System (then a CommonSpirit affiliate in Colorado/Kansas) was explicitly named in the April 2023 CommonSpirit 164-facility ransomware update. Patient data from CO Centura facilities was exposed in the September\u2013October 2022 attack. Total CommonSpirit breach: 623,774 individuals; CO-specific count not disclosed.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$160 million CommonSpirit system-wide",
    "operational_impact": "EHR offline; CO Centura operations disrupted",
    "remediation_disclosed": "Systems restored with enhanced monitoring; law enforcement notified",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and"
    ],
    "confidence_notes": "High confidence; Centura Health System explicitly listed in CommonSpirit April 2023 164-facility update",
    "sources_used": [
      "HIPAA Journal",
      "FierceHealthcare"
    ],
    "id": "INC-00331",
    "year": 2023,
    "lat": 39.6482059,
    "lng": -104.9879641,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Community Health Systems Professional Services Corporation (CHSPSC) / Community Health Systems",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Franklin",
    "hq_county": "Williamson",
    "discovery_date": "2023-02-02",
    "disclosure_date": "2023-02-13",
    "executive_summary": "Community Health Systems (CHS), a for-profit hospital operator with ~80 hospitals in 16 states, was one of the first major healthcare victims of the Cl0p group's exploitation of a zero-day vulnerability (CVE-2023-0669) in Fortra's GoAnywhere MFT secure file transfer solution. The attack occurred January 28-30, 2023; CHS was notified February 2. In an SEC 8-K filing February 13, 2023, CHS disclosed that the PHI of up to 1 million individuals had potentially been compromised. CHS confirmed no encryption occurred \u2014 data was exfiltrated only. The Cl0p group claimed responsibility for attacking 130+ organizations via GoAnywhere.",
    "attack_type": "Supply Chain / GoAnywhere Zero-Day Exploit / Data Exfiltration (CVE-2023-0669)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1000000,
    "residents_affected_in_state": 16,
    "financial_impact": "Not separately quantified by CHS beyond SEC 8-K disclosure. No ransom payment confirmed (Cl0p uses extortion without encryption).",
    "operational_impact": "No operational disruption (no encryption). Data exfiltration only from GoAnywhere file transfer platform.",
    "remediation_disclosed": "GoAnywhere patched (emergency patch 7.1.2 issued Feb 7, 2023). HHS OCR notified. Notification letters sent mid-March 2023. Credit monitoring offered. SEC 8-K filed.",
    "primary_source_url": "https://www.sec.gov/Archives/edgar/data/1108320/000110832023000014/0001108320-23-000014-index.htm",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/community-health-systems-goanywhere-data-breach/",
      "https://www.bleepingcomputer.com/news/security/clop-ransomware-claims-it-breached-130-orgs-using-goanywhere-zero-day/",
      "https://fortifiedhealthsecurity.com/blog/threat-bulletin/clop-ransomware-group-targets-healthcare-sector-with-new-zero-day-vulnerability-2/"
    ],
    "confidence_notes": "High confidence. CHS SEC 8-K confirmed breach and up to 1M affected. Cl0p claimed GoAnywhere campaign publicly. CVE-2023-0669 documented by CISA.",
    "sources_used": [
      "CHS SEC 8-K filing",
      "HIPAA Journal",
      "BleepingComputer",
      "Fortified Health Security"
    ],
    "id": "INC-00332",
    "year": 2023,
    "lat": 35.9251,
    "lng": -86.8689,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Community Memorial Healthcare (Kansas)",
    "organization_type": "Community Hospital / Healthcare System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "KS",
    "hq_city": "Marysville",
    "hq_county": "Marshall",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Community Memorial Healthcare, based in Marysville, Kansas, reported a hacking incident to HHS OCR in December 2023 affecting 14,798 individuals. The incident was listed in the HIPAA Journal December 2023 healthcare data breach report. Community Memorial Healthcare serves north-central Kansas communities. Specific details about the attack vector and operational impact were not further disclosed.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14798,
    "residents_affected_in_state": "Kansas residents \u2014 primarily Marshall County area",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not fully disclosed",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal December 2023 report citing HHS OCR. 14,798 individuals confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00333",
    "year": 2023,
    "lat": 39.84173,
    "lng": -96.6480642,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "CompleteCare Health Network",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NJ",
    "hq_city": "Vineland",
    "hq_county": "Cumberland",
    "discovery_date": "2023-10-12",
    "disclosure_date": "2023-12-18",
    "executive_summary": "CompleteCare Health Network, a federally qualified health center in southern New Jersey, detected and stopped a ransomware attack on October 12, 2023. The breach affected 313,973 individuals. Compromised data may have included names, DOBs, SSNs, and medical information. CompleteCare notified affected patients in December 2023.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 313973,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems partially impacted; network disruption",
    "remediation_disclosed": "Third-party cybersecurity experts engaged; law enforcement notified; credit monitoring offered",
    "primary_source_url": "https://completecarenj.org/about-completecare-nj/notice-of-cybersecurity-incident/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/completecare-health-network-data-breach/"
    ],
    "confidence_notes": "CompleteCare official notice; OCR breach report confirmed 313,973 affected",
    "sources_used": [
      "CompleteCare official notice",
      "HIPAA Journal"
    ],
    "id": "INC-00334",
    "year": 2023,
    "lat": 39.4862777,
    "lng": -75.0254256,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Corewell Health (via HealthEC breach)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Grand Rapids",
    "hq_county": "Kent",
    "discovery_date": "2023-12-20",
    "disclosure_date": "2023-12-26",
    "executive_summary": "HealthEC, LLC, a population health management platform serving Corewell Health's southeastern Michigan properties, suffered a cyberattack that affected more than 1 million Michigan residents. This was Corewell's second major breach disclosed within weeks. Compromised data included names, addresses, DOBs, SSNs, medical record numbers, diagnoses, prescription information, health insurance information, and billing/claims information. Michigan AG Dana Nessel noted some Corewell patients would receive two separate breach notifications.",
    "attack_type": "Hacking / Network Server Breach",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1000000,
    "residents_affected_in_state": 1000000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "HealthEC's systems compromised; Corewell's own systems not directly affected; patient notification required",
    "remediation_disclosed": "Yes \u2014 HealthEC offering 12 months credit monitoring via TransUnion; patients notified",
    "primary_source_url": "https://www.michigan.gov/ag/news/press-releases/2023/12/26/second-corewell-health-data-breach-exposes-info-of-one-million-michigan-patients",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Michigan AG press release.",
    "sources_used": [
      "Michigan AG"
    ],
    "id": "INC-00335",
    "year": 2023,
    "lat": 42.9634,
    "lng": -85.6681,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Corewell Health (via Welltok/Virgin Pulse MOVEit breach)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Grand Rapids",
    "hq_county": "Kent",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Welltok, Inc., a software company contracted by Corewell Health to provide communications services, was affected by the MOVEit Transfer vulnerability exploited on May 30, 2023, via Virgin Pulse (Welltok's parent company). The breach exposed names, DOBs, email addresses, phone numbers, medical diagnoses, health insurance information, and SSNs for approximately 1 million Corewell Health patients in southeastern Michigan. Michigan AG Dana Nessel issued a public warning. This was Corewell's first of two major data breaches announced in late 2023.",
    "attack_type": "Third-Party Vendor Breach (MOVEit vulnerability exploitation)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p ransomware (MOVEit campaign)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1000000,
    "residents_affected_in_state": 1000000,
    "financial_impact": "Not publicly disclosed for Corewell specifically",
    "operational_impact": "Corewell systems not directly breached; vendor's systems were compromised; patient notification required",
    "remediation_disclosed": "Yes \u2014 Welltok notified patients; 12 months credit monitoring via TransUnion; vendor relationship reviewed",
    "primary_source_url": "https://www.michigan.gov/ag/news/press-releases/2023/12/01/corewell-health-data-breach-exposes-info-of-one-million-michigan-patients",
    "secondary_source_urls": [
      "https://www.forthepeople.com/blog/corewell-health-data-breach-affects-1m-patients/"
    ],
    "confidence_notes": "High confidence. Michigan AG press release, HHS OCR breach portal, Morgan & Morgan reporting.",
    "sources_used": [
      "Michigan AG",
      "Morgan & Morgan"
    ],
    "id": "INC-00336",
    "year": 2023,
    "lat": 42.9634,
    "lng": -85.6681,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Credit Control Corporation (CCC) \u2014 Virginia hospitals",
    "organization_type": "Business Associate / Medical Billing / Debt Collection",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "VA",
    "hq_city": "Richmond",
    "hq_county": "Richmond City",
    "discovery_date": "2023-03-07",
    "disclosure_date": "2023-05-04",
    "executive_summary": "Credit Control Corporation, a debt collection firm serving Virginia healthcare providers, disclosed a cyberattack in which files were copied from its network between March 2-7, 2023. The breach affected patients of multiple Virginia hospitals and medical groups including Sentara Health, Riverside Health System, Children's Hospital of Richmond (CHoR), King's Daughters Medical Center, Chesapeake Regional Medical Center, Bayview Physicians, and Pariser Dermatology. Names, addresses, SSNs, and account information were exposed.",
    "attack_type": "Network Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient billing and collection account data exposed for patients of multiple major Virginia healthcare systems",
    "remediation_disclosed": "CCC notified business partners May 4, 2023; patient notification letters sent",
    "primary_source_url": "https://www.youtube.com/watch?v=i8EyXSXKoY4",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence \u2014 Local TV news report (WTKR) identified affected entities; no primary breach notice URL found. Credit Control Corp breach confirmed by multiple media outlets.",
    "sources_used": [
      "WTKR Local News (YouTube)",
      "Sentara Health communications"
    ],
    "id": "INC-00337",
    "year": 2023,
    "lat": 37.5407,
    "lng": -77.436,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "DLP Central Carolina Medical Center",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Sanford",
    "hq_county": "Lee",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Sanford, NC-based DLP Central Carolina Medical Center was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Patient data was potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00338",
    "year": 2023,
    "lat": 35.4798757,
    "lng": -79.1802994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Delta Dental of California and affiliates",
    "organization_type": "Health Plan / Dental Insurer",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "San Francisco, CA",
    "hq_county": "San Francisco County",
    "discovery_date": "2023-05-27",
    "disclosure_date": "2023-12-14",
    "executive_summary": "What Happened? Progress Software announced a previously unknown vulnerability within their widely used MOVEit file-transfer software program. This vulnerability led to a global data security incident that is reported to have impacted many organizations, including corporations, government agencies, insurance providers, pension funds, financial institutions, state education systems and more. On June 1, 2023, the Company learned unauthorized actors exploited a vulnerability affecting the MOVEit file transfer software application. Immediately after being alerted of the incident, we launched a thor",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 6928932,
    "residents_affected_in_state": "CA: majority (California-based insurer); exact CA count not separately disclosed",
    "financial_impact": "Not publicly disclosed; class action lawsuits filed",
    "operational_impact": "MOVEit file transfer software exploited; data accessed without encryption",
    "remediation_disclosed": "['Identity protection services offered', 'Law enforcement notified', 'Forensic investigation conducted', 'Passwords reset']",
    "primary_source_url": "https://oag.ca.gov/system/files/ELN-20464%20Delta%20Dental%20DDC%20Ad%202yr%20r4prf%20L01%20r4prf.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/delta-dental-of-california-data-breach/",
      "https://www.bleepingcomputer.com/news/security/delta-dental-of-california-exposes-data-of-69m-patients/",
      "https://www.classaction.org/news/may-2023-moveit-data-breach-triggers-class-action-against-delta-dental",
      "https://slingscore.ai/delta-dental-of-california-data-breach/",
      "https://info.safelinkconsulting.com/blog/delta-dental-of-california-data-breach"
    ],
    "confidence_notes": "Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification",
      "ClassAction.org",
      "SafeLink Consulting",
      "Sling Score / Emsisoft data"
    ],
    "id": "INC-00339",
    "year": 2023,
    "lat": 37.7749,
    "lng": -122.4194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Denver Public Schools Medical Plans",
    "organization_type": "Health Plan (School District)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2023-01-13",
    "disclosure_date": "2023-03-01",
    "executive_summary": "Denver Public Schools (DPS) Medical Plans experienced a data breach between December 13, 2022, and January 13, 2023, in which a hacked network server exposed protected health information of 35,068 health plan members (employees and their dependents). This was a hacking and data theft incident that compromised member health plan information. DPS notified members and established a response hotline.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Hacking and Data Theft",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 35068,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan data exposed; school operations not disrupted",
    "remediation_disclosed": "Notification letters sent; DPS response hotline established (855-951-428)",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://denverteachers.org/addressing-the-dps-data-breach/"
    ],
    "confidence_notes": "HHS OCR confirmed 35,068 affected; listed in HIPAA Journal March 2023 Monthly Report; Denver teachers union confirmed incident details",
    "sources_used": [
      "HIPAA Journal March 2023 Monthly Report, Denver Classroom Teachers Association"
    ],
    "id": "INC-00340",
    "year": 2023,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Dignity Health (via R1 RCM breach)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Francisco",
    "hq_county": "San Francisco",
    "discovery_date": "2023-11-23 (R1 RCM breach detected)",
    "disclosure_date": "2023",
    "executive_summary": "Data breach at R1 RCM (revenue cycle management company) impacted Dignity Health's St. Rose Dominican Hospital and other Dignity Health facilities. Hacker exfiltrated patient data.",
    "attack_type": "Hacking/IT Incident \u2014 Supply chain attack via business associate (R1 RCM) network intrusion",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately confirmed in available sources",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$675,000 class action settlement (R1 RCM + Dignity Health, final 2025)",
    "operational_impact": "No reported major clinical disruption at CA facilities",
    "remediation_disclosed": "Not publicly disclosed in detail",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/r1-rcm-dignity-health-data-breach-settlement/"
    ],
    "confidence_notes": "Covered entity headquartered in San Francisco with extensive CA operations. Settlement covers patients of Dignity Health's St. Rose Dominican Hospital (Henderson, NV). CA operations confirmed as Dignity Health is CA-based.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00341",
    "year": 2023,
    "lat": 37.7749,
    "lng": -122.4194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Duke University Health System (via Nuance/MOVEit)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Durham",
    "hq_county": "Durham",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Durham, NC-based Duke University Health System was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Radiology documentation data was potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure and Charlotte Observer reporting.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00342",
    "year": 2023,
    "lat": 35.994,
    "lng": -78.8986,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Duly Health and Care (formerly DuPage Medical Group) \u2014 2020-2023 Meta Pixel Tracking",
    "organization_type": "Multispecialty Physician Group Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "IL",
    "hq_city": "Downers Grove",
    "hq_county": "DuPage",
    "discovery_date": "2020-07-24",
    "disclosure_date": "2023-03-01",
    "executive_summary": "Duly Health and Care (operating as Midwest Physician Administrative Services, formerly DuPage Medical Group), the largest independent physician group in Illinois, was sued in a class action (Case No. 1:23-cv-03132) alleging that the company installed a Meta tracking pixel on its website without patient knowledge or consent between July 24, 2020, and April 10, 2023. The pixel transmitted confidential personal and medical information to Meta (Facebook) when patients logged into the authenticated DulyHealthandCare.com portal. Approximately 272,373 patients had their portal activity shared with Meta. The $1.88 million settlement received final approval on April 15, 2026.",
    "attack_type": "Unauthorized Tracking Pixel Disclosure (Meta Pixel)",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable \u2014 internal privacy configuration issue",
    "attribution_status": "unknown",
    "individuals_affected_reported": 272373,
    "residents_affected_in_state": "Illinois patients \u2014 primarily DuPage Cook Will Kane counties",
    "financial_impact": "$1.88 million class action settlement; final approval April 15, 2026",
    "operational_impact": "No clinical operations disruption; patient portal privacy violation",
    "remediation_disclosed": "Yes \u2014 Meta Pixel removed by April 2023; $1.88M settlement implemented",
    "primary_source_url": "https://www.classaction.org/news/1.88m-duly-health-and-care-settlement-ends-class-action-lawsuit-over-alleged-online-privacy-violations",
    "secondary_source_urls": [
      "https://www.almeidalawgroup.com/updates/duly-health-data-privacy-litigation/"
    ],
    "confidence_notes": "High confidence. ClassAction.org, Almeida Law Group, US District Court Northern District of Illinois. 272,373 class members confirmed.",
    "sources_used": [
      "ClassAction.org",
      "Almeida Law Group",
      "US District Court"
    ],
    "id": "INC-00343",
    "year": 2023,
    "lat": 41.7936822,
    "lng": -88.0102281,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ECU Health (University Health Systems of Eastern Carolina)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Greenville",
    "hq_county": "Pitt",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "ECU Health (Greenville, NC) was among the 13 North Carolina healthcare provider clients affected by the Nuance Communications MOVEit Transfer breach. Data including patient names, DOBs, imaging reports, diagnoses, treatment information, and medication dosages were potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure. Individual ECU Health count not separately reported.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00344",
    "year": 2023,
    "lat": 35.613224,
    "lng": -77.3724593,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ESO Solutions (NE affiliate hospitals)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Austin",
    "hq_county": "Travis",
    "discovery_date": "2023-09-17",
    "disclosure_date": "2023-12-26",
    "executive_summary": "ESO Solutions, an EMS and hospital software vendor, suffered a ransomware attack in September 2023, with files encrypted and data of 2.7 million individuals stolen from at least 12 healthcare systems and hospitals, several of which are in the NE region. ESO provides software to hundreds of hospitals and EMS agencies. NE hospital clients received notification of the breach.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "2.7M records from 12+ health systems compromised",
    "remediation_disclosed": "Law enforcement notified; affected health system clients notified",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach report; HIPAA Journal December 2023 report; NE hospitals among affected clients",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00345",
    "year": 2023,
    "lat": 30.2672,
    "lng": -97.7431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "ESO Solutions \u2014 SE Aggregate",
    "organization_type": "Business Associate / Healthcare Software",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TN",
    "hq_city": "Austin",
    "hq_county": "Travis County (TX-based)",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-19",
    "executive_summary": "ESO Solutions, a healthcare software provider serving hospitals and EMS agencies, suffered a ransomware attack September 28, 2023 affecting 2.7 million individuals. SE-based affected entities include: Tallahassee Memorial Healthcare (FL), Manatee Memorial Hospital (FL), Mississippi Baptist Medical Center (MS), Merit Health Biloxi (MS), Merit Health River Oaks (MS), Forrest General Hospital (MS), Memorial Hospital at Gulfport (MS), and CaroMont Health (NC). This aggregate entry captures the overall ESO breach with SE focus.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (no group claimed responsibility)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; FBI investigating",
    "operational_impact": "Patient EMS and hospital records including names, SSNs, DOBs, injury types, treatment dates exposed across multiple SE healthcare systems",
    "remediation_disclosed": "FBI notified; state AGs notified; breach letters sent December 12, 2023; 24-month Kroll identity monitoring offered",
    "primary_source_url": "https://therecord.media/nearly-three-mil-affected-ransomware-medtech",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/eso-solutions-data-breach-update-eso-6676886/",
      "https://www.classaction.org/data-breach-lawsuits/eso-solutions-inc-december-2023"
    ],
    "confidence_notes": "High confidence \u2014 The Record, JD Supra, ClassAction.org reporting. ESO aggregate entry consolidates the SE hospital impacts covered in individual entries #115-119.",
    "sources_used": [
      "The Record",
      "JD Supra",
      "ClassAction.org",
      "Heimdal Security"
    ],
    "id": "INC-00346",
    "year": 2023,
    "lat": 35.2017484,
    "lng": -88.2392038,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ESO Solutions, Inc.",
    "organization_type": "Business Associate (Healthcare Software \u2013 EMS/Hospital Data)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Austin",
    "hq_county": "Travis",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-19",
    "executive_summary": "ESO Solutions, an Austin-based software company serving hospitals, EMS agencies, and fire departments, was hit by a ransomware attack on September 28, 2023. The attack encrypted systems and a forensic investigation confirmed on October 23 that patient information was accessed. 2,700,000 individuals were ultimately affected. Compromised data included names, dates of birth, injury type, treatment dates, medical record numbers, and in some cases Social Security numbers.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported (national EMS/hospital client base)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "ESO systems taken offline; viables backups used for restoration",
    "remediation_disclosed": "FBI notified; systems restored via backups; 24-month identity monitoring offered via Kroll; rolling notifications to hospital clients starting Dec 12",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [
      "https://www.forthepeople.com/blog/27m-affected-eso-solutions-inc-data-breach/",
      "https://thehipaaetool.com/eso-solutions-hit-by-ransomware-attack/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 2,700,000; multiple sources consistent",
    "sources_used": [
      "HIPAA Journal, Morgan & Morgan, The HIPAA E-Tool"
    ],
    "id": "INC-00347",
    "year": 2023,
    "lat": 30.2672,
    "lng": -97.7431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "East Georgia Healthcare Center (via HealthEC)",
    "organization_type": "Healthcare Provider / Federally Qualified Health Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Swainsboro",
    "hq_county": "Emanuel",
    "discovery_date": "2023-10-26",
    "disclosure_date": "2023-12-22",
    "executive_summary": "East Georgia Healthcare Center, a Federally Qualified Health Center in Swainsboro, Georgia, was identified as one of the HealthEC clients affected by the July 2023 data breach. Patient data managed through HealthEC's population health management platform was among the 4.6 million compromised records.",
    "attack_type": "Business Associate Breach (HealthEC) / Network Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4656293,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of $5.48M HealthEC class action settlement",
    "operational_impact": "Patient PHI including diagnoses, prescriptions, and SSNs exposed",
    "remediation_disclosed": "HealthEC notified clients October 2023; breach letters December 22, 2023",
    "primary_source_url": "https://www.securityweek.com/4-5-million-individuals-affected-by-data-breach-at-healthec/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthec-data-breach/"
    ],
    "confidence_notes": "High confidence \u2014 SecurityWeek named East Georgia Healthcare Center as HealthEC client.",
    "sources_used": [
      "SecurityWeek",
      "HIPAA Journal"
    ],
    "id": "INC-00348",
    "year": 2023,
    "lat": 32.5973857,
    "lng": -82.3337376,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "East Houston Med and Ped Clinic",
    "organization_type": "Healthcare Provider (Medical Clinic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-07-01",
    "executive_summary": "East Houston Med and Ped Clinic reported a data breach involving unauthorized access or disclosure. 10,000 individuals were affected. The breach was reported to HHS in July 2023 as an unauthorized access/disclosure incident involving storage units sold containing boxes of patient records.",
    "attack_type": "Unauthorized Access/Disclosure \u2013 Physical Records Improperly Disposed",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 10000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; OCR listed in July 2023 breach report; limited additional information",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00349",
    "year": 2023,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Eisenhower Medical Center (now Eisenhower Health) \u2014 Meta Pixel Disclosure",
    "organization_type": "Nonprofit teaching hospital and health system",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Rancho Mirage",
    "hq_county": "Riverside County",
    "discovery_date": "2023-05-03",
    "disclosure_date": "2023-01-01",
    "executive_summary": "Eisenhower Medical Center used Meta Pixel and other third-party tracking technologies on its website, including the MyChart patient portal, between January 1, 2019, and May 3, 2023. These tools allegedly transmitted private patient health information \u2014 including medical conditions, treatments, appointments, and providers \u2014 to Facebook (Meta), Google, and other third parties without patient consent. A class-action lawsuit was filed; Eisenhower agreed to an $875,000 settlement, which received final court approval October 20, 2025. Eisenhower agreed to cease use of Meta Pixel for at least two years.",
    "attack_type": "Tracking pixel / third-party data disclosure (not a network intrusion)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "NOT_APPLICABLE",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2019,
    "residents_affected_in_state": "Primarily CA (Coachella Valley patient base)",
    "financial_impact": "{'litigation_settlement': 875000, 'notes': \"$875K settlement (B.K. v. Eisenhower Medical Center; final approval Oct 20, 2025). Attorneys' fees \u2264$288,750.\"}",
    "operational_impact": "No patient care disruption. Data shared via tracking tools.",
    "remediation_disclosed": "Meta Pixel removed; Web Governance Committee established; commitment to not use Meta Pixel for at least 2 years.",
    "primary_source_url": "https://www.hipaajournal.com/california-teaching-hospital-settles-meta-pixel-data-breach-lawsuit/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/875k-eisenhower-medical-center-settlement-ends-meta-pixel-data-sharing-class-action-lawsuit",
      "https://www.claimdepot.com/settlements/emc-web-settlement",
      "https://www.almeidalawgroup.com/updates/final-approval-granted-in-eisenhower-medical-center-data-privacy-settlement/"
    ],
    "confidence_notes": "Tracking pixel litigation is distinct from traditional data breaches (no hacker, no exfiltration). Settlement claim deadline Oct 2, 2025. Eisenhower Medical Center rebranded as Eisenhower Health. Case: 5:23-cv-02092-JGB-DTB (C.D. Cal.).",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00350",
    "year": 2023,
    "lat": 33.7397,
    "lng": -116.4128,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Electa Health (GoodRx Holdings, Inc.)",
    "organization_type": "Telehealth / Health Tech Platform",
    "organization_type_bucket": "Other healthcare entity",
    "state": "CA",
    "hq_city": "Santa Monica",
    "hq_county": "Los Angeles",
    "discovery_date": "2023-02-01",
    "disclosure_date": "2023-02-01",
    "executive_summary": "GoodRx Holdings, a Santa Monica-based digital health and prescription discount platform, reached a landmark $1.5 million FTC settlement in February 2023 \u2014 the first-ever FTC enforcement action under the Health Breach Notification Rule. GoodRx had shared sensitive health information about users' medication purchases, health conditions, and personal data with advertisers including Facebook and Google without proper consent and without required disclosures. The FTC alleged that GoodRx disclosed users' prescription drug purchase information and related health conditions to third parties for advertising purposes from approximately 2017 to early 2020. The FTC also required GoodRx to stop sharing health data for advertising purposes. The action was a landmark precedent for privacy enforcement in digital health.",
    "attack_type": "Unauthorized Disclosure to Third-Party Advertisers / Health Breach Notification Rule Violation",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "N/A (internal business practice)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately disclosed (millions of GoodRx users)",
    "residents_affected_in_state": "Nationwide (digital health platform across all states)",
    "financial_impact": "$1.5M FTC settlement (February 2023) \u2014 first-ever FTC Health Breach Notification Rule enforcement action. GoodRx also barred from sharing health data for advertising going forward.",
    "operational_impact": "No clinical disruption. Privacy violation affecting prescription drug purchase data and health condition proxies for millions of GoodRx users.",
    "remediation_disclosed": "Data sharing with advertisers stopped. FTC consent order implemented. Mandatory disclosure of health data sharing practices.",
    "primary_source_url": "https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-takes-action-against-goodrx-sharing-consumers-sensitive-health-information-advertisers",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/goodrx-ftc-health-breach-notification-rule-settlement/",
      "https://www.theverge.com/2023/2/1/23580679/goodrx-ftc-settlement-health-breach-notification-rule"
    ],
    "confidence_notes": "High confidence. FTC press release is primary source. Landmark regulatory precedent well-documented. HIPAA Journal and The Verge corroborate.",
    "sources_used": [
      "FTC press release",
      "HIPAA Journal",
      "The Verge"
    ],
    "id": "INC-00351",
    "year": 2023,
    "lat": 34.0194704,
    "lng": -118.491227,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Electrostim Medical Services, Inc. (EMSI)",
    "organization_type": "Healthcare Provider (Medical Device/DME)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Tampa",
    "hq_county": "Hillsborough",
    "discovery_date": "2023-05-13",
    "disclosure_date": "2023-12-28",
    "executive_summary": "Tampa-based EMSI (electrical stimulation medical devices) detected suspicious network activity on May 13, 2023. Investigation confirmed unauthorized access between April 27 and May 13, 2023. Attackers accessed patient data including names, addresses, emails, phone numbers, diagnoses, insurance, and order histories of 542,990 patients. Data theft was not confirmed but could not be ruled out.",
    "attack_type": "Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 542990,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data potentially accessed for ~2 weeks",
    "remediation_disclosed": "Systems secured; third-party cybersecurity specialists engaged; notifications mailed December 28, 2023",
    "primary_source_url": "https://www.hipaajournal.com/electrostim-medical-services-data-breach/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/electrostim-medical-services-notifies-2215745/"
    ],
    "confidence_notes": "HHS OCR lists 542,990 affected. HIPAA Journal and JD Supra corroborate.",
    "sources_used": [
      "HIPAA Journal",
      "JD Supra"
    ],
    "id": "INC-00352",
    "year": 2023,
    "lat": 27.9506,
    "lng": -82.4572,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Elgon Information Systems",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MA",
    "hq_city": "Boston",
    "hq_county": "Suffolk",
    "discovery_date": "2023-03-31",
    "disclosure_date": "2023-06-01",
    "executive_summary": "Elgon Information Systems, a Massachusetts company providing EMR and billing support to healthcare entities, discovered a ransomware attack via ransom note on March 31, 2023 (six days after the initial breach on March 25). Over 31,000 individuals had SSNs, driver's license numbers, and healthcare information compromised. HHS OCR reached an $80,000 settlement with Elgon for HIPAA violations including failure to conduct a proper risk analysis.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 31000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$80,000 OCR settlement",
    "operational_impact": "31K+ patient records compromised; ransom note discovered 6 days after breach",
    "remediation_disclosed": "$80K OCR settlement; corrective action plan; risk analysis required; workforce training",
    "primary_source_url": "https://therecord.media/massachusetts-health-firm-reaches-settlement",
    "secondary_source_urls": [],
    "confidence_notes": "OCR settlement officially announced; The Record reporting",
    "sources_used": [
      "The Record"
    ],
    "id": "INC-00353",
    "year": 2023,
    "lat": 42.3601,
    "lng": -71.0589,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Elgon Information Systems (2023 OCR settlement)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MA",
    "hq_city": "Boston",
    "hq_county": "Suffolk",
    "discovery_date": "2023-03-25",
    "disclosure_date": "2023-06-01",
    "executive_summary": "This entry consolidates the Elgon 2023 ransomware attack (see entry #33). Elgon Information Systems, a Massachusetts company providing EMR and billing support, was struck by ransomware on March 25, 2023, discovered via ransom note six days later on March 31. Over 31,000 individuals had sensitive healthcare and SSN data compromised. HHS OCR reached an $80,000 settlement for HIPAA Security Rule violations. This entry provides the HHS formal announcement URL.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 31000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$80,000 OCR settlement (January 2025)",
    "operational_impact": "31K+ patient records compromised; 6-day delay in breach discovery",
    "remediation_disclosed": "$80K OCR settlement; corrective action plan; risk analysis required; workforce training mandated",
    "primary_source_url": "https://www.hhs.gov/about/news/2025/01/07/hhs-office-civil-rights-reaches-settlement-elgon-information-systems-ransomware-attack.html",
    "secondary_source_urls": [
      "https://therecord.media/massachusetts-health-firm-reaches-settlement"
    ],
    "confidence_notes": "HHS OCR official settlement announcement January 7, 2025; The Record reporting",
    "sources_used": [
      "HHS OCR",
      "The Record"
    ],
    "id": "INC-00354",
    "year": 2023,
    "lat": 42.3601,
    "lng": -71.0589,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Enzo Clinical Labs / Enzo Biochem",
    "organization_type": "Healthcare Provider (Laboratory)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "NY",
    "hq_city": "Farmingdale",
    "hq_county": "Suffolk",
    "discovery_date": "2023-04-06",
    "disclosure_date": "2023-05-31",
    "executive_summary": "Enzo Clinical Labs, a New York-based clinical laboratory subsidiary of Enzo Biochem, suffered a ransomware and data theft attack on April 4-6, 2023. Attackers used two compromised employee login credentials to access the network, exfiltrate data on approximately 2.47 million patients, and encrypt files. The breach exposed names, dates of birth, Social Security numbers, and diagnostic test information. A multi-state $4.5 million settlement was reached with the NY, NJ, and CT Attorneys General in August 2024.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2470000,
    "residents_affected_in_state": 1457843,
    "financial_impact": "$4.5 million multi-state AG settlement (2024); multiple class action lawsuits filed",
    "operational_impact": "Clinical test data for ~2.4 million patients stolen and encrypted; lab operations disrupted",
    "remediation_disclosed": "NY, NJ, CT AG settlement with corrective action plan; cybersecurity improvements mandated",
    "primary_source_url": "https://ag.ny.gov/press-release/2024/attorney-general-james-secures-45-million-biotech-company-failing-protect-new",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/enzo-biochem-hipaa-settlement-ny-nj-ct/",
      "https://www.classaction.org/news/enzo-clinical-labs-facing-class-action-over-2023-data-breach-impacting-2.5m-patients"
    ],
    "confidence_notes": "NY AG confirms 1,457,843 NY residents; multi-state AG settlement highly credible; SEC filing corroborates",
    "sources_used": [
      "NY AG",
      "HIPAA Journal",
      "ClassAction.org"
    ],
    "id": "INC-00355",
    "year": 2023,
    "lat": 40.7328811,
    "lng": -73.4458564,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Eye Physicians of Central Florida, P.L.C.",
    "organization_type": "Healthcare Provider (Ophthalmology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Orlando",
    "hq_county": "Orange",
    "discovery_date": "2023-11-05",
    "disclosure_date": "2023-12-28",
    "executive_summary": "Eye Physicians of Central Florida discovered unauthorized access to its computer network on November 5, 2023. Investigation confirmed a third party accessed and exfiltrated files containing patient data. 31,189 individuals were affected per HHS OCR. Exposed data included names, DOBs, addresses, diagnoses, treatment data, insurance, financial information, and prescription details. A class action settlement is pending.",
    "attack_type": "Unauthorized Network Access / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 31189,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Settlement amount not yet publicly disclosed",
    "operational_impact": "Patient PHI and financial data exfiltrated",
    "remediation_disclosed": "Network secured; investigation launched; notifications issued",
    "primary_source_url": "https://www.hipaajournal.com/eye-physicians-of-central-florida-data-breach-settlement/",
    "secondary_source_urls": [
      "https://eyephysicianscentralflsettlement.com",
      "https://www.compliancejunction.com/eye-physicians-of-central-florida-settles-class-action-lawsuit/"
    ],
    "confidence_notes": "HHS OCR lists 31,189 affected. Settlement confirmed by multiple sources.",
    "sources_used": [
      "HIPAA Journal",
      "Settlement Website",
      "ComplianceJunction"
    ],
    "id": "INC-00356",
    "year": 2023,
    "lat": 28.5383,
    "lng": -81.3792,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Fairfax Oral and Maxillofacial Surgery",
    "organization_type": "Healthcare Provider (Oral Surgery Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Fairfax",
    "hq_county": "Fairfax",
    "discovery_date": "2023-08-17",
    "disclosure_date": "2023-08-18",
    "executive_summary": "Fairfax Oral and Maxillofacial Surgery detected a security breach on August 17, 2023. A forensic investigation found access via a compromised desktop computer. The HHS OCR breach report listed 208,194 individuals affected. This was a hacking/IT incident. Specific attack type (ransomware or unauthorized access) and data types not fully detailed in available sources.",
    "attack_type": "Network Hacking via Desktop Computer",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 208194,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network access via compromised endpoint",
    "remediation_disclosed": "Third-party forensics engaged; notifications mailed August 18, 2023",
    "primary_source_url": "https://www.hipaajournal.com/236000-fairfax-oral-and-maxillofacial-surgery-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.turkestrauss.com/2023/08/25/fairfax-oral-maxillofacial-surgery-data-breach-investigation/"
    ],
    "confidence_notes": "HHS OCR lists 208,194 (July 2023 monthly report). HIPAA Journal provides additional details.",
    "sources_used": [
      "HIPAA Journal",
      "Turke & Strauss LLP"
    ],
    "id": "INC-00357",
    "year": 2023,
    "lat": 38.8462236,
    "lng": -77.3063733,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Family Vision of Anderson, P.A.",
    "organization_type": "Healthcare Provider (Optometry Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Anderson",
    "hq_county": "Anderson",
    "discovery_date": "2023-05-21",
    "disclosure_date": "2023-07-26",
    "executive_summary": "Family Vision of Anderson, SC was hit by ransomware on May 21, 2023. An employee discovered the attack and investigation confirmed ransomware was installed on its server. The breach exposed 62,631 individuals' data including names, DOBs, SSNs, driver's licenses, addresses, phone numbers, emails, genders, health insurance, and PHI. The SC Consumer Affairs office was notified on July 27, 2023, listing 53,861 SC residents affected.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 62631,
    "residents_affected_in_state": 53861,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Server ransomware-encrypted; patient data exposed",
    "remediation_disclosed": "Maine AG and SC Consumer Affairs notified; credit monitoring offered; notifications mailed July 26, 2023",
    "primary_source_url": "https://www.jdsupra.com/legalnews/family-vision-of-anderson-data-breach-1534646/",
    "secondary_source_urls": [
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
      "https://cybernews.com/news/ransomware-attack-family-vision-optometry-clinic-usa/"
    ],
    "confidence_notes": "HHS OCR lists 62,631. SC Consumer Affairs confirms 53,861 SC residents. Confirmed ransomware attack.",
    "sources_used": [
      "JD Supra",
      "SC Consumer Affairs",
      "CyberNews"
    ],
    "id": "INC-00358",
    "year": 2023,
    "lat": 34.5258335,
    "lng": -82.652962,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "FirstHealth of the Carolinas",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Pinehurst",
    "hq_county": "Moore",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Pinehurst, NC-based FirstHealth of the Carolinas was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Patient data including names, DOBs, imaging reports, diagnoses, treatment information, and medication dosages were potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure. Individual count not separately reported.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00359",
    "year": 2023,
    "lat": 35.1951981,
    "lng": -79.4692796,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Florida Health Sciences Center (Tampa General Hospital)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Tampa",
    "hq_county": "Hillsborough",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-07-20",
    "executive_summary": "Tampa General Hospital detected an intrusion on May 31, 2023. Attackers had access to the network for approximately three weeks (May 12\u201330, 2023) and exfiltrated files containing patient PII. The hospital's security systems prevented file encryption, though data theft occurred. The HHS breach report was later amended to 2,430,920 individuals. The Snatch and Nokoyawa ransomware groups claimed credit. A $6.8M class action settlement was reached in 2025.",
    "attack_type": "Ransomware / Data Exfiltration (encryption prevented)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Snatch; Nokoyawa (both claimed credit)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 2430920,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$6.8 million class action settlement (2025)",
    "operational_impact": "Affected systems taken offline; EMR not accessed",
    "remediation_disclosed": "Affected systems taken offline; third-party forensics engaged; notifications mailed July 2023",
    "primary_source_url": "https://www.hipaajournal.com/tampa-general-hospital-says-hackers-exfiltrated-the-data-of-1-2-million-patients/",
    "secondary_source_urls": [
      "https://www.wusf.org/health-news-florida/2023-07-20/tampa-general-hospital-hack-affects-data-of-1-2m-patients-involves-social-security-numbers",
      "https://thisweekhealth.com/news_story/tampa-general-hospital-settles-6-8m-class-action-over-major-data-breach/"
    ],
    "confidence_notes": "Well-documented; HHS OCR breach portal lists 2,430,920. Initial report was 1.3M, later amended.",
    "sources_used": [
      "HIPAA Journal",
      "WUSF",
      "This Week Health"
    ],
    "id": "INC-00360",
    "year": 2023,
    "lat": 27.9506,
    "lng": -82.4572,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Florida Health Sciences Center, Inc. d/b/a Tampa General Hospital",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Tampa",
    "hq_county": "Hillsborough",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-07-19",
    "executive_summary": "Tampa General Hospital, a Level 1 trauma center and one of Florida's largest hospitals, discovered unusual network activity May 31, 2023. The investigation confirmed a criminal group had infiltrated the network between May 12-30, 2023, and exfiltrated files containing patient information. Crucially, Tampa General's monitoring systems detected and prevented encryption, averting a full ransomware disruption. Approximately 1.3 million patient records were compromised. Stolen data included names, Social Security numbers, addresses, phone numbers, dates of birth, health insurance data, medical record numbers, account numbers, dates of service, and limited treatment information. TGH did not pay a ransom. A $6.8 million settlement was reached in January 2025 to resolve class action lawsuits.",
    "attack_type": "Data Exfiltration / Prevented Ransomware Encryption",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (reported as a 'criminal group' by TGH)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1313636,
    "residents_affected_in_state": "Florida; specific count not separately reported",
    "financial_impact": "$6.8 million class action settlement (January 2025). No ransom paid (confirmed by TGH).",
    "operational_impact": "Encryption attempt foiled. No EHR system downtime. Normal patient care continued during breach period.",
    "remediation_disclosed": "FBI and law enforcement notified. Third-party forensic firm engaged. Credit monitoring offered to affected individuals whose SSNs were compromised. Defensive tools implemented and monitoring enhanced.",
    "primary_source_url": "https://www.tgh.org/notice-of-data-security-incident",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/tampa-general-hospital-sued-over-1-2-million-record-data-breach/",
      "https://www.wusf.org/health-news-florida/2023-07-20/tampa-general-hospital-hack-affects-data-of-1-2m-patients-involves-social-security-numbers",
      "https://www.infosecurity-magazine.com/news/tampa-hospital-data-breach/"
    ],
    "confidence_notes": "High confidence. OCR portal: 1,313,636. TGH published official notice. $6.8M settlement confirmed.",
    "sources_used": [
      "Tampa General Hospital official notice",
      "HIPAA Journal",
      "WUSF",
      "Infosecurity Magazine",
      "Fox 13"
    ],
    "id": "INC-00361",
    "year": 2023,
    "lat": 27.9506,
    "lng": -82.4572,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Florida Medical Clinic (Florida Medical Clinic Orlando Health)",
    "organization_type": "Healthcare Provider (Multi-Specialty Clinic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Zephyrhills",
    "hq_county": "Pasco",
    "discovery_date": "2023-01-09",
    "disclosure_date": "2023-03-10",
    "executive_summary": "Florida Medical Clinic detected suspicious activity on January 9, 2023 and confirmed a ransomware attack. Attackers accessed and encrypted certain files but the EHR system was not affected. 94,132 files were exposed; most (95%+) contained only names. A small subset included medical info, phone numbers, emails, DOBs, addresses, and 115 SSNs. Organization obtained evidence that stolen files were permanently deleted.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 94132,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Files encrypted; EHR not affected; evidence of file deletion obtained",
    "remediation_disclosed": "Remote access protocols replaced; system components replaced; notifications mailed March 10, 2023",
    "primary_source_url": "https://www.floridamedicalclinic.com/press-release/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/florida-medical-clinic-notifies-nearly-2402737/"
    ],
    "confidence_notes": "Organization's own press release is primary source. HHS OCR filing corroborates 94,132 affected.",
    "sources_used": [
      "Florida Medical Clinic (official website)",
      "JD Supra"
    ],
    "id": "INC-00362",
    "year": 2023,
    "lat": 28.2336196,
    "lng": -82.1811947,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Forrest General Hospital (via ESO Solutions)",
    "organization_type": "Healthcare Provider / Regional Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MS",
    "hq_city": "Hattiesburg",
    "hq_county": "Forrest",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Forrest General Hospital (Forrest Health) in Hattiesburg, Mississippi was identified as one of the entities affected by the ESO Solutions ransomware attack of September 2023. Patient emergency department and EMS data was exposed through ESO's compromised software systems.",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient EMS records exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 2023; 24-month Kroll identity monitoring",
    "primary_source_url": "https://therecord.media/nearly-three-mil-affected-ransomware-medtech",
    "secondary_source_urls": [
      "https://heimdalsecurity.com/blog/major-data-breach-at-eso-solutions-affects-2-7-million-patients/"
    ],
    "confidence_notes": "High confidence \u2014 The Record named Forrest General Hospital (Forrest Health) as ESO client.",
    "sources_used": [
      "The Record",
      "Heimdal Security"
    ],
    "id": "INC-00363",
    "year": 2023,
    "lat": 31.3271189,
    "lng": -89.2903392,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Fred Hutchinson Cancer Center (Fred Hutch / UW Medicine)",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2023-11-19",
    "disclosure_date": "2023-12-14",
    "executive_summary": "Between November 10 and November 25, 2023, the Hunters International ransomware group breached the Fred Hutchinson Cancer Center's clinical network, exfiltrating the protected health information of approximately 2.1 million individuals including current and former patients of Fred Hutch and its partner UW Medicine. Hackers stole names, contact information, medical information, and Social Security numbers. When Fred Hutch declined to pay the ransom, Hunters International directly emailed affected patients demanding $50 to delete their stolen data \u2014 a tactic mirroring the concurrent Integris Health extortion. A class action lawsuit was filed encompassing Fred Hutch and the University of Washington. The total settlement reached approximately $52.5 million: $11.5 million in cash, $25.5 million in fraud monitoring, and $13.5 million in cybersecurity improvements.",
    "attack_type": "Ransomware / Data Theft / Patient Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "Hunters International",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2100000,
    "residents_affected_in_state": "WA: majority (Seattle-based system); exact count not separately disclosed",
    "financial_impact": "~$52.5M total settlement: $11.5M in cash (class members), $25.5M in fraud/medical monitoring, $13.5M in security improvements. University of Washington co-defendant. Ransom payment status: Not publicly disclosed.",
    "operational_impact": "Clinical network compromised. Patient extortion emails sent directly. No confirmed EHR shutdown reported, but FBI and law enforcement notified. UW Medicine patient data also implicated.",
    "remediation_disclosed": "FBI notified. External cybersecurity response. Network restored. HHS OCR breach notification. $52.5M settlement encompassing Fred Hutch and UW Medicine.",
    "primary_source_url": "https://www.hipaajournal.com/fred-hutchinson-cancer-center-data-breach-settlement/",
    "secondary_source_urls": [
      "https://securityaffairs.com/155955/data-breach/hunters-international-hacked-fred-hutch.html",
      "https://www.scworld.com/brief/nearly-52-5m-settlement-to-be-paid-by-fred-hutch-over-2023-cyberattack"
    ],
    "confidence_notes": "High confidence. Settlement figures documented by HIPAA Journal and SC Media. Hunters International claimed on dark web leak site. Patient extortion emails corroborated by Seattle Times reporting cited in Security Affairs.",
    "sources_used": [
      "HIPAA Journal",
      "Security Affairs",
      "SC Media"
    ],
    "id": "INC-00364",
    "year": 2023,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Fred Hutchinson Cancer Center (Fred Hutch)",
    "organization_type": "Healthcare Provider (Cancer Center / Research Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2023-11-19",
    "disclosure_date": "2023-12-01",
    "executive_summary": "The Hunters International ransomware group exploited the Citrix Bleed vulnerability (CVE-2023-4966) to breach Fred Hutchinson Cancer Center's clinical network between November 10 and November 25, 2023. Approximately 2.1 million patients' records were stolen, including names, addresses, Social Security numbers, and sensitive medical information. Attackers sent individual ransom demands of $50 to affected patients, threatening to publish their data. Fred Hutch refused to pay the ransom. A $52.5 million settlement was agreed, comprising $11.5 million cash, $13.5 million in security improvements, and $25.5 million for credit monitoring.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Hunters International",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2100000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$52.5 million total settlement commitment; $25 million direct costs",
    "operational_impact": "Clinical network taken offline; attackers extorted individual patients directly",
    "remediation_disclosed": "Citrix systems patched; $13.5M invested in cybersecurity infrastructure; $11.5M settlement fund; credit monitoring provided",
    "primary_source_url": "https://www.fredhutch.org/en/news/releases/2023/12/notice-of-information-security-incident-involving-fred-hutchinso.html",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/fred-hutchinson-cancer-center-data-breach-settlement/",
      "https://www.theregister.com/2025/05/30/fred_hutch_cancer_center_commits/",
      "https://www.fredhutchsettlement.com",
      "https://jsis.washington.edu/news/assessing-hipaa-security-rule-in-fred-hutchinson-cancer-center-and-uw-medicine-2023-mass-data-breach/"
    ],
    "confidence_notes": "HHS OCR listed 1,840,927 on breach portal; total affected individuals revised to ~2.1M in litigation; settlement received preliminary court approval",
    "sources_used": [
      "Fred Hutch official notice",
      "HIPAA Journal",
      "The Register",
      "UW Jackson School analysis"
    ],
    "id": "INC-00365",
    "year": 2023,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Good Shepherd Health Care System",
    "organization_type": "Healthcare Provider (Regional Hospital / Health System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Hermiston",
    "hq_county": "Umatilla",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-11-01",
    "executive_summary": "Good Shepherd Health Care System in Hermiston, Oregon was confirmed as a victim of the Welltok MOVEit Transfer breach of May 2023, along with numerous other US health systems. The Clop ransomware group exploited CVE-2023-34362 in MOVEit Transfer on May 30, 2023, gaining access to Welltok's server containing member communications data used by Good Shepherd. Compromised data included member names, dates of birth, addresses, health information, and for some members, SSNs and Medicare/Medicaid IDs.",
    "attack_type": "SQL injection exploit / Data exfiltration (MOVEit zero-day)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 14760000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health system member/patient data exposed via Welltok platform",
    "remediation_disclosed": "Notifications sent; credit monitoring offered (as part of Welltok's response)",
    "primary_source_url": "https://www.hipaajournal.com/welltok-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Good Shepherd Health Care System confirmed as Welltok client per HIPAA Journal reporting on Welltok breach victims; confidence moderate \u2014 specific affected count not separately reported",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR Breach Portal (Welltok filing)"
    ],
    "id": "INC-00366",
    "year": 2023,
    "lat": 45.8404101,
    "lng": -119.28946,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Goshen Health System",
    "organization_type": "Nonprofit Regional Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Goshen",
    "hq_county": "Elkhart",
    "discovery_date": "2020-01-01",
    "disclosure_date": "2023-05-23",
    "executive_summary": "Goshen Health System, operating Goshen Health Hospital in Elkhart County, Indiana, faced a class action lawsuit filed May 23, 2023, alleging that the health system deployed Meta Pixel and other tracking technologies on its website and patient portal between January 1, 2020, and December 31, 2023. These technologies allegedly captured user interactions and transmitted patient-identifying information to Meta (Facebook), Google, and marketing firms without patient consent, violating the Indiana Deceptive Consumer Sales Act and Indiana Wiretapping Act. Goshen Health settled the class action in 2025, providing $25 cash payments and identity theft protection (Privacy Shield) to patient portal account holders who logged in during the covered period.",
    "attack_type": "Unauthorized Tracking Pixel Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable \u2014 internal privacy configuration issue",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1,
    "residents_affected_in_state": "Indiana residents \u2014 primarily Elkhart and surrounding counties",
    "financial_impact": "Class action settlement: $25 cash per class member + 1-year Privacy Shield product; settlement final approval December 16, 2025",
    "operational_impact": "No clinical operations disruption; patient data privacy violation affecting portal users",
    "remediation_disclosed": "Yes \u2014 tracking technologies removed, settlement implemented, credit monitoring/Privacy Shield provided",
    "primary_source_url": "https://www.hipaajournal.com/goshen-health-hancock-health-pixel-lawsuit-settlements/",
    "secondary_source_urls": [
      "https://hipaatimes.com/goshen-health-faces-payout-after-hidden-pixel-data-leak",
      "https://www.classaction.org/news/goshen-health-settlement-ends-class-action-lawsuit-over-alleged-meta-pixel-data-sharing"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, ClassAction.org, court-approved settlement. HIPAA Journal article cited but may require verification of exact article URL.",
    "sources_used": [
      "HIPAA Journal",
      "HIPAA Times",
      "ClassAction.org",
      "Elkhart County Superior Court"
    ],
    "id": "INC-00367",
    "year": 2023,
    "lat": 41.5821,
    "lng": -85.8344,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "HCA Healthcare",
    "organization_type": "Hospital / Health System (Multistate)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Nashville, TN (national / multistate)",
    "hq_county": "N/A \u2014 national / multistate",
    "discovery_date": "2023-06-29",
    "disclosure_date": "2023-08-01",
    "executive_summary": "Preliminary investigation suggests the information was obtained by the unauthorized party in late June in what appears to be a theft from an external storage location exclusively used to automate the formatting of email messages, such as reminders that patients may wish to schedule an appointment and education on healthcare programs and services. This incident has caused no disruption to the care and services HCA Healthcare affiliates provide to patients and communities.",
    "attack_type": "Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown criminal threat actor",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11270000,
    "residents_affected_in_state": "Patients from AK CA CO FL GA ID IN KS KY LA MO MS NV NH NC SC TN TX UT VA",
    "financial_impact": "Not publicly disclosed; class action lawsuits filed",
    "operational_impact": "No operational disruption reported; data posted on hacking forum",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/HCA%20-%20General%20Individual%20Notification%20Letter.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/hca-healthcare-data-breach-11-million-patients/",
      "https://www.bleepingcomputer.com/news/security/hca-healthcare-data-breach-affects-11-million-patients/",
      "https://www.hipaajournal.com/hca-healthcare-cyberattack-data-breach-2023/",
      "https://www.statnews.com/2023/07/10/hca-data-breach/",
      "https://www.cbsnews.com/news/hca-healthcare-data-breach-hack-11-million-patients-affected/",
      "https://hcahealthcare.com/util/forms/privacy/hca-data-event-notice.dot",
      "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "CBS News",
      "California AG Breach Notification",
      "HCA Healthcare official notice",
      "HIPAA Journal",
      "STAT News"
    ],
    "id": "INC-00368",
    "year": 2023,
    "lat": 37.85370537714604,
    "lng": -120.04907214100497,
    "is_multistate": true,
    "hq_outside_state": "Nashville",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "HCA Healthcare (Texas facilities)",
    "organization_type": "Healthcare Provider (For-Profit Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Nashville (TN HQ) / Multiple TX locations",
    "hq_county": "Multiple TX counties",
    "discovery_date": "2023-07-05",
    "disclosure_date": "2023-07-10",
    "executive_summary": "HCA Healthcare announced hackers had obtained data from an external electronic storage location used to automate patient communication emails. The breach affected approximately 11,270,000 patients across 20 states including Texas (San Antonio HCA division data was specifically leaked). While the largest healthcare breach of 2023, the compromised data was limited to names, contact information, dates of birth, service dates, and appointment scheduling data \u2014 no clinical treatment or financial data.",
    "attack_type": "Hacking/IT Incident \u2013 External Storage Facility Hack",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown (individual posted data for sale on dark web)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11270000,
    "residents_affected_in_state": 20,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed; breach limited to external storage (not core systems)",
    "remediation_disclosed": "Law enforcement notified; third-party forensic advisors retained; patient notification hotline established",
    "primary_source_url": "https://www.hipaajournal.com/hca-healthcare-cyberattack-data-breach-2023/",
    "secondary_source_urls": [
      "https://www.cbsnews.com/news/hca-healthcare-data-breach-hack-11-million-patients-affected/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 11,270,000; Texas facilities explicitly listed",
    "sources_used": [
      "HIPAA Journal, CBS News"
    ],
    "id": "INC-00369",
    "year": 2023,
    "lat": 29.824235,
    "lng": -95.2844687,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "HCA Healthcare \u2013 SC/FL/Other SE State Hospitals",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Multiple FL/SC/VA locations",
    "hq_county": "Multiple",
    "discovery_date": "2023-07-05",
    "disclosure_date": "2023-07-10",
    "executive_summary": "HCA Healthcare's July 2023 breach (see incident #1) affected patients at HCA hospitals in multiple SE states including Florida (numerous hospitals), South Carolina (Trident Health, Grand Strand, etc.), Virginia (Chippenham, Henrico Doctors', etc.). The 11.27M total is reported under the TN entity but SE state residents were substantially represented.",
    "attack_type": "Unauthorized Access / Data Exfiltration from External Storage",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11270000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Included in HCA total",
    "operational_impact": "SE state HCA hospitals patients' demographic data exposed",
    "remediation_disclosed": "See HCA incident #1",
    "primary_source_url": "https://www.hipaajournal.com/hca-healthcare-cyberattack-data-breach-2023/",
    "secondary_source_urls": [],
    "confidence_notes": "Cross-reference to incident #1. Listed separately to capture SE state impact of the HCA breach.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00370",
    "year": 2023,
    "lat": 26.2059761,
    "lng": -80.1460117,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Harris Health System (Harris County Hospital District)",
    "organization_type": "Healthcare Provider (County Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-06-02",
    "disclosure_date": "2023-09-12",
    "executive_summary": "Harris Health System was affected by the global MOVEit Transfer zero-day exploit by the Clop ransomware group. Unauthorized access to its MOVEit server occurred on May 28, 2023. 224,703 Harris Health patients had data accessed, including addresses, dates of birth, medical record numbers, driver's license numbers, and government-issued ID numbers.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day Exploitation",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 224703,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "MOVEit service only; hospital operations continued",
    "remediation_disclosed": "Immediate security safeguards implemented; MOVEit server secured; forensic investigation with third-party experts",
    "primary_source_url": "https://www.click2houston.com/news/local/2023/09/12/thousands-of-houston-healthcare-patients-warned-about-massive-data-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "High confidence; OCR breach report confirmed 224,703; Houston news station verified",
    "sources_used": [
      "Click2Houston/KPRC 2, HIPAA Journal"
    ],
    "id": "INC-00371",
    "year": 2023,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Harvard Pilgrim Health Care",
    "organization_type": "Health Plan (Multistate)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Wellesley, MA (multistate health plan)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2023-03-28",
    "disclosure_date": "2023-08-25",
    "executive_summary": "Harvard Pilgrim and UnitedHealthcare (\u201cUHC\u201d) participate in an alliance relationship in support of joint product offerings. We provide services to support the administration of these products, including eligibility verification and claims pricing for Harvard Pilgrim contracted providers. On April 17, 2023, Harvard Pilgrim discovered it was the victim of a cybersecurity ransomware incident that impacted systems used to service clients, including UHC. After detecting the unauthorized party, we proactively took our systems offline to contain the threat. We notified law enforcement and regulators",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2550922,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; multiple class action lawsuits filed",
    "operational_impact": "Systems taken offline; member data accessed; ongoing litigation",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/Harvard%20Pilgrim%20Health%20Care%20-%20Sample%20Notice_0.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/harvard-pilgrim-health-care-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/harvard-pilgrim-health-care-discloses-ransomware-attack-data-theft/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00372",
    "year": 2023,
    "lat": 35.711065250072316,
    "lng": -120.56452328576489,
    "is_multistate": true,
    "hq_outside_state": "Wellesley",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Harvard Pilgrim Health Care / Point32Health",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MA",
    "hq_city": "Canton",
    "hq_county": "Norfolk",
    "discovery_date": "2023-04-17",
    "disclosure_date": "2023-06-15",
    "executive_summary": "Harvard Pilgrim Health Care suffered a ransomware attack discovered in April 2023 that led to unauthorized access to its systems between March 28 and April 17, 2023. The breach eventually affected at least 2,860,795 individuals\u2014one of the largest healthcare data breaches of 2023. Compromised data included names, DOBs, SSNs, health insurance account information, and clinical data. A $16 million settlement was reached.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2860795,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$16 million settlement (2025)",
    "operational_impact": "Systems disrupted; systems inaccessible for investigation period; broad notification required",
    "remediation_disclosed": "Third-party cybersecurity experts engaged; law enforcement notified; credit monitoring offered; $16M settlement",
    "primary_source_url": "https://www.hipaajournal.com/harvard-pilgrim-health-care-increases-ransomware-attack-2023/",
    "secondary_source_urls": [
      "https://news.bloomberglaw.com/privacy-and-data-security/harvard-pilgrim-to-pay-16-million-to-end-ransomware-lawsuits",
      "https://hipaatimes.com/harvard-pilgrim-to-pay-16.5m-settlement-over-2023-data-breach"
    ],
    "confidence_notes": "OCR breach report confirmed; Maine AG notice filed; $16M settlement approved",
    "sources_used": [
      "HIPAA Journal",
      "Bloomberg Law",
      "Paubox"
    ],
    "id": "INC-00373",
    "year": 2023,
    "lat": 42.1584324,
    "lng": -71.1447732,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Hawaii Community College (University of Hawaii system)",
    "organization_type": "Education / Healthcare-Adjacent (Student Health Records)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Hilo",
    "hq_county": "Hawaii",
    "discovery_date": "2023-06-13",
    "disclosure_date": "2023-07-28",
    "executive_summary": "Hawaii Community College (HCC), part of the University of Hawaii system, suffered a ransomware attack on June 19, 2023, carried out by the NoEscape ransomware group. The attack led to the theft of data belonging to approximately 28,000 students and staff, including names, Social Security numbers, financial aid information, and bank information. To prevent the ransomware group from publishing the stolen data on the dark web, HCC paid a ransom in the low six-figure range (under $250,000). The university worked with outside cybersecurity experts and national security officials before deciding to pay. Affected individuals were notified and offered credit monitoring and identity theft protection through Experian. The University of Hawaii system subsequently increased network monitoring and implemented mandatory Duo MFA across all campuses.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "NoEscape ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 28000,
    "residents_affected_in_state": 28000,
    "financial_impact": "Ransom paid (under $250,000; exact amount not disclosed)",
    "operational_impact": "Student and staff data exfiltrated and threatened for publication; credit monitoring required; network taken offline",
    "remediation_disclosed": "Ransom paid to obtain data destruction commitment; Experian credit monitoring offered; UH system-wide MFA (Duo) implemented October 2023; increased network scanning",
    "primary_source_url": "https://www.bleepingcomputer.com/news/security/hawaii-community-college-pays-ransomware-gang-to-prevent-data-leak/",
    "secondary_source_urls": [
      "https://westoahu.hawaii.edu/cyber/forensics-weekly-executive-summmaries/2023-hawaii-community-college-ransomware-attack-forensic-analysis/",
      "https://www.insidehighered.com/news/quick-takes/2023/07/31/hawaii-community-college-pays-ransom-after-data-breach/"
    ],
    "confidence_notes": "Moderate confidence for healthcare classification: HCC is an educational institution but holds student health records and financial aid data containing SSNs; ransomware attack with data theft qualifies as cyber incident; included as part of UH system breach pattern",
    "sources_used": [
      "BleepingComputer",
      "University of Hawaii West Oahu Cyber Forensics",
      "Inside Higher Ed"
    ],
    "id": "INC-00374",
    "year": 2023,
    "lat": 19.7297,
    "lng": -155.09,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Hayward Sisters Hospital d/b/a St. Rose Hospital",
    "organization_type": "Hospital (Hayward / St. Rose Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Hayward, CA",
    "hq_county": "Alameda County",
    "discovery_date": "2022-11-18",
    "disclosure_date": "2023-08-03",
    "executive_summary": "In response, we immediately took steps to secure our systems and initiated an investigation into the nature and scope of the event with the assistance of third-party computer forensic specialists. The investigation determined that an unknown actor gained access to certain computer systems on our network and acquired certain files from those systems on or about November 18, 2022. We identified the affected files and conducted a thorough review of the files in order to identify whether an",
    "attack_type": "Hacking / Network Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/St.%20Rose%20Hospital%20-%20Sample%20Notice_0.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00375",
    "year": 2023,
    "lat": 37.6688,
    "lng": -122.0808,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Health Alliance Hospital Mary's Avenue Campus",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Kingston",
    "hq_county": "Ulster",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Health Alliance Hospital Mary's Avenue Campus reported a hacking incident in December 2023 that involved data theft and affected 264,197 individuals. This is the OCR breach report associated with the October 2023 cyberattack that forced ambulance diversions at HealthAlliance Hospital and Margaretville Hospital in New York.",
    "attack_type": "Hacking/IT Incident (data theft confirmed)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 264197,
    "residents_affected_in_state": 242641,
    "financial_impact": "$550,000 active penalty ($1.4M total with $850K suspended)",
    "operational_impact": "Ambulances diverted; significant system disruptions across 3 facilities",
    "remediation_disclosed": "NY AG $550K penalty; corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://ag.ny.gov/press-release/2024/attorney-general-james-secures-550000-hudson-valley-health-care-facility"
    ],
    "confidence_notes": "OCR breach portal; NY AG press release; separate from the 2022 network server breach at the same facility",
    "sources_used": [
      "HIPAA Journal",
      "NY AG"
    ],
    "id": "INC-00376",
    "year": 2023,
    "lat": 41.9287812,
    "lng": -74.0023825,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Health Plan of San Mateo",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "San Mateo",
    "hq_county": "San Mateo",
    "discovery_date": "2023-02 to 2023-03 (email account unauthorized access)",
    "disclosure_date": "03/2023",
    "executive_summary": "Unauthorized accessing of employee email account at Health Plan of San Mateo (county health plan for low-income residents).",
    "attack_type": "Hacking/IT Incident \u2014 Phishing / unauthorized email account access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11894,
    "residents_affected_in_state": 11894,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No reported clinical operational disruption",
    "remediation_disclosed": "Not publicly disclosed in detail",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "County health plan serving low-income San Mateo County residents on Medi-Cal. Reported per HIPAA Journal March 2023 breach report.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00377",
    "year": 2023,
    "lat": 37.563,
    "lng": -122.3255,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "HealthAlliance Hospital (Westchester Medical Center Health Network)",
    "organization_type": "Hospital",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NY",
    "hq_city": "Kingston",
    "hq_county": "Ulster",
    "discovery_date": "2023-10-20",
    "disclosure_date": "2023-10-23",
    "executive_summary": "A cyberattack struck HealthAlliance Hospital in Kingston, Margaretville Hospital, and Mountainside Residential Care Center in October 2023, forcing ambulance diversions from HealthAlliance and Margaretville hospitals. The NY AG investigated and found that HealthAlliance failed to address a known vulnerability, resulting in a $550,000 penalty (with $850,000 suspended). The breach compromised data of 242,641 New York residents.",
    "attack_type": "Hacking/IT Incident (exploitation of known vulnerability)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 242641,
    "residents_affected_in_state": 242641,
    "financial_impact": "$1.4 million penalty ($550,000 active; $850,000 suspended due to financial condition)",
    "operational_impact": "Ambulances diverted from HealthAlliance and Margaretville hospitals; patient care disrupted",
    "remediation_disclosed": "NY AG agreement; corrective action plan; $550K penalty paid",
    "primary_source_url": "https://ag.ny.gov/press-release/2024/attorney-general-james-secures-550000-hudson-valley-health-care-facility",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthalliance-550000-penalty-cybersecurity-failure/",
      "https://www.insurancejournal.com/news/east/2023/10/23/745200.htm",
      "https://kingstonwire.com/news/2024/12/09/attorney-general-healthalliance-must-pay-fine-for-2023-cyberattack/774ZkL"
    ],
    "confidence_notes": "NY AG press release; OCR breach report; ambulance diversion confirmed by WMCHealth",
    "sources_used": [
      "NY AG",
      "HIPAA Journal",
      "Insurance Journal",
      "Kingston Wire"
    ],
    "id": "INC-00378",
    "year": 2023,
    "lat": 41.9287812,
    "lng": -74.0023825,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "HealthEC LLC",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NJ",
    "hq_city": "Edison",
    "hq_county": "Middlesex",
    "discovery_date": "2023-07-14",
    "disclosure_date": "2023-12-22",
    "executive_summary": "HealthEC, a New Jersey-based population health analytics vendor, was hacked between July 14-23, 2023. Attackers exfiltrated files containing sensitive health data from the platform used by over 1 million healthcare professionals. The breach ultimately affected 4,656,293 individuals across multiple health system clients including MD Valuecare and Corewell Health. HealthEC settled related litigation for $5.48 million.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4656293,
    "residents_affected_in_state": "Nationwide; not broken out by state",
    "financial_impact": "$5.48 million settlement",
    "operational_impact": "4.6+ million patient records exfiltrated; delayed notification (5 months)",
    "remediation_disclosed": "Enhanced security measures; settlement; affected clients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthec-data-breach/",
    "secondary_source_urls": [
      "https://databreaches.net/2025/06/17/healthec-agrees-to-5-48-million-settlement-to-end-data-breach-lawsuit/",
      "https://www.seegerweiss.com/data-security-breaches/healthec-data-breach-lawsuit/",
      "https://www.securityweek.com/4-5-million-individuals-affected-by-data-breach-at-healthec/",
      "https://www.infosecurity-magazine.com/news/healthec-breach-millions-patients/",
      "https://thehipaaetool.com/healthec-cyberattack-affects-4-45-million/",
      "https://healthec.com/notice-of-data-security-incident/"
    ],
    "confidence_notes": "OCR breach portal; NJ federal court case; $5.48M settlement | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "DataBreaches.Net",
      "HIPAA Journal",
      "HealthEC official notice",
      "Infosecurity Magazine",
      "SecurityWeek",
      "Seeger Weiss",
      "The HIPAA E-Tool"
    ],
    "id": "INC-00379",
    "year": 2023,
    "lat": 40.5187,
    "lng": -74.4121,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "HealthPartners (Medica Community Health / Dean Health Plan / WellFirst \u2014 MOVEit Fortra)",
    "organization_type": "Health Insurance / Managed Care",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WI",
    "hq_city": "Madison",
    "hq_county": "Dane",
    "discovery_date": "2023-03-10",
    "disclosure_date": "2023-07-21",
    "executive_summary": "Medica Community Health Plan, Dean Health Plan (Madison, Wisconsin), and Dean Health Service Company (branded as WellFirst Health) reported a data breach stemming from the Fortra GoAnywhere MFT vulnerability exploited in January-March 2023. The breach date of record was March 10, 2023, with public notification on July 21, 2023. Data accessed included full names, addresses, dates of birth, email addresses, claims information, health insurance ID numbers, healthcare provider names, medical record numbers, and Social Security numbers. A total of approximately 540 Wisconsin residents were affected across the three entities (9 Medica, 350 Dean Health Plan, 181 WellFirst). The Wisconsin DATCP breach archive confirmed this incident.",
    "attack_type": "Third-Party Vendor Breach (Fortra GoAnywhere MFT exploit)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p (CL0P) \u2014 attributed to Cl0p GoAnywhere campaign",
    "attribution_status": "unknown",
    "individuals_affected_reported": 540,
    "residents_affected_in_state": 540,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health insurance member data exposed via third-party vendor; no clinical disruption",
    "remediation_disclosed": "Yes \u2014 members notified July 2023, Wisconsin DATCP notified",
    "primary_source_url": "https://datcp.wi.gov/Pages/Programs_Services/DataBreachArchive.aspx",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Wisconsin DATCP official breach archive. Fortra/GoAnywhere breach is well-documented.",
    "sources_used": [
      "Wisconsin DATCP",
      "Wisconsin AG breach archive"
    ],
    "id": "INC-00380",
    "year": 2023,
    "lat": 43.0731,
    "lng": -89.4012,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Heart of Texas Behavioral Health Network",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "TX",
    "hq_city": "Waco",
    "hq_county": "McLennan",
    "discovery_date": "2023-12-12",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Heart of Texas Behavioral Health Network, a Waco-area behavioral health provider, reported a hacking incident to HHS OCR in December 2023 that affected 63,776 individuals. The breach involved unauthorized access to its network server. The organization provides mental health and substance abuse treatment services across central Texas.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 63776,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://data.vcstar.com/health-care-data-breaches/heart-of-texas-behavioral-health-network-tx-63776-20231212-hacking-network/"
    ],
    "confidence_notes": "HHS OCR confirmed 63,776 affected; listed in HIPAA Journal December 2023 Monthly Report",
    "sources_used": [
      "HIPAA Journal December 2023 Monthly Report, VCStar health data breaches database"
    ],
    "id": "INC-00381",
    "year": 2023,
    "lat": 31.5491899,
    "lng": -97.1474628,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Henry Ford Health System",
    "organization_type": "Nonprofit Academic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Detroit",
    "hq_county": "Wayne",
    "discovery_date": "2023-03-30",
    "disclosure_date": "2023-07-18",
    "executive_summary": "Henry Ford Health System suffered a targeted email phishing campaign discovered on March 30, 2023. Employees were tricked into providing credentials, allowing unauthorized access to email accounts. The investigation confirmed that on May 16, 2023, patient PHI could have been accessed. Information compromised included names, genders, DOBs, lab results, procedure types, diagnoses, dates of service, phone numbers, medical record numbers, and internal tracking numbers for approximately 168,000 patients. A $700,000 class action settlement was reached.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 168000,
    "residents_affected_in_state": "Primarily Michigan residents",
    "financial_impact": "$700,000 class action settlement fund",
    "operational_impact": "Minimal operational disruption; PHI potentially accessed via email",
    "remediation_disclosed": "Yes \u2014 accounts secured; forensic investigation; patient notifications July 18, 2023; security improvements committed",
    "primary_source_url": "https://www.jdsupra.com/legalnews/henry-ford-health-system-announces-data-8629834/",
    "secondary_source_urls": [
      "https://www.hfhsdatasecuritysettlement.com"
    ],
    "confidence_notes": "High confidence. Henry Ford Health website notice, JD Supra coverage, settlement site.",
    "sources_used": [
      "JD Supra",
      "Henry Ford Health Settlement Site"
    ],
    "id": "INC-00382",
    "year": 2023,
    "lat": 42.3314,
    "lng": -83.0458,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Henry Schein, Inc.",
    "organization_type": "BA / Vendor (Healthcare Products & Solutions)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "Melville",
    "hq_county": "Suffolk",
    "discovery_date": "2023-10-14",
    "disclosure_date": "2023-10-15",
    "executive_summary": "Henry Schein, a Fortune 500 global distributor of healthcare products and solutions, suffered two back-to-back ransomware attacks by ALPHV/BlackCat in October and November 2023. The first attack disrupted manufacturing and distribution operations. ALPHV/BlackCat publicly claimed responsibility, initially claiming to have stolen 35 TB of data including payroll, financial, and patient data. In November, ALPHV re-encrypted Schein's systems after negotiations broke down, claiming Schein had tried to take data back. In October 2024 \u2014 more than a year later \u2014 Henry Schein confirmed in a notification to the Maine AG that 166,432 individuals had their personal and protected health information stolen.",
    "attack_type": "Ransomware / Double Extortion / Data Exfiltration (two attacks: Oct and Nov 2023)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "claimed",
    "individuals_affected_reported": 166432,
    "residents_affected_in_state": "Nationwide; not broken out by state",
    "financial_impact": "Not publicly disclosed as a specific dollar amount. Extended operational disruption. Ransom payment status not confirmed.",
    "operational_impact": "Manufacturing and distribution operations disrupted in October and November 2023. Systems re-encrypted in November after failed negotiations.",
    "remediation_disclosed": "Systems isolated and rebuilt (twice). External cybersecurity experts engaged. Notification letters to 166,432 individuals in October 2024. 24-month credit monitoring and identity theft protection offered.",
    "primary_source_url": "https://www.henryschein.com/us-en/images/corporate/Notice_of_Data_Breach.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/blackcat-ransomware-group-re-encrypts-henry-schein-data/",
      "https://www.bleepingcomputer.com/news/security/henry-schein-discloses-data-breach-a-year-after-ransomware-attack/",
      "https://phishingtackle.com/blog/blackcat-alphv-ransomwares-massive-data-breach-at-henry-schein-healthcare"
    ],
    "confidence_notes": "High confidence. Maine AG notification confirmed 166,432 affected. ALPHV/BlackCat publicly claimed and named Schein's cybersecurity firm. Delayed notification of 12+ months is notable.",
    "sources_used": [
      "Henry Schein official notice",
      "HIPAA Journal",
      "BleepingComputer",
      "Phishing Tackle"
    ],
    "id": "INC-00383",
    "year": 2023,
    "lat": 40.7835914,
    "lng": -73.4075575,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Heritage Provider Network / Regal Medical Group (and affiliates)",
    "organization_type": "Physician network / managed care organization (IPA) \u2014 affiliates include Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, Greater Covina Medical",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "Arcadia / Thousand Oaks",
    "hq_county": "Los Angeles County",
    "discovery_date": "2022-12-08",
    "disclosure_date": "2023-02-01",
    "executive_summary": "On or about December 1, 2022, ransomware actors gained access to servers operated by Regal Medical Group and affiliated entities under the Heritage Provider Network umbrella. Staff noticed server access difficulties on December 2, and malware was confirmed December 8. The attackers exfiltrated patient data including SSNs, diagnoses, lab results, radiology reports, and prescription data. The HHS Office for Civil Rights breach portal recorded 3,300,638 patients affected across four affiliated groups, constituting the largest healthcare data breach reported in 2023. A preliminary settlement of $49.99 million was approved in 2025.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3300638,
    "residents_affected_in_state": "Predominantly CA residents given network's CA-only coverage",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'litigation_settlement': 49995000, 'notes': '$49.99M class-action settlement (Head v. Regal Medical Group), prelim approved Oct 2025. Claim deadline Dec 22, 2025.'}",
    "operational_impact": "Server access disrupted; investigation and system restoration required. No reported EHR shutdowns or care-delivery diversion publicly confirmed.",
    "remediation_disclosed": "Third-party cybersecurity vendors engaged; additional security protections implemented; HHS, CA AG, and law enforcement notified. One year of Norton LifeLock credit monitoring offered to affected patients.",
    "primary_source_url": "https://oag.ca.gov/system/files/Regal%20John%20Doe%20Letter%20Feb%201%202023.pdf",
    "secondary_source_urls": [
      "https://www.bleepingcomputer.com/news/security/california-medical-group-data-breach-impacts-33-million-patients/",
      "https://www.paubox.com/blog/heritage-provider-network-pays-50m-over-massive-ransomware-data-breach",
      "https://www.claimdepot.com/settlements/regal-medical-settlement",
      "https://schneiderdowns.com/our-thoughts-on/2023-heritage-provider-network-attack/"
    ],
    "confidence_notes": "Breach date: ~Dec 1, 2022. Discovered Dec 8, 2022. Notifications sent Feb 1, 2023. Total settlement class: ~3,413,000 individuals. No ransom payment publicly disclosed. Threat actor identity unknown.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00384",
    "year": 2023,
    "lat": 34.1397,
    "lng": -118.0353,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Highlands Oncology Group (First Ransomware Incident)",
    "organization_type": "Healthcare Provider (Oncology)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Fayetteville",
    "hq_county": "Washington",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2023-12-22",
    "executive_summary": "Highlands Oncology Group, a provider of cancer care across six locations in Northwest Arkansas, experienced its first ransomware attack in November 2023. The organization notified HHS OCR on December 22, 2023, with the breach affecting 55,297 patients. PHI involved included names, addresses, dates of birth, Social Security numbers, claims information, diagnoses, conditions, lab results, medications, and other treatment information. The organization implemented additional system monitoring safeguards, revised policies regarding remote access, and implemented additional technical safeguards following the incident.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 55297,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network disruption; systems encrypted",
    "remediation_disclosed": "Additional system monitoring; remote access policy revisions; additional technical safeguards implemented",
    "primary_source_url": "https://databreaches.net/2025/08/02/highlands-oncology-group-notifies-113575-people-after-ransomware-attack-by-medusa/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "HHS OCR confirmed 55,297 affected; OCR closing statement confirms details; DataBreaches.net documented both incidents",
    "sources_used": [
      "DataBreaches.net, HIPAA Journal December 2023 Monthly Report"
    ],
    "id": "INC-00385",
    "year": 2023,
    "lat": 36.0822,
    "lng": -94.1719,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Highlands Oncology Group PA \u2013 2023 Breach",
    "organization_type": "Healthcare Provider (Oncology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Fayetteville",
    "hq_county": "Washington",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2023-12-22",
    "executive_summary": "Fayetteville, AR-based Highlands Oncology Group experienced a ransomware attack that was disclosed December 22, 2023 to HHS OCR as affecting 55,297 individuals.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 55297,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data potentially exposed",
    "remediation_disclosed": "HHS OCR notified December 22, 2023",
    "primary_source_url": "https://databreaches.net/2025/08/02/highlands-oncology-group-notifies-113575-people-after-ransomware-attack-by-medusa/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "HHS OCR lists 55,297 for December 2023 breach report. First of two Highlands Oncology incidents.",
    "sources_used": [
      "DataBreaches.net",
      "HIPAA Journal"
    ],
    "id": "INC-00386",
    "year": 2023,
    "lat": 36.0822,
    "lng": -94.1719,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Highmark Inc.",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "PA",
    "hq_city": "Pittsburgh",
    "hq_county": "Allegheny",
    "discovery_date": "2022-12-13",
    "disclosure_date": "2023-02-10",
    "executive_summary": "Highmark Inc., a major Pennsylvania-based health plan, reported a data security incident in December 2022 affecting approximately 559 Delaware residents (DE AG filing). The breach occurred December 13-15, 2022 and involved unauthorized access to member information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly disclosed (total)",
    "residents_affected_in_state": 559,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member data exposed",
    "remediation_disclosed": "Multiple state AG notifications; affected members notified",
    "primary_source_url": "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/",
    "secondary_source_urls": [],
    "confidence_notes": "Delaware AG database; limited public detail on total affected",
    "sources_used": [
      "Delaware AG database"
    ],
    "id": "INC-00387",
    "year": 2023,
    "lat": 40.4406,
    "lng": -79.9959,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Hillsborough County, Florida (Health Care Services & Aging Services)",
    "organization_type": "Healthcare Provider (Government Health Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Tampa",
    "hq_county": "Hillsborough",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-07-14",
    "executive_summary": "Hillsborough County was caught in the global Clop/MOVEit breach as a customer of MOVEit. Files from the Health Care Services and Aging Services departments were potentially exposed. The county mailed notifications to 70,636 individuals, including names, SSNs, DOBs, home addresses, medical conditions, diagnoses, and disability codes.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 70636,
    "residents_affected_in_state": 70636,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health Care Services and Aging Services data exposed",
    "remediation_disclosed": "Security measures installed; FL AG notified; credit monitoring offered; notifications mailed July 2023",
    "primary_source_url": "https://www.tampabay.com/news/business/2023/07/14/hillsborough-notifies-70000-potential-data-breach-health-aging-services/",
    "secondary_source_urls": [
      "https://www.fox13news.com/news/global-data-breach-could-impact-70000-residents-vendor-employees-with-hillsborough-county"
    ],
    "confidence_notes": "Well-documented by Tampa Bay Times and Fox 13. HHS OCR lists 70,636 affected.",
    "sources_used": [
      "Tampa Bay Times",
      "Fox 13 Tampa Bay"
    ],
    "id": "INC-00388",
    "year": 2023,
    "lat": 27.9506,
    "lng": -82.4572,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "HonorHealth (HealthEC vendor breach)",
    "organization_type": "Health System",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "AZ",
    "hq_city": "Scottsdale",
    "hq_county": "Maricopa",
    "discovery_date": "2023-07-14",
    "disclosure_date": "2023-12-22",
    "executive_summary": "HonorHealth was among ~17 healthcare clients whose data was stolen in the July 2023 HealthEC cyberattack. Hackers accessed HealthEC's population health management platform July 14\u201323, 2023. Total HealthEC breach: 4,656,293 individuals; HonorHealth's AZ-specific count not separately disclosed. $5.48M class action settlement (HealthEC system-wide).",
    "attack_type": "Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4656293,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; $5.48M HealthEC class action settlement (system-wide)",
    "operational_impact": "Population health management data compromised",
    "remediation_disclosed": "HealthEC offered 12-month credit monitoring; security improvements",
    "primary_source_url": "https://www.hipaajournal.com/healthec-data-breach/",
    "secondary_source_urls": [
      "https://thehipaaetool.com/healthec-cyberattack-affects-4-45-million/"
    ],
    "confidence_notes": "High confidence HonorHealth affected; explicitly named as HealthEC client in multiple sources; AZ-specific count not separately disclosed",
    "sources_used": [
      "HIPAA Journal",
      "The HIPAA E-Tool"
    ],
    "id": "INC-00389",
    "year": 2023,
    "lat": 33.4942,
    "lng": -111.9261,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "INTEGRIS Health",
    "organization_type": "Healthcare Provider (Nonprofit Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2023-11-28",
    "disclosure_date": "2023-12-24",
    "executive_summary": "INTEGRIS Health, Oklahoma's largest not-for-profit health system, confirmed its internal systems were compromised beginning November 28, 2023. An unauthorized actor (Hunters International threat group) exfiltrated patient data without encrypting files and then directly contacted patients on Christmas Eve 2023, demanding $50 payments to prevent their data from being sold. The attacker claimed 2+ million patients affected. HHS was formally notified in February 2024 that 2,385,646 individuals were affected. Compromised data included names, dates of birth, contact info, demographic info, and Social Security numbers.",
    "attack_type": "Hacking/IT Incident \u2013 Data Theft / Extortion (No Encryption)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Hunters International",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2385646,
    "residents_affected_in_state": "Primarily Oklahoma residents",
    "financial_impact": "$30M class action settlement (2025)",
    "operational_impact": "Systems accessible; data exfiltrated without encryption; direct patient extortion emails sent",
    "remediation_disclosed": "Law enforcement engaged; immediate containment actions; class action settled for $30M",
    "primary_source_url": "https://www.hipaajournal.com/integris-health-data-breach/",
    "secondary_source_urls": [
      "https://www.newsweek.com/integris-health-agrees-to-30-million-settlement-over-2023-data-breach-access-health-10883504",
      "https://hipaatimes.com/integris-health-reaches-30-million-settlement-over-2023-data-breach",
      "https://www.reddit.com/r/oklahoma/comments/18q4zk3/integrisok_data_breach/",
      "https://www.healthcareitnews.com/news/top-15-largest-us-healthcare-provider-data-breaches-2024"
    ],
    "confidence_notes": "Very high confidence; OCR confirmed 2,385,646; $30M settlement confirmed by Newsweek and HIPAA Journal | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HIPAA Journal",
      "HIPAA Journal, Newsweek, Paubox/HIPAA Times",
      "HIPAATimes (Paubox)",
      "Healthcare IT News",
      "Reddit (r/oklahoma for threat actor contact details)"
    ],
    "id": "INC-00390",
    "year": 2023,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Independent Living Systems, LLC",
    "organization_type": "BA / Vendor (Managed Care Administration)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Miami",
    "hq_county": "Miami-Dade",
    "discovery_date": "2022-07-05",
    "disclosure_date": "2023-03-14",
    "executive_summary": "Independent Living Systems (ILS), a Miami-based vendor of clinical and third-party administrative services to managed care organizations serving elderly and disabled Medicaid/Medicare patients, experienced an intrusion between June 30 and July 5, 2022, causing 'inaccessibility of certain computer systems' (consistent with ransomware). ILS posted a preliminary breach notice September 2, 2022, but only completed its investigation by January 17, 2023. Individual notifications began March 14, 2023 \u2014 more than 8 months after the breach \u2014 affecting 4,226,508 individuals. Multiple lawsuits alleged unreasonable notification delay. Compromised data included names, SSNs, Medicare/Medicaid IDs, financial account information, medical records, and diagnosis codes.",
    "attack_type": "Ransomware (suspected) / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4226508,
    "residents_affected_in_state": "Primarily Florida; ILS operates FL Community Care (statewide Medicaid network) and FL Complete Care (Medicare Advantage SNP)",
    "financial_impact": "Not publicly disclosed. Multiple class action lawsuits filed. No ransom payment confirmed.",
    "operational_impact": "Computer systems inaccessible for up to 6 days. Impact on Medicaid/Medicare managed care administration for elderly and disabled populations.",
    "remediation_disclosed": "Third-party cybersecurity specialists engaged. Website preliminary notice September 2022. Individual notifications March 14, 2023. Credit monitoring offered.",
    "primary_source_url": "https://www.ilsfl.com/data-breach-notice",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/independent-living-systems-sued-over-4-million-record-data-breach/",
      "https://siliconangle.com/2023/03/16/4-2m-records-exposed-breach-healthcare-provider-independent-living-systems/",
      "https://www.bankinfosecurity.com/long-term-care-services-firm-says-breach-affects-42-million-a-21448"
    ],
    "confidence_notes": "High confidence. Maine AG filing confirms 4,226,508 affected. ILS itself disclosed in March 2023 notice. Notification delay of 8+ months confirmed by multiple sources.",
    "sources_used": [
      "ILS official breach notice",
      "HIPAA Journal",
      "SiliconAngle",
      "BankInfoSecurity",
      "McKnight's Senior Living"
    ],
    "id": "INC-00391",
    "year": 2023,
    "lat": 25.7617,
    "lng": -80.1918,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Independent Living Systems, LLC (ILS)",
    "organization_type": "Business Associate (Managed Care/Long-Term Support Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Miami",
    "hq_county": "Miami-Dade",
    "discovery_date": "2022-07-05",
    "disclosure_date": "2023-03-14",
    "executive_summary": "Miami-based ILS, a provider of long-term support services for Medicare/Medicaid populations, discovered on July 5, 2022 that malicious third parties accessed its network and acquired sensitive files. The breach affected 4,226,508 individuals\u2014one of the largest healthcare data breaches of 2022. SSNs, taxpayer IDs, and medical/insurance data were stolen. Notification was delayed until March 2023. A $14 million class action settlement received preliminary approval in 2025.",
    "attack_type": "Unauthorized Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4226508,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$14 million class action settlement (preliminary approval 2025)",
    "operational_impact": "Sensitive files exfiltrated; notification delayed ~8 months",
    "remediation_disclosed": "$2 million+ invested in security improvements post-breach; HHS OCR notified",
    "primary_source_url": "https://www.hipaajournal.com/independent-living-systems-data-breach-settlement/",
    "secondary_source_urls": [
      "https://ilsdatabreachsettlement.com",
      "https://www.marconet.com/blog/what-long-term-care-facilities-should-know-about-the-independent-living-systems-data-breach"
    ],
    "confidence_notes": "HHS OCR confirms 4,226,508. Settlement website corroborates. Delay in notification is widely documented.",
    "sources_used": [
      "HIPAA Journal",
      "ILS Settlement Website",
      "Marco Technologies"
    ],
    "id": "INC-00392",
    "year": 2023,
    "lat": 25.7617,
    "lng": -80.1918,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Jefferson County Health Center (Iowa \u2014 Karakurt ransomware)",
    "organization_type": "Rural Community Hospital / Critical Access Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Fairfield",
    "hq_county": "Jefferson",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Jefferson County Health Center, a critical access hospital in Fairfield, Iowa, reported a hacking incident to HHS OCR in July 2023, with data theft confirmed. The Karakurt threat group was identified as responsible. Approximately 53,827 individuals were affected. Karakurt, a data theft and extortion group linked to Conti ransomware operations, typically steals data without encrypting files and demands ransom to prevent the release or sale of stolen data. This incident is documented in the HIPAA Journal July 2023 healthcare data breach report.",
    "attack_type": "Data Theft / Extortion (no encryption)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Karakurt",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 53827,
    "residents_affected_in_state": "Iowa residents \u2014 primarily Jefferson County area",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data stolen; Karakurt extortion demand; no file encryption reported",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal July 2023 report cites HHS OCR breach portal. Karakurt attribution confirmed in report.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00393",
    "year": 2023,
    "lat": 41.0072342,
    "lng": -91.9630039,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "John Muir Health Walnut Creek Medical Center",
    "organization_type": "Nonprofit community hospital and health system (two major Contra Costa County hospitals)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Walnut Creek",
    "hq_county": "Contra Costa County",
    "discovery_date": "2023-03-22",
    "disclosure_date": "2023-04-13",
    "executive_summary": "On July 1, 2021, a John Muir Health Walnut Creek Medical Center staff member created an internal website linking to an external Excel file containing patient information, not realizing it was accessible outside JMH. On March 22, 2023, the JMH Privacy Office was notified of the exposure. The file was disabled March 23\u201324, 2023. The exposed data included patient names, facility names, room numbers, diagnoses/conditions, and dates. JMH confirmed no external access occurred September 28, 2022 \u2013 March 23, 2023, but could not rule out access July 1, 2021 \u2013 September 27, 2022. 821 patients were notified.",
    "attack_type": "Accidental data exposure (internal error \u2014 not a malicious attack)",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "NOT_APPLICABLE",
    "attribution_status": "unknown",
    "individuals_affected_reported": 821,
    "residents_affected_in_state": "Primarily CA (Contra Costa County patients)",
    "financial_impact": "{'notes': 'No financial penalties or settlements disclosed.'}",
    "operational_impact": "No clinical disruption. Accidental exposure resolved upon discovery.",
    "remediation_disclosed": "Website decommissioned March 24, 2023; JMH re-educating staff; reviewing policies and practices.",
    "primary_source_url": "https://oag.ca.gov/system/files/JMH%20Sample%20of%20Notice%20-%20Security%20Breach%20Notification%2020230412_1.pdf",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/john-muir-health-walnut-creek-medical-6784720/",
      "https://www.techtarget.com/healthtechsecurity/news/366594355/Excel-File-Exposed-to-Internet-at-CA-Health-System"
    ],
    "confidence_notes": "This is an accidental exposure, not a cyberattack. Included given the public reporting and CA AG filing. No financial data compromised. 821 patients notified April 2023.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00394",
    "year": 2023,
    "lat": 37.9101,
    "lng": -122.0652,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Johnson & Johnson Health Care Systems, Inc. (Janssen CarePath)",
    "organization_type": "BA/Vendor (Pharmaceutical Patient Support Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NJ",
    "hq_city": "Horsham",
    "hq_county": "Montgomery",
    "discovery_date": "2023-08-02",
    "disclosure_date": "2023-09-29",
    "executive_summary": "Johnson & Johnson Health Care Systems disclosed in September 2023 that a third-party IT vendor breach had exposed the protected health information of patients enrolled in its Janssen CarePath patient support program. An unauthorized actor gained access to a database maintained by IBM, a third-party service provider for CarePath, and accessed information for patients who had applied for CarePath assistance for J&J medications including STELARA, TREMFYA, INVEGA, and others \u2014 medications often associated with immunology and oncology conditions. Approximately 2.9 million individuals were affected. Compromised data included names, contact information, dates of birth, health insurance information, medication details, and diagnoses. IBM was the vendor whose systems were breached.",
    "attack_type": "Third-Party Vendor Compromise / Unauthorized Database Access",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2900000,
    "residents_affected_in_state": "Not separately reported by state (nationwide patient support program)",
    "financial_impact": "Class action lawsuits filed. Settlement not publicly disclosed. IBM contract reviewed.",
    "operational_impact": "Patient support program data exposed. Sensitive medication data including immunology and oncology drug information affected. No clinical service disruption.",
    "remediation_disclosed": "IBM vendor access terminated. Third-party forensics. HHS OCR breach reported. Notification letters mailed. Credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/johnson-johnson-carepatch-data-breach/",
    "secondary_source_urls": [
      "https://www.bleepingcomputer.com/news/security/johnson-johnsons-janssen-carepatch-data-breach-exposes-29m-patients/",
      "https://healthitsecurity.com/news/jj-carepatch-breach-exposes-2-9m-patient-records"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report. HIPAA Journal and BleepingComputer corroborate IBM as vendor and ~2.9M count. Medication names specifically documented in breach notices.",
    "sources_used": [
      "HIPAA Journal",
      "BleepingComputer",
      "Health IT Security"
    ],
    "id": "INC-00395",
    "year": 2023,
    "geocode_note": "Exact city not resolved; placed at NJ state centroid.",
    "lat": 40.580573295143495,
    "lng": -74.79328108262243,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Kaiser Foundation Health Plan of Washington (tracking pixel disclosure)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Renton",
    "hq_county": "King",
    "discovery_date": "2023-03-01",
    "disclosure_date": "2023-04-12",
    "executive_summary": "Kaiser Permanente disclosed in April 2023 that it had installed tracking technologies (including Google and Microsoft Bing tracking pixels) on its website and mobile app that may have transmitted protected health information to third-party advertising platforms without authorization. The disclosure affected approximately 13.4 million individuals nationally across all Kaiser Permanente health plans. Kaiser Foundation Health Plan of Washington (KFHPW), serving approximately 870,000 members in Washington, was among the affected entities. In August 2024, Kaiser agreed to a $49 million settlement with the California Attorney General over related tracking pixel issues. A separate national class-action settlement of $46 million was reached to resolve consumer claims.",
    "attack_type": "Unauthorized disclosure via tracking pixel / third-party technology",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not applicable (third-party tracking technology)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13400000,
    "residents_affected_in_state": 870000,
    "financial_impact": "$46 million national class-action settlement; $49 million CA AG settlement (KP national)",
    "operational_impact": "PHI transmitted to Google and Microsoft Bing advertising platforms without patient authorization",
    "remediation_disclosed": "Tracking pixels removed; notification issued to 13.4M affected individuals; settlement funds distributed",
    "primary_source_url": "https://www.hipaajournal.com/kaiser-permanente-health-plan-data-breach-13-4-million/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594773/Kaiser-Permanente-Discloses-Data-Breach-at-WA-Health-Plan-69K-Impacted"
    ],
    "confidence_notes": "Moderate confidence: Kaiser KFHPW listed separately in HHS OCR notices; national-level tracking pixel disclosure; WA-specific count not disaggregated from 13.4M national total. Note: WA-009 covers the separate Dec 2021 VMMC email phishing breach (69,589 affected)",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget HealthTech Security"
    ],
    "id": "INC-00396",
    "year": 2023,
    "lat": 47.4829,
    "lng": -122.2171,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kent County Community Mental Health (Michigan) \u2014 Unauthorized Email Access",
    "organization_type": "Community Mental Health Authority",
    "organization_type_bucket": "Behavioral / Mental health",
    "state": "MI",
    "hq_city": "Grand Rapids",
    "hq_county": "Kent",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Kent County Community Mental Health Authority (Network180), based in Grand Rapids, Michigan, reported an unauthorized email account access incident to HHS OCR in December 2023, affecting 59,334 individuals. This was listed in the HIPAA Journal December 2023 healthcare data breach report. Patient protected health information stored in email accounts was potentially exposed. The specific nature of the email compromise, attack vector, and operational impact were not further detailed in available public sources.",
    "attack_type": "Unauthorized Email Account Access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 59334,
    "residents_affected_in_state": "Michigan residents \u2014 primarily Kent County",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Email account compromised; PHI potentially accessed",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified December 2023; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal December 2023 breach report citing HHS OCR. 59,334 individuals confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00397",
    "year": 2023,
    "lat": 42.9634,
    "lng": -85.6681,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Lehigh Valley Health Network",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "PA",
    "hq_city": "Allentown",
    "hq_county": "Lehigh",
    "discovery_date": "2023-02-06",
    "disclosure_date": "2023-02-22",
    "executive_summary": "Lehigh Valley Health Network (LVHN), operating 13 hospitals and multiple clinics in Pennsylvania, detected an intrusion on February 6, 2023, and publicly disclosed a cyberattack on February 22. The ALPHV/BlackCat ransomware group claimed responsibility and, in March 2023, took the highly provocative step of posting sensitive clinical photographs of breast cancer patients \u2014 including nude images taken during treatment \u2014 to extort LVHN. LVHN refused to pay the ransom, triggering the data leak. The incident affected approximately 135,000 patients and employees. In September 2024, LVHN agreed to pay $65 million to settle the resulting class action lawsuit, among the largest healthcare breach settlements in U.S. history.",
    "attack_type": "Ransomware / Double Extortion / Patient Data Publication",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 135000,
    "residents_affected_in_state": "Primarily Pennsylvania residents; not separately broken out",
    "financial_impact": "$65 million class action settlement agreed September 2024. Ransom not paid (confirmed by LVHN). Legal fees and reputational costs additional.",
    "operational_impact": "Network taken offline. Clinical photos of cancer patients published on dark web. Reputational harm to patients. No confirmed care delivery deaths.",
    "remediation_disclosed": "Network taken offline and rebuilt. Law enforcement engaged. Credit monitoring offered. Legal settlement with 135,000 class members.",
    "primary_source_url": "https://www.lvhn.org/news/lehigh-valley-health-network-notices",
    "secondary_source_urls": [
      "https://www.compliancepoint.com/healthcare/lehigh-valley-health-to-pay-65m-after-ransomware-attack-exposed-patient-photos/",
      "https://cyberscoop.com/patient-sues-leigh-valley-ransomware/",
      "https://www.malwarebytes.com/blog/news/2023/03/breast-cancer-photos-published-by-ransomware-gang",
      "https://www.huntress.com/threat-library/ransomware/lehigh-valley-health-network-ransomware"
    ],
    "confidence_notes": "High confidence. Ransomware group publicly claimed responsibility and published exfiltrated data including patient photos as proof. $65M settlement from court records.",
    "sources_used": [
      "LVHN official notices",
      "CompliancePoint",
      "CyberScoop",
      "Malwarebytes",
      "Huntress"
    ],
    "id": "INC-00398",
    "year": 2023,
    "lat": 40.6084,
    "lng": -75.4902,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Lehigh Valley Health Network (LVHN)",
    "organization_type": "Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "PA",
    "hq_city": "Allentown",
    "hq_county": "Lehigh",
    "discovery_date": "2023-02-06",
    "disclosure_date": "2023-02-22",
    "executive_summary": "Lehigh Valley Health Network was struck by a BlackCat/ALPHV ransomware attack targeting its physician group (LVPG Delta Medix) in February 2023. Attackers stole sensitive data including nude photos of cancer patients undergoing radiation therapy and published them online when LVHN refused to pay the ransom. The incident affected approximately 134,000 patients and employees. LVHN ultimately agreed to a $65 million settlement.",
    "attack_type": "Ransomware with triple extortion (ALPHV/BlackCat)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 134000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$65 million class action settlement (2024)",
    "operational_impact": "Patient data including sensitive medical photos published on dark web; significant reputational harm; LVPG-Delta Medix systems compromised",
    "remediation_disclosed": "Ransom refused; FBI notified; cybersecurity experts engaged; class action settled for $65M",
    "primary_source_url": "https://www.compliancepoint.com/healthcare/lehigh-valley-health-to-pay-65m-after-ransomware-attack-exposed-patient-photos/",
    "secondary_source_urls": [
      "https://www.huntress.com/threat-library/ransomware/lehigh-valley-health-network-ransomware",
      "https://hipaatimes.com/lvhn-reaches-65-million-settlement-over-2023-data-breach",
      "https://www.netizen.net/news/post/5306/case-study-2023-cyberattack-on-lehigh-valley-health-network"
    ],
    "confidence_notes": "Extensively documented; LVHN confirmed; $65M settlement approved; OCR breach portal entry",
    "sources_used": [
      "CompliancePoint",
      "Huntress",
      "Paubox/HIPAATimes",
      "Netizen"
    ],
    "id": "INC-00399",
    "year": 2023,
    "lat": 40.6084,
    "lng": -75.4902,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Liberty Hospital (New Liberty Hospital Corporation)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "Liberty",
    "hq_county": "Clay",
    "discovery_date": "2023-12-19",
    "disclosure_date": "2023-12-19",
    "executive_summary": "On December 19, 2023, Liberty Hospital in Liberty, Missouri experienced a ransomware attack (attributed to INC ransomware group based on ransom note language) that forced the hospital to take its entire computer network offline, divert ambulances, and cancel appointments. The attackers claimed to have downloaded all confidential data. Notifications were sent to 264,541 individuals. Exposed information included patient names, medical and treatment information, demographic data, contact information, dates of birth, Social Security numbers, driver's license numbers, financial account numbers, and health insurance information. A class-action settlement was reached in 2025.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "INC ransomware group (suspected, based on ransom note language)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 264541,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class-action settlement reached (preliminary approval 2025); settlement amount not publicly disclosed",
    "operational_impact": "Entire computer network taken offline; ambulance diversions to other Kansas City area hospitals; elective appointments canceled; emergency department limited capacity",
    "remediation_disclosed": "Third-party cybersecurity specialists engaged; additional safety protocols implemented; systems restored over several days",
    "primary_source_url": "https://www.hipaajournal.com/ransomware-groups-attack-3-healthcare-providers/",
    "secondary_source_urls": [
      "https://databreaches.net/2023/12/20/self-proclaimed-hackers-take-credit-for-computer-problems-at-liberty-hospital/",
      "https://www.paubox.com/blog/liberty-hospital-reaches-preliminary-settlement-after-2023-data-breach",
      "https://www.libertyhospitaldataincidentsettlement.com"
    ],
    "confidence_notes": "High confidence. Liberty Hospital publicly confirmed the breach. HIPAA Journal reported 264,541 individuals affected. Paubox confirmed settlement in 2025. INC ransomware attribution is from security researcher analysis of ransom note language, not official hospital attribution.",
    "sources_used": [
      "HIPAA Journal",
      "DataBreaches.net",
      "Paubox",
      "Beacon Kansas City",
      "Healthcare Finance News"
    ],
    "id": "INC-00400",
    "year": 2023,
    "lat": 39.246479,
    "lng": -94.419079,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Life Management Center of Northwest Florida, Inc. (LMC)",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Panama City",
    "hq_county": "Bay",
    "discovery_date": "2023-03-31",
    "disclosure_date": "2023-07-25",
    "executive_summary": "Panama City, FL-based LMC detected a data security incident on March 31, 2023. Investigation confirmed an unauthorized actor accessed its systems and files containing patient PHI and employee data. The types of information potentially exposed included names, SSNs, driver's license numbers, medical treatment and diagnosis information, and health insurance data. Notifications mailed July 25, 2023.",
    "attack_type": "Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 19107,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Files containing PHI and PII accessed",
    "remediation_disclosed": "Digital environment secured; external cybersecurity experts engaged; notifications mailed July 25, 2023",
    "primary_source_url": "https://www.prnewswire.com/news-releases/life-management-center-of-northwest-florida-inc-provides-notice-following-data-security-incident-301885539.html",
    "secondary_source_urls": [
      "https://www.turkestrauss.com/2023/07/28/life-management-center-data-breach-investigation/"
    ],
    "confidence_notes": "HHS OCR lists 19,107 affected. PR Newswire official notice is primary source.",
    "sources_used": [
      "PR Newswire",
      "Turke & Strauss LLP"
    ],
    "id": "INC-00401",
    "year": 2023,
    "lat": 30.1586518,
    "lng": -85.6602936,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Los Angeles County Department of Mental Health",
    "organization_type": "County Health Department",
    "organization_type_bucket": "Behavioral / Mental health",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2023-10-17",
    "disclosure_date": "2023-12-21",
    "executive_summary": "While we are not aware of any actual or attempted misuse of your information, we are providing you with an overview of the incident, our ongoing response, and resources available to you right now to help protect your information, should you feel it is appropriate to do so. What Happened On October 17, 2023, the Department of Children's and Family Services (DCFS) fell victim to a cyber- attack. Specifically, a malicious actor or actors were able to access DCFS\u2019",
    "attack_type": "Credential-based Attack / Phishing",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Notice%20of%20Data%20Breach%20Sample%204861-2942-5048%20v1.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00402",
    "year": 2023,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "MD Valuecare (via HealthEC) \u2014 Virginia",
    "organization_type": "Healthcare Provider / Physician Network",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Virginia Beach",
    "hq_county": "Virginia Beach City",
    "discovery_date": "2023-10-26",
    "disclosure_date": "2023-12-22",
    "executive_summary": "MD Valuecare, a Virginia physician network, was identified as one of the first HealthEC clients notified of the July 2023 data breach. MD Valuecare's patient data \u2014 including names, SSNs, DOBs, diagnoses, prescriptions, and insurance information \u2014 was among the 4.6 million records compromised. MD Valuecare's breach count was reported as 112,005 records.",
    "attack_type": "Business Associate Breach (HealthEC) / Network Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 112005,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of $5.48M HealthEC class action settlement",
    "operational_impact": "Patient data including diagnoses, prescriptions, and insurance information exposed",
    "remediation_disclosed": "HealthEC notified MD Valuecare October 26, 2023; data breach letters sent December 22, 2023; $5.48M settlement reached",
    "primary_source_url": "https://www.hipaajournal.com/healthec-data-breach/",
    "secondary_source_urls": [
      "https://www.securityweek.com/4-5-million-individuals-affected-by-data-breach-at-healthec/"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal named MD Valuecare as HealthEC client with 112,005 records; SecurityWeek coverage.",
    "sources_used": [
      "HIPAA Journal",
      "SecurityWeek"
    ],
    "id": "INC-00403",
    "year": 2023,
    "lat": 36.8529,
    "lng": -75.978,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MNGI Digestive Health",
    "organization_type": "Gastroenterology Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2023-08-25",
    "disclosure_date": "2023-10-01",
    "executive_summary": "ALPHV/BlackCat ransomware attacked MNGI Digestive Health (a multi-location MN gastroenterology practice) on August 20, 2023, with detection on August 25. Attackers exfiltrated more than 2 terabytes of data. When MNGI did not pay the ransom, BlackCat posted 'TIME IS UP' and leaked over 800 GB of data, then threatened further spam and harassment campaigns. PHI of 767,670 patients was compromised including names, SSNs, medical information, health insurance data, financial account information, biometric data, usernames/passwords, and passport numbers \u2014 among the most extensive data types compromised in any healthcare breach. Individual notification letters not sent until July 2024. A $2.8 million settlement was reached in 2025.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 767670,
    "residents_affected_in_state": "Primarily Minnesota residents",
    "financial_impact": "$2.8 million class action settlement + $2.7M in mandatory security improvements (3 years); ransom not paid",
    "operational_impact": "800+ GB of patient data leaked publicly; massive PHI exposure; reputational damage; delayed notifications",
    "remediation_disclosed": "Yes \u2014 forensic investigation; settlement includes mandatory security measures for 3 years; notifications July 2024",
    "primary_source_url": "https://www.hipaajournal.com/mngi-digestive-health-data-breach-settlement/",
    "secondary_source_urls": [
      "https://databreaches.net/2025/06/24/mngi-digestive-health-settles-class-action-lawsuit-stemming-from-blackcat-attack/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, DataBreaches.net, HHS OCR breach portal (767,670 victims).",
    "sources_used": [
      "HIPAA Journal",
      "DataBreaches.net"
    ],
    "id": "INC-00404",
    "year": 2023,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MOVEit Transfer Supply Chain Campaign (Cl0p) \u2014 Healthcare Sector",
    "organization_type": "Supply Chain / Multiple Healthcare Organizations",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MULTIPLE",
    "hq_city": "Multiple",
    "hq_county": "Multiple",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-06-06",
    "executive_summary": "The Cl0p ransomware group exploited a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer file transfer application beginning May 27-31, 2023, affecting an estimated 2,600+ organizations globally and 85+ million individuals. In healthcare specifically, major confirmed victims include Maximus Federal Services (8-11M), Welltok (14.76M), Pension Benefit Information LLC (1.2M, via funeral/benefits services), Johns Hopkins Medicine (310K), Harris Health System (225K), UT Southwestern (98K), and dozens more. Cl0p did not encrypt data \u2014 pure data theft and extortion. HHS issued an alert to the healthcare sector. At least 734 organizations are confirmed affected with 42-47M records stolen in the healthcare-adjacent space.",
    "attack_type": "Supply Chain / MOVEit Zero-Day SQL Injection (CVE-2023-34362) / Data Theft",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 85000000,
    "residents_affected_in_state": "Nationwide and global; healthcare-specific affected count tracked by KonBriefing",
    "financial_impact": "No encryption ransom; Cl0p used data extortion model. Affected organizations faced remediation costs, notification costs, and legal fees. Total industry costs not aggregated.",
    "operational_impact": "No encryption/ransomware deployed. Pure data theft. Operational disruption only where organizations shut down MOVEit applications as precaution.",
    "remediation_disclosed": "Progress Software issued emergency patch May 31, 2023. Affected organizations decommissioned MOVEit. HHS issued sector alert. Individual organizations filed HHS OCR breach reports.",
    "primary_source_url": "https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
      "https://www.bleepingcomputer.com/news/security/clop-ransomware-claims-it-breached-130-orgs-using-goanywhere-zero-day/",
      "https://www.cybersecuritydive.com/news/prospect-medical-data-stolen/691945/"
    ],
    "confidence_notes": "High confidence on campaign-level facts. Individual organization counts vary by HHS OCR filings. Global totals from Emsisoft/KonBriefing tracking. CVE-2023-34362 officially documented by CISA.",
    "sources_used": [
      "Progress Software security advisory",
      "HIPAA Journal monthly breach report",
      "BleepingComputer",
      "Cybersecurity Dive",
      "Emsisoft tracking"
    ],
    "id": "INC-00405",
    "year": 2023,
    "lat": 39.8283,
    "lng": -98.5795,
    "geocode_source": "fallback_us_center",
    "is_multistate": true,
    "hq_outside_state": "MULTIPLE",
    "geocode_note": "Could not resolve location; placed at US geographic center."
  },
  {
    "organization_name": "Malama I Ke Ola Health Center (Community Clinic of Maui) \u2014 NASCO/Elevance connection",
    "organization_type": "Health Plan (Regence/NASCO MOVEit breach affecting HI members)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "Honolulu",
    "discovery_date": "2023-07-12",
    "disclosure_date": "2023-10-17",
    "executive_summary": "NASCO, a claims processing vendor for Elevance Health (formerly Anthem Blue Cross Blue Shield) and Regence health plans, was a victim of the MOVEit Transfer zero-day attack by the Clop ransomware group in July 2023. NASCO discovered the cyberattack on July 12, 2023. Regence health plan members \u2014 including those in Hawaii served through Regence/HMSA partnerships \u2014 had member data from 2015-2018 stored on NASCO's MOVEit server. NASCO notified Elevance on August 2, 2023 and confirmed Regence member impact on October 17, 2023. Compromised data included member names, IDs, dates of birth, addresses, phone numbers, and medication information.",
    "attack_type": "SQL injection exploit / Data exfiltration (MOVEit zero-day)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately reported for HI members",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member data 2015-2018 exposed; NASCO MOVEit server decommissioned",
    "remediation_disclosed": "MOVEit server decommissioned; FBI notified; notifications to affected members; cybersecurity firm retained",
    "primary_source_url": "https://www.usu.edu/legal/data-breach/10-31-2023-moveit",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/welltok-data-breach/"
    ],
    "confidence_notes": "NASCO/Regence MOVEit breach confirmed per Utah State University legal disclosure (details NASCO and Welltok/Virgin Pulse breaches affecting Regence members); Hawaii Regence/HMSA members potentially affected; confidence moderate \u2014 HI-specific count not separately reported. Note to parent: this may be better merged with HI-001 (HMSA/Navvis MOVEit) if both affect HMSA members via different vendors in same breach wave.",
    "sources_used": [
      "Utah State University Legal (Regence disclosure)",
      "HIPAA Journal"
    ],
    "id": "INC-00406",
    "year": 2023,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Managed Care of North America (MCNA Dental)",
    "organization_type": "Business Associate (Dental Benefits Plan)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "GA",
    "hq_city": "Fort Lauderdale (operations)",
    "hq_county": "Broward",
    "discovery_date": "2023-03-06",
    "disclosure_date": "2023-05-26",
    "executive_summary": "MCNA Dental, the nation's largest dental insurer for state Medicaid and CHIP programs, was hit by a LockBit ransomware attack. Attackers accessed systems and exfiltrated data between February 26 and March 7, 2023. MCNA refused to pay a $10 million ransom; LockBit published all stolen data on April 7, 2023. The breach is registered under the GA HIPAA entity address and impacted 8,923,662 individuals\u2014one of the largest healthcare breaches on record.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 8923662,
    "residents_affected_in_state": 17,
    "financial_impact": "Not publicly disclosed; $10M ransom demanded and refused",
    "operational_impact": "All stolen data published on LockBit dark web leak site",
    "remediation_disclosed": "Ransom refused; forensic investigation; HHS OCR and Maine AG notified",
    "primary_source_url": "https://www.hipaajournal.com/managed-care-of-north-america-hacking-incident-impacts-8-9-million-individuals/",
    "secondary_source_urls": [
      "https://www.twingate.com/blog/tips/MCNA%20Dental-data-breach",
      "https://www.kellerrohrback.com/news/mcna-data-breach",
      "https://www.bleepingcomputer.com/news/security/dental-insurer-mcna-discloses-data-breach-affecting-89-million-people/",
      "https://healthitsecurity.com/news/mcna-dental-data-breach-impacts-9m-individuals",
      "https://www.hipaajournal.com/mcna-dental-data-breach/"
    ],
    "confidence_notes": "HHS OCR confirms 8,923,662 affected. LockBit claim well-documented across multiple sources. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BleepingComputer",
      "HIPAA Journal",
      "Health IT Security",
      "Keller Rohrback",
      "Twingate"
    ],
    "id": "INC-00407",
    "year": 2023,
    "lat": 26.1223084,
    "lng": -80.1433786,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Managed Health Care Associates (NJ - MedStar related)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NJ",
    "hq_city": "Florham Park",
    "hq_county": "Morris",
    "discovery_date": "2023-04-01",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Managed Health Care Associates (MHCA), a New Jersey-based healthcare group purchasing organization and managed services company, reported a data security incident. The breach involved unauthorized access to data held on behalf of healthcare provider clients in the Northeast region.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare provider client data potentially compromised",
    "remediation_disclosed": "HHS OCR and clients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing; NJ healthcare BA; limited public detail",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00408",
    "year": 2023,
    "lat": 40.7881643,
    "lng": -74.3891647,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Manatee Memorial Hospital (via ESO Solutions) \u2014 FL",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Bradenton",
    "hq_county": "Manatee",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Manatee Memorial Hospital in Bradenton, Florida was one of the entities affected by the ESO Solutions ransomware attack of September 2023. ESO provided software for the hospital's emergency department and EMS operations. Patient data was exposed.",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient EMS records exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 2023; 24-month Kroll identity monitoring",
    "primary_source_url": "https://heimdalsecurity.com/blog/major-data-breach-at-eso-solutions-affects-2-7-million-patients/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 Heimdal Security and Morgan & Morgan named Manatee Memorial Hospital as ESO client.",
    "sources_used": [
      "Heimdal Security",
      "Morgan & Morgan"
    ],
    "id": "INC-00409",
    "year": 2023,
    "lat": 27.4989278,
    "lng": -82.5748194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Maternal & Family Health Services (MFHS)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Wilkes-Barre",
    "hq_county": "Luzerne",
    "discovery_date": "2022-04-04",
    "disclosure_date": "2023-01-10",
    "executive_summary": "Maternal & Family Health Services, one of Pennsylvania's largest healthcare providers, suffered a sophisticated ransomware attack detected on April 4, 2022. Unauthorized access to its systems spanned August 21, 2021 to April 4, 2022. The breach affected 461,070 individuals with data including names, DOBs, SSNs, financial account information, and medical records exposed. MFHS waited approximately 9 months to notify affected individuals.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 461070,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Nearly 8 months of unauthorized access; 461K records compromised",
    "remediation_disclosed": "Law enforcement notified; third-party forensics; credit monitoring offered",
    "primary_source_url": "https://mfhs.org/important-information-about-maternal-family-health-services-2022-cybersecurity-incident/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/maternal-family-health-services-sued-over-ransomware-attack-and-data-breach/",
      "https://www.jdsupra.com/legalnews/maternal-family-health-services-inc-3327501/"
    ],
    "confidence_notes": "Maine AG notice; class action filed; MFHS official notice",
    "sources_used": [
      "MFHS official notice",
      "HIPAA Journal",
      "JD Supra"
    ],
    "id": "INC-00410",
    "year": 2023,
    "lat": 41.2464824,
    "lng": -75.8817316,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Maximus Federal Services, Inc.",
    "organization_type": "Federal Contractor / Government Services",
    "organization_type_bucket": "Other healthcare entity",
    "state": "VA",
    "hq_city": "Reston",
    "hq_county": "Fairfax",
    "discovery_date": "2023-05-30",
    "disclosure_date": "2023-07-26",
    "executive_summary": "Maximus Federal Services, a government contractor providing Medicare and Medicaid appeals processing services to CMS and other federal agencies, was struck by the Cl0p group's MOVEit zero-day exploitation in late May 2023. Maximus stopped using MOVEit on May 31; CMS was notified June 2. Maximus disclosed in an SEC 8-K filing that between 8 and 11 million individuals may have been affected. CMS initially estimated 612,000 Medicare beneficiaries; this was later updated to 2,342,357 by CMS and to 2,781,617 on the HHS OCR portal. The breach compromised Social Security numbers, Medicare IDs, medical diagnoses, health insurance claims, and other sensitive federal beneficiary data.",
    "attack_type": "Supply Chain / MOVEit Zero-Day Exploit / Data Theft",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p (Clop ransomware group)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 11000000,
    "residents_affected_in_state": "Nationwide federal beneficiaries; not broken out by state",
    "financial_impact": "$15 million in expenses recorded by Maximus for Q2 2023 relating to the breach. Ongoing litigation. Disclosed in SEC 8-K filing.",
    "operational_impact": "MOVEit application taken offline May 31. No disruption to CMS benefit payments. Data exfiltration only.",
    "remediation_disclosed": "MOVEit patched and decommissioned. CMS briefed. Notification letters and 24-month free credit monitoring offered to affected Medicare beneficiaries. SEC 8-K filed disclosing incident and financial impact.",
    "primary_source_url": "https://www.cms.gov/newsroom/press-releases/cms-responding-data-breach-contractor",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/up-to-11-million-health-records-maximus-data-breach/",
      "https://www.healthcaredive.com/news/612K-Medicare-beneficiaries-affected-MoveIt-data-breach/689346/",
      "https://www.aha.org/news/headline/2023-07-28-medicare-beneficiaries-alerted-contractor-data-breach",
      "https://www.cms.gov/newsroom/press-releases/cms-notifies-additional-individuals-potentially-impacted-moveit-data-breach"
    ],
    "confidence_notes": "High confidence. Maximus SEC 8-K filing confirmed 8-11M range. HHS OCR portal: 2,781,617. CMS official press releases confirm Medicare-specific impact.",
    "sources_used": [
      "CMS.gov press releases",
      "HIPAA Journal",
      "Healthcare Dive",
      "AHA News",
      "Maximus SEC 8-K"
    ],
    "id": "INC-00411",
    "year": 2023,
    "lat": 38.953282,
    "lng": -77.3464516,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Maximus, Inc.",
    "organization_type": "Business Associate (Government Services Contractor)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "VA",
    "hq_city": "Reston",
    "hq_county": "Fairfax",
    "discovery_date": "2023-05-30",
    "disclosure_date": "2023-07-26",
    "executive_summary": "Reston, VA-based Maximus (government contractor managing Medicare/Medicaid programs) was one of the largest victims of the Clop group's MOVEit Transfer zero-day exploitation. Between 8 and 11 million individuals may have been affected. The breach was disclosed in an SEC 8-K filing. The Clop group claimed to have stolen 169 GB of data. Maximus recorded $15 million in expenses for Q2 2023 related to the breach.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2781617,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$15 million in breach-related expenses recorded in Q2 2023",
    "operational_impact": "Up to 11M individuals' PHI potentially accessed; SEC 8-K disclosure",
    "remediation_disclosed": "MOVEit stopped; patches installed; CMS and HHS notified; notifications issued",
    "primary_source_url": "https://www.hipaajournal.com/up-to-11-million-health-records-maximus-data-breach/",
    "secondary_source_urls": [
      "https://www.washingtontechnology.com/companies/2023/07/maximus-hit-moveit-ranswomware-breach/388901/",
      "https://www.cms.gov/newsroom/press-releases/cms-notifies-additional-individuals-potentially-impacted-moveit-data-breach"
    ],
    "confidence_notes": "HHS OCR lists 2,781,617 for Maximus; initial SEC filing cited 8-11M range. CMS press release confirms Medicare beneficiary impact.",
    "sources_used": [
      "HIPAA Journal",
      "Washington Technology",
      "CMS.gov"
    ],
    "id": "INC-00412",
    "year": 2023,
    "lat": 38.953282,
    "lng": -77.3464516,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Maximus, Inc. (Medicare/CMS \u2013 second filing)",
    "organization_type": "Business Associate (Government Services Contractor)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "VA",
    "hq_city": "Reston",
    "hq_county": "Fairfax",
    "discovery_date": "2023-05-30",
    "disclosure_date": "2023-11-16",
    "executive_summary": "Following the initial Maximus MOVEit disclosure, CMS notified 330,000 additional Medicare beneficiaries in November 2023. This second notification reflects the expanding scope of the Maximus/MOVEit breach affecting Medicare program participants, including Medicare Beneficiary Identifier numbers, SSNs, medical histories, and health insurance data.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) \u2013 Medicare beneficiary supplement",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 330000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Included in $15M total breach expenses",
    "operational_impact": "Additional 330,000 Medicare beneficiaries identified as affected",
    "remediation_disclosed": "CMS and Maximus jointly notified Medicare beneficiaries November 2023; 24-month credit monitoring offered",
    "primary_source_url": "https://www.cms.gov/newsroom/press-releases/cms-notifies-additional-individuals-potentially-impacted-moveit-data-breach",
    "secondary_source_urls": [],
    "confidence_notes": "CMS official press release is primary source. This is a supplement to incident #43 (Maximus primary).",
    "sources_used": [
      "CMS.gov"
    ],
    "id": "INC-00413",
    "year": 2023,
    "lat": 38.953282,
    "lng": -77.3464516,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "McLaren Health Care Corporation",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Grand Blanc",
    "hq_county": "Genesee",
    "discovery_date": "2023-08-22",
    "disclosure_date": "2023-10-04",
    "executive_summary": "McLaren Health Care, a 13-hospital nonprofit health system in Michigan, detected suspicious activity on or around August 22, 2023, and subsequently confirmed an ALPHV/BlackCat ransomware attack. The threat actor had access to McLaren's network between July 28 and August 23, 2023. In October 2023, ALPHV/BlackCat publicly claimed responsibility. McLaren filed a HIPAA breach report confirming 2,192,515 individuals were affected (later updated to 2,103,881 on the OCR portal). Compromised data included personal, insurance, and clinical information. McLaren's computer network was taken offline during containment, causing disruption across all 14 facilities, although patient care continued at all locations.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2192515,
    "residents_affected_in_state": "Primarily Michigan residents; not separately broken out",
    "financial_impact": "Not publicly disclosed. Multiple class action lawsuits filed. Ransom payment status unknown.",
    "operational_impact": "Network taken offline across 13 hospitals and associated facilities. Staff reverted to downtime procedures. No confirmed patient care deaths in official disclosures.",
    "remediation_disclosed": "Network isolated and restored. External forensic experts engaged. Law enforcement notified. HIPAA breach report filed Oct 10, 2023 (placeholder 501), updated to full count. Notification letters sent.",
    "primary_source_url": "https://www.mclaren.org/main/article/data-security-incident-notification-oct-2023",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/mclaren-health-care-ransomware-attack-may-affect-up-to-2-5-million-patients/",
      "https://techcrunch.com/2023/11/13/mclaren-cyberattack-millions-patients-ransomware/",
      "https://www.cshub.com/attacks/articles/iotw-mclaren-health-care-data-breach-impacts-22-million-people",
      "https://www.hipaajournal.com/mclaren-health-care-alphv-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/mclaren-health-care-breach-exposes-info-of-22-million-patients/",
      "https://oag.ca.gov/system/files/McLaren%20-%20Notice%20of%20Data%20Breach%20-%20CA_0.pdf"
    ],
    "confidence_notes": "High confidence. Breach reported to Maine AG: 2,192,515 affected. OCR portal: 2,103,881. ALPHV/BlackCat publicly claimed. McLaren confirmed data access in breach notices. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "CS Hub",
      "California AG Breach Notification",
      "HIPAA Journal",
      "McLaren Health Care official notice",
      "TechCrunch"
    ],
    "id": "INC-00414",
    "year": 2023,
    "lat": 36.203745472305805,
    "lng": -118.4695209226399,
    "is_multistate": true,
    "hq_outside_state": "Grand Blanc, Michigan",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "McLaren Health Care Corporation \u2014 2023 BlackCat Ransomware",
    "organization_type": "Nonprofit Integrated Health System (12 hospitals)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Grand Blanc",
    "hq_county": "Genesee",
    "discovery_date": "2023-08-22",
    "disclosure_date": "2023-11-09",
    "executive_summary": "ALPHV/BlackCat ransomware group accessed McLaren Health Care's systems between July 28 and August 23, 2023, exfiltrating approximately 6 terabytes of data including Social Security numbers and medical records of 2,103,881 patients. McLaren did not publicly acknowledge the breach until October 2023 following the hacker group's public claim, and notification letters were not mailed until November 9, 2023 \u2014 roughly three months after the breach. Class action lawsuits were consolidated in Eastern District of Michigan.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2103881,
    "residents_affected_in_state": "Primarily Michigan residents; some California residents also affected",
    "financial_impact": "$14 million class action settlement (preliminary approval sought April 2026); up to $5,000 per claimant for documented losses",
    "operational_impact": "Disruption to clinical operations at 12 Michigan hospitals; widespread patient data theft; cancer center (Karmanos) operations disrupted",
    "remediation_disclosed": "Yes \u2014 systems secured; forensic investigation completed; notification issued; security enhancements mandated under settlement for minimum 2 years",
    "primary_source_url": "https://compliancejunction.com/mclaren-health-care-settles-data-breach-lawsuit-for-14-million/",
    "secondary_source_urls": [
      "https://www.eko.law/mclaren-health-data-breach",
      "https://bridgemi.com/michigan-health-watch/ten-months-later-mclaren-reveals-740000-impacted-ransomware-attack/",
      "https://www.itcpeacademy.org/blog/news-mclaren-health-care-to-pay-14-million-over-back-to-back-ransomware-attacks"
    ],
    "confidence_notes": "High confidence. OCR breach portal, class action filings, extensive Michigan media coverage.",
    "sources_used": [
      "ComplianceJunction",
      "EKO Law",
      "Bridge Michigan",
      "ITCP Academy"
    ],
    "id": "INC-00415",
    "year": 2023,
    "lat": 42.9275,
    "lng": -83.6299,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Medinform Inc. (affecting Cleveland Clinic patients)",
    "organization_type": "Medical Billing Company (third-party vendor)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OH",
    "hq_city": "Cleveland (Cleveland Clinic patients affected)",
    "hq_county": "Cuyahoga",
    "discovery_date": "2022-12-21",
    "disclosure_date": "2023-05-24",
    "executive_summary": "MedInform, Inc., a medical billing company serving Cleveland Clinic, discovered suspicious activity December 21, 2022, leading to confirmation that an unauthorized party accessed its computer network between December 5 and December 21, 2022. PHI of Cleveland Clinic patients stored on MedInform's network was exposed. Approximately 14,453 patient files were potentially compromised including names, addresses, SSNs, medical billing information, and financial account information. A data breach notice was filed with the Massachusetts AG on May 24, 2023.",
    "attack_type": "Hacking / Network Server Breach",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown actor ('unknown actor' per breach notice)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14453,
    "residents_affected_in_state": "Primarily Ohio (Cleveland Clinic) patients; some out-of-state",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Billing data compromised; Cleveland Clinic's own systems not breached",
    "remediation_disclosed": "Yes \u2014 systems secured; investigation launched; notifications mailed May 2023",
    "primary_source_url": "https://www.jdsupra.com/legalnews/medinform-inc-announces-data-breach-6424529/",
    "secondary_source_urls": [
      "https://www.lawampm.com/medinform-data-breach/"
    ],
    "confidence_notes": "High confidence. JD Supra (Massachusetts AG filing), law firm reporting on Cleveland Clinic patient impact.",
    "sources_used": [
      "JD Supra",
      "Finkelstein & Partners"
    ],
    "id": "INC-00416",
    "year": 2023,
    "lat": 41.4993,
    "lng": -81.6944,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Memorial Hospital at Gulfport (via ESO Solutions)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MS",
    "hq_city": "Gulfport",
    "hq_county": "Harrison",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Memorial Hospital at Gulfport Health System was named as one of the entities affected by the ESO Solutions ransomware attack of September 2023. Patient EMS and hospital data was exposed through ESO's compromised software systems.",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient EMS records exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 12, 2023; 24-month Kroll identity monitoring offered",
    "primary_source_url": "https://heimdalsecurity.com/blog/major-data-breach-at-eso-solutions-affects-2-7-million-patients/",
    "secondary_source_urls": [
      "https://therecord.media/nearly-three-mil-affected-ransomware-medtech"
    ],
    "confidence_notes": "High confidence \u2014 Heimdal Security and The Record named Memorial Hospital at Gulfport as ESO client.",
    "sources_used": [
      "Heimdal Security",
      "The Record"
    ],
    "id": "INC-00417",
    "year": 2023,
    "lat": 30.3674198,
    "lng": -89.0928155,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Mercy Medical Center (via PJ&A breach)",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Canton",
    "hq_county": "Stark",
    "discovery_date": "2023-10-10",
    "disclosure_date": "2023-12-08",
    "executive_summary": "Mercy Medical Center in Canton, Ohio, learned on October 10, 2023 that its patient data was among the data compromised in the Perry Johnson & Associates (PJ&A) transcription service breach (March 27 \u2013 May 2, 2023). PJ&A confirmed that a backup of a database containing Mercy Medical Center data had been obtained by hackers. The investigation confirmed names, DOBs, addresses, admission/discharge dates, SSNs, and medical examination information were stolen for 97,132 individuals. Mercy chose to report directly to HHS OCR on November 3, 2023 rather than having PJ&A report on its behalf.",
    "attack_type": "Third-Party Vendor Breach (transcription service)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (PJ&A breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 97132,
    "residents_affected_in_state": "Ohio (Canton area) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Mercy's own systems not breached; transcription vendor's database backup stolen",
    "remediation_disclosed": "Yes \u2014 PJ&A services discontinued; patients notified December 8, 2023; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/pja-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal PJ&A comprehensive coverage with Mercy Medical Center Ohio specifically identified.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00418",
    "year": 2023,
    "lat": 40.7985464,
    "lng": -81.3749508,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Mercy Medical Center Iowa (via PJ&A breach \u2014 2023)",
    "organization_type": "Community Hospital (CommonSpirit/MercyOne affiliate)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2023-03-27",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Mercy Medical Center in Des Moines, Iowa (affiliated with CommonSpirit/MercyOne) was among the healthcare organizations affected by the Perry Johnson & Associates (PJ&A) transcription vendor breach of March\u2013May 2023. PJ&A, a medical transcription services vendor, had its network compromised, with hackers accessing patient data. Approximately 97,132 Mercy Medical Center Iowa patients were affected. Data exposed included name, address, date of birth, medical record number, hospital account number, admission diagnosis, and \u2014 for some \u2014 Social Security number and insurance information. This is the Iowa MercyOne/Mercy Medical component of the PJ&A breach documented in HIPAA Journal's December 2023 breach report.",
    "attack_type": "Third-Party Vendor Breach (PJ&A medical transcription hacking)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 97132,
    "residents_affected_in_state": "Iowa residents \u2014 primarily Polk County and central Iowa",
    "financial_impact": "Covered under broader PJ&A/Concentra liability",
    "operational_impact": "Mercy Medical Center's own systems not disrupted; transcription vendor breach",
    "remediation_disclosed": "Yes \u2014 patients notified December 2023; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/pja-data-breach/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal December 2023 report and PJ&A breach coverage confirm Mercy Medical Center Iowa (97,132 patients).",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR",
      "PJ&A breach reports"
    ],
    "id": "INC-00419",
    "year": 2023,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "MercyOne Iowa Hospitals (CommonSpirit / CHI Mercy \u2014 2022 Ransomware Component)",
    "organization_type": "Nonprofit Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-04-06",
    "executive_summary": "MercyOne Iowa hospitals, affiliated with CommonSpirit Health through the CHI Health at Home and MercyOne brand, were confirmed in CommonSpirit's April 2023 disclosure as having been affected by the October 2022 ransomware attack. Specifically affected Iowa entities included CHI Health Mercy Council Bluffs, CHI Health Missouri Valley, CHI Health Mercy Corning, Mercy Medical Center Des Moines and Affiliates, Mercy Home Health Services Iowa, and Mercy Hospice Johnston Iowa. This represents the Iowa-specific component of the broader CommonSpirit breach (MW-092).",
    "attack_type": "Ransomware (CommonSpirit parent system attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Iowa residents at Council Bluffs Missouri Valley Corning and Des Moines area facilities",
    "financial_impact": "Part of CommonSpirit $160M total loss",
    "operational_impact": "Iowa MercyOne facilities experienced EHR downtime, appointment delays, staff using paper fallback during attack and recovery",
    "remediation_disclosed": "Yes \u2014 systems restored; see CommonSpirit disclosure (MW-092)",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. CommonSpirit April 2023 update explicitly lists Iowa MercyOne/CHI Mercy facilities. Iowa-specific subset of MW-092.",
    "sources_used": [
      "HIPAA Journal",
      "CommonSpirit official statement (April 2023)"
    ],
    "id": "INC-00420",
    "year": 2023,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Meridian Behavioral Healthcare, Inc.",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Trenton",
    "hq_county": "Gilchrist",
    "discovery_date": "2023-08-11",
    "disclosure_date": "2023-12-22",
    "executive_summary": "Trenton, FL-based Meridian Behavioral Healthcare (30 locations, North Central Florida) detected unauthorized activity on August 11, 2023. Investigation confirmed unauthorized access to its network and files containing names, addresses, SSNs, DOBs, diagnoses, treatment data, health insurance, and prescription data. 98,808 individuals affected. Notifications mailed December 22, 2023.",
    "attack_type": "Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 98808,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI including SSNs and behavioral health diagnoses exposed",
    "remediation_disclosed": "Network secured; passwords reset; third-party forensics; notifications mailed December 22, 2023",
    "primary_source_url": "https://www.hipaajournal.com/meridian-behavioral-healthcare-data-breach/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/meridian-behavioral-healthcare-notifies-5920422/"
    ],
    "confidence_notes": "HHS OCR and HIPAA Journal corroborate 98,808 affected.",
    "sources_used": [
      "HIPAA Journal",
      "JD Supra"
    ],
    "id": "INC-00421",
    "year": 2023,
    "lat": 29.6132942,
    "lng": -82.8176203,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Merit Health Biloxi (via ESO Solutions)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MS",
    "hq_city": "Biloxi",
    "hq_county": "Harrison",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Merit Health Biloxi was among the healthcare providers affected by the ESO Solutions ransomware attack of September 2023. Merit Health River Oaks (also in MS) was also affected. ESO's software used for hospital emergency departments was compromised, exposing patient data.",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient EMS records exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 12, 2023; 24-month Kroll identity monitoring offered",
    "primary_source_url": "https://therecord.media/nearly-three-mil-affected-ransomware-medtech",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/eso-solutions-data-breach-update-eso-6676886/"
    ],
    "confidence_notes": "High confidence \u2014 The Record and Maine AG filing named Merit Health Biloxi as ESO client.",
    "sources_used": [
      "The Record",
      "JD Supra",
      "Maine AG filing"
    ],
    "id": "INC-00422",
    "year": 2023,
    "lat": 30.4007626,
    "lng": -88.8893818,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Merritt Healthcare Advisors",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CT",
    "hq_city": "Hamden",
    "hq_county": "New Haven",
    "discovery_date": "2023-02-01",
    "disclosure_date": "2023-03-15",
    "executive_summary": "Merritt Healthcare Advisors, a Connecticut-based business associate, reported an unauthorized email account access breach in March 2023 affecting 77,258 individuals. An employee email account was compromised and contained PHI.",
    "attack_type": "Phishing / unauthorized email account access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 77258,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email account with 77K+ individuals' PHI compromised",
    "remediation_disclosed": "HHS OCR breach report filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal March 2023 report",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00423",
    "year": 2023,
    "lat": 41.3836233,
    "lng": -72.9020069,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Mid-Florida Hematology & Oncology Centers (via HealthEC)",
    "organization_type": "Healthcare Provider / Oncology Practice",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Orange City",
    "hq_county": "Volusia",
    "discovery_date": "2023-10-26",
    "disclosure_date": "2023-12-22",
    "executive_summary": "Mid-Florida Hematology & Oncology Centers, P.A. (d/b/a Mid-Florida Cancer Centers) was identified as a HealthEC client affected by the July 2023 data breach. Patient data managed through HealthEC's population health management platform was exposed, including cancer patient diagnoses, prescriptions, and insurance information.",
    "attack_type": "Business Associate Breach (HealthEC) / Network Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4656293,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of $5.48M HealthEC class action settlement",
    "operational_impact": "Oncology patient data including diagnoses and prescriptions potentially exposed",
    "remediation_disclosed": "HealthEC notified clients; breach letters December 22, 2023",
    "primary_source_url": "https://www.seegerweiss.com/data-security-breaches/healthec-data-breach-lawsuit/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthec-data-breach/"
    ],
    "confidence_notes": "High confidence \u2014 Seeger Weiss LLP HealthEC lawsuit filing named Mid-Florida Hematology & Oncology Centers as impacted client.",
    "sources_used": [
      "Seeger Weiss LLP",
      "HIPAA Journal"
    ],
    "id": "INC-00424",
    "year": 2023,
    "lat": 28.9488761,
    "lng": -81.2986741,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Mission Health System (now HCA / Asheville area)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Asheville",
    "hq_county": "Buncombe",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Asheville-based Mission Health System was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Patient data was potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00425",
    "year": 2023,
    "lat": 35.5951,
    "lng": -82.5515,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Mississippi Baptist Medical Center (via ESO Solutions)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MS",
    "hq_city": "Jackson",
    "hq_county": "Hinds",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Mississippi Baptist Medical Center was one of the named affected entities in the ESO Solutions ransomware attack of September 2023. ESO Solutions, which provides software for hospital EMS departments, was compromised. Patient data including names, SSNs, DOBs, injury types, and treatment dates was exposed.",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient EMS and hospital data exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 12, 2023; 24-month Kroll identity monitoring offered",
    "primary_source_url": "https://therecord.media/nearly-three-mil-affected-ransomware-medtech",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/eso-solutions-data-breach-update-eso-6676886/",
      "https://heimdalsecurity.com/blog/major-data-breach-at-eso-solutions-affects-2-7-million-patients/"
    ],
    "confidence_notes": "High confidence \u2014 The Record named Mississippi Baptist Medical Center as confirmed ESO affected entity; also confirmed by JD Supra and Heimdal Security.",
    "sources_used": [
      "The Record",
      "JD Supra",
      "Heimdal Security"
    ],
    "id": "INC-00426",
    "year": 2023,
    "lat": 32.2988,
    "lng": -90.1848,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Monument Inc.",
    "organization_type": "Healthcare Provider (Telehealth)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2023-01-15",
    "disclosure_date": "2023-03-15",
    "executive_summary": "Monument Inc., a New York-based telehealth company specializing in alcohol use disorder treatment, disclosed that tracking pixels on its website transmitted sensitive health information of 108,584 individuals (including substance use disorder information) to third parties including Meta and Google without patient authorization, violating HIPAA and substance use disorder privacy regulations.",
    "attack_type": "Tracking pixel / unauthorized disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 108584,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Sensitive SUD-related PHI transmitted to Meta, Google without consent",
    "remediation_disclosed": "Tracking pixels removed; HHS OCR breach filed; FTC investigation",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal; notably involved SUD records with enhanced privacy protections",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00427",
    "year": 2023,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Morris Hospital & Healthcare Centers",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Morris",
    "hq_county": "Grundy",
    "discovery_date": "2023-04-23",
    "disclosure_date": "2023-08-18",
    "executive_summary": "Morris Hospital & Healthcare Centers suffered a network intrusion in April 2023 that was identified by Royal ransomware on its leak site on May 22. The Royal ransomware group later leaked more than 1 TB of data. The hospital notified 248,943 individuals of the breach, which exposed names, addresses, DOBs, SSNs, medical record numbers, account numbers, diagnostic codes, and employee information. A $1.36 million class action settlement was reached in 2025.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Royal ransomware",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 248943,
    "residents_affected_in_state": "Primarily Illinois residents",
    "financial_impact": "$1.36 million class action settlement (September 2025)",
    "operational_impact": "Network breach; patient records stolen; 1TB+ published; EHR and hospital operations reportedly unaffected",
    "remediation_disclosed": "Yes \u2014 investigation launched; breach reported to Maine AG; patients notified August 2023; law enforcement engaged",
    "primary_source_url": "https://www.hipaajournal.com/morris-hospital-data-breach-settlement/",
    "secondary_source_urls": [
      "https://databreaches.net/2023/08/18/il-morris-hospital-discloses-breach-that-royal-claimed-responsibility-for-in-may-notifies-248943/",
      "https://therecord.media/illinois-hospital-notifies-patients-employees-of-cyber-incident"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, DataBreaches.net, The Record.",
    "sources_used": [
      "HIPAA Journal",
      "DataBreaches.net",
      "The Record"
    ],
    "id": "INC-00428",
    "year": 2023,
    "lat": 41.3574135,
    "lng": -88.4215234,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Multiple NC Health Systems via Nuance/MOVEit (Atrium, Duke, UNC, WakeMed, Novant, ECU, Charlotte Radiology, FirstHealth, Mission, Catawba Valley, DLP Central Carolina, Wake Radiology, Novant New Hanover)",
    "organization_type": "Healthcare Provider (Multiple Systems via BA)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Multiple (Charlotte, Durham, Chapel Hill, Raleigh, Winston-Salem, Greenville, Pinehurst, Asheville, Hickory, Sanford, Wilmington)",
    "hq_county": "Multiple",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Nuance Communications (Microsoft subsidiary), a radiology documentation BA, was affected by the Clop group's MOVEit Transfer zero-day exploitation on May 28\u201329, 2023. Nuance disclosed the breach on behalf of 13 North Carolina healthcare provider clients. Data included names, addresses, DOBs, clinical data, imaging reports, diagnoses, treatments, medication dosages, and medical record numbers. Nuance reported the HIPAA breach to HHS OCR as affecting 1,225,054 individuals. An $8.5M class action settlement was reached with Nuance.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$8.5 million class action settlement with Nuance",
    "operational_impact": "Radiology documentation data stolen for 13 NC healthcare systems",
    "remediation_disclosed": "MOVEit patched; notifications mailed September 22, 2023; $8.5M settlement",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [
      "https://www.bankinfosecurity.com/nuance-notifying-13-nc-healthcare-clients-moveit-hacks-a-23107",
      "https://www.charlotteobserver.com/news/business/article279392684.html",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/8-5m-nuance-communications-moveit-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "HHS OCR lists 1,225,054 for Nuance (NC entity). 13 healthcare clients listed by name in multiple reliable sources.",
    "sources_used": [
      "HIPAA Journal",
      "BankInfoSecurity",
      "Charlotte Observer",
      "Top Class Actions"
    ],
    "id": "INC-00429",
    "year": 2023,
    "lat": 35.8231417,
    "lng": -78.6181239,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Muskogee City County Enhanced 911 Trust Authority (Oklahoma)",
    "organization_type": "Government Agency (Emergency Services)",
    "organization_type_bucket": "Other healthcare entity",
    "state": "OK",
    "hq_city": "Muskogee",
    "hq_county": "Muskogee",
    "discovery_date": "2023-01-01",
    "disclosure_date": "2023-06-01",
    "executive_summary": "Muskogee City County Enhanced 911 Trust Authority in Oklahoma reported a data breach. The HIPAA Journal referenced this entity in breach coverage. Limited additional details publicly available.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence; HIPAA Journal reference only",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00430",
    "year": 2023,
    "lat": 35.6630196,
    "lng": -95.3927706,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Nanticoke Memorial Hospital / DMS Health Technologies (Delaware MOVEit/supply chain)",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "DE",
    "hq_city": "Seaford",
    "hq_county": "Sussex",
    "discovery_date": "2023-03-27",
    "disclosure_date": "2023-11-10",
    "executive_summary": "DMS Health Technologies, a vendor providing health IT services to Nanticoke Memorial Hospital and Bayhealth Medical Center in Delaware, suffered a cyberattack on March 27, 2023, exposing data of 3,527 Delaware residents. The breach affected patients of both Delaware hospitals served by DMS Health Technologies.",
    "attack_type": "Hacking/IT Incident via vendor",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3527,
    "residents_affected_in_state": 3527,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "DE hospital patient data compromised via vendor",
    "remediation_disclosed": "Delaware AG notification filed; patients notified",
    "primary_source_url": "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/",
    "secondary_source_urls": [],
    "confidence_notes": "Delaware AG database confirms both Nanticoke and Bayhealth patient impact",
    "sources_used": [
      "Delaware AG database"
    ],
    "id": "INC-00431",
    "year": 2023,
    "lat": 38.6413452,
    "lng": -75.6114584,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "NationsBenefits Holdings, LLC",
    "organization_type": "BA/Vendor (Supplemental Benefits Management / Health Plan Services)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "FL",
    "hq_city": "Fort Lauderdale",
    "hq_county": "Broward",
    "discovery_date": "2023-01-30",
    "disclosure_date": "2023-03-14",
    "executive_summary": "NationsBenefits Holdings, LLC, a Fort Lauderdale, Florida-based company providing supplemental benefits management services to Medicare Advantage health plans, experienced a breach through the GoAnywhere MFT zero-day vulnerability (CVE-2023-0669) exploited by the Cl0p ransomware group in January 2023. NationsBenefits manages supplemental benefits (dental, vision, hearing, OTC card) for Medicare Advantage members across major health plans. HHS OCR breach notification confirmed 3,037,303 individuals affected, with compromised data including names, dates of birth, addresses, Social Security numbers, member ID numbers, health insurance information, and benefit information.",
    "attack_type": "Supply Chain / GoAnywhere MFT Zero-Day (CVE-2023-0669) / Data Theft",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 3037303,
    "residents_affected_in_state": "Not separately reported by state (nationwide Medicare Advantage members across multiple health plans)",
    "financial_impact": "Class action lawsuits filed. Settlement not publicly disclosed.",
    "operational_impact": "Supplemental benefits management data exposed for 3M+ Medicare Advantage members. Pure data theft via zero-day; no encryption of operational systems.",
    "remediation_disclosed": "GoAnywhere application patched. Third-party forensics. HHS OCR breach reported. Notification letters mailed. Credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/nationsbenefits-data-breach/",
    "secondary_source_urls": [
      "https://www.bleepingcomputer.com/news/security/clop-ransomware-claims-it-breached-130-orgs-using-goanywhere-zero-day/",
      "https://healthitsecurity.com/news/nationsbenefits-data-breach-3m-medicare-advantage-members",
      "https://www.scworld.com/brief/nationsbenefits-impacted-by-clop-goanywhere-attacks",
      "https://www.hipaajournal.com/nationsbenefits-holdings-confirms-3-million-record-data-breach/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report confirms 3,037,303. Cl0p GoAnywhere campaign well-documented. HIPAA Journal and Health IT Security corroborate. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BleepingComputer",
      "HIPAA Journal",
      "Health IT Security",
      "SC Media"
    ],
    "id": "INC-00432",
    "year": 2023,
    "lat": 26.1224,
    "lng": -80.1373,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Neuromusculoskeletal Center of the Cascades / Cascade Surgicenter LLC",
    "organization_type": "Healthcare Provider (Specialty Medical Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Bend",
    "hq_county": "Deschutes",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "The Neuromusculoskeletal Center of the Cascades, PC, and Cascade Surgicenter LLC in Oregon suffered an email breach in October 2023 when unauthorized actors accessed employee email accounts over a two-day period. Compromised data included names, contact details, dates of birth, Social Security numbers, driver's license numbers, financial data, medical records, health insurance information, and digital signatures for 22,796 individuals. Notification letters were mailed December 1, 2023. A class-action settlement was preliminarily approved.",
    "attack_type": "Email compromise / Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 22796,
    "residents_affected_in_state": "Majority OR-based (Central Oregon)",
    "financial_impact": "Class-action settlement; up to $2,500 reimbursement for identity theft losses",
    "operational_impact": "PHI and sensitive PII of 22,796 individuals exposed",
    "remediation_disclosed": "Email accounts secured; notifications sent; settlement offering credit monitoring and reimbursements",
    "primary_source_url": "https://hipaatimes.com/oregon-medical-center-offers-settlement-after-2023-data-breach",
    "secondary_source_urls": [],
    "confidence_notes": "Reported by Paubox/HIPAA Times; settlement preliminarily approved",
    "sources_used": [
      "HIPAA Times / Paubox"
    ],
    "id": "INC-00433",
    "year": 2023,
    "lat": 44.0582,
    "lng": -121.3153,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "New York-Presbyterian Hospital",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2022-06-01",
    "disclosure_date": "2023-03-20",
    "executive_summary": "New York-Presbyterian Hospital disclosed in March 2023 that its website used tracking pixels (from Meta, Google, and others) between 2016 and 2022 that transmitted patient information to third parties without consent. The breach affected 54,396 individuals. NYP was fined $300,000 by the NY AG and settled with OCR. A separate network server hacking incident affecting 12,000 patients was also reported in November 2022.",
    "attack_type": "Tracking pixel / unauthorized disclosure; separate network server hacking",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 54396,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$300,000 NY AG fine; OCR settlement $300,000",
    "operational_impact": "6 years of tracking pixel data transmitted to Meta, Google and other third parties",
    "remediation_disclosed": "Tracking tools disabled June 2022; third-party forensic assessment; $300K NY AG fine",
    "primary_source_url": "https://www.hipaajournal.com/new-york-presbyterian-pixel-settlement/",
    "secondary_source_urls": [
      "https://www.weitzlux.com/consumer-protection/data-privacy/newyork-presbyterian-meta-tracking-pixel/",
      "https://www.psqh.com/news/data-breach-costs-ny-presbyterian-300k/"
    ],
    "confidence_notes": "NYP confirmed; OCR breach report; NY AG settlement; Markup journalist report triggered disclosure",
    "sources_used": [
      "HIPAA Journal",
      "Weitz & Luxenberg",
      "PSQH"
    ],
    "id": "INC-00434",
    "year": 2023,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Northeast Surgical Group (ME/NH)",
    "organization_type": "Healthcare Provider (Surgical Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Portland",
    "hq_county": "Cumberland",
    "discovery_date": "2022-11-01",
    "disclosure_date": "2023-02-01",
    "executive_summary": "Northeast Surgical Group, a multi-site surgical practice operating in Maine and New Hampshire, reported a data security incident involving unauthorized access to patient surgical records and personal information. The breach affected patients who underwent surgical procedures at Northeast Surgical Group locations.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Surgical patient data including procedure and clinical records compromised",
    "remediation_disclosed": "HHS OCR and patients notified; Maine AG notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing; NE surgical practice; limited press coverage",
    "sources_used": [
      "Maine AG"
    ],
    "id": "INC-00435",
    "year": 2023,
    "lat": 43.6591,
    "lng": -70.2568,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Northwell Health (Pixel Tracking / FollowMyHealth)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New Hyde Park",
    "hq_county": "Nassau",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2023-06-01",
    "executive_summary": "Northwell Health was found to have shared patient information through tracking pixels embedded in its FollowMyHealth patient portal and website booking systems with third parties including Google and Facebook, without patient authorization. The data sharing constituted a HIPAA impermissible disclosure. Northwell settled a class action lawsuit resulting from the tracking pixel use.",
    "attack_type": "Tracking pixel / unauthorized disclosure to third parties",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Settlement amount undisclosed; $15 cash payment + monitoring services for class members",
    "operational_impact": "Patient portal and appointment booking data shared with Google, Facebook without consent",
    "remediation_disclosed": "Tracking pixels removed; class action settlement",
    "primary_source_url": "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/northwell-health-pixel-tracking-class-action-settlement/",
    "secondary_source_urls": [],
    "confidence_notes": "Class action settlement; Northwell confirmed via settlement process",
    "sources_used": [
      "Top Class Actions"
    ],
    "id": "INC-00436",
    "year": 2023,
    "lat": 40.7352157,
    "lng": -73.6883239,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Northwell Health / Perry Johnson & Associates (PJ&A)",
    "organization_type": "Health System (via Business Associate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "New Hyde Park",
    "hq_county": "Nassau",
    "discovery_date": "2023-05-02",
    "disclosure_date": "2023-11-03",
    "executive_summary": "Perry Johnson & Associates (PJ&A), a medical transcription company, was breached between March 27 and May 2, 2023. Northwell Health, New York's largest healthcare provider, was notified by PJ&A on July 21, 2023. The breach exposed PHI of Northwell patients including names, addresses, DOBs, medical records, SSNs, and clinical data. Approximately 3.9 million Northwell patients were initially estimated affected; NY AG confirmed ~4 million New Yorkers affected by the broader PJ&A breach.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3891565,
    "residents_affected_in_state": 4000000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI of millions of patients at Northwell and Crouse Health exposed",
    "remediation_disclosed": "Affected individuals notified; credit monitoring offered; NY AG warning issued",
    "primary_source_url": "https://www.hipaajournal.com/northwell-health-pja-data-breach/",
    "secondary_source_urls": [
      "https://ag.ny.gov/press-release/2023/attorney-general-james-warns-new-yorkers-impacted-medical-companys-data-breach",
      "https://www.classaction.org/data-breach-lawsuits/northwell-health-november-2023"
    ],
    "confidence_notes": "Northwell confirmed; NY AG press release; PJ&A OCR report: 8.95M total; class action filed",
    "sources_used": [
      "HIPAA Journal",
      "NY AG",
      "ClassAction.org"
    ],
    "id": "INC-00437",
    "year": 2023,
    "lat": 40.7352157,
    "lng": -73.6883239,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Norton Healthcare",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "KY",
    "hq_city": "Louisville",
    "hq_county": "Jefferson",
    "discovery_date": "2023-05-09",
    "disclosure_date": "2023-05-09",
    "executive_summary": "Louisville-based Norton Healthcare (8 hospitals, KY and IN) suffered a ransomware attack in May 2023. Attackers accessed network storage devices between May 7\u20139, 2023. The breach ultimately affected up to 2.5 million patients and employees. Medical record system and MyChart were not accessed. Norton did not pay the ransom. The BlackCat/ALPHV ransomware group claimed responsibility. A class action lawsuit was settled for $11 million in 2026.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat (ALPHV)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2500000,
    "residents_affected_in_state": "Primarily Kentucky residents; not separately broken out",
    "financial_impact": "$11 million class action settlement (2026)",
    "operational_impact": "Network storage devices compromised; computer systems partially disabled",
    "remediation_disclosed": "Ransom not paid; systems restored from backups; notifications mailed December 8, 2023",
    "primary_source_url": "https://www.hipaajournal.com/norton-healthcare-data-breach/",
    "secondary_source_urls": [
      "https://www.cybersecuritydive.com/news/norton-healthcare-ransomware-attack/702140/",
      "https://www.courier-journal.com/story/news/local/2026/02/24/norton-healthcare-settles-2023-data-breach-lawsuit/88841602007/",
      "https://www.hipaajournal.com/norton-healthcare-alphv-blackcat-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/norton-healthcare-discloses-data-breach-after-may-ransomware-attack/",
      "https://oag.ca.gov/system/files/Norton%20-%20CA_0.pdf",
      "https://www.techtarget.com/healthtechsecurity/news/366593939/Kentucky-Health-System-Confirms-Ransomware-Attack-Impacting-25M-Individuals",
      "https://www.securityweek.com/norton-healthcare-ransomware-hack-2-5-million-personal-records-stolen/",
      "https://www.hipaajournal.com/norton-healthcare-data-breach/",
      "https://nortonhealthcare.com/notice-of-data-security-incident/"
    ],
    "confidence_notes": "Highly reliable; Maine AG filing confirmed 2.5M affected. HIPAA Journal and Cybersecurity Dive corroborate. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification",
      "Courier-Journal",
      "Cybersecurity Dive",
      "HIPAA Journal",
      "Norton Healthcare official notice",
      "SecurityWeek",
      "TechTarget"
    ],
    "id": "INC-00438",
    "year": 2023,
    "lat": 35.82047913977181,
    "lng": -119.1730995090126,
    "is_multistate": true,
    "hq_outside_state": "Louisville",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Novant Health New Hanover Regional Medical Center",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Wilmington",
    "hq_county": "New Hanover",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Wilmington, NC-based Novant Health New Hanover Regional Medical Center was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Patient data was potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/",
    "secondary_source_urls": [],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00439",
    "year": 2023,
    "lat": 34.2352853,
    "lng": -77.9487284,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Ohio Trinity Medical Center / Trinity Hospital Twin City (CommonSpirit 2022 \u2014 Ohio component)",
    "organization_type": "Nonprofit Catholic Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Steubenville",
    "hq_county": "Jefferson",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-04-06",
    "executive_summary": "Trinity Medical Center East and West (Steubenville, Ohio) and Trinity Hospital Twin City (Dennison, Ohio), along with associated Ross Park Pharmacy (Steubenville), Trinity Professional Group, and Trinity Home Health \u2014 all part of the CommonSpirit Health / Catholic Health Initiatives system \u2014 were confirmed as affected by the October 2022 CommonSpirit ransomware attack in the April 2023 update. These Ohio facilities represent the Ohio-specific component of the CommonSpirit breach (MW-092). Patients who received care at these Ohio CHI facilities had their PHI potentially exposed.",
    "attack_type": "Ransomware (CommonSpirit parent system attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Ohio residents in Jefferson County and Tuscarawas County areas",
    "financial_impact": "Part of CommonSpirit $160M total loss",
    "operational_impact": "Eastern Ohio hospital facilities experienced EHR outage, appointment delays",
    "remediation_disclosed": "Yes \u2014 systems restored; see CommonSpirit disclosure (MW-092)",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. CommonSpirit April 2023 update lists Ohio Trinity facilities. Ohio-specific subset of MW-092.",
    "sources_used": [
      "HIPAA Journal",
      "CommonSpirit official statement (April 2023)"
    ],
    "id": "INC-00440",
    "year": 2023,
    "lat": 40.3600714,
    "lng": -80.6151034,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Optum Medical Care of New Jersey (phishing breach)",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "NJ",
    "hq_city": "East Hanover",
    "hq_county": "Morris",
    "discovery_date": "2023-03-01",
    "disclosure_date": "2023-05-01",
    "executive_summary": "Optum Medical Care of New Jersey experienced a phishing attack in March 2023 in which an employee's email account was compromised, exposing records of fewer than 2,000 individuals. The incident led to a $160,000 HHS OCR settlement for HIPAA Right of Access violations that predated the phishing breach. NJOAG also investigated the entity for separate compliance issues.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$160,000 OCR settlement",
    "operational_impact": "Employee email account compromised; <2,000 patient records exposed",
    "remediation_disclosed": "HHS OCR $160K settlement; corrective action plan",
    "primary_source_url": "https://abyde.com/hipaa-fine-announced-ocr-cracks-down-after-multiple-hipaa-complaints-over-patient-right-of-access",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/optum-medical-care-new-jersey-hipaa-settlement/"
    ],
    "confidence_notes": "OCR settlement confirmed; limited affected count",
    "sources_used": [
      "Abyde",
      "HIPAA Journal"
    ],
    "id": "INC-00441",
    "year": 2023,
    "lat": 40.8200998,
    "lng": -74.3648731,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "OrthoAlaska, LLC",
    "organization_type": "Healthcare Provider (Orthopedic Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Anchorage",
    "hq_county": "Anchorage Municipality",
    "discovery_date": "2023-07-31",
    "disclosure_date": "2023-10-11",
    "executive_summary": "OrthoAlaska detected unauthorized activity on July 31, 2023. An investigation revealed an unauthorized third party had access to a single server between July 2 and August 4, 2023. The breach was reported to HHS OCR on September 22, 2023, covering 176,203 patients. Potentially compromised data included names, addresses, dates of birth, driver's license numbers, state identification numbers, diagnoses, treatment information, health insurance information, and payment card information. OrthoAlaska also had a separate 2022 employee data breach.",
    "attack_type": "Hacking / Unauthorized server access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 176203,
    "residents_affected_in_state": "Majority AK-based",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Single server with patient PHI accessed for ~one month",
    "remediation_disclosed": "Systems secured; law enforcement notified; notifications sent",
    "primary_source_url": "https://www.hipaajournal.com/176200-ortho-alaska-patients-affected-by-data-breach/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/orthoalaska-announces-files-notice-of-4479612/"
    ],
    "confidence_notes": "HHS OCR confirmed 176,203 individuals; filed to OCR September 22, 2023",
    "sources_used": [
      "HIPAA Journal",
      "JD Supra"
    ],
    "id": "INC-00442",
    "year": 2023,
    "lat": 61.2181,
    "lng": -149.9003,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "OrthoAlaska, LLC (employee data breach \u2014 separate 2022 incident)",
    "organization_type": "Healthcare Provider (Orthopedic Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Anchorage",
    "hq_county": "Anchorage Municipality",
    "discovery_date": "2022-10-12",
    "disclosure_date": "2023-04-03",
    "executive_summary": "OrthoAlaska detected unauthorized activity on October 12, 2022. Investigation determined that employee data (names, SSNs, dates of birth, bank account numbers) was involved. Notifications were issued to affected former and current employees on April 3, 2023. This is a separate incident from OrthoAlaska's larger 2023 patient breach (AK-002).",
    "attack_type": "Hacking / Unauthorized access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 9580,
    "residents_affected_in_state": "AK-based employees",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee PII exposed",
    "remediation_disclosed": "Notifications sent; systems reviewed",
    "primary_source_url": "https://www.hipaajournal.com/176200-ortho-alaska-patients-affected-by-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Mentioned in HIPAA Journal coverage of AK-002 as a prior separate breach; 9,580 employees notified",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00443",
    "year": 2023,
    "lat": 61.2181,
    "lng": -149.9003,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Pan-American Life Insurance Group, Inc. (PALIG)",
    "organization_type": "Health Plan (Life/Health Insurance)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "LA",
    "hq_city": "New Orleans",
    "hq_county": "Orleans Parish",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-12-04",
    "executive_summary": "New Orleans-based PALIG (serves 7M+ policyholders across the Americas) was a victim of the Clop group's MOVEit Transfer zero-day exploitation. Files were exfiltrated on approximately May 28, 2023. The breach was confirmed on October 5, 2023 after file review. Two HHS OCR breach reports were filed: 105,387 and 94,807 individuals. Data included names, addresses, SSNs, DOBs, driver's licenses, medical data, financial and credit card info, and biometric data.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 200194,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "MOVEit Transfer disabled; files containing sensitive data exfiltrated",
    "remediation_disclosed": "MOVEit Transfer disabled; security patches applied; law enforcement notified; 24-month credit monitoring offered; notifications mailed December 4, 2023",
    "primary_source_url": "https://www.hipaajournal.com/pan-american-life-insurance-group-data-breach/",
    "secondary_source_urls": [
      "https://www.katc.com/news/covering-louisiana/pan-american-life-insurance-group-announces-data-security-incident"
    ],
    "confidence_notes": "HHS OCR filed two reports: 105,387 and 94,807. Total ~200,194. Clop MOVEit campaign well-established.",
    "sources_used": [
      "HIPAA Journal",
      "KATC News"
    ],
    "id": "INC-00444",
    "year": 2023,
    "lat": 29.9511,
    "lng": -90.0715,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Penn Yan Express / Upstate Regional Healthcare (MOVEit affiliates)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Various NY",
    "hq_county": "Various",
    "discovery_date": "2023-05-27",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Multiple New York healthcare providers were affected by the Clop ransomware group's exploitation of the MOVEit Transfer zero-day vulnerability in May-June 2023. These include various NY healthcare organizations using Progress Software's MOVEit product. The broader MOVEit campaign affected thousands of organizations globally including numerous NE healthcare entities.",
    "attack_type": "Supply chain (MOVEit zero-day)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (TA505)",
    "attribution_status": "reported",
    "individuals_affected_reported": "Multiple NE organizations; total not separately compiled",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare data exfiltrated from multiple NE entities using MOVEit",
    "remediation_disclosed": "Progress Software patches; law enforcement notified; OCR breach filings",
    "primary_source_url": "https://www.hhs.gov/sites/default/files/move-it-sector-alert-tlpclear.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "HHS sector alert on MOVEit; multiple NE healthcare orgs confirmed affected including UR, Mass General Brigham, and others",
    "sources_used": [
      "HHS.gov"
    ],
    "id": "INC-00445",
    "year": 2023,
    "geocode_note": "Exact city not resolved; placed at NY state centroid.",
    "lat": 42.03549932568742,
    "lng": -75.08101388429684,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Pension Benefit Information LLC (Minnesota \u2014 MOVEit breach)",
    "organization_type": "Benefits Verification Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Pension Benefit Information LLC (PBI), a Minneapolis, Minnesota-based benefits verification company serving health plans and insurers, was among the largest victims of the 2023 MOVEit file transfer software vulnerability exploitation by the Cl0p hacking group. PBI used MOVEit to transfer sensitive plan member data; the Cl0p group exploited the zero-day vulnerability between May 27\u201331, 2023. PBI reported to HHS OCR that 1,209,825 individuals were affected by the breach. The breach exposed sensitive personal and health-related information of health plan members whose data PBI processed for death-audit and benefits verification services. PBI is listed as a Minnesota business associate in the HHS OCR breach portal.",
    "attack_type": "MOVEit Zero-Day Exploitation / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Cl0p (CL0P)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1209825,
    "residents_affected_in_state": "Minnesota and other states \u2014 benefits plan members across multiple payers",
    "financial_impact": "Not separately disclosed; class action lawsuits filed",
    "operational_impact": "Benefits verification data exfiltrated; no confirmed clinical disruption",
    "remediation_disclosed": "Yes \u2014 MOVEit patched, HHS OCR notified, plan member notifications issued",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [
      "https://www.pbilawsuit.com",
      "https://www.cloaked.com/post/pbi-data-breach"
    ],
    "confidence_notes": "High confidence. HHS OCR breach portal, HIPAA Journal July 2023 report (1,209,825 individuals), class action documentation.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR",
      "PBI Lawsuit website",
      "Cloaked.com"
    ],
    "id": "INC-00446",
    "year": 2023,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Performance Health Technology (PH Tech) / Oregon Health Plan",
    "organization_type": "Business Associate (Health Data Management) / Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Beaverton",
    "hq_county": "Washington",
    "discovery_date": "2023-06-02",
    "disclosure_date": "2023-08-03",
    "executive_summary": "Performance Health Technology (PH Tech), an Oregon-based provider of data management services to health insurers, suffered a data breach when the Clop ransomware group exploited a zero-day vulnerability in Progress Software's MOVEit Transfer on May 28, 2023. The breach affected PH Tech's data files for Health Share of Oregon and other health plan clients. Approximately 1.7 million Oregon Health Plan (Medicaid) members were affected \u2014 among the largest healthcare breaches in Oregon history. Data stolen included names, dates of birth, Social Security numbers, addresses, insurance authorization, diagnosis codes, and claims information.",
    "attack_type": "MOVEit Transfer zero-day exploitation / Data theft",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Clop (Cl0p) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1752076,
    "residents_affected_in_state": 1700000,
    "financial_impact": "Not publicly disclosed; multiple class-action lawsuits filed",
    "operational_impact": "PH Tech took systems offline; 1.7M OR Medicaid members' data exposed",
    "remediation_disclosed": "System taken offline; access rebuilt; FBI notified; notifications sent; credit monitoring offered",
    "primary_source_url": "https://techcrunch.com/2023/08/04/oregon-health-data-accessed-moveit-mass-hacks/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/performance-health-technology-lawsuits-moveit-cyberattack/",
      "https://www.forthepeople.com/blog/oregon-health-plan-data-breach/"
    ],
    "confidence_notes": "HHS OCR breach portal: 1,752,076 individuals; OR Health Authority confirmed 1.7M OHP members affected",
    "sources_used": [
      "TechCrunch",
      "HIPAA Journal",
      "Morgan & Morgan / Oregon Health Plan notice"
    ],
    "id": "INC-00447",
    "year": 2023,
    "lat": 45.4871723,
    "lng": -122.80378,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Perry Johnson & Associates, Inc. (PJ&A)",
    "organization_type": "BA / Vendor (Medical Transcription)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NV",
    "hq_city": "Henderson",
    "hq_county": "Clark",
    "discovery_date": "2023-05-02",
    "disclosure_date": "2023-10-31",
    "executive_summary": "Perry Johnson & Associates (PJ&A), the largest privately owned medical transcription company in the U.S., suffered an unauthorized network intrusion between March 27 and May 2, 2023, with data exfiltration occurring April 7-9. PJ&A detected the breach May 2, completed its investigation September 28, 2023, and began notifying clients and patients October 31. The breach, reported to HHS OCR as affecting 8,952,212 individuals, became the largest healthcare data breach of 2023 when client-side reporting (notably Concentra: 3.99M, Cook County Health: 1.2M, North Kansas City Hospital: 502K) was added, bringing the total to at least 14 million. Compromised data included names, dates of birth, medical record numbers, Social Security numbers, insurance data, and clinical transcription content.",
    "attack_type": "Hacking / Data Exfiltration (type not specified by PJ&A)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 8952212,
    "residents_affected_in_state": "Nationwide; not separately reported by state",
    "financial_impact": "Not publicly disclosed. 40+ class action lawsuits filed against PJ&A and client healthcare organizations. No ransom disclosed.",
    "operational_impact": "No operational disruption to healthcare delivery. Data exfiltration only.",
    "remediation_disclosed": "Systems isolated. Third-party forensic investigation completed Sep 28, 2023. Client notifications began Oct 31, 2023. PJ&A filed HHS OCR report Nov 2, 2023. Individual notifications sent Nov 10, 2023 by PJ&A; some clients sent independent notifications.",
    "primary_source_url": "https://www.pja.com/data-security-incident-notice",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/pja-data-breach/",
      "https://techcrunch.com/2023/11/15/9-million-patients-had-data-stolen-after-us-medical-transcription-firm-hacked/",
      "https://www.scworld.com/news/hack-of-pja-tops-2023-us-healthcare-data-breaches-as-tally-jumps-by-4m"
    ],
    "confidence_notes": "High confidence. OCR report confirms 8.95M from PJ&A itself. Total including client-side reports exceeds 14M. Concentra separately confirmed 3.99M. Investigation completion date confirmed.",
    "sources_used": [
      "PJ&A official notice",
      "HIPAA Journal",
      "TechCrunch",
      "SC Media",
      "PR Newswire"
    ],
    "id": "INC-00448",
    "year": 2023,
    "lat": 36.0395,
    "lng": -114.9817,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Perry Johnson & Associates, Inc. dba PJ&A",
    "organization_type": "Business Associate (Medical Transcription)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NV",
    "hq_city": "Henderson",
    "hq_county": "Clark",
    "discovery_date": "2023-05-02",
    "disclosure_date": "2023-11-02",
    "executive_summary": "Perry Johnson & Associates (PJ&A), a Henderson, Nevada-based medical transcription company serving hospitals and physicians nationwide, suffered a major cyberattack. Unauthorized actors accessed PJ&A's systems from March 27 to May 2, 2023. The breach was reported to HHS as affecting 9,302,588 individuals, making it the second-largest US healthcare breach of 2023. Additional client-reported breaches (e.g., Concentra at ~4M additional) brought the total to well above 13 million. Stolen data included patient names, addresses, dates of birth, medical record numbers, SSNs, insurance information, and clinical records.",
    "attack_type": "Hacking/IT Incident \u2013 Network Intrusion / Data Theft",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 9302588,
    "residents_affected_in_state": "Not separately reported (nationwide client base)",
    "financial_impact": "Not publicly disclosed; multiple class action lawsuits filed; at least 40 lawsuits filed",
    "operational_impact": "Affected transcription services for multiple hospital clients nationally",
    "remediation_disclosed": "Clients notified July 21, 2023; forensic investigation completed September 28; patient notifications starting October 31",
    "primary_source_url": "https://www.hipaajournal.com/pja-data-breach/",
    "secondary_source_urls": [
      "https://techcrunch.com/2023/11/15/9-million-patients-had-data-stolen-after-us-medical-transcription-firm-hacked/",
      "https://www.yahoo.com/news/9-million-patients-had-data-200504968.html"
    ],
    "confidence_notes": "Very high confidence; OCR confirmed 9,302,588; Concentra separately confirmed 3,998,163 additional",
    "sources_used": [
      "HIPAA Journal, TechCrunch, Yahoo Finance/TechCrunch"
    ],
    "id": "INC-00449",
    "year": 2023,
    "lat": 36.0395,
    "lng": -114.9817,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "PharMerica Corporation",
    "organization_type": "Healthcare Provider (Pharmacy)",
    "organization_type_bucket": "Pharmacy",
    "state": "KY",
    "hq_city": "Louisville",
    "hq_county": "Jefferson",
    "discovery_date": "2023-03-29",
    "disclosure_date": "2023-05-12",
    "executive_summary": "Louisville-based PharMerica (Fortune 1000 long-term care pharmacy) discovered suspicious network activity in March 2023. Investigation confirmed the Money Message ransomware group had accessed systems and stolen 4.7 TB of data including PHI of 5,815,591 individuals. Stolen data included SSNs, medications, health insurance, addresses, and DOBs. Ransom was not publicly confirmed as paid; data was leaked. A $5.2M class action settlement received preliminary approval in 2026.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Money Message",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 5815591,
    "residents_affected_in_state": "Not separately reported by state (multi-state long-term care operations)",
    "financial_impact": "$5.2 million class action settlement (preliminary approval 2026)",
    "operational_impact": "4.7 TB of data stolen and reportedly leaked on dark web",
    "remediation_disclosed": "Third-party forensics engaged; HHS OCR notified; notifications mailed to affected individuals",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366637383/PharMerica-settles-data-breach-lawsuit-for-52M",
      "https://www.paubox.com/blog/pharmerica-reaches-5.2m-settlement-from-2023-breach",
      "https://www.bleepingcomputer.com/news/security/pharmerica-discloses-data-breach-impacting-58-million-patients/",
      "https://www.databreaches.net/pharmerica-reports-breach-affecting-nearly-6-million-individuals/",
      "https://www.hipaajournal.com/pharmerica-data-breach/"
    ],
    "confidence_notes": "HHS OCR portal lists 5,815,591 affected. Money Message attribution widely reported. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BleepingComputer",
      "DataBreaches.Net",
      "HIPAA Journal",
      "Paubox",
      "TechTarget"
    ],
    "id": "INC-00450",
    "year": 2023,
    "lat": 38.2527,
    "lng": -85.7585,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Phoenician Medical Center",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Phoenician Medical Center in Phoenix, Arizona reported a hacking incident in which data theft was confirmed. 162,500 individuals were affected. The breach was reported to HHS in July 2023.",
    "attack_type": "Hacking/IT Incident \u2013 Data Theft",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 162500,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; OCR data listed in HIPAA Journal monthly report for July 2023; limited additional sources",
    "sources_used": [
      "HIPAA Journal July 2023 Breach Report"
    ],
    "id": "INC-00451",
    "year": 2023,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Pima County / Maximus Health Services (Tucson MOVEit breach)",
    "organization_type": "Government / Business Associate (COVID-19 Contact Tracing)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "AZ",
    "hq_city": "Tucson",
    "hq_county": "Pima",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-08-30",
    "executive_summary": "Pima County, Arizona notified approximately 110,000 Tucson-area residents that their data was compromised in the global MOVEit breach via its contractor Maximus Health Services. Maximus had handled COVID-19 case investigations and contact tracing for the county from 2020 to 2022. Compromised data included names, addresses, dates of birth, phone numbers, email addresses, COVID-19 test results, symptoms, and treatment-related survey information. SSNs were not included.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day (via Maximus BA)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 110000,
    "residents_affected_in_state": 110000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Two years of complimentary credit monitoring and identity restoration via Experian offered",
    "primary_source_url": "https://tucson.com/news/local/article_d341a000-4768-11ee-812f-6f96662dacb5.html",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; Tucson.com/Arizona Daily Star documented; Pima County official announcement",
    "sources_used": [
      "Arizona Daily Star (Tucson.com)"
    ],
    "id": "INC-00452",
    "year": 2023,
    "lat": 32.2226,
    "lng": -110.9747,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Postmeds, Inc. (dba Truepill)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "San Mateo County / Bay Area",
    "hq_county": "Unknown",
    "discovery_date": "2023-08-30 to 2023-09-01",
    "disclosure_date": "Reported Oct 30, 2023 (notifications sent)",
    "executive_summary": "Unauthorized network access to files used for pharmacy management and fulfillment services at Truepill (Postmeds), a B2B pharmacy platform.",
    "attack_type": "Hacking/IT Incident \u2014 Data exfiltration / network intrusion",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown ('bad actor')",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2364359,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$7.5 million class action settlement (preliminary approval 2024)",
    "operational_impact": "No clinical operational disruption",
    "remediation_disclosed": "Enhanced security protocols and technical safeguards; additional workforce cybersecurity training; credit monitoring not offered due to limited SSN exposure",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.bleepingcomputer.com/news/security/pharmacy-provider-truepill-data-breach-hits-23-million-customers/",
      "https://www.hipaajournal.com/postmeds-truepill-sued-over-2-3-million-record-data-breach/",
      "https://www.fiercehealthcare.com/health-tech/digital-pharmacy-startup-truepill-confirms-hackers-accessed-health-data-23m-users"
    ],
    "confidence_notes": "PHI included patient names, medication type, demographic information, prescribing physician names. No SSNs compromised. Notifications sent 2+ months after breach discovery.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00453",
    "year": 2023,
    "lat": 37.563,
    "lng": -122.3255,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Precision Anesthesia Billing, LLC (PAB)",
    "organization_type": "Business Associate (Medical Billing)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Not separately reported",
    "hq_county": "Unknown",
    "discovery_date": "2023-05-04",
    "disclosure_date": "2023-07-07",
    "executive_summary": "Florida-based Precision Anesthesia Billing filed an HHS OCR breach report on July 7, 2023 following a ransomware attack that occurred between May 4 and May 7, 2023. The breach exposed names, SSNs, demographic information, PHI, and health insurance information of approximately 209,200 individuals, including patients of Athens Anesthesia Associates and other client practices.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 209200,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network server compromised; PHI of multiple healthcare clients exposed",
    "remediation_disclosed": "Network secured; law enforcement notified; third-party cybersecurity engaged",
    "primary_source_url": "https://www.jdsupra.com/legalnews/precision-anesthesia-billing-llc-files-7278172/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR lists 209,200 affected. JD Supra provides breach notice details.",
    "sources_used": [
      "JD Supra"
    ],
    "id": "INC-00454",
    "year": 2023,
    "geocode_note": "Exact city not resolved; placed at FL state centroid.",
    "lat": 27.56240968201409,
    "lng": -82.08544655713662,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Premier Health Partners",
    "organization_type": "Nonprofit Health System (Dayton, OH)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Dayton",
    "hq_county": "Montgomery",
    "discovery_date": "2023-07-12",
    "disclosure_date": "2023-10-12",
    "executive_summary": "Premier Health Partners identified suspicious activity on July 12, 2023. An investigation confirmed unauthorized access between July 7 and July 12, 2023, during which files were acquired. PHI exposed included names, DOBs, driver's licenses, SSNs, passport numbers, taxpayer IDs, digital signatures, login credentials, financial account information, and medical/insurance information for 10,833 individuals. Reported to HHS OCR October 12, 2023. Services remained fully operational throughout the incident.",
    "attack_type": "Network Server Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 10833,
    "residents_affected_in_state": "Ohio (Dayton area) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal \u2014 no disruption to clinical services; data exfiltrated from network",
    "remediation_disclosed": "Yes \u2014 investigation launched; notifications sent; credit monitoring and identity theft protection offered",
    "primary_source_url": "https://www.hipaajournal.com/premier-health-partners-2023-data-breach/",
    "secondary_source_urls": [
      "https://hipaatimes.com/premier-health-data-breach-exposes-sensitive-patient-and-employee-information"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, HHS OCR breach portal, Paubox/HIPAA Times.",
    "sources_used": [
      "HIPAA Journal",
      "Paubox/HIPAA Times"
    ],
    "id": "INC-00455",
    "year": 2023,
    "lat": 39.7589,
    "lng": -84.1916,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Premier Health Partners (via Welltok breach)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Dayton",
    "hq_county": "Montgomery",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2023-11-15",
    "executive_summary": "Premier Health Partners was among the healthcare organizations whose patients were affected by the Welltok, Inc. data breach (MOVEit vulnerability exploitation, May 30, 2023). Welltok sent warnings to Premier Health patients in November 2023 that they could be affected. The exact number of Premier Health patients affected by the Welltok breach was not separately confirmed in available sources. This is distinct from Premier Health's own July 2023 breach (MW-035).",
    "attack_type": "Third-Party Vendor Breach (MOVEit vulnerability)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p ransomware (MOVEit campaign)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately reported for Premier Health patients specifically",
    "residents_affected_in_state": "Ohio patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Premier Health's own systems not directly affected",
    "remediation_disclosed": "Yes \u2014 Welltok notified customers; Premier Health issued patient advisory",
    "primary_source_url": "https://dayton247now.com/news/local/ransomware-attack-affects-5700-in-huber-heights-2000-need-credit-monitoring",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. Dayton local news report references Welltok/Premier Health connection; no separate HHS OCR Premier Health/Welltok filing confirmed.",
    "sources_used": [
      "WKEF Dayton 24/7 Now"
    ],
    "id": "INC-00456",
    "year": 2023,
    "lat": 39.7589,
    "lng": -84.1916,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Prospect Medical Holdings",
    "organization_type": "For-profit hospital chain (16 hospitals, 165+ clinics in CA, CT, PA, RI)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles County",
    "discovery_date": "2023-08-03",
    "disclosure_date": "2023-08-04",
    "executive_summary": "On August 3, 2023, Prospect Medical Holdings discovered a ransomware attack that forced it to take systems offline across all its facilities in California, Connecticut, Pennsylvania, and Rhode Island. Emergency departments in multiple states closed and ambulances were redirected. The Rhysida ransomware group claimed responsibility in late August, stating it had stolen 1 TB of unique files and a 1.3 TB SQL database containing 500,000+ Social Security numbers and patient records. HHS OCR breach filings confirmed 1,309,096 individuals were affected.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1309096,
    "residents_affected_in_state": "NOT_SEPARATELY_DISCLOSED",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'notes': 'Rhysida listed stolen data for 50 Bitcoin (~$1.3M) on dark web Aug 2023. No confirmed payment disclosed by Prospect. Multiple class-action lawsuits pending.'}",
    "operational_impact": "EDs closed in CT (Manchester Memorial, Rockville General); ambulance diversions in multiple states; elective surgeries suspended; outpatient services including podiatry, wound care, women's wellness, gastroenterology suspended; paper charting across all facilities. Systems described as 'back up and running' by September 2023.",
    "remediation_disclosed": "Systems taken offline; third-party cybersecurity specialists engaged; FBI notified and investigating. Free credit monitoring and identity theft protection offered. New administrative and technical safeguards implemented.",
    "primary_source_url": "https://www.hipaajournal.com/prospect-medical-holdings-data-breach-lawsuit-survives-motion-to-dismiss/",
    "secondary_source_urls": [
      "https://www.cbsnews.com/news/prospect-medical-cyberattack-california-pennsylvania-hospital/",
      "https://www.cybersecuritydive.com/news/prospect-medical-data-stolen/691945/",
      "https://www.axios.com/2023/08/24/ransomware-stolen-data-prospect-medical-attack",
      "https://www.nytimes.com/2023/08/05/us/cyberattack-hospitals-california.html",
      "https://www.hipaajournal.com/prospect-medical-holdings-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/prospect-medical-holdings-ransomware-attack-impacted-16-hospitals/",
      "https://oag.ca.gov/system/files/Prospect%20-%20California%20Notification.pdf",
      "https://www.hipaajournal.com/ransomware-attack-on-prospect-medical-holdings-affects-facilities-in-multiple-states/",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
      "https://www.jdsupra.com/legalnews/prospect-medical-holdings-confirms-8735339/",
      "https://www.esentire.com/blog/rhysida-ransomware-group-turns-its-wrath-warns-esentire",
      "https://prospectmedical.com/cybersecurity-incident"
    ],
    "confidence_notes": "Rhysida claimed credit Aug 24, 2023 (not initially confirmed by Prospect). Rhysida listed 45% of data as leaked and 55% sold. Class action lawsuit (PA federal court) survived motion to dismiss Aug 2024. | HHS offered federal assistance during the attack. Rhysida is a relatively new RaaS group emerged May 2023. Multiple nationwide media coverage. Class action lawsuit filed naming multiple plaintiffs. | Cross-referenced across multiple authoritative sources. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Axios",
      "California AG Breach Notification",
      "Cybersecurity Dive",
      "HHS OCR Breach Portal",
      "JD Supra",
      "Organization notice / News / SEC",
      "Prospect Medical Holdings official notice",
      "eSentire"
    ],
    "id": "INC-00457",
    "year": 2023,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Prospect Medical Holdings / Crozer Health (Crozer-Keystone)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Springfield",
    "hq_county": "Delaware",
    "discovery_date": "2023-08-03",
    "disclosure_date": "2023-08-03",
    "executive_summary": "Crozer Health (owned by Prospect Medical Holdings) had its computer systems knocked offline by a ransomware attack on August 3, 2023, affecting four Delaware County, PA hospitals: Crozer-Chester Medical Center, Taylor Hospital, Delaware County Memorial Hospital, and Springfield Hospital. The attack was part of the broader Prospect Medical/Rhysida attack affecting facilities in multiple states. Patient care was disrupted significantly.",
    "attack_type": "Ransomware (Rhysida)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not separately disclosed for PA",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "4 Delaware County hospitals offline; computer systems down; staff reverted to paper records",
    "remediation_disclosed": "FBI notified; cybersecurity experts engaged; systems restored over weeks",
    "primary_source_url": "https://whyy.org/articles/4-delaware-county-hospitals-fall-victim-to-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.inquirer.com/health/crozer-health-computer-systems-down-20230803.html",
      "https://www.turkestrauss.com/2023/08/07/crozer-health-data-breach-investigation/"
    ],
    "confidence_notes": "Confirmed as part of broader Prospect Medical attack; WHYY and Philadelphia Inquirer reporting",
    "sources_used": [
      "WHYY",
      "Philadelphia Inquirer",
      "Turke & Strauss"
    ],
    "id": "INC-00458",
    "year": 2023,
    "lat": 39.9306677,
    "lng": -75.3201879,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Prospect Medical Holdings / Eastern Connecticut Health Network (ECHN)",
    "organization_type": "Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CT",
    "hq_city": "Manchester",
    "hq_county": "Hartford",
    "discovery_date": "2023-08-03",
    "disclosure_date": "2023-08-03",
    "executive_summary": "Rhysida ransomware struck Prospect Medical Holdings on August 3, 2023, affecting its Eastern Connecticut Health Network (ECHN) including Manchester Memorial and Rockville General hospitals. Rhysida claimed to have stolen 500,000 SSNs, corporate documents, and patient records. ECHN closed diagnostic labs, elective surgeries, and outpatient services for weeks; some facilities diverted ambulances for 17 days. Over 100,000 Connecticut residents had data compromised.",
    "attack_type": "Ransomware (Rhysida)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": 100000,
    "residents_affected_in_state": 100000,
    "financial_impact": "State advanced ~$7.5M to hospitals unable to bill Medicaid during outage; significant operational losses",
    "operational_impact": "Manchester Memorial diverted ambulances for 17 days; labs, elective surgeries, outpatient imaging closed for weeks; nearly half of elective procedures cancelled",
    "remediation_disclosed": "FBI notified; third-party cybersecurity experts; systems gradually restored over weeks; CT legislation introduced",
    "primary_source_url": "https://www.hipaajournal.com/ransomware-attack-on-prospect-medical-holdings-affects-facilities-in-multiple-states/",
    "secondary_source_urls": [
      "https://www.nytimes.com/2023/08/05/us/cyberattack-hospitals-california.html",
      "https://ctmirror.org/2024/03/18/ct-hospital-data-breach-bill/",
      "https://www.jdsupra.com/legalnews/prospect-medical-holdings-confirms-8735339/"
    ],
    "confidence_notes": "Extensively reported; CT Mirror investigation; CT AG and legislature involvement",
    "sources_used": [
      "HIPAA Journal",
      "NY Times",
      "CT Mirror",
      "JD Supra"
    ],
    "id": "INC-00459",
    "year": 2023,
    "lat": 41.7834017,
    "lng": -72.5231973,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Quorum Health Group / QuoRUM (NJ) - Atlantic Dialysis Management Services",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2023-02-01",
    "disclosure_date": "2023-03-15",
    "executive_summary": "Atlantic Dialysis Management Services, a New York-based business associate providing management services to dialysis centers, suffered a cyberattack in early 2023 that resulted in 18 separate breach reports to HHS OCR - one for each of its dialysis center clients. The attack led to New York having 18 breach reports in March 2023 alone, making it the most reported state that month. The total affected individuals across all reports ran to tens of thousands.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Multiple reports for each dialysis client; total unclear",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Multiple dialysis centers' patient PHI compromised via BA breach",
    "remediation_disclosed": "18 separate OCR breach reports filed; clients notified",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal March 2023 report explicitly notes Atlantic Dialysis Management Services caused NY to have 18 breach reports; 14 from this single BA",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00460",
    "year": 2023,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Regal Medical Group, Inc.",
    "organization_type": "Medical Group / IPA",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "Northridge, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2022-12-01",
    "disclosure_date": "2023-03-29",
    "executive_summary": "The incident occurred as follows: What On Friday, December 2, 2022, we noticed difficulty in accessing some of our Happened servers. After extensive review, malware was detected on some of our servers, which we later learned resulted in the threat actor accessing and exfiltrating certain data from our systems. We hired third-party vendors experienced in this area to assist with our response to the incident. The Regal team worked with our vendors to efficiently restore access to our systems and to analyze the impacted data. What At t",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3300638,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "At least 11 class action lawsuits filed in California courts within 3 weeks of disclosure",
    "operational_impact": "Systems encrypted; patient data exposed; Regal serves San Fernando Valley / LA area",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/Regal%20John%20Doe%20Letter%20Feb%201%202023_1.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/regal-medical-group-data-breach-3-million-patients/",
      "https://www.bleepingcomputer.com/news/security/regal-medical-group-data-breach-impacted-32-million-patients/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00461",
    "year": 2023,
    "lat": 34.2381,
    "lng": -118.5301,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Regal Medical Group, Lakeside Medical Organization, ADOC Acquisition, & Greater Covina Medical Group",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Bernardino / Orange County (Heritage Provider Network affiliate)",
    "hq_county": "Unknown",
    "discovery_date": "2022-12-01 (discovered 2022-12-02)",
    "disclosure_date": "2023-02-01",
    "executive_summary": "Ransomware attack on Heritage Provider Network affiliate Regal Medical Group and affiliates. Malware detected on servers; threat actor accessed and exfiltrated data before deploying ransomware.",
    "attack_type": "Hacking/IT Incident \u2014 Ransomware with prior data exfiltration (double extortion model)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ransomware group not publicly identified)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 3388856,
    "residents_affected_in_state": "Not separately reported (all operations in CA)",
    "financial_impact": "$49.99 million class action settlement (preliminary approval Oct 2025); 26 lawsuits consolidated into Head, et al. v. Regal Medical Group",
    "operational_impact": "Difficulty accessing servers reported; systems restored using third-party vendors",
    "remediation_disclosed": "Third-party cybersecurity vendors engaged; email spam filtering implemented; Norton LifeLock 12-month credit monitoring offered; law enforcement notified; FBI engaged",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://therecord.media/ransomware-attack-leads-to-massive-data-breach-from-california-health-network",
      "https://oag.ca.gov/system/files/Regal%20John%20Doe%20Letter%20Feb%201%202023.pdf",
      "https://www.securityweek.com/3-3-million-impacted-by-ransomware-attack-at-california-healthcare-provider/",
      "https://www.hipaajournal.com/regal-medical-group-ransomware-attack-southeast-colorado-hospital-district-email-breach/"
    ],
    "confidence_notes": "Largest healthcare data breach of 2023 at time of disclosure. PHI included names, SSNs, addresses, DOBs, diagnoses, lab results, prescriptions, radiology reports, health plan member numbers.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00462",
    "year": 2023,
    "lat": 34.1083,
    "lng": -117.2898,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Regence BlueCross BlueShield of Oregon (Welltok MOVEit)",
    "organization_type": "Health Plan (Health Insurance)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2023-07-26",
    "disclosure_date": "2023-11-17",
    "executive_summary": "Regence BlueCross BlueShield of Oregon was among healthcare plans affected by the Welltok MOVEit Transfer breach of May 2023. The Clop ransomware group exploited a zero-day vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer file transfer tool on May 30, 2023, gaining access to Welltok's server that contained member data for Regence's Oregon health plan. Compromised data included member names, dates of birth, addresses, health information, insurance details, and for some individuals, Social Security numbers and Medicare/Medicaid IDs. The Welltok breach is among the largest healthcare data breaches ever, affecting 14.76 million individuals total across 165+ clients.",
    "attack_type": "SQL injection exploit / Data exfiltration (MOVEit zero-day)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 14760000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member data exposed; PHI including SSNs and Medicare/Medicaid IDs for some members compromised",
    "remediation_disclosed": "Notifications sent November 2023; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/welltok-data-breach/",
    "secondary_source_urls": [
      "https://www.medicalrecords.com/hospital_breaches/regence-bluecross-blueshield-of-oregon",
      "https://techcrunch.com/2023/11/20/hackers-accessed-sensitive-health-data-of-welltok-patients/"
    ],
    "confidence_notes": "Regence BlueCross BlueShield of Oregon confirmed as Welltok client per HIPAA Journal and MedicalRecords.com reporting; specific Oregon plan count not separately disclosed; part of HHS OCR Welltok filing",
    "sources_used": [
      "HIPAA Journal",
      "MedicalRecords.com (National Center for Medical Records)",
      "TechCrunch",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00463",
    "year": 2023,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Regional Family Medicine",
    "organization_type": "Healthcare Provider (Primary Care Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Mountain Home",
    "hq_county": "Baxter",
    "discovery_date": "2023-06-26",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Mountain Home, AR-based Regional Family Medicine discovered what appeared to be an IT outage on June 26, 2023. Investigation confirmed unauthorized network access between June 8 and June 26, 2023. 80,166 individuals were affected. Exposed data included names, SSNs, driver's licenses, DOBs, biometric data, medical information, health insurance info, and account numbers.",
    "attack_type": "Network Intrusion / Data Exfiltration (Possible Ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 80166,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network inaccessible; PHI potentially exfiltrated",
    "remediation_disclosed": "Investigation concluded October 13, 2023; notifications mailed December 12, 2023",
    "primary_source_url": "https://www.jdsupra.com/legalnews/regional-family-medicine-confirms-data-4926313/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/regional-family-medicine-december-2023",
      "https://www.ktlo.com/2023/12/18/regional-family-medicine-alerts-patients-of-data-incident/"
    ],
    "confidence_notes": "Maine AG filing confirms 80,166 affected. JD Supra provides breach details. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "ClassAction.org",
      "JD Supra",
      "JD Supra, KTLO, ClassAction.org"
    ],
    "id": "INC-00464",
    "year": 2023,
    "lat": 36.3361391,
    "lng": -92.3801187,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Retina Group of Washington",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "MD",
    "hq_city": "Chevy Chase",
    "hq_county": "Montgomery",
    "discovery_date": "2023-03-26",
    "disclosure_date": "2023-12-22",
    "executive_summary": "Retina Group of Washington, an ophthalmology clinic chain operating in Maryland and Virginia, discovered a ransomware attack on March 26, 2023. Attackers encrypted files and exfiltrated data of 455,935 patients including names, addresses, DOBs, SSNs, driver's license numbers, medical records, and health insurance information. A $3.6 million settlement was reached.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 455935,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3.6 million settlement",
    "operational_impact": "Patient data access disrupted; 455K+ patient records exfiltrated",
    "remediation_disclosed": "Enhanced security policy; staff training; $3.6M settlement",
    "primary_source_url": "https://www.hipaajournal.com/retina-group-of-washington-data-breach-settlement/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/the-retina-group-of-washington-hit-with-class-action-over-march-2023-cyberattack",
      "https://www.sdosecurity.com/post/retina-group-of-washington-breach-and-3-6m-settlement"
    ],
    "confidence_notes": "OCR breach report; $3.6M settlement; 7 lawsuits consolidated; D. Maryland court",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "SDO Security"
    ],
    "id": "INC-00465",
    "year": 2023,
    "lat": 38.9813699,
    "lng": -77.0849245,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Reventics, LLC",
    "organization_type": "Business Associate (Revenue Cycle Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Not separately reported",
    "hq_county": "Unknown",
    "discovery_date": "2022-12-15",
    "disclosure_date": "2023-02-10",
    "executive_summary": "Florida-based Reventics (revenue cycle management, clinical documentation) suffered a Royal ransomware attack in December 2022. Attackers accessed and exfiltrated data. The initial breach report listed ~250,918 individuals; the HHS OCR report was later amended to 4,212,823 individuals. The Royal ransomware group added Reventics to its dark web leak site, publishing 16+ GB of files. Multiple class action lawsuits were filed.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Royal",
    "attribution_status": "claimed",
    "individuals_affected_reported": 4212823,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "16+ GB of files published by Royal on dark web leak site",
    "remediation_disclosed": "Systems secured; HHS OCR notified February 10, 2023; class action lawsuits filed",
    "primary_source_url": "https://www.hipaajournal.com/reventics-class-action-lawsuit-ransomware/",
    "secondary_source_urls": [
      "https://www.bankinfosecurity.com/reventics-lawsuit-a-21404",
      "https://www.medicalrecords.com/hospital_breaches/reventics-llc"
    ],
    "confidence_notes": "HHS OCR lists 4,212,823 (amended from initial 250,918). Royal attribution confirmed via dark web post.",
    "sources_used": [
      "HIPAA Journal",
      "BankInfoSecurity",
      "MedicalRecords.com"
    ],
    "id": "INC-00466",
    "year": 2023,
    "geocode_note": "Exact city not resolved; placed at FL state centroid.",
    "lat": 27.715299634732176,
    "lng": -82.01669220019967,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "SSM Health Care Corporation (via Navvis & Company breach)",
    "organization_type": "Nonprofit Catholic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "St. Louis",
    "hq_county": "St. Louis",
    "discovery_date": "2023-07-25",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Navvis & Company, a healthcare management company serving SSM Health, suffered a ransomware attack and data exfiltration between July 12\u201325, 2023. Attackers gained unauthorized access to Navvis's network, exfiltrated sensitive data, and deployed ransomware. Approximately 2.8 million individuals across multiple SSM Health client systems were affected, including SSM Health patients in Illinois, Missouri, Oklahoma, and Wisconsin. Compromised data included names, DOBs, SSNs, beneficiary HIC numbers, and detailed health plan/clinical information. A $6.5 million settlement was reached in April 2025.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2800000,
    "residents_affected_in_state": "MO IL OK WI patients; not separately reported by state",
    "financial_impact": "$6.5 million class action settlement (preliminary approval 2025); up to $7,000 per class member",
    "operational_impact": "Navvis's systems compromised; SSM Health's own systems not directly affected; patient notification on rolling basis Sept. 2023 \u2013 June 2024",
    "remediation_disclosed": "Yes \u2014 Navvis implemented additional safeguards; 12 months credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/navvis-ssm-health-data-breach-settlement/",
    "secondary_source_urls": [
      "https://stranchlaw.com/defendants-in-st-louis-data-breach-class-action-suit-agree-to-6-5-million-settlement/",
      "https://www.pcmatic.com/blog/ssm-health-patients-warned-of-data-breach/"
    ],
    "confidence_notes": "High confidence. Settlement court filings, HIPAA Journal, PC Matic.",
    "sources_used": [
      "HIPAA Journal",
      "Stranch Law",
      "PC Matic"
    ],
    "id": "INC-00467",
    "year": 2023,
    "lat": 38.627,
    "lng": -90.1994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Saint Francis Health System (MOVEit breach)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Tulsa",
    "hq_county": "Tulsa",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-07-26",
    "executive_summary": "Saint Francis Health System in Tulsa, Oklahoma, experienced a MOVEit Transfer vulnerability exploit. An unauthorized person exploited the zero-day vulnerability and copied files from SFHS's database on May 28, 2023. The compromised files contained limited patient billing and invoice information for medical devices, including names, dates of birth, medical record numbers, billing account numbers, and medical device information. 18,911 individuals were affected. Financial account information and Social Security numbers were not included.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day Exploitation",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 18911,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR system was separate from MOVEit and not impacted; limited billing data only",
    "remediation_disclosed": "Notifications sent; enhanced security measures",
    "primary_source_url": "https://www.medicalrecords.com/hospital_breaches/saint-francis-health-system",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 18,911 in July 2023 breach report; MedicalRecords.com detailed",
    "sources_used": [
      "MedicalRecords.com, HIPAA Journal"
    ],
    "id": "INC-00468",
    "year": 2023,
    "lat": 36.154,
    "lng": -95.9928,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Salem Regional Medical Center (Ohio) \u2014 PJ&A breach",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Salem",
    "hq_county": "Columbiana",
    "discovery_date": "2023-09-29",
    "disclosure_date": "2023-11-10",
    "executive_summary": "Salem Regional Medical Center in Salem, Ohio was confirmed affected by the Perry Johnson & Associates (PJ&A) transcription service breach (March 2 \u2013 May 2, 2023). Compromised data included names, SSNs, DOBs, addresses, phone numbers, medical records, and hospital account numbers. PJ&A provided free identity theft protection.",
    "attack_type": "Third-Party Vendor Breach (transcription service)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (PJ&A breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately reported",
    "residents_affected_in_state": "Ohio patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Salem's own systems not directly breached",
    "remediation_disclosed": "Yes \u2014 PJ&A providing free identity theft protection; patients notified",
    "primary_source_url": "https://www.hipaajournal.com/pja-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. HIPAA Journal confirmed Salem Regional as PJ&A breach victim; patient count not separately reported.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00469",
    "year": 2023,
    "lat": 40.9008923,
    "lng": -80.8567502,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Sanford Health (via DMS Health Technologies breach \u2014 2023)",
    "organization_type": "Rural Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2023-09-15",
    "disclosure_date": "2023-09-15",
    "executive_summary": "DMS Health Technologies, Sanford Health's mobile heart screening imaging vendor, experienced a data security incident between March 27 and April 24, 2023. Sanford Health patient information was among the data potentially compromised. A total of 21,211 Sanford Health patients were notified, including 10,334 in North Dakota, 4,967 in Minnesota, 2,685 in South Dakota, 1,058 in Iowa, and others across 36 states. Compromised data included patient names, DOBs, dates of service, physician names, and exam types.",
    "attack_type": "Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 21211,
    "residents_affected_in_state": 2685,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Sanford's own systems not directly affected; imaging vendor breached",
    "remediation_disclosed": "Yes \u2014 DMS Health notified affected patients; identity monitoring via Kroll offered",
    "primary_source_url": "https://news.sanfordhealth.org/news-release/vendor-for-sanford-health-announces-data-security-event/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Official Sanford Health press release with specific state-by-state patient counts.",
    "sources_used": [
      "Sanford Health News"
    ],
    "id": "INC-00470",
    "year": 2023,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Santa Clara Family Health Plan",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "San Jose",
    "hq_county": "Santa Clara",
    "discovery_date": "2023-01-30 (Fortra GoAnywhere exploit)",
    "disclosure_date": "2023-03-30",
    "executive_summary": "Santa Clara Family Health Plan affected by Clop ransomware group's exploitation of a zero-day vulnerability in Fortra's GoAnywhere MFT solution via vendor NationsBenefits. Data exfiltrated without file encryption.",
    "attack_type": "Hacking/IT Incident \u2014 Supply chain attack via Fortra GoAnywhere zero-day vulnerability (CVE-2023-0669); data exfiltration without encryption; 130 organizations attacked over 10-day period",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 276993,
    "residents_affected_in_state": 276993,
    "financial_impact": "$20 million Fortra class action settlement (final approval Sept 2025), Santa Clara Family Health Plan included as subclass",
    "operational_impact": "No clinical operational disruption; file transfer platform discontinued",
    "remediation_disclosed": "GoAnywhere usage stopped; law enforcement notified; cybersecurity firm engaged; new Microsoft Azure SFTP solution implemented; notifications mailed April 17, 2023; credit monitoring offered to SSN-exposed individuals",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/277000-santa-clara-family-health-plan-members-affected-by-goanywhere-hack/",
      "https://oag.ca.gov/system/files/SCFHP%20Nations%20security%20breach%20letter.pdf"
    ],
    "confidence_notes": "PHI included names, contact info, DOBs, SCFHP member ID, Medi-Cal CIN, health insurance numbers, SSNs, provider names, dates of service. Incident affected NationsBenefits, which notified SCFHP Feb 22, 2023.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00471",
    "year": 2023,
    "lat": 37.3382,
    "lng": -121.8863,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sentara Healthcare (via Credit Control Corporation)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Norfolk",
    "hq_county": "Norfolk City",
    "discovery_date": "2023-03-07",
    "disclosure_date": "2023-05-13",
    "executive_summary": "Norfolk-based Sentara Healthcare (12 hospitals, VA and NC) was impacted by a breach at R&B Corporation of Virginia (Credit Control Corporation), its debt collection contractor. An unauthorized party accessed CCC's systems between March 2 and March 7, 2023 and copied patient data including names, addresses, SSNs, account numbers, account balances, and dates of service. Sentara posted a data incident notice on May 13, 2023.",
    "attack_type": "Business Associate Data Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Sentara patient account and SSN data exposed via debt collection vendor",
    "remediation_disclosed": "CCC systems isolated; Sentara notified patients May 13, 2023",
    "primary_source_url": "https://www.jdsupra.com/legalnews/sentara-healthcare-patient-data-leaked-4756813/",
    "secondary_source_urls": [],
    "confidence_notes": "JD Supra provides breach details based on CCC Maine AG filing. Number of affected not publicly specified.",
    "sources_used": [
      "JD Supra"
    ],
    "id": "INC-00472",
    "year": 2023,
    "lat": 36.8508,
    "lng": -76.2859,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sharp HealthCare",
    "organization_type": "Nonprofit integrated health system (San Diego's largest; 4 acute care, 3 specialty, 2 affiliated hospitals)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Diego",
    "hq_county": "San Diego County",
    "discovery_date": "2023-01-12",
    "disclosure_date": "2023-02-03",
    "executive_summary": "On January 12, 2023, Sharp HealthCare detected unauthorized access to its website server (sharp.com). A threat actor accessed the server for a few hours and downloaded a file containing payment information for 62,777 patients who had paid medical bills online between August 12, 2021, and January 12, 2023. The stolen data was limited to names, internal identification numbers, invoice numbers, payment amounts, and facility names \u2014 notably excluding SSNs, bank account data, health insurance information, and clinical information. Sharp notified affected individuals by mail on February 3, 2023, and enhanced website security.",
    "attack_type": "Website server compromise / web server hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 62777,
    "residents_affected_in_state": "Predominantly CA given Sharp's San Diego patient base",
    "financial_impact": "{'ransom_paid': 'NOT_APPLICABLE', 'notes': 'No ransom involved. No litigation settlement publicly announced for this specific incident. Separate 2025 Episource breach via UnitedHealth subsidiary also affected Sharp patients (ransomware, scope TBD).'}",
    "operational_impact": "Limited to website server. EHR systems and FollowMyHealth patient portal were not affected. No care disruption reported.",
    "remediation_disclosed": "Affected server immediately taken offline Jan 12, 2023; third-party forensic firm engaged; enhanced website security tools implemented; dedicated toll-free line 833-753-3819.",
    "primary_source_url": "https://www.hipaajournal.com/hackers-compromised-sharp-healthcare-web-server-and-stole-patient-data/",
    "secondary_source_urls": [
      "https://thecyberexpress.com/sharp-healthcare-data-breach/",
      "https://www.10news.com/news/local-news/san-diego-news/sharp-healthcare-notifies-patients-of-data-breach",
      "https://www.hipaajournal.com/hackers-compromised-sharp-healthcare-web-server-and-stole-patient-data/",
      "https://www.kpbs.org/news/local/2023/02/06/sharp-healthcare-notifies-patients-of-data-breach",
      "https://www.securityweek.com/patient-information-compromised-in-data-breach-at-san-diego-healthcare-provider/",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf"
    ],
    "confidence_notes": "Notably limited in scope compared to other incidents \u2014 no SSNs or clinical data stolen. Separate 2025 Episource (UHG subsidiary) ransomware breach also impacted Sharp patients (health plan details, diagnoses, test results exposed). Sharp HIPAA right-of-access settlement ($70K with OCR, 2021) is unrelated to this incident. | Limited PHI: names, internal Sharp ID numbers, invoice numbers, payment amounts, Sharp facility names. No SSNs, bank info, dates of birth, clinical info, or medical records accessed. No credit monitoring offered due to limited exposure. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HHS OCR Breach Portal",
      "Organization notice / News / SEC"
    ],
    "id": "INC-00473",
    "year": 2023,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Singing River Health System",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MS",
    "hq_city": "Pascagoula",
    "hq_county": "Jackson",
    "discovery_date": "2023-08-16",
    "disclosure_date": "2023-12-18",
    "executive_summary": "Singing River Health System (3 hospitals, MS Gulf Coast) suffered a Rhysida ransomware attack in August 2023. The breach was initially reported as affecting 501 individuals (placeholder), revised to 252,890 in December 2023, and ultimately confirmed at 895,204 in May 2024. The Rhysida group reportedly leaked ~80% of the stolen data (754 GB, 420,766 files). Data included names, addresses, DOBs, SSNs, driver's licenses, and medical/insurance information.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": 895204,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "~754 GB of data leaked; hospital operations disrupted",
    "remediation_disclosed": "Third-party cybersecurity specialists engaged; 24-month credit monitoring offered; breach amended multiple times",
    "primary_source_url": "https://www.hipaajournal.com/singing-river-health-system-895000-breach/",
    "secondary_source_urls": [
      "https://heimdalsecurity.com/blog/singing-river-health-system-ransomware-attack-affects-nearly-900000/"
    ],
    "confidence_notes": "Maine AG breach notification confirms 895,204. Rhysida claim widely reported. Heimdal Security provides additional detail.",
    "sources_used": [
      "HIPAA Journal",
      "Heimdal Security"
    ],
    "id": "INC-00474",
    "year": 2023,
    "lat": 30.3658,
    "lng": -88.5561,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sleep Center Hawaii",
    "organization_type": "Healthcare Provider (Sleep Disorders Clinic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "Honolulu",
    "discovery_date": "2022-12-01",
    "disclosure_date": "2023-01-27",
    "executive_summary": "Sleep Center Hawaii was identified as a victim of hacker/unauthorized access affecting 5,097 Hawaii residents, per the Hawaii DCCA breach notification filed January 27, 2023.",
    "attack_type": "Hacking / Unauthorized access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5097,
    "residents_affected_in_state": 5097,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://cca.hawaii.gov/ocp/notices/security-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Hawaii DCCA confirmed; limited additional detail available Note: Hawaii DCCA Case 2023-0245 (notified 2023-01-27) lists 5,097 HI residents, consistent with OCR filing.",
    "sources_used": [
      "Hawaii DCCA Security Breach Notices"
    ],
    "id": "INC-00475",
    "year": 2023,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Southeastern Orthopaedic Specialists, PA",
    "organization_type": "Healthcare Provider (Orthopedics Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Greensboro",
    "hq_county": "Guilford",
    "discovery_date": "2023-10-25",
    "disclosure_date": "2023-12-01",
    "executive_summary": "Southeastern Orthopaedic Specialists (Piedmont Triad, NC) was attacked by the NoEscape ransomware group on October 25, 2023. The group claimed to have exfiltrated 3 GB of data and reportedly launched a DDoS attack against the organization's website. The HHS OCR breach report listed 35,533 individuals affected. SSNs, health records, and PHI were potentially exposed.",
    "attack_type": "Ransomware / Data Exfiltration / DDoS",
    "attack_category": "Ransomware",
    "threat_actor_name": "NoEscape",
    "attribution_status": "claimed",
    "individuals_affected_reported": 35533,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Website possibly DDoS-attacked; 3 GB of data claimed stolen",
    "remediation_disclosed": "Systems secured; law enforcement notified; investigation ongoing",
    "primary_source_url": "https://thehipaaetool.com/lawyers-move-fast-to-investigate-noescape-ransomware/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "HHS OCR lists 35,533 affected. NoEscape claim reported by HIPAA E-Tool and DataBreaches.net.",
    "sources_used": [
      "HIPAA E-Tool",
      "HIPAA Journal"
    ],
    "id": "INC-00476",
    "year": 2023,
    "lat": 36.0726,
    "lng": -79.792,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "St. Bernards Healthcare (via Welltok/MOVEit)",
    "organization_type": "Healthcare Provider / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Jonesboro",
    "hq_county": "Craighead",
    "discovery_date": "2023-05-30",
    "disclosure_date": "2023-12-04",
    "executive_summary": "St. Bernards Healthcare, Inc. in Arkansas was one of many healthcare organizations affected by the Welltok MOVEit Transfer data breach. Welltok's server was accessed May 30, 2023 by the Clop ransomware group exploiting a MOVEit zero-day (CVE-2023-34362). St. Bernards separately reported the breach to the Maine AG as affecting 89,556 individuals.",
    "attack_type": "MOVEit Exploit (Supply-Chain via Welltok)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 89556,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient health plan member data including names, DOBs, SSNs, addresses, Medicare/Medicaid IDs, and health insurance information exposed",
    "remediation_disclosed": "Welltok notified Maine AG December 4, 2023; breach letters sent to affected individuals; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/welltok-data-breach/",
    "secondary_source_urls": [
      "https://techcrunch.com/2023/11/20/hackers-accessed-sensitive-health-data-of-welltok-patients/"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal specifically named St. Bernards Healthcare with 89,556 count; TechCrunch and Maine AG filing.",
    "sources_used": [
      "HIPAA Journal",
      "TechCrunch",
      "Maine AG filing"
    ],
    "id": "INC-00477",
    "year": 2023,
    "lat": 35.8348088,
    "lng": -90.7045297,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "St. Luke's Diagnostic Cath Lab / Diagnostic Heart Center (CommonSpirit OH \u2014 2022)",
    "organization_type": "Cardiac Diagnostic Services",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "OH",
    "hq_city": "Houston / Boca Raton (CommonSpirit TX operated; OH-operated separately)",
    "hq_county": "Unknown",
    "discovery_date": "2022-10-02",
    "disclosure_date": "2023-02-01",
    "executive_summary": "St. Luke's Diagnostic Cath Lab and the Diagnostic Heart Center were specifically named in CommonSpirit Health's February 2023 update regarding the October 2022 ransomware attack. These cardiovascular service entities under CommonSpirit's network had their patient data included in the file servers accessed by the ransomware attackers. CommonSpirit sent individual patient notifications in February 2023 for patients of these facilities. This entry captures the cardiovascular care facilities within the CommonSpirit OH footprint that were separately called out in the February 2023 notification update.",
    "attack_type": "Ransomware (CommonSpirit parent system attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 623774,
    "residents_affected_in_state": "Ohio patients of these cardiovascular facilities",
    "financial_impact": "Part of CommonSpirit $160M total loss",
    "operational_impact": "Patient data on file servers accessed by attackers",
    "remediation_disclosed": "Yes \u2014 notifications sent February 2023; see CommonSpirit (MW-092)",
    "primary_source_url": "https://www.hipaajournal.com/commonspirit-health-issues-update-confirming-164-facilities-affected-by-ransomware-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. CommonSpirit February 2023 update specifically names these facilities.",
    "sources_used": [
      "HIPAA Journal",
      "CommonSpirit official statement (February 2023)"
    ],
    "id": "INC-00478",
    "year": 2023,
    "lat": 40.2544929,
    "lng": -84.336892,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "SundaySky Inc.",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2023-01-08",
    "disclosure_date": "2023-03-07",
    "executive_summary": "SundaySky, a New York-based video marketing software company serving health plans, detected unauthorized access to its US cloud-based environment on January 8, 2023. Hackers copied files containing Health Savings Account information and email addresses of 37,095 individuals between January 6-8, 2023.",
    "attack_type": "Hacking/IT Incident (cloud server breach)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 37095,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health savings account data and email addresses of 37K+ individuals exposed",
    "remediation_disclosed": "HHS OCR breach filed; affected individuals notified",
    "primary_source_url": "https://www.jdsupra.com/legalnews/sundaysky-inc-notifies-37-095-consumers-9885854/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/sundaysky-cyberattack-impacts-37000-health-plan-members/"
    ],
    "confidence_notes": "OCR breach report; JD Supra and HIPAA Journal reporting",
    "sources_used": [
      "JD Supra",
      "HIPAA Journal"
    ],
    "id": "INC-00479",
    "year": 2023,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sutter Health",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Sacramento, CA",
    "hq_county": "Sacramento County",
    "discovery_date": "2023-05-30",
    "disclosure_date": "2023-11-03",
    "executive_summary": "We had previously installed all published patches and security upgrades immediately upon such patches being made available by Progress Software, the maker of the MOVEit Transfer tool and conducted an examination of our systems and networks using all information available to determine the potential impact of the published vulnerabilities\u2019 presence on the MOVEit Transfer server and the security of data housed on the server and confirmed that there was no indication of any compromise at th",
    "attack_type": "Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 845441,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action filed Nov 2023; part of MOVEit MDL No. 3083",
    "operational_impact": "Welltok/Virgin Pulse (vendor) MOVEit server exploited May 30-31, 2023; Sutter not notified until September 22, 2023; disclosed November 3, 2023",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals']",
    "primary_source_url": "https://oag.ca.gov/system/files/Welltok%20Patient%20Notification%20Letter_Redacted.pdf",
    "secondary_source_urls": [
      "https://vitals.sutterhealth.org/sutter-health-vendor-reports-patient-information-incident/",
      "https://databreach.com/breach/sutterhealth.org-2024"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00480",
    "year": 2023,
    "lat": 38.5816,
    "lng": -121.4944,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sutter Health / Welltok (Virgin Pulse) \u2014 MOVEit Supply Chain Breach",
    "organization_type": "Nonprofit integrated health system (via business associate Welltok/Virgin Pulse)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Sacramento",
    "hq_county": "Sacramento County",
    "discovery_date": "2023-09-22",
    "disclosure_date": "2023-11-03",
    "executive_summary": "Sutter Health's patient engagement vendor Welltok (a Virgin Pulse company) was compromised during the global Cl0p MOVEit Transfer zero-day exploit campaign (CVE-2023-34362). The exfiltration occurred May 30\u201331, 2023, affecting approximately 845,441 Sutter Health patients. Data included names, dates of birth, health insurance information, provider names, and clinical details such as diagnoses and treatment codes. SSNs and financial information were not in the dataset. Sutter Health was notified by Virgin Pulse on September 22, 2023, and disclosed publicly November 3, 2023. A separate tracking pixel lawsuit (2015\u20132020 portal period) resulted in a $21.5M settlement in 2025.",
    "attack_type": "Supply-chain vulnerability exploitation (MOVEit zero-day; Cl0p ransomware group)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Cl0p (Clop) ransomware gang",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 845441,
    "residents_affected_in_state": "Predominantly CA given Sutter Health's Northern CA patient base",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'litigation_settlement_tracking_pixel': 21500000, 'notes': '$21.5M settlement (Jane Doe v. Sutter Health, tracking pixel lawsuit, 2015\u20132020 portal; court approved 2026). MOVEit-related litigation TBD.'}",
    "operational_impact": "No operational care disruption reported. Patient data exposed via vendor's MOVEit server; Sutter's own systems not directly compromised.",
    "remediation_disclosed": "Virgin Pulse applied MOVEit patches and implemented mitigation steps upon discovery. Sutter Health posted notice Nov 3, 2023; Virgin Pulse mailed individual notifications; 1 year of Experian credit monitoring offered. Dedicated hotline: 800-628-2141.",
    "primary_source_url": "https://vitals.sutterhealth.org/sutter-health-vendor-reports-patient-information-incident/",
    "secondary_source_urls": [
      "https://www.twingate.com/blog/tips/Sutter%20Health-data-breach",
      "https://databreach.com/breach/sutterhealth.org-2024",
      "https://www.sfchronicle.com/health/article/sutter-health-data-privacy-settlement-22162458.php"
    ],
    "confidence_notes": "Cl0p published MOVEit victim data online Dec 2024 (1.46M rows). MOVEit zero-day affected ~2,500 organizations globally. Sutter's tracking pixel lawsuit (unrelated to MOVEit) covered portal period June 2015\u2013March 2020.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00481",
    "year": 2023,
    "lat": 38.5816,
    "lng": -121.4944,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sutter North Surgery Center",
    "organization_type": "Ambulatory Surgery Center",
    "organization_type_bucket": "Other healthcare entity",
    "state": "CA",
    "hq_city": "Yuba City, CA",
    "hq_county": "Sutter County",
    "discovery_date": "2022-02-09",
    "disclosure_date": "2023-09-08",
    "executive_summary": "As a result of the investigation, we learned that an unauthorized actor accessed certain files and data stored within our systems. Upon learning this, we launched a comprehensive review of all potentially affected information to identify the individuals and information involved. On June 14, 2023, we determined that p",
    "attack_type": "Hacking / Third-Party Vendor Breach (MOVEit)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/Template%20Letter%20-%20Sightpath.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00482",
    "year": 2023,
    "lat": 39.1404,
    "lng": -121.6169,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Synergy Healthcare Services",
    "organization_type": "Business Associate (Healthcare Management Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "GA",
    "hq_city": "Not separately reported",
    "hq_county": "Unknown",
    "discovery_date": "2022-12-03",
    "disclosure_date": "2023-07-27",
    "executive_summary": "Synergy Healthcare Services detected unauthorized access between November 30 and December 3, 2022. The breach affected patients of Consulate Health Care, Raydiant Health Care, Independence Living Centers, Nspire Health Care, and affiliated care centers. Notification was delayed approximately 8 months. Exposed data included names, SSNs, DOBs, signatures, insurance details, contact info, government IDs, medical history, treatment details, and financial information. Over 58,000 individuals were affected per Texas AG filing.",
    "attack_type": "Network Server Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 25772,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI of patients at multiple care facilities exposed",
    "remediation_disclosed": "Investigation launched with cybersecurity experts; results provided May 16, 2023; notifications mailed late July 2023",
    "primary_source_url": "https://classlawdc.com/2023/08/01/synergy-healthcare-services-data-breach-investigation/",
    "secondary_source_urls": [
      "https://www.businesswire.com/news/home/20230802090632/en/Federman-Sherwood-Investigates-Synergy-Healthcare-Services-for-Data-Breach",
      "https://www.classaction.org/data-breach-lawsuits/synergy-healthcare-services-july-2023"
    ],
    "confidence_notes": "HHS OCR lists 25,772 (GA entity). Texas AG filing cites 58,000+ total affected. Delay in notification widely reported.",
    "sources_used": [
      "Migliaccio & Rathod LLP",
      "BusinessWire",
      "ClassAction.org"
    ],
    "id": "INC-00483",
    "year": 2023,
    "geocode_note": "Exact city not resolved; placed at GA state centroid.",
    "lat": 33.11869857159039,
    "lng": -83.98717243083266,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Syracuse ASC (Specialty Surgery Center of Central New York)",
    "organization_type": "Healthcare Provider (Ambulatory Surgery Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Syracuse",
    "hq_county": "Onondaga",
    "discovery_date": "2023-01-01",
    "disclosure_date": "2023-06-01",
    "executive_summary": "Specialty Surgery Center of Central New York (Syracuse ASC) in Syracuse, New York, an ambulatory surgery center, reported a data breach involving unauthorized access to patient health information. HHS OCR reached a $250,000 HIPAA settlement in 2025 addressing security rule deficiencies related to the incident.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$250,000 HHS OCR settlement (2025)",
    "operational_impact": "Surgical patient PHI compromised",
    "remediation_disclosed": "HHS OCR settlement with corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal 2025 OCR penalties table confirms $250K settlement for NY ASC",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00484",
    "year": 2023,
    "lat": 43.0481,
    "lng": -76.1474,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Tallahassee Memorial HealthCare (TMH)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Tallahassee",
    "hq_county": "Leon",
    "discovery_date": "2023-02-03",
    "disclosure_date": "2023-03-31",
    "executive_summary": "Tallahassee Memorial HealthCare detected unusual system activity on February 3, 2023. Investigation determined attackers accessed systems between January 26 and February 2, 2023 and exfiltrated files. TMH was forced to divert some emergency patients and cancel non-emergency procedures during the incident. The breach involved 20,376 individuals per HHS OCR. Data included names, addresses, DOBs, SSNs, health insurance, and limited treatment information.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 20376,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Emergency patient diversion; non-emergency procedure cancellations; EMR not accessed",
    "remediation_disclosed": "Systems secured; third-party forensics engaged; notifications mailed March 31, 2023",
    "primary_source_url": "https://www.hipaajournal.com/tallahassee-memorial-healthcare-patient-data-stolen-in-cyberattack/",
    "secondary_source_urls": [
      "https://www.cnn.com/2023/02/03/politics/cyberattack-hospital-tallahassee-memorial-florida",
      "https://www.portnox.com/blog/cyber-attacks/examining-the-tallahassee-memorial-hospital-cyber-attack/"
    ],
    "confidence_notes": "Well-documented; CNN reported on patient diversion. HHS OCR lists 20,376 affected.",
    "sources_used": [
      "HIPAA Journal",
      "CNN",
      "Portnox"
    ],
    "id": "INC-00485",
    "year": 2023,
    "lat": 30.4383,
    "lng": -84.2807,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Tallahassee Memorial Healthcare (via ESO Solutions)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Tallahassee",
    "hq_county": "Leon",
    "discovery_date": "2023-09-28",
    "disclosure_date": "2023-12-12",
    "executive_summary": "Tallahassee Memorial Healthcare was one of multiple hospitals affected by the ESO Solutions ransomware attack of September 28, 2023. ESO Solutions, a healthcare software provider for EMS and hospital systems, was targeted by ransomware. Patient data including names, SSNs, DOBs, injury types, injury dates, and treatment information was exposed. This is a separate incident from TMH's February 2023 ransomware attack (already in #11).",
    "attack_type": "Ransomware (Supply-Chain via ESO Solutions)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ESO Solutions ransomware)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2700000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately reported",
    "operational_impact": "Patient data including EMS records exposed through ESO vendor system",
    "remediation_disclosed": "ESO notified affected hospitals December 12, 2023; 24-month Kroll identity monitoring offered",
    "primary_source_url": "https://www.jdsupra.com/legalnews/eso-solutions-data-breach-update-eso-6676886/",
    "secondary_source_urls": [
      "https://therecord.media/nearly-three-mil-affected-ransomware-medtech",
      "https://www.hipaajournal.com/june-2022-healthcare-data-breach-report/"
    ],
    "confidence_notes": "Medium confidence \u2014 JD Supra/HIPAA Journal identified Tallahassee Memorial as ESO client affected; separate from the direct TMH February 2023 incident.",
    "sources_used": [
      "JD Supra",
      "The Record",
      "Heimdal Security"
    ],
    "id": "INC-00486",
    "year": 2023,
    "lat": 30.4383,
    "lng": -84.2807,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "TennCare (via HealthEC)",
    "organization_type": "Government Health Plan / Medicaid",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "TN",
    "hq_city": "Nashville",
    "hq_county": "Davidson",
    "discovery_date": "2023-10-26",
    "disclosure_date": "2023-12-22",
    "executive_summary": "TennCare (Tennessee's Medicaid program) was one of the covered entities whose beneficiary data was compromised in the HealthEC data breach of July 2023. HealthEC, a population health management platform, was hacked between July 14-23, 2023. The Division of TennCare / State of Tennessee was listed as an impacted HealthEC client. The number of TennCare beneficiaries affected was included in the total 4.6 million HealthEC breach.",
    "attack_type": "Business Associate Breach (HealthEC) / Network Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4656293,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of $5.48M HealthEC class action settlement",
    "operational_impact": "Medicaid beneficiary data including names, SSNs, DOBs, diagnoses, prescriptions, and insurance information exposed",
    "remediation_disclosed": "HealthEC notified clients October 26, 2023; data breach letters sent December 22, 2023; $5.48M settlement reached",
    "primary_source_url": "https://www.hipaajournal.com/healthec-data-breach/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/healthec-december-2023",
      "https://www.securityweek.com/4-5-million-individuals-affected-by-data-breach-at-healthec/"
    ],
    "confidence_notes": "High confidence \u2014 HealthEC named Division of TennCare as impacted client in breach notices; SecurityWeek, HIPAA Journal, HealthEC data breach $5.48M settlement.",
    "sources_used": [
      "HIPAA Journal",
      "SecurityWeek",
      "ClassAction.org",
      "Seeger Weiss LLP"
    ],
    "id": "INC-00487",
    "year": 2023,
    "lat": 36.1627,
    "lng": -86.7816,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "The Harris Center for Mental Health and IDD (MOVEit)",
    "organization_type": "Healthcare Provider (Mental Health/Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-07-12",
    "executive_summary": "The Harris Center for Mental Health and IDD was affected by the global MOVEit Transfer zero-day exploit. The breach exposed the PHI of 599,367 individuals. This was the first of two major breaches at the Harris Center in 2023 \u2014 a ransomware attack later followed in November.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day Exploitation",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 599367,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal reported operational disruption from MOVEit breach",
    "remediation_disclosed": "MOVEit server secured; notifications sent",
    "primary_source_url": "https://www.medicalrecords.com/hospital_breaches/the-harris-center-for-mental-health-and-idd",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/hipaa-breaches/"
    ],
    "confidence_notes": "High confidence; OCR breach report listed separately from Nov 2023 ransomware event",
    "sources_used": [
      "MedicalRecords.com, HIPAA Journal"
    ],
    "id": "INC-00488",
    "year": 2023,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "The Harris Center for Mental Health and IDD (Ransomware)",
    "organization_type": "Healthcare Provider (Mental Health/Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-11-07",
    "disclosure_date": "2023-11-09",
    "executive_summary": "The Harris Center for Mental Health and IDD suffered a ransomware attack on November 7, 2023, when its network was disrupted and employee files became inaccessible due to encryption. An unauthorized individual accessed and obtained data from the network between November 6 and November 7. The breach ultimately affected 238,463 individuals (in addition to the earlier MOVEit breach of 599,367). Compromised data included highly sensitive mental health PHI including diagnoses, prescriptions, SSNs, and Medicare/Medicaid IDs.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 238463,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network shut down preemptively; patient care delays; staff had limited file access",
    "remediation_disclosed": "Law enforcement notified; Harris County Office of Homeland Security engaged; third-party security specialists hired; policies reviewed",
    "primary_source_url": "https://www.theharriscenter.org/notice-data-security-incident",
    "secondary_source_urls": [
      "https://www.medicalrecords.com/hospital_breaches/the-harris-center-for-mental-health-and-idd",
      "https://www.govtech.com/security/harris-county-texas-hhs-provider-hit-with-ransomware"
    ],
    "confidence_notes": "High confidence; official notice from Harris Center website; GovTech documented",
    "sources_used": [
      "Harris Center official website, MedicalRecords.com, GovTech"
    ],
    "id": "INC-00489",
    "year": 2023,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "The Vitality Group LLC (Illinois \u2014 MOVEit breach)",
    "organization_type": "Employee Wellness Program Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-07-01",
    "executive_summary": "The Vitality Group LLC, a Chicago, Illinois-based employee wellness program company and health plan business associate, was affected by the 2023 MOVEit file transfer software zero-day vulnerability exploitation. The Vitality Group used MOVEit for transferring protected health information. The Cl0p hacking group exploited the vulnerability between May 27\u201331, 2023. Approximately 15,569 individuals were affected. The Vitality Group is listed as an Illinois business associate in HHS OCR's July 2023 breach report.",
    "attack_type": "MOVEit Zero-Day Exploitation / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Cl0p (CL0P)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 15569,
    "residents_affected_in_state": "Illinois residents among wellness program members",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI in MOVEit transfer system exfiltrated; no clinical disruption",
    "remediation_disclosed": "Yes \u2014 MOVEit patched; HHS OCR notified; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal July 2023 report citing HHS OCR. 15,569 individuals confirmed.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00490",
    "year": 2023,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Tower Health (PA - ransomware/hacking)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "West Reading",
    "hq_county": "Berks",
    "discovery_date": "2023-04-01",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Tower Health, a Reading, Pennsylvania health system operating Reading Hospital and several community hospitals in Berks, Chester, and Montgomery counties, reported a data security incident in 2023. The breach involved unauthorized access to patient health and financial information. Tower Health serves over 300,000 patients annually in southeastern Pennsylvania.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Southeastern PA multi-hospital patient data potentially compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal listing 2023; PA health system; limited press coverage",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00491",
    "year": 2023,
    "lat": 40.3337038,
    "lng": -75.9474322,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Transformative Healthcare / Fallon Ambulance Service",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Newton",
    "hq_county": "Middlesex",
    "discovery_date": "2023-04-21",
    "disclosure_date": "2023-12-27",
    "executive_summary": "Transformative Healthcare, parent of the now-defunct Fallon Ambulance Service in Massachusetts, detected unauthorized access to its archive environment in April 2023. ALPHV/BlackCat ransomware group claimed responsibility. The breach exposed data of 911,757 individuals who had previously received Fallon ambulance services, including names, addresses, SSNs, medical information, and COVID-19 testing data.",
    "attack_type": "Hacking/IT Incident (data exfiltration from archive)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "claimed",
    "individuals_affected_reported": 911757,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Data from archived systems of defunct Fallon Ambulance accessed; 911K individuals affected",
    "remediation_disclosed": "Law enforcement notified; class action filed",
    "primary_source_url": "https://www.hipaajournal.com/fallon-ambulance-service-data-breach/",
    "secondary_source_urls": [
      "https://therecord.media/transformative-healthcare-data-breach-ambulance",
      "https://www.classaction.org/news/transformative-healthcare-hit-with-class-action-over-2023-data-breach-affecting-911k-fallon-ambulance-service-patients"
    ],
    "confidence_notes": "OCR breach report; Maine AG notice; ALPHV/BlackCat claimed; class action filed",
    "sources_used": [
      "HIPAA Journal",
      "The Record",
      "ClassAction.org"
    ],
    "id": "INC-00492",
    "year": 2023,
    "lat": 42.3300435,
    "lng": -71.194862,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Tufts Health Plan / Point32Health (MOVEit/Welltok)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MA",
    "hq_city": "Canton",
    "hq_county": "Norfolk",
    "discovery_date": "2023-07-26",
    "disclosure_date": "2023-11-15",
    "executive_summary": "Point32Health, the Massachusetts-based parent of Tufts Health Plan, was among the healthcare organizations whose member data was compromised in the Welltok/MOVEit data breach affecting Tufts members. This was separate from the April 2023 ransomware attack on Harvard Pilgrim (also a Point32Health subsidiary). The Welltok breach exposed additional member data through the vendor's MOVEit file transfer vulnerability exploited by the Clop ransomware group.",
    "attack_type": "MOVEit Transfer vulnerability exploit (supply chain via Welltok)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P)",
    "attribution_status": "reported",
    "individuals_affected_reported": "Not separately reported from Welltok total",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed (separate from Harvard Pilgrim $16M settlement)",
    "operational_impact": "Additional MA Tufts Health Plan member data compromised via Welltok vendor",
    "remediation_disclosed": "HHS OCR notified; members notified; Welltok/MOVEit remediation",
    "primary_source_url": "https://www.hipaajournal.com/harvard-pilgrim-health-care-increases-ransomware-attack-2023/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence - documented as Welltok affected client; separate from Harvard Pilgrim incident",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00493",
    "year": 2023,
    "lat": 42.1584324,
    "lng": -71.1447732,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "UC San Diego Health (2023 Tracking Technology Breach)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Diego",
    "hq_county": "San Diego",
    "discovery_date": "Not specified (tracking technology active period)",
    "disclosure_date": "03/2023",
    "executive_summary": "UC San Diego Health disclosed impermissible disclosure of patient data to third parties via tracking code used by a business associate on UCSD Health websites.",
    "attack_type": "Unauthorized Access/Disclosure \u2014 Tracking pixel/analytics code impermissible disclosure to third parties",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable",
    "attribution_status": "unknown",
    "individuals_affected_reported": 23000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed (separate from 2021 phishing settlement)",
    "operational_impact": "No clinical operational disruption",
    "remediation_disclosed": "Tracking code removed; additional privacy safeguards implemented",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "Separate incident from 2021 phishing breach. 23,000 individuals affected per OCR report.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00494",
    "year": 2023,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "UCHealth (Nuance/MOVEit breach)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CO",
    "hq_city": "Aurora",
    "hq_county": "Arapahoe",
    "discovery_date": "2023-07-01",
    "disclosure_date": "2023-09-15",
    "executive_summary": "UCHealth was informed by Nuance Communications that its MOVEit Transfer product had been accessed by an unauthorized third party, potentially exposing data for approximately 13,000 UCHealth patients. Potentially accessed data included patient names, medical record numbers, dates of services, dates of birth, and physician names. Social Security numbers and financial information were not included. UCHealth's own systems were not directly impacted.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day (via Nuance Communications)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "UCHealth's EMR not impacted",
    "remediation_disclosed": "Nuance and UCHealth implementing additional safeguards; notifications sent",
    "primary_source_url": "https://www.uchealth.org/notifications/software-vendor-shares-information-about-data-breach-2/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; UCHealth official website notice",
    "sources_used": [
      "UCHealth official website"
    ],
    "id": "INC-00495",
    "year": 2023,
    "lat": 39.7294,
    "lng": -104.8319,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UHS of Delaware Inc. (email account breach)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "PA",
    "hq_city": "King of Prussia",
    "hq_county": "Montgomery",
    "discovery_date": "2023-01-01",
    "disclosure_date": "2023-03-15",
    "executive_summary": "UHS of Delaware Inc., a Universal Health Services subsidiary operating as a business associate, reported unauthorized access to employee email accounts in March 2023, affecting 40,290 individuals. The breach involved PHI contained within the email accounts.",
    "attack_type": "Phishing / unauthorized email account access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 40290,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "40K+ individuals' PHI in email accounts potentially accessed",
    "remediation_disclosed": "HHS OCR breach report filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal March 2023 report",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00496",
    "year": 2023,
    "lat": 40.0947625,
    "lng": -75.3851334,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "US Wellness Inc.",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MD",
    "hq_city": "Annapolis",
    "hq_county": "Anne Arundel",
    "discovery_date": "2023-01-29",
    "disclosure_date": "2023-03-30",
    "executive_summary": "US Wellness Inc., a Maryland-based wellness program administrator and business associate, was affected by the Clop ransomware group's exploitation of a zero-day vulnerability in Fortra's GoAnywhere managed file transfer solution in early 2023. The breach compromised data of 11,459 individuals associated with its healthcare clients.",
    "attack_type": "Supply chain (GoAnywhere zero-day exploitation)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "reported",
    "individuals_affected_reported": 11459,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "11K+ individuals' data exfiltrated via GoAnywhere exploitation",
    "remediation_disclosed": "HHS OCR breach filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/march-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal March 2023 report; Clop GoAnywhere campaign confirmed",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00497",
    "year": 2023,
    "lat": 38.9784,
    "lng": -76.4922,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UT Southwestern Medical Center (MOVEit breach)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Dallas",
    "hq_county": "Dallas",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-07-01",
    "executive_summary": "UT Southwestern Medical Center was one of hundreds of organizations affected by the global MOVEit Transfer zero-day vulnerability exploited by the Clop group in May 2023. 98,437 patients had their protected health information compromised, including names, dates of birth, Social Security numbers, financial account information, driver's license information, and medical information including diagnoses, treatment information, and physician information.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day Exploitation",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 98437,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "UTSW's systems were not directly compromised; MOVEit transfer tool affected",
    "remediation_disclosed": "Third-party forensic firm engaged; notifications sent; this was one of multiple UTSW breaches in 2023-2024",
    "primary_source_url": "https://www.hipaajournal.com/ut-southwestern-medical-center-data-breach-43000/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 98,437 in July 2023 breach report",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00498",
    "year": 2023,
    "lat": 32.7767,
    "lng": -96.797,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Uintah Basin Healthcare",
    "organization_type": "Healthcare Provider (Community Hospital)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "UT",
    "hq_city": "Roosevelt",
    "hq_county": "Duchesne",
    "discovery_date": "2022-11-07",
    "disclosure_date": "2023-04-07",
    "executive_summary": "Uintah Basin Healthcare (UBH) discovered suspicious network activity on November 7, 2022 and immediately secured its systems. However, it was not until April 7, 2023 that UBH confirmed patient data may have been accessed or acquired. The breach affected 103,974 patients who received care at UBH between March 2012 and November 2022. Compromised data included names, SSNs, addresses, health insurance, diagnoses, medications, test results, and procedures.",
    "attack_type": "Hacking/IT Incident \u2013 Network Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 103974,
    "residents_affected_in_state": "Primarily Uintah Basin (northeastern Utah) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems secured promptly; delayed determination of PHI exposure",
    "remediation_disclosed": "Security enhancements implemented; patient notifications sent; credit monitoring recommended",
    "primary_source_url": "https://www.techtarget.com/healthtechsecurity/news/366594230/Utah-Health-System-Suffers-Healthcare-Data-Breach-103K-Impacted",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; TechTarget documented; HHS OCR breach report confirmed",
    "sources_used": [
      "TechTarget HealthTech Security"
    ],
    "id": "INC-00499",
    "year": 2023,
    "lat": 40.299403,
    "lng": -109.9887605,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Umpqua Health Alliance / AllCare CCO (PH Tech MOVEit)",
    "organization_type": "Health Plan (Coordinated Care Organization / Medicaid)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Roseburg",
    "hq_county": "Douglas",
    "discovery_date": "2023-06-16",
    "disclosure_date": "2023-07-31",
    "executive_summary": "Umpqua Health Alliance and AllCare CCO (and other coordinated care organizations using Performance Health Technology / PH Tech for claims processing) were victims of the MOVEit Transfer zero-day attack by the Clop ransomware group on May 30, 2023. PH Tech, which administers services for Oregon Medicaid coordinated care organizations, was informed of the breach on June 2, 2023, and discovered that 1.75 million Oregon Health Plan members' data had been stolen. In addition to the primary OHA/PH Tech breach (covered as OR-001), the individual coordinated care organizations \u2014 Umpqua Health, AllCare CCO, Yamhill Community Care, and Health Share of Oregon \u2014 were separately notified as affected clients. This entry captures the distinct organizational notifications required from these Oregon CCOs as separate HIPAA-covered entities.",
    "attack_type": "SQL injection exploit / Data exfiltration (MOVEit zero-day)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Clop (CL0P) ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1750000,
    "residents_affected_in_state": "Not separately reported per CCO",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member enrollment, authorization, and claims data exposed; names, DOBs, SSNs, address, diagnosis and procedure codes compromised",
    "remediation_disclosed": "PH Tech disabled MOVEit access; rebuilt platform; individual notifications July 31, 2023; free identity theft protection via IDX",
    "primary_source_url": "https://www.bankinfosecurity.com/contractor-says-several-health-plans-affected-by-moveit-hack-a-22730",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/1-7-million-oregon-health-plan-members-affected-by-moveit-hack/",
      "https://phtech.com/notification.html"
    ],
    "confidence_notes": "AllCare CCO, Umpqua Health, Yamhill Community Care, and Health Share of Oregon confirmed as PH Tech clients in BankInfoSecurity and HIPAA Journal reporting; this is a companion entry to OR-001 (PH Tech/OHP primary filing). The individual CCOs may have had separate HHS OCR filings; confidence high for breach impact, moderate for separate OCR filing counts",
    "sources_used": [
      "BankInfoSecurity",
      "HIPAA Journal",
      "PH Tech official notice",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00500",
    "year": 2023,
    "lat": 43.216505,
    "lng": -123.3417381,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "University of Colorado Hospital Authority (UCHealth) \u2013 Diligent breach",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CO",
    "hq_city": "Aurora",
    "hq_county": "Arapahoe",
    "discovery_date": "2022-12-01",
    "disclosure_date": "2023-01-17",
    "executive_summary": "UCHealth (University of Colorado Hospital Authority) was affected by a cybersecurity incident at its vendor Diligent Corporation. The breach exposed protected health information and personally identifiable information of 48,879 UCHealth patients, including names, Social Security numbers, financial account information, dates of birth, and PHI. UCHealth's systems (including email and EMR) were not directly impacted.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (Diligent Corp attacker)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 48879,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "UCHealth's systems not impacted",
    "remediation_disclosed": "Patient notifications sent; security of Diligent's systems enhanced",
    "primary_source_url": "https://www.jdsupra.com/legalnews/university-of-colorado-hospital-2697397/",
    "secondary_source_urls": [
      "https://classlawdc.com/2023/02/01/uchealth-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence; JD Supra documented OCR filing; 48,879 confirmed",
    "sources_used": [
      "JD Supra, Migliaccio & Rathod LLP"
    ],
    "id": "INC-00501",
    "year": 2023,
    "lat": 39.7294,
    "lng": -104.8319,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "University of Kansas Health System (KU Health) \u2014 Insider Access",
    "organization_type": "Academic Medical Center / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "KS",
    "hq_city": "Kansas City",
    "hq_county": "Wyandotte",
    "discovery_date": "2023-02-01",
    "disclosure_date": "2023-04-01",
    "executive_summary": "A KU Health physical therapist used their employee credentials in Epic's electronic medical record portal to access the medical records \u2014 including nude clinical photographs \u2014 of 425+ women treated at Plastic Surgery Specialists of Lawrence (Lawrence Memorial Hospital), an unaffiliated institution, without any clinical justification. The unauthorized access began in February 2021 and went undetected for more than 2 years until February 2023. KU Health notified affected patients in April 2023 but omitted critical details about the motive and scope. A class action lawsuit was filed in April 2025 against KU Health, Lawrence Memorial Hospital, and Epic Systems.",
    "attack_type": "Insider Unauthorized Access (employee snooping)",
    "attack_category": "Insider threat",
    "threat_actor_name": "KU Health employee (physical therapist; name not disclosed)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 425,
    "residents_affected_in_state": "Kansas (Lawrence area) patients",
    "financial_impact": "Class action lawsuit pending; damages sought include compensatory and punitive; settlement not yet reached",
    "operational_impact": "Highly sensitive nude clinical photographs and medical records accessed without consent; profound privacy violation",
    "remediation_disclosed": "Yes \u2014 employee terminated February 2023; patient notifications April 2023; lawsuit under review",
    "primary_source_url": "https://hipaatimes.com/ku-health-sued-over-unauthorized-access-to-patient-photos",
    "secondary_source_urls": [
      "https://www.stuevesiegel.com/how-news-KU-Health-Class-Action-Lawsuit",
      "https://www.yahoo.com/news/lawsuit-ku-health-worker-accessed-210819843.html"
    ],
    "confidence_notes": "High confidence. Paubox/HIPAA Times, Stueve Siegel Hanson LLP filing, Yahoo News.",
    "sources_used": [
      "HIPAA Times/Paubox",
      "Stueve Siegel Hanson LLP",
      "Yahoo News"
    ],
    "id": "INC-00502",
    "year": 2023,
    "lat": 39.1142,
    "lng": -94.6275,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "University of Kansas Health System \u2013 St. Francis Campus (Ardent Health Services)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "KS",
    "hq_city": "Topeka",
    "hq_county": "Shawnee",
    "discovery_date": "2023-11-23",
    "disclosure_date": "2023-11-27",
    "executive_summary": "The University of Kansas Health System St. Francis Campus in Topeka, Kansas was affected by a ransomware attack on its parent company Ardent Health Services on November 23, 2023 (Thanksgiving Day). The attack forced the Topeka hospital to divert emergency room patients to other facilities, suspend access to clinical applications and Epic EHR software, and postpone non-emergent elective procedures. Ardent Health serves multiple hospitals across Oklahoma, New Mexico, Texas, Idaho, and Kansas. The full scope of patient data exposure was under investigation. This was one of the most operationally disruptive hospital ransomware attacks of 2023.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Emergency room patient diversions; suspension of Epic EHR and clinical applications; elective procedures postponed; limited service for approximately one month",
    "remediation_disclosed": "Third-party forensic and threat intelligence advisors retained; law enforcement notified; systems restored over approximately one month",
    "primary_source_url": "https://www.kansascity.com/news/local/article282469858.html",
    "secondary_source_urls": [
      "https://apnews.com/article/ransomware-attack-hospitals-emergency-rooms-0841defe1b881b71eccb8826ed46130e",
      "https://thebeaconnews.org/stories/2024/01/25/how-ransomware-attacks-at-kansas-city-hospitals-threaten-your-privacy/"
    ],
    "confidence_notes": "High confidence for the incident. Patient data count not confirmed per public filings. The Topeka campus was one of several Ardent hospitals affected; Ardent Health Services is headquartered in Nashville but the affected facility is in Topeka, Kansas.",
    "sources_used": [
      "Kansas City Star",
      "AP News",
      "Beacon Kansas City",
      "WIBW Topeka"
    ],
    "id": "INC-00503",
    "year": 2023,
    "lat": 39.0473,
    "lng": -95.6752,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "University of Rochester / URMC (MOVEit)",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Rochester",
    "hq_county": "Monroe",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2023-07-28",
    "executive_summary": "The University of Rochester was notified by Progress Software (MOVEit) on May 31, 2023 that its MOVEit file transfer software had been exploited by the Clop ransomware group (TA505). Hackers stole University of Rochester data including SSNs of students, faculty, and employees, affecting approximately 88,050 individuals. The incident was part of the broader Clop/MOVEit supply chain attack affecting thousands of organizations globally.",
    "attack_type": "Supply chain (MOVEit zero-day exploitation)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (TA505)",
    "attribution_status": "reported",
    "individuals_affected_reported": 88050,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "88K+ individuals' SSNs and PII exfiltrated",
    "remediation_disclosed": "Third-party cybersecurity engaged; law enforcement notified; credit monitoring offered; class action filed",
    "primary_source_url": "https://rochesterbeacon.com/2023/08/21/ur-faces-suit-over-ransomware-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "UR confirmed via notification letter; Rochester Beacon reporting; Clop claimed MOVEit attacks",
    "sources_used": [
      "Rochester Beacon"
    ],
    "id": "INC-00504",
    "year": 2023,
    "lat": 43.1566,
    "lng": -77.6088,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "University of Utah Health Plans (MOVEit/TMG Health)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "UT",
    "hq_city": "Salt Lake City",
    "hq_county": "Salt Lake",
    "discovery_date": "2023-06-21",
    "disclosure_date": "2023-08-11",
    "executive_summary": "University of Utah Health Plans reported that vendor TMG Health's MOVEit file transfer server was exploited, exposing data of 3,914 health plan members. The unauthorized access and download of files occurred between May 30 and June 2, 2023. Affected members were notified with one year of complimentary personal identity and privacy protection monitoring.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day (via TMG Health BA)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3914,
    "residents_affected_in_state": "Utah health plan members",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member data affected; U. Health's own systems not impacted",
    "remediation_disclosed": "TMG Health access blocked; law enforcement investigating; 1-year identity protection offered",
    "primary_source_url": "https://www.ksl.com/article/news/utah/health/data-breach-may-have-affected-almost-4000-university-of-utah-health-plan-members/50708165",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; KSL.com documented; University of Utah Health Plans confirmed 3,914",
    "sources_used": [
      "KSL.com (Salt Lake City)"
    ],
    "id": "INC-00505",
    "year": 2023,
    "lat": 40.7608,
    "lng": -111.891,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "VNS Health (VNS Choice) Health Plans",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2023-10-01",
    "disclosure_date": "2023-12-01",
    "executive_summary": "VNS Choice (operating as VNS Health Health Plans), a New York-based managed care plan providing home and community-based services, reported an unauthorized email account access breach in December 2023 affecting 13,584 individuals. Employee email accounts were compromised and may have contained protected health information.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13584,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; PHI in email accounts potentially accessed",
    "remediation_disclosed": "HHS OCR breach report filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/december-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach portal; HIPAA Journal December 2023 report",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00506",
    "year": 2023,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Vanderbilt University Medical Center (VUMC)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Nashville",
    "hq_county": "Davidson",
    "discovery_date": "2023-11-27",
    "disclosure_date": "2023-11-27",
    "executive_summary": "Vanderbilt University Medical Center was added to the Meow ransomware group's dark web leak site on Thanksgiving 2023. VUMC confirmed a cybersecurity incident in which a database was compromised and launched an investigation. Preliminary findings indicated the compromised database did not contain personal or protected patient/employee information. The attack appears to have been data extortion rather than traditional ransomware.",
    "attack_type": "Data Extortion / Unauthorized Database Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Meow",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Database compromised; VUMC stated no patient/employee PHI involved",
    "remediation_disclosed": "Incident contained; investigation launched; preliminary findings indicate no PHI in compromised DB",
    "primary_source_url": "https://therecord.media/vanderbilt-university-medical-center-investigating-cyber-incident-meow-ransomware",
    "secondary_source_urls": [
      "https://www.scworld.com/brief/meow-ransomware-hits-vanderbilt-university-medical-center",
      "https://www.breachsense.com/breaches/vanderbilt-university-medical-center-data-breach/"
    ],
    "confidence_notes": "The Record and SC Media corroborate. VUMC stated no PHI in compromised DB; however, Meow listing indicates some level of compromise.",
    "sources_used": [
      "The Record",
      "SC Media",
      "BreachSense"
    ],
    "id": "INC-00507",
    "year": 2023,
    "lat": 36.1627,
    "lng": -86.7816,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Virginia DMAS (via Molina Healthcare/Maximus supplement)",
    "organization_type": "Government Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "VA",
    "hq_city": "Richmond",
    "hq_county": "Richmond City",
    "discovery_date": "2023-05-27",
    "disclosure_date": "2023-07-01",
    "executive_summary": "The Virginia Department of Medical Assistance Services (DMAS) and its Medicaid managed care enrollees were impacted through Maximus Federal Services' MOVEit Transfer breach. Virginia DMAS was one of many state Medicaid programs whose beneficiary data was exposed when CMS contractor Maximus was breached by Clop via MOVEit. Separately, Virginia DMAS had its own hacking incident (#42 in this database). This entry captures the Maximus/MOVEit chain impact on Virginia Medicaid specifically.",
    "attack_type": "MOVEit Exploit (Supply-Chain via Maximus)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop (CL0P)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2781617,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Part of Maximus breach impact",
    "operational_impact": "Virginia Medicaid beneficiary data exposed through Maximus Federal Services MOVEit breach",
    "remediation_disclosed": "See Maximus entry (#43); CMS coordinated notifications",
    "primary_source_url": "https://www.cms.gov/newsroom/press-releases/cms-notifies-additional-individuals-potentially-impacted-moveit-data-breach",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/up-to-11-million-health-records-maximus-data-breach/"
    ],
    "confidence_notes": "Cross-reference entry for Virginia-specific Medicaid impact from Maximus/MOVEit chain breach.",
    "sources_used": [
      "CMS Press Release",
      "HIPAA Journal"
    ],
    "id": "INC-00508",
    "year": 2023,
    "lat": 37.5407,
    "lng": -77.436,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Virginia Department of Medical Assistance Services (DMAS)",
    "organization_type": "Health Plan (State Medicaid Agency)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "VA",
    "hq_city": "Richmond",
    "hq_county": "Richmond City",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-09-18",
    "executive_summary": "Virginia's DMAS (oversees Medicaid for 1.4M+ Virginians) reported a network server hacking incident to HHS OCR on September 18, 2023. The breach affected 1,229,333 individuals. The incident is linked to the broader MOVEit Transfer vulnerability exploitation by the Clop group. Specific data types were not publicly disclosed in HHS OCR filing.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) / Network Server Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1229333,
    "residents_affected_in_state": 1229333,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Medicaid beneficiary data potentially exposed",
    "remediation_disclosed": "HHS OCR notified September 18, 2023; notifications issued",
    "primary_source_url": "https://www.jdsupra.com/legalnews/virginia-department-of-medical-5615812/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR lists 1,229,333. JD Supra provides filing details. DMAS did not confirm MOVEit vector publicly per available sources.",
    "sources_used": [
      "JD Supra"
    ],
    "id": "INC-00509",
    "year": 2023,
    "lat": 37.5407,
    "lng": -77.436,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "WVU Health (Web Development Server Exposure)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WV",
    "hq_city": "Morgantown",
    "hq_county": "Monongalia",
    "discovery_date": "2022-11-25",
    "disclosure_date": "2023-03-01",
    "executive_summary": "WVU was notified on November 25, 2022 that a website created for software development in December 2021 had contained university information that was accidentally publicly accessible. On January 4, 2023, during ongoing review, a document listing patient file names was discovered to have also been accessible and downloaded by external parties. No SSNs, financial info, or dates of birth were exposed\u2014only patient names and one of: medical test name, procedure name, or disease exposure.",
    "attack_type": "Inadvertent Public Web Exposure / Unauthorized Download",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Limited PHI (names + one medical field) inadvertently exposed and downloaded",
    "remediation_disclosed": "Website deleted November 28, 2022; HHS OCR notified March 2023",
    "primary_source_url": "https://wvutoday.wvu.edu/stories/2023/03/01/wvu-provides-notice-of-data-breach-involving-limited-patient-information",
    "secondary_source_urls": [
      "https://health.wvu.edu/finance-and-business/risk-management/data-incident-management/"
    ],
    "confidence_notes": "WVU Today (official university news) is primary source. Low severity incident; no financial data exposed.",
    "sources_used": [
      "WVU Today (official)",
      "WVU Health (official)"
    ],
    "id": "INC-00510",
    "year": 2023,
    "lat": 39.6295,
    "lng": -79.9559,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Wake Family Eye Care",
    "organization_type": "Healthcare Provider (Optometry Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Raleigh",
    "hq_county": "Wake",
    "discovery_date": "2023-06-01",
    "disclosure_date": "2023-07-01",
    "executive_summary": "Wake Family Eye Care in Raleigh, NC suffered a ransomware attack in 2023. The HHS OCR July 2023 breach report listed the incident as affecting 14,264 individuals.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14264,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data potentially exposed",
    "remediation_disclosed": "HHS OCR notified July 2023",
    "primary_source_url": "https://www.hipaajournal.com/july-2023-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR July 2023 breach report lists 14,264 affected.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00511",
    "year": 2023,
    "lat": 35.7796,
    "lng": -78.6382,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Wake Radiology Diagnostic Imaging",
    "organization_type": "Healthcare Provider (Radiology Practice)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "NC",
    "hq_city": "Raleigh",
    "hq_county": "Wake",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "Raleigh, NC-based Wake Radiology Diagnostic Imaging was among the 13 NC healthcare systems affected by the Nuance/MOVEit breach. Patient data was potentially compromised.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1225054,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.turkestrauss.com/2023/10/05/wake-radiology-data-breach-investigation/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/nuance-communications-13-healthcare-clients-in-north-carolina-affected-by-moveit-hack/"
    ],
    "confidence_notes": "Listed in Nuance/HIPAA Journal disclosure. Turke & Strauss confirming investigation.",
    "sources_used": [
      "Turke & Strauss LLP",
      "HIPAA Journal"
    ],
    "id": "INC-00512",
    "year": 2023,
    "lat": 35.7796,
    "lng": -78.6382,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Warren General Hospital",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Warren",
    "hq_county": "Warren",
    "discovery_date": "2023-09-24",
    "disclosure_date": "2023-11-09",
    "executive_summary": "Warren General Hospital in Warren, Pennsylvania detected suspicious activity on its network on September 24, 2023, and determined an unauthorized actor had accessed systems between September 15 and September 23. Downloaded files contained patient and employee names, dates of birth, Social Security numbers, financial account information, health insurance claims data, and medical information including diagnoses, medications, and lab results. RansomHouse threat group claimed responsibility, reporting theft of 150 GB of data. Approximately 168,921 individuals were affected.",
    "attack_type": "Hacking/IT Incident (data theft, ransomware claimed)",
    "attack_category": "Ransomware",
    "threat_actor_name": "RansomHouse",
    "attribution_status": "claimed",
    "individuals_affected_reported": 168921,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient and employee PHI exfiltrated; 150 GB of data stolen per threat actor claim",
    "remediation_disclosed": "Third-party cybersecurity experts engaged; law enforcement notified; HHS OCR notified; security controls enhanced",
    "primary_source_url": "https://www.hipaajournal.com/warren-general-hospital-data-breach-affects-169000-patients/",
    "secondary_source_urls": [
      "https://www.healthcarefinancenews.com/news/pennsylvania-hospital-hit-data-breach-affecting-169k",
      "https://www.breachsense.com/breaches/warren-general-hospital-data-breach/"
    ],
    "confidence_notes": "HIPAA Journal confirmed 168,921 HHS OCR report; RansomHouse attribution from Breachsense; well documented",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare Finance News",
      "Breachsense"
    ],
    "id": "INC-00513",
    "year": 2023,
    "lat": 41.8119602,
    "lng": -79.2654452,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Welltok / BlueCross BlueShield TN \u2014 TN Welltok MOVEit",
    "organization_type": "Business Associate / Patient Engagement Technology",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TN",
    "hq_city": "Denver",
    "hq_county": "Denver County (CO-based)",
    "discovery_date": "2023-05-30",
    "disclosure_date": "2023-11-17",
    "executive_summary": "Welltok's MOVEit Transfer server breach (May 30, 2023 by Clop) affected numerous health plan members, with the total eventually reaching 14.76 million individuals nationally. Tennessee BlueCross BlueShield and other SE-based health plan sponsors had members affected. The SC Consumer Affairs breach portal listed Welltok, Inc. affecting 135,359 SC residents. Total affected: 14,762,475.",
    "attack_type": "MOVEit Exploit (Clop ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Clop (CL0P)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14762475,
    "residents_affected_in_state": 135359,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Health plan member data including names, DOBs, SSNs, Medicare/Medicaid IDs, health insurance information, and provider data exposed",
    "remediation_disclosed": "Welltok notified Maine AG December 4, 2023; individual notifications sent November 17, 2023 and later",
    "primary_source_url": "https://www.hipaajournal.com/welltok-data-breach/",
    "secondary_source_urls": [
      "https://techcrunch.com/2023/11/20/hackers-accessed-sensitive-health-data-of-welltok-patients/",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal comprehensive Welltok coverage; SC Consumer Affairs (135,359 SC residents); TechCrunch. Primary HQ is CO but SE health plan members significantly impacted.",
    "sources_used": [
      "HIPAA Journal",
      "TechCrunch",
      "SC Consumer Affairs Breach Portal",
      "Maine AG Filing"
    ],
    "id": "INC-00514",
    "year": 2023,
    "lat": 36.0470046,
    "lng": -87.9208635,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Welltok Inc. (Northeast healthcare plan clients)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2023-07-26",
    "disclosure_date": "2023-11-06",
    "executive_summary": "Welltok Inc., a Denver, Colorado health information company serving major health plans as a business associate, suffered a MOVEit Transfer vulnerability exploit (Clop ransomware gang) on July 26, 2023. The breach affected 14,782,887 individuals nationally including members of multiple Northeast health plans. Affected NE entities included Point32Health (MA), Blue Cross Blue Shield of Minnesota with NE members, and other regional health plan clients. The breach ranked among the five largest healthcare data breaches in US history.",
    "attack_type": "MOVEit Transfer vulnerability exploit (Clop ransomware gang supply chain)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Clop (CL0P)",
    "attribution_status": "reported",
    "individuals_affected_reported": 14782887,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "14.7M+ individuals' health plan data stolen; multiple NE health plan members affected",
    "remediation_disclosed": "HHS OCR notified; affected health plans notified their members; MOVEit patched",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR confirms 14.78M affected; ranked #4 largest US healthcare breach; NE health plan client exposure well documented; Clop MOVEit campaign attributed by multiple sources",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00515",
    "year": 2023,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Welltok, Inc.",
    "organization_type": "Business Associate (Patient Engagement / Health Plan Services)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2023-07-26",
    "disclosure_date": "2023-11-17",
    "executive_summary": "Welltok, a Denver-based patient engagement company owned by Virgin Pulse, was victimized by the Clop group's exploitation of a MOVEit Transfer zero-day vulnerability on May 30, 2023. Despite applying the patch the following day, the vulnerability had already been exploited. After extended forensic review, the breach was confirmed to affect 14,782,887 individuals \u2014 making it the second-largest healthcare data breach in US history at the time. Affected data included names, dates of birth, addresses, health information, Social Security numbers, Medicare/Medicaid IDs, and insurance information of health plan members.",
    "attack_type": "Hacking/IT Incident \u2013 MOVEit Zero-Day Exploitation",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 14782887,
    "residents_affected_in_state": "Not separately reported (national health plan membership data)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Welltok's core systems unaffected; MOVEit file transfer server compromised",
    "remediation_disclosed": "MOVEit server patched immediately; data theft confirmed on Aug 26; substitute breach notice published October 2023; SEC investigation of Progress Software initiated",
    "primary_source_url": "https://www.hipaajournal.com/welltok-data-breach/",
    "secondary_source_urls": [
      "https://www.securitymagazine.com/articles/100304-colorado-wellness-company-suffers-data-breach",
      "https://www.jdsupra.com/legalnews/welltok-confirms-recent-moveit-9675889/"
    ],
    "confidence_notes": "Very high confidence; OCR confirmed 14,782,887; second-largest US healthcare breach at time of disclosure",
    "sources_used": [
      "HIPAA Journal, Security Magazine, JD Supra"
    ],
    "id": "INC-00516",
    "year": 2023,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Welltok, Inc. (Virgin Pulse subsidiary)",
    "organization_type": "BA / Vendor (Patient Engagement SaaS)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2023-07-26",
    "disclosure_date": "2023-10-01",
    "executive_summary": "Welltok, a Denver-based patient engagement SaaS company serving health plans across the U.S., was compromised via the Cl0p group's exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer file transfer solution in May 2023. Welltok detected the breach on July 26, 2023 (after confirming data exfiltration), and began notifying affected clients in August-November 2023. Initially reported as affecting 8.5 million individuals, the final OCR breach portal count was updated to 14,762,475 \u2014 making it the second-largest healthcare data breach ever reported to HHS. At least 165 health plan clients were affected, including Blue Cross Blue Shield plans in multiple states, Sutter Health (845K), Corewell Health (~1M), Stanford Health Care (1.6M+), and others.",
    "attack_type": "Supply Chain / MOVEit Zero-Day Exploit / Data Theft",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p (Clop ransomware group)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 14762475,
    "residents_affected_in_state": "MN AL KS NC MI NE IL MA and many others; full breakdown not published",
    "financial_impact": "Not publicly disclosed. Multiple class action lawsuits expected. No encryption ransom; data theft extortion model.",
    "operational_impact": "No operational disruption to healthcare delivery. Data theft only via third-party file transfer tool.",
    "remediation_disclosed": "MOVEit server patched and decommissioned. Clients notified beginning August 2023 with substitute breach notice published in October 2023. Notifications sent November 2023 onward.",
    "primary_source_url": "https://www.welltok.com/security-notice",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/welltok-data-breach/",
      "https://techcrunch.com/2023/11/20/hackers-accessed-sensitive-health-data-of-welltok-patients/",
      "https://www.techtarget.com/healthtechsecurity/news/366594153/85M-Records-Impacted-By-Welltok-Data-Breach-Stemming-From-MOVEit-Hack"
    ],
    "confidence_notes": "High confidence. Final OCR count 14,762,475 (updated post-April 2024). Multiple client-side confirmations. Cl0p attribution confirmed via public claims for MOVEit campaign.",
    "sources_used": [
      "Welltok official security notice",
      "HIPAA Journal",
      "TechCrunch",
      "TechTarget"
    ],
    "id": "INC-00517",
    "year": 2023,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "West Virginia University Health System (via Nuance/MOVEit)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WV",
    "hq_city": "Morgantown",
    "hq_county": "Monongalia",
    "discovery_date": "2023-05-28",
    "disclosure_date": "2023-09-22",
    "executive_summary": "West Virginia University Health System was listed among clients impacted by the Nuance Communications MOVEit Transfer breach. This is a separate incident from WVU's 2022 web development server exposure.",
    "attack_type": "Supply-Chain Exploit (MOVEit Transfer Zero-Day) via Nuance",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Clop",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown (included in Nuance total)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "Patient radiology documentation data stolen via Nuance",
    "remediation_disclosed": "Notifications mailed September 22, 2023 via Nuance",
    "primary_source_url": "https://www.bankinfosecurity.com/nuance-notifying-13-nc-healthcare-clients-moveit-hacks-a-23107",
    "secondary_source_urls": [],
    "confidence_notes": "BankInfoSecurity lists WVU Health System among Nuance clients. Noted as 14th client in some reports.",
    "sources_used": [
      "BankInfoSecurity"
    ],
    "id": "INC-00518",
    "year": 2023,
    "lat": 39.6295,
    "lng": -79.9559,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Yukon-Kuskokwim Health Corporation (YKHC)",
    "organization_type": "Healthcare Provider (Tribal Health Organization)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Bethel",
    "hq_county": "Bethel (Census Area)",
    "discovery_date": "2023-03-28",
    "disclosure_date": "2023-05-31",
    "executive_summary": "Yukon-Kuskokwim Health Corporation, which provides healthcare to the Yup'ik, Cup'ik, Athabascan, and Aleut peoples in the YK Delta region, discovered a ransomware attack on March 28, 2023. The attack temporarily disrupted computer systems and servers. YKHC engaged third-party forensic experts and notified federal law enforcement. The organization is providing free credit monitoring through CyberScout. A CyberScout representative confirmed the attack was ransomware.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "AK-based tribal community members (YK Delta region)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Computer systems and servers temporarily disrupted",
    "remediation_disclosed": "Systems secured; forensic investigation; federal law enforcement notified; credit monitoring offered",
    "primary_source_url": "https://www.kucb.org/alaska-state-news/2023-06-08/yukon-kuskokwim-health-corporation-issues-notification-of-a-data-security-incident",
    "secondary_source_urls": [
      "https://www.ykhc.org/wp-content/uploads/2023/05/DataSecurityNotice053123.pdf"
    ],
    "confidence_notes": "Kyuk.org (local AK public media) confirmed ransomware via CyberScout representative; official YKHC notification letter available",
    "sources_used": [
      "KYUK Public Media (Bethel, AK)",
      "YKHC official notice PDF"
    ],
    "id": "INC-00519",
    "year": 2023,
    "lat": 60.7922222,
    "lng": -161.755833,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ZOLL Medical Corporation",
    "organization_type": "Healthcare Provider / Medical Device Manufacturer",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Chelmsford",
    "hq_county": "Middlesex",
    "discovery_date": "2023-01-28",
    "disclosure_date": "2023-03-10",
    "executive_summary": "ZOLL Medical Corporation, a Chelmsford, MA medical device company, detected unauthorized access to its internal network on January 28, 2023. The incident was ZOLL's second major breach in four years, affecting 1,004,443 individuals including patients and employees. Data compromised included names, addresses, DOBs, and SSNs. ZOLL agreed to a $3.5 million settlement in 2026.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1004443,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3.5 million settlement (2026)",
    "operational_impact": "1M+ patient and employee records exposed; no impact on medical devices",
    "remediation_disclosed": "Credit monitoring offered; enhanced security; $3.5M settlement",
    "primary_source_url": "https://www.massdevice.com/zoll-medical-email-phishing-cyberattack-data-breach/",
    "secondary_source_urls": [
      "https://milberg.com/news/zoll-data-breach-lawsuit/",
      "https://news.bloomberglaw.com/us-law-week/zoll-offers-3-5-million-to-end-medical-device-data-breach-suit"
    ],
    "confidence_notes": "Maine AG notice confirmed 1,004,443; ZOLL confirmed; $3.5M settlement filed",
    "sources_used": [
      "MassDevice",
      "Milberg",
      "Bloomberg Law"
    ],
    "id": "INC-00520",
    "year": 2023,
    "lat": 42.5968617,
    "lng": -71.3517602,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "A&A Services LLC d/b/a Sav-Rx",
    "organization_type": "BA/Vendor (Pharmacy Benefit Management)",
    "organization_type_bucket": "Pharmacy",
    "state": "NE",
    "hq_city": "Fremont",
    "hq_county": "Dodge",
    "discovery_date": "2023-10-08",
    "disclosure_date": "2024-05-28",
    "executive_summary": "Sav-Rx, a Fremont, Nebraska-based pharmacy benefit management and medication benefits management company, detected an intrusion on its computer network on October 8, 2023. The company restored systems the following day with no material disruption to patient care or prescription fulfillment. However, the investigation \u2014 completed April 30, 2024 \u2014 confirmed that an unauthorized party had accessed and exfiltrated files from non-clinical systems on October 3\u20138, 2023. Sav-Rx confirmed 2,812,336 individuals were affected, with compromised data including names, dates of birth, email addresses, phone numbers, Social Security numbers, eligibility data, insurance identification numbers, and addresses. The company's statement that the acquired data 'was destroyed and has not been disseminated' suggests a ransom payment may have been made.",
    "attack_type": "Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2812336,
    "residents_affected_in_state": "Not separately reported by state (multi-state health plan members and employees)",
    "financial_impact": "Class action lawsuits filed (Bloomberg Law reported multiple federal suits June 2024). Ransom payment status: Strongly suggested by company's statement about data destruction. Settlement not yet disclosed.",
    "operational_impact": "No material disruption to patient care or prescription fulfillment. Adjudication system unaffected. Clinical and financial information not accessed.",
    "remediation_disclosed": "Systems restored within 24 hours. Third-party cybersecurity experts engaged. MFA implemented. Network segmentation improved. Linux system hardening. Enhanced geo-blocking. Individual notifications mailed May 2024.",
    "primary_source_url": "https://www.hipaajournal.com/sav-rx-data-breach/",
    "secondary_source_urls": [
      "https://www.techtarget.com/healthtechsecurity/news/366594046/Sav-Rx-data-breach-affects-28M-individuals",
      "https://news.bloomberglaw.com/privacy-and-data-security/sav-rx-hit-with-suits-over-breach-affecting-2-8-million-people"
    ],
    "confidence_notes": "High confidence. HIPAA Journal confirms 2,812,336 OCR count. TechTarget and Bloomberg Law corroborate. Six-month delay between incident and notification notable.",
    "sources_used": [
      "HIPAA Journal",
      "TechTarget / Health Tech Security",
      "Bloomberg Law"
    ],
    "id": "INC-00521",
    "year": 2024,
    "lat": 41.4338363,
    "lng": -96.4960449,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "ALN Medical Management (Nebraska clients via vendor breach)",
    "organization_type": "Business Associate / Revenue Cycle Management",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NE",
    "hq_city": "Lincoln",
    "hq_county": "Lancaster",
    "discovery_date": "2024-03-01",
    "disclosure_date": "2024-05-23",
    "executive_summary": "ALN Medical Management, a revenue cycle management and billing firm based in Nebraska, detected suspicious activity on some systems hosted by a vendor in March 2024. An investigation determined an unauthorized person had accessed and potentially stolen data. The breach affected 1,323,720 individuals. Compromised data included names, dates of birth, addresses, government ID information (including Social Security numbers), financial account and payment card details, and medical information including health insurance details and diagnosis and treatment information. Breach notifications began in spring 2025.",
    "attack_type": "Hacking / Unauthorized Access via Vendor",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1323720,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Data exfiltration from vendor-hosted systems",
    "remediation_disclosed": "Vendor relationship reviewed; affected individuals notified; credit monitoring offered",
    "primary_source_url": "https://www.healthcaredive.com/news/tracking-healthcare-data-breaches-cybersecurity-hacking-hospitals/696184/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for the breach. ALN Medical Management listed as Nebraska entity in Healthcare Dive's breach tracker per HHS OCR filing. Date reported to HHS OCR was May 23, 2024.",
    "sources_used": [
      "Healthcare Dive breach tracker",
      "HHS OCR breach portal"
    ],
    "id": "INC-00522",
    "year": 2024,
    "lat": 40.8136,
    "lng": -96.7026,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Acadian Ambulance Service (Northeast operations / billing)",
    "organization_type": "Healthcare Provider (Emergency Medical Services)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "LA",
    "hq_city": "Lafayette",
    "hq_county": "Lafayette",
    "discovery_date": "2023-09-01",
    "disclosure_date": "2024-01-01",
    "executive_summary": "Acadian Ambulance Service, which operates emergency medical services in multiple states including the Northeast, reported a data security incident involving unauthorized access to patient billing and medical data. The breach affected patients who received ambulance services from Acadian-operated or contracted services in Northeast states.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EMS patient billing and medical data compromised",
    "remediation_disclosed": "HHS OCR and patients notified",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Lower confidence for NE specificity; included for EMS/ambulance coverage category; limited public detail on NE exposure",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00523",
    "year": 2024,
    "lat": 30.2241,
    "lng": -92.0198,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Acadian Ambulance Service, Inc.",
    "organization_type": "Healthcare Provider (Emergency Medical Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "LA",
    "hq_city": "Lafayette",
    "hq_county": "Lafayette Parish",
    "discovery_date": "2024-06-21",
    "disclosure_date": "2024-08-20",
    "executive_summary": "Lafayette, LA-based Acadian Ambulance (major medical transportation provider) detected suspicious activity in late June 2024. Attackers had access to systems between June 19 and June 21, 2024. The Daixin Team ransomware group claimed responsibility, stating they stole ~10 million unique records and demanded a $7 million ransom, which Acadian refused (offering $173,000). HHS OCR was notified as affecting 2,896,985 individuals. Data included names, DOBs, SSNs, medical histories, and employment info.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Daixin Team",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 2896985,
    "residents_affected_in_state": "LA MS TX TN \u2014 state breakdown not separately published",
    "financial_impact": "$7M ransom demanded; not paid; class action lawsuit filed",
    "operational_impact": "Computer systems disrupted; 10M+ unique records allegedly stolen",
    "remediation_disclosed": "Systems locked down; law enforcement notified; credit monitoring offered; notifications mailed November 2024",
    "primary_source_url": "https://www.hipaajournal.com/acadian-ambulance-ransomware-attack/",
    "secondary_source_urls": [
      "https://databreach.com/breach/acadian-ambulance-2024",
      "https://www.murray-lawfirm.com/notices/acadian-ambulance-data-breach",
      "https://www.hipaajournal.com/acadian-ambulance-ransomware-attack/",
      "https://acadianambulance.com/wp-content/uploads/Acadian-Ambulance-Service-Inc.-Notice-of-Data-Privacy-Event.pdf"
    ],
    "confidence_notes": "HHS OCR lists 2,896,985 affected. Daixin Team attribution well-documented across multiple security sources. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Acadian Ambulance official notice (PDF)",
      "DataBreach.com",
      "HIPAA Journal",
      "HIPAA Journal, DataBreach.com, HIPAA Journal 2024 Healthcare Data Breach Report",
      "Murray Law Firm"
    ],
    "id": "INC-00524",
    "year": 2024,
    "lat": 30.2241,
    "lng": -92.0198,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Adventist Health Tulare \u2014 Signature Performance Breach",
    "organization_type": "Nonprofit faith-based hospital and health system (CA hospital affected via business associate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Tulare",
    "hq_county": "Tulare County",
    "discovery_date": "2024-01-18",
    "disclosure_date": "2024-06-08",
    "executive_summary": "In January 2024, Signature Performance \u2014 a business associate that collects payments for Adventist Health Tulare \u2014 detected suspicious network activity between January 17 and 18, 2024. A forensic investigation confirmed unauthorized access to files on Signature Performance's network containing PHI of 70,802 Adventist Health Tulare patients. Exposed data included names, SSNs, driver's license numbers, dates of birth, and other medical/insurance information. Adventist Health stated it has no reason to believe information has been misused.",
    "attack_type": "Hacking / unauthorized network access (via business associate Signature Performance)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 70802,
    "residents_affected_in_state": "Predominantly CA (Tulare County Central Valley)",
    "financial_impact": "{'notes': 'No financial penalties or settlements publicly disclosed.'}",
    "operational_impact": "No clinical disruption to Adventist Health Tulare operations reported.",
    "remediation_disclosed": "Signature Performance investigated with third-party experts; notification letters mailed; monitoring offered. Separate OCR filing by Signature Performance for 106,540 total individuals across all clients.",
    "primary_source_url": "https://www.hipaajournal.com/70000-adventist-health-tulare-patients-data-breach/",
    "secondary_source_urls": [
      "https://thelyonfirm.com/blog/adventist-health-tulare-data-breach-signature-performance/",
      "https://abc30.com/post/adventist-health-discovers-data-breach-could-impact-tulare/14926722/"
    ],
    "confidence_notes": "Adventist Health is headquartered in Roseville, CA (statewide system). This entry focuses on the Tulare hospital as the CA location specifically affected. Note: Separate Adventist Health Hanford HIPAA settlement (Jun 2024 with CA AG Bonta) concerned unauthorized disclosure of patient medical information to law enforcement \u2014 not a cyber incident.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00525",
    "year": 2024,
    "lat": 36.2077,
    "lng": -119.3473,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Alabama Cardiovascular Group (ACG)",
    "organization_type": "Healthcare Provider / Cardiology Practice",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Birmingham",
    "hq_county": "Jefferson",
    "discovery_date": "2024-07-02",
    "disclosure_date": "2024-08-30",
    "executive_summary": "Alabama Cardiovascular Group discovered a data breach on July 2, 2024, in which an unauthorized third party gained access to its IT network from June 6 to July 2, 2024. The breach affected 280,534 individuals and exposed names, contact details, Social Security numbers, medical insurance data, and health data. ACG agreed to a $2,225,000 class action settlement.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 280534,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$2,225,000 class action settlement",
    "operational_impact": "PHI and PII of patients and employees exfiltrated over 26-day window",
    "remediation_disclosed": "Systems secured; third-party forensics engaged; law enforcement notified; class action settlement agreed",
    "primary_source_url": "https://compliancejunction.com/alabama-cardiovascular-group-pays-2225000-to-settle-its-data-breach-lawsuit/",
    "secondary_source_urls": [
      "https://www.alabamacardiodatasettlement.com"
    ],
    "confidence_notes": "High confidence \u2014 settlement website, ComplianceJunction reporting, court filings.",
    "sources_used": [
      "ComplianceJunction",
      "Alabama Cardiovascular Group Settlement Website",
      "Court records"
    ],
    "id": "INC-00526",
    "year": 2024,
    "lat": 33.5186,
    "lng": -86.8104,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Allina Health \u2014 2024 Former Employee Improper Access",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2024-01-01",
    "disclosure_date": "2024-05-06",
    "executive_summary": "Allina Health System in Minneapolis discovered in January 2024 that a former employee (no longer employed since 2022) had improperly accessed the health records of 715 patients. The review completed March 2024 confirmed the unauthorized access. Data potentially viewed included names, addresses, photo IDs, insurance information, limited clinical information, and last 4 digits of SSNs. All affected patients were notified and offered 2 years of complimentary identity theft and credit monitoring services.",
    "attack_type": "Insider Unauthorized Access (former employee)",
    "attack_category": "Insider threat",
    "threat_actor_name": "Former Allina Health employee",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 715,
    "residents_affected_in_state": "Minnesota patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal; internal audit identified unauthorized access",
    "remediation_disclosed": "Yes \u2014 HIPAA and policy retraining; notifications; 2 years credit monitoring",
    "primary_source_url": "https://www.hipaajournal.com/hypertension-nephrology-associates-data-breach/",
    "secondary_source_urls": [
      "https://data.norwichbulletin.com/health-care-data-breaches/allina-health-system-mn-715-20240506-unauthorized-electronic/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal (Allina section), HHS OCR breach portal (715 individuals, reported May 6, 2024).",
    "sources_used": [
      "HIPAA Journal",
      "Norwich Bulletin HHS Data"
    ],
    "id": "INC-00527",
    "year": 2024,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "AlohaCare (Change Healthcare 2024 impact)",
    "organization_type": "Health Plan (Managed Care Organization / Medicaid)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "Honolulu",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-04-01",
    "executive_summary": "AlohaCare, Hawaii's only non-profit Medicaid health plan serving approximately 90,000 members, was significantly disrupted by the nationwide Change Healthcare ransomware attack beginning February 21, 2024. As a QUEST Integration plan contractor using Change Healthcare for claims and payment processing, AlohaCare experienced disruptions to its ability to process insurance claims and payments for its Medicaid members. The ALPHV/BlackCat ransomware group attacked Change Healthcare, a UnitedHealth Group subsidiary, severing connections for approximately half of all US health transactions.",
    "attack_type": "Third-party ransomware attack (Change Healthcare/UHG upstream)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat ransomware group (via Change Healthcare)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 190000000,
    "residents_affected_in_state": 90000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Medicaid claims processing and payment severely disrupted; ~90,000 Hawaii Medicaid members' care coordination affected",
    "remediation_disclosed": "Temporary payment workarounds utilized; operations gradually restored as Change Healthcare systems recovered",
    "primary_source_url": "https://fm.kuac.org/health/2024-04-01/alaska-healthcare-business-damaged-by-national-cyberattack",
    "secondary_source_urls": [
      "https://cca.hawaii.gov/ocp/notices/security-breach/"
    ],
    "confidence_notes": "AlohaCare confirmed as Hawaii Medicaid plan using Change Healthcare for processing; downstream impact well-documented via Change Healthcare reporting. Note: This represents operational disruption rather than a direct breach of AlohaCare's own systems, though member data was likely included in Change Healthcare's mass breach. Confidence moderate \u2014 Hawaii-specific AlohaCare Change Healthcare impact sourcing could be stronger.",
    "sources_used": [
      "KUAC FM (general Change Healthcare impact on AK/HI healthcare)",
      "Hawaii DCCA OCP",
      "Change Healthcare public reporting"
    ],
    "id": "INC-00528",
    "year": 2024,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Anchorage Project Access / SEARHC (network disruption context)",
    "organization_type": "Healthcare Provider (Community Health Network)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "AK",
    "hq_city": "Anchorage",
    "hq_county": "Municipality of Anchorage",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-04-01",
    "executive_summary": "Anchorage-area healthcare providers, including Anchorage Project Access and community health networks, were disrupted by the February 2024 Change Healthcare cyberattack. The Alaska Attorney General's office issued a consumer advisory in July 2024 noting that Alaskan healthcare providers were 'damaged' by the national Change Healthcare cyberattack. At least one Alaska health provider was reported near closure due to inability to process claims and reimbursements after Change Healthcare's systems went offline. KUAC FM reported an Alaska health provider may close following the attack. The attack disrupted prescription processing, prior authorizations, and insurance verification for Alaska healthcare organizations.",
    "attack_type": "Third-party disruption (via Change Healthcare ransomware attack)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat (Change Healthcare attackers)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately reported",
    "residents_affected_in_state": "Alaska residents dependent on affected healthcare providers",
    "financial_impact": "At least one Alaska health provider reported potential closure; AK state sought emergency financial assistance",
    "operational_impact": "Prescription processing, claims submission, and prior authorization disrupted for Alaska providers; potential provider insolvency",
    "remediation_disclosed": "Alaska AG issued consumer advisories; Change Healthcare offered free credit monitoring for AK residents; systems gradually restored",
    "primary_source_url": "https://fm.kuac.org/health/2024-04-01/alaska-healthcare-business-damaged-by-national-cyberattack",
    "secondary_source_urls": [
      "https://law.alaska.gov/press/releases/2024/070924-Cyberattack.html"
    ],
    "confidence_notes": "Moderate confidence: KUAC FM confirmed Alaska health provider impact; AK AG advisory confirms statewide concern; specific organization not named in available sources. Included as Alaska-specific context for Change Healthcare breach impact.",
    "sources_used": [
      "KUAC FM",
      "Alaska AG official press release"
    ],
    "id": "INC-00529",
    "year": 2024,
    "lat": 61.2181,
    "lng": -149.9003,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Ann & Robert H. Lurie Children's Hospital of Chicago",
    "organization_type": "Pediatric Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2024-01-31",
    "disclosure_date": "2024-02-01",
    "executive_summary": "Rhysida ransomware group attacked Lurie Children's Hospital, with unauthorized access occurring January 26\u201331, 2024. The attack forced the hospital to take all IT systems offline including Epic EHR, email, and phone systems. Epic was restored March 5, 2024, after more than a month. Rhysida listed Lurie on its dark web leak site Feb. 27, 2024, demanding 60 bitcoin (~$3.4M) and subsequently claimed to have sold the stolen data (~$3M+). The breach affected 791,784 individuals per Maine AG notification (775,860 per HHS OCR portal). Class action lawsuits filed. FBI Chicago engaged.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 791784,
    "residents_affected_in_state": "Primarily Illinois residents",
    "financial_impact": "Rhysida claimed $3M+ from data sale; hospital financial impact not publicly disclosed",
    "operational_impact": "All IT systems offline including EHR for ~5 weeks; phone and email disrupted; patient care coordination severely impacted; some surgeries and procedures delayed; pediatric patients affected",
    "remediation_disclosed": "Yes \u2014 Epic restored March 5; full systems restored by March 18, 2024; FBI investigation ongoing; 24 months complimentary credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/january-2024-cyberattack-on-lurie-childrens-hospital-affects-792k-individuals/",
    "secondary_source_urls": [
      "https://www.cm-alliance.com/cybersecurity-blog/lurie-childrens-hospital-of-chicago-ransomware-attack-timeline",
      "https://www.classaction.com/news/lurie-childrens-hospital-data-breach/",
      "https://www.hipaajournal.com/january-2024-cyberattack-on-lurie-childrens-hospital-affects-792k-individuals/",
      "https://www.classaction.org/news/chicagos-lurie-childrens-hospital-hit-with-class-action-over-january-2024-ransomware-attack",
      "https://www.luriechildrens.org/en/blog/cybersecurity-matter-updates/"
    ],
    "confidence_notes": "High confidence. HHS OCR portal, Maine AG filing, FBI statement, extensive media coverage. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "CM Alliance",
      "CM-Alliance",
      "ClassAction.com",
      "ClassAction.org",
      "HIPAA Journal",
      "Lurie Children's Hospital official updates",
      "WTTW News"
    ],
    "id": "INC-00530",
    "year": 2024,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Ascension Health",
    "organization_type": "Hospital / Health System (Multistate)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "St. Louis, MO (national / multistate)",
    "hq_county": "N/A \u2014 national / multistate",
    "discovery_date": "2024-02-29",
    "disclosure_date": "2024-12-19",
    "executive_summary": "On May 8, 2024, we detected unauthorized activity on certain of Ascension\u2019s technology systems resulting from a ransomware attack. Upon discovering the unauthorized activity, we initiated an investigation with the assistance of leading cybersecurity experts. Through this investigation, we found evidence that on May 7 and 8, a cybercriminal obtained a copy of certain files containing personal information of our patients and associates.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Black Basta",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 5599699,
    "residents_affected_in_state": "Not separately reported by state",
    "financial_impact": "Not publicly disclosed (Ascension reported $1.8B investment portfolio write-down unrelated, but incident costs undisclosed)",
    "operational_impact": "Clinical operations diverted; EHR systems offline; staff reverted to manual processes; surgical procedures rescheduled",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified', 'Additional security measures implemented']",
    "primary_source_url": "https://oag.ca.gov/system/files/Ascension%20Health%20%E2%80%93%20Exhibit%20A%20%E2%80%93%20Notice%20Template.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/ascension-health-ransomware-attack-black-basta/",
      "https://www.bleepingcomputer.com/news/security/ascension-healthcare-confirms-black-basta-ransomware-attack/",
      "https://www.hipaajournal.com/ascension-cyberattack-2024/",
      "https://www.bleepingcomputer.com/news/security/ascension-health-data-of-56-million-stolen-in-ransomware-attack/",
      "https://www.securityweek.com/5-6-million-impacted-by-ransomware-attack-on-healthcare-giant-ascension/",
      "https://www.healthcarefinancenews.com/news/56-million-people-affected-ascension-cyberattack",
      "https://www.ascension.org/news/2024/may/ascension-cyber-security-event",
      "https://www.crn.com/news/security/2024/black-basta-ransomware-attack-brought-down-ascension-it-systems-report",
      "https://www.blackfog.com/ascension-ransomware-attack/",
      "https://www.wrtv.com/news/local-news/ascension-st-vincent-affected-by-cyber-attack-to-its-network"
    ],
    "confidence_notes": "Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Ascension official website",
      "BlackFog",
      "BleepingComputer",
      "CNN sourcing",
      "CRN",
      "California AG Breach Notification",
      "HIPAA Journal",
      "Healthcare Finance News",
      "SecurityWeek",
      "WRTV Indianapolis"
    ],
    "id": "INC-00531",
    "year": 2024,
    "lat": 36.63785312911233,
    "lng": -120.01859900940896,
    "is_multistate": true,
    "hq_outside_state": "St. Louis",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Ascension Health (SE Hospitals \u2013 Black Basta Ransomware)",
    "organization_type": "Healthcare Provider (Hospital System - Multistate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TN",
    "hq_city": "Nashville (SE operations)",
    "hq_county": "Davidson",
    "discovery_date": "2024-05-08",
    "disclosure_date": "2024-05-08",
    "executive_summary": "Ascension Health (multistate, MO-HQ), which operates hospitals in Tennessee and other SE states, suffered a Black Basta ransomware attack detected May 8, 2024. The attack disrupted clinical operations across its 140-hospital network. HHS OCR lists the breach as affecting 5,599,699 individuals. Data included SSNs, medical records, and insurance data. Ascension operates in TN (Saint Thomas Health), VA (Sacred Heart), and other SE states. HHS OCR registered under MO entity.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Black Basta",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 5599699,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Clinical operations disrupted; patient diversions; EHR taken offline",
    "remediation_disclosed": "Systems taken offline; FBI and CISA engaged; EHR restored; notifications issued",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR lists 5,599,699 (MO entity). Included as Ascension has significant SE hospital presence. Black Basta widely attributed.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00532",
    "year": 2024,
    "lat": 36.1627,
    "lng": -86.7816,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Ascension Health (Texas hospitals)",
    "organization_type": "Healthcare Provider (Nonprofit Catholic Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "St. Louis (MO HQ) / Multiple TX locations",
    "hq_county": "Multiple TX counties",
    "discovery_date": "2024-05-08",
    "disclosure_date": "2024-07-26",
    "executive_summary": "Ascension Health was struck by a Black Basta ransomware attack on May 8, 2024. As the largest nonprofit Catholic health system in the US with 140 hospitals in 18 states (including Texas), the attack disrupted EHR systems, pharmacy operations, and forced staff to use paper records. Only 7 of 25,000 servers were compromised, but these contained significant PHI. The breach ultimately affected 5,599,699 individuals nationwide. Initial access vector was a malicious file downloaded by an employee. Texas hospitals (in Austin and other markets) were among the first to have EHR access restored.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware (Black Basta)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Black Basta",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5599699,
    "residents_affected_in_state": "Not separately reported (Texas portion of nationwide figure)",
    "financial_impact": "$79M operating losses in first 10 months of fiscal year; significant remediation costs; ambulance diversions, pharmacy closures",
    "operational_impact": "EHR systems offline ~6 weeks; ambulances diverted; pharmacies closed; elective procedures postponed; 8-12% volume decline May-June 2024",
    "remediation_disclosed": "Mandiant engaged; systems rebuilt; EHR restored in phases; law enforcement notified; FBI/CISA advisory issued on Black Basta",
    "primary_source_url": "https://www.hipaajournal.com/ascension-cyberattack-2024/",
    "secondary_source_urls": [
      "https://www.blackfog.com/ascension-ransomware-attack/",
      "https://www.v-comply.com/blog/ascensiorn-cyber-attack/"
    ],
    "confidence_notes": "Very high confidence; OCR confirmed 5,599,699 (updated Dec 2024 from 500 placeholder); third-largest 2024 breach",
    "sources_used": [
      "HIPAA Journal, BlackFog, VComply"
    ],
    "id": "INC-00533",
    "year": 2024,
    "lat": 32.3082876,
    "lng": -95.3299535,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Ascension St. Vincent Indiana (part of Ascension May 2024 attack)",
    "organization_type": "Nonprofit Catholic Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2024-05-08",
    "disclosure_date": "2024-05-14",
    "executive_summary": "Ascension St. Vincent hospitals in Indiana were among the facilities disrupted in the Ascension Health Black Basta ransomware attack of May 2024. WRTV Indianapolis reported hospital operations affected statewide across Indiana. This is the Indiana-specific component of the Ascension system-wide attack (see MW-002) with operations disrupted at St. Vincent hospitals across Indiana.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Black Basta",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5600000,
    "residents_affected_in_state": "Indiana residents (St. Vincent hospital system)",
    "financial_impact": "Covered under Ascension system-wide impact",
    "operational_impact": "All Ascension St. Vincent Indiana facilities disrupted; clinical operations impacted; staff reverting to paper records",
    "remediation_disclosed": "Yes \u2014 same as Ascension MW-002 remediation",
    "primary_source_url": "https://www.wrtv.com/news/local-news/ascension-st-vincent-affected-by-cyber-attack-to-its-network",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. WRTV Indianapolis confirmed Indiana Ascension St. Vincent impact.",
    "sources_used": [
      "WRTV Indianapolis"
    ],
    "id": "INC-00534",
    "year": 2024,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Atrium Health (NC) \u2013 Email Phishing Attack",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Charlotte",
    "hq_county": "Mecklenburg",
    "discovery_date": "2024-04-29",
    "disclosure_date": "2024-09-16",
    "executive_summary": "On April 29, 2024, Atrium Health detected suspicious activity in its email environment. Investigation confirmed an email phishing attack between April 29\u201330, 2024 that compromised employee email accounts. The compromised accounts contained sensitive patient and employee information including SSNs, bank account details, access credentials, and treatment/diagnosis data. The review was completed July 17, 2024; notifications began September 2024.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; PHI and credentials exposed",
    "remediation_disclosed": "Compromised accounts secured; additional email security measures implemented; notifications mailed September 2024",
    "primary_source_url": "https://straussborrelli.com/2024/09/16/atrium-health-data-breach-investigation-2/",
    "secondary_source_urls": [
      "https://securityaffairs.com/171747/data-breach/atrium-health-disclosed-a-data-breach.html"
    ],
    "confidence_notes": "Breach notice confirmed by Strauss Borrelli. Security Affairs also reports the April 2024 phishing incident separately. Number of affected individuals not confirmed at time of research.",
    "sources_used": [
      "Strauss Borrelli PLLC",
      "SecurityAffairs"
    ],
    "id": "INC-00535",
    "year": 2024,
    "lat": 35.2271,
    "lng": -80.8431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Atrium Health (NC) \u2013 Meta Pixel / Online Tracking",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Charlotte",
    "hq_county": "Mecklenburg",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2024-12-06",
    "executive_summary": "Atrium Health disclosed in December 2024 that online tracking technologies (Google, Meta/Facebook pixels) were present on its MyAtriumHealth (formerly MyCarolinas) patient portal from January 2015 to July 2019, potentially transmitting patient data to third parties. The HHS OCR notification listed 585,959 individuals. No SSNs, financial accounts, or clinical records were exposed. There is no evidence of misuse.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (tracking pixels)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 585959,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI of portal users potentially transmitted to Google and Meta",
    "remediation_disclosed": "Tracking technologies removed; HHS OCR notified December 2024",
    "primary_source_url": "https://www.securityweek.com/atrium-health-data-breach-impacts-585000-people/",
    "secondary_source_urls": [
      "https://securityaffairs.com/171747/data-breach/atrium-health-disclosed-a-data-breach.html"
    ],
    "confidence_notes": "HHS OCR lists 585,959 affected. SecurityWeek and SecurityAffairs corroborate. Note: HHS categorizes as 'Unauthorized Access/Disclosure' not Hacking. Included as cyber/tracking incident per task scope.",
    "sources_used": [
      "SecurityWeek",
      "SecurityAffairs"
    ],
    "id": "INC-00536",
    "year": 2024,
    "lat": 35.2271,
    "lng": -80.8431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Avera Health / Avera McKennan (via Change Healthcare 2024)",
    "organization_type": "Nonprofit Catholic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-05-01",
    "executive_summary": "Avera Health, the Sioux Falls, South Dakota-based Catholic health system serving South Dakota, Minnesota, North Dakota, Iowa, and Nebraska, was significantly affected by the February 2024 Change Healthcare ransomware attack. As a major regional health system, Avera relied on Change Healthcare for claims processing, eligibility verification, and prior authorization. The attack caused significant operational disruptions and financial losses for Avera facilities, which include Avera McKennan Hospital and dozens of clinics and critical access hospitals across the region. The full financial impact was not separately quantified by Avera beyond general disclosures about revenue cycle disruptions common to the Change Healthcare attack.",
    "attack_type": "Third-Party Operational Impact (Change Healthcare ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV (Change Healthcare attacker)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately reported \u2014 Avera patient data not directly breached; operational impact",
    "residents_affected_in_state": "South Dakota patients experienced care and billing delays",
    "financial_impact": "Not separately quantified by Avera; part of nationwide $1.5B+ Change Healthcare losses",
    "operational_impact": "Claims processing disrupted; eligibility verification unavailable; revenue cycle impact across Avera facilities",
    "remediation_disclosed": "Yes \u2014 Avera implemented workarounds; see Change Healthcare disclosure (MW-001)",
    "primary_source_url": "https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. Avera's specific exposure documented in regional healthcare reporting. Avera did not separately report a direct breach but was a major operational victim.",
    "sources_used": [
      "HIPAA Journal (Change Healthcare)",
      "AHA (American Hospital Association) reports on impact"
    ],
    "id": "INC-00537",
    "year": 2024,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Axis Health System",
    "organization_type": "Behavioral Health / Community Health",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CO",
    "hq_city": "Durango",
    "hq_county": "La Plata",
    "discovery_date": "2024-08-01",
    "disclosure_date": "2024-10-10",
    "executive_summary": "Rhysida ransomware group breached Axis Health System's 13 western Colorado facilities from July 9 to September 4, 2024. 2.8 TB of mental health, substance abuse, and primary care patient records stolen. 25 BTC ransom (~$1.6M) not paid; data leaked on dark web. Patient portal taken offline.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not publicly disclosed; OCR filing pending",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; ransom not paid",
    "operational_impact": "Patient portal offline; behavioral health records leaked",
    "remediation_disclosed": "Incident response activated; portal offline; patient notifications by mail",
    "primary_source_url": "https://www.hipaajournal.com/axis-health-system-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.durangoherald.com/articles/hackers-leak-thousands-of-confidential-files-from-axis-health-system/",
      "https://www.bankinfosecurity.com/rhysida-threats-a-26516"
    ],
    "confidence_notes": "High confidence; Rhysida confirmed on dark web; Durango Herald verified PHI in leaked files",
    "sources_used": [
      "HIPAA Journal",
      "Durango Herald",
      "BankInfoSecurity"
    ],
    "id": "INC-00538",
    "year": 2024,
    "lat": 37.2769484,
    "lng": -107.8766,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Bayhealth Medical Center",
    "organization_type": "Hospital",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "DE",
    "hq_city": "Dover",
    "hq_county": "Kent",
    "discovery_date": "2024-07-27",
    "disclosure_date": "2024-08-08",
    "executive_summary": "Bayhealth Medical Center in Delaware was targeted by the Rhysida ransomware group in July 2024. Rhysida demanded a 25 Bitcoin ransom (~$1.4M) and exfiltrated sensitive patient data including passport scans, SSNs, and employee documents, publishing some on the dark web. The breach affected 483,378 individuals. Bayhealth agreed to a $2.5 million settlement.",
    "attack_type": "Ransomware (Rhysida)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": 483378,
    "residents_affected_in_state": 483378,
    "financial_impact": "$2.5 million settlement; 25 BTC ransom demanded",
    "operational_impact": "Sensitive patient data published on dark web; significant data exposure",
    "remediation_disclosed": "Law enforcement notified; data monitoring offered; $2.5M settlement pending approval",
    "primary_source_url": "https://bayhealthdataincidentsettlement.com",
    "secondary_source_urls": [
      "https://www.delawarepublic.org/science-health-tech/2025-09-22/bayhealth-medical-settles-a-lawsuit-following-patient-data-breach",
      "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/"
    ],
    "confidence_notes": "DE AG filing confirmed 483,378 DE residents; settlement website; Rhysida claimed",
    "sources_used": [
      "Bayhealth Settlement Website",
      "Delaware Public Media",
      "Delaware AG"
    ],
    "id": "INC-00539",
    "year": 2024,
    "lat": 39.1582,
    "lng": -75.5244,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Bluebonnet Trails Community Services",
    "organization_type": "Behavioral Health / Community Mental Health",
    "organization_type_bucket": "Behavioral / Mental health",
    "state": "TX",
    "hq_city": "Georgetown",
    "hq_county": "Williamson",
    "discovery_date": "2023-10-04",
    "disclosure_date": "2024-04-30",
    "executive_summary": "Unauthorized access to employee email accounts July 20\u2013October 6, 2023. 76,165 individuals affected including mental health patients across central Texas. Data included names, SSNs, financial account numbers, medical and health insurance information.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 76165,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email environment compromised",
    "remediation_disclosed": "Email accounts secured; additional safeguards implemented; HHS notified",
    "primary_source_url": "https://www.hipaajournal.com/email-breaches-medstar-bluebonnet-trails-community-services-bluegrass-care-navigators/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/bluebonnet-trails-community-services-april-2024"
    ],
    "confidence_notes": "High confidence; 76,165 per HHS OCR; HIPAA Journal confirmed; ClassAction.org documented class action",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org"
    ],
    "id": "INC-00540",
    "year": 2024,
    "lat": 30.6370152,
    "lng": -97.6775634,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Boston Children's Health Physicians (BCHP)",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "NY",
    "hq_city": "Valhalla",
    "hq_county": "Westchester",
    "discovery_date": "2024-09-10",
    "disclosure_date": "2024-10-18",
    "executive_summary": "Boston Children's Health Physicians, a pediatric group operating in New York and Connecticut, discovered a cyberattack on September 10, 2024 after an IT vendor detected unusual activity on September 6. BianLian ransomware group claimed responsibility and listed BCHP on its dark web site, claiming possession of patient, financial, and HR data. Affected data included names, SSNs, addresses, DOBs, and limited treatment information. EHR systems were not affected.",
    "attack_type": "Ransomware (BianLian) with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "BianLian",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "IT systems in limited parts of network shut down; patient and employee data exfiltrated",
    "remediation_disclosed": "Affected systems shut down; third-party forensic firm engaged; law enforcement notified",
    "primary_source_url": "https://classlawdc.com/2024/10/18/boston-childrens-health-physicians-data-breach-investigation/",
    "secondary_source_urls": [
      "https://blog.cloudticity.com/boston-childrens-cyberattack",
      "https://www.paubox.com/blog/learning-from-the-boston-childrens-health-physicians-ransomware-attack"
    ],
    "confidence_notes": "BCHP confirmed breach; BianLian claimed; The Record reporting; EHR confirmed unaffected",
    "sources_used": [
      "Migliaccio & Rathod",
      "Cloudticity",
      "Paubox"
    ],
    "id": "INC-00541",
    "year": 2024,
    "lat": 41.075213,
    "lng": -73.7750061,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Cedars-Sinai Medical Center \u2014 DDoS Attack (Anonymous Sudan)",
    "organization_type": "Nonprofit academic medical center (tertiary referral hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles County",
    "discovery_date": "2024-02-01",
    "disclosure_date": "2024-10-16",
    "executive_summary": "In February 2024, Anonymous Sudan conducted a DDoS attack against Cedars-Sinai Medical Center that shut down the emergency department, forcing incoming patients to be redirected to other facilities for approximately eight hours. The attack was part of a broader campaign by the group targeting US critical infrastructure. Two Sudanese nationals \u2014 Ahmed Salah Yousif Omer (age 22) and Alaa Salah Yusuuf Omer (age 27) \u2014 were indicted by a federal grand jury in October 2024 for operating Anonymous Sudan, which is alleged to have conducted 35,000+ DDoS attacks. Total damages to US victims exceeded $10 million. No patient data breach was reported.",
    "attack_type": "Distributed Denial of Service (DDoS)",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "Anonymous Sudan",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "NOT_APPLICABLE (no patient data breach)",
    "residents_affected_in_state": "NOT_APPLICABLE",
    "financial_impact": "{'notes': 'DOJ cited over $10M in damages across US victims in the Anonymous Sudan campaign; Cedars-Sinai-specific damages not separately disclosed.'}",
    "operational_impact": "Emergency department shutdown for approximately 8 hours; patient diversions to alternative facilities.",
    "remediation_disclosed": "Emergency department restored; law enforcement notified. FBI seized Anonymous Sudan's DDoS tool (DCAT).",
    "primary_source_url": "https://www.justice.gov/usao-cdca/pr/two-sudanese-nationals-indicted-alleged-role-anonymous-sudan-cyberattacks-hospitals",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/two-men-indicted-cyberattack-on-cedars-sinai/",
      "https://hackread.com/us-charges-anonymous-sudan-35000-ddos-attacks/"
    ],
    "confidence_notes": "Specific February 2024 date based on indictment timeline. No PHI breach associated with DDoS attack. Indictment unsealed October 16, 2024. This is a different category from data breaches \u2014 included as landmark operational incident per task instructions.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00542",
    "year": 2024,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Center for Vein Restoration \u2014 SC impact",
    "organization_type": "Healthcare Provider / Vascular Medicine",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Greenbelt",
    "hq_county": "Prince George's County (MD-based)",
    "discovery_date": "2024-09-01",
    "disclosure_date": "2024-12-12",
    "executive_summary": "Center for Vein Restoration, which operates vein treatment centers in multiple SE states including South Carolina, reported a data breach affecting 6,207 South Carolina residents per the SC AG. The breach exposed patient PHI and PII from vein treatment records.",
    "attack_type": "Unauthorized Access / Network Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 6207,
    "residents_affected_in_state": 6207,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Vein treatment patient PHI exposed",
    "remediation_disclosed": "SC AG notified December 2024",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing with 6,207 SC residents December 2024.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00543",
    "year": 2024,
    "lat": 32.9361774,
    "lng": -80.257314,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Centers for Medicare & Medicaid Services / Wisconsin Physicians Service Insurance Corporation (WPS)",
    "organization_type": "Federal Agency / Government Contractor",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WI",
    "hq_city": "Madison",
    "hq_county": "Dane",
    "discovery_date": "2024-07-08",
    "disclosure_date": "2024-09-06",
    "executive_summary": "Wisconsin Physicians Service Insurance Corporation (WPS), a Medicare administrative contractor for the Centers for Medicare & Medicaid Services (CMS), used Progress Software's MOVEit Transfer to move large files of Medicare beneficiary data. The Cl0p ransomware group exploited CVE-2023-34362 between May 27\u201331, 2023, before WPS applied the patch. WPS discovered evidence of the intrusion only in a May 2024 re-investigation, and on July 8, 2024 identified personal information in the exfiltrated files. CMS notified the public September 6, 2024 and reported to HHS OCR a total of 3,112,815 individuals affected \u2014 946,801 current Medicare beneficiaries received notification letters; the remainder were deceased individuals or others in WPS's CMS-related databases. Compromised data included Medicare Beneficiary Identifiers (MBI), Social Security numbers, dates of service, and other sensitive Medicare data.",
    "attack_type": "Supply Chain / MOVEit Zero-Day SQL Injection (CVE-2023-34362) / Data Theft",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 3112815,
    "residents_affected_in_state": "Nationwide (Medicare beneficiaries across all U.S. states)",
    "financial_impact": "Federal agency costs not separately disclosed. CMS coordinating with law enforcement and forensics consultants. 12 months of credit monitoring offered to 946,801 current Medicare beneficiaries.",
    "operational_impact": "Pure data theft. No encryption or service disruption. Medicare data including MBIs and SSNs compromised \u2014 high identity theft risk for elderly population.",
    "remediation_disclosed": "WPS applied MOVEit patch early June 2023. Secondary investigation May 2024 discovered exfiltration. Law enforcement engaged. CMS and WPS coordinating remediation. Credit monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/cms-wisconsin-physicians-service-moveit-hack/",
    "secondary_source_urls": [
      "https://www.compliancejunction.com/moveit-hack-on-wisconsin-physicians-service-impacted-3-1-million-individuals/",
      "https://infosecdefence.com/blogdetails/CMS-Reports-Data-Breach-Affecting-Millions"
    ],
    "confidence_notes": "High confidence. CMS is a federal agency with public press releases. HHS OCR breach report public. HIPAA Journal detailed coverage. Discrepancy between 946K notified and 3.1M total OCR count explained by CMS.",
    "sources_used": [
      "HIPAA Journal",
      "ComplianceJunction",
      "InfoSec Defence",
      "CMS official press release"
    ],
    "id": "INC-00544",
    "year": 2024,
    "lat": 43.0731,
    "lng": -89.4012,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Change Healthcare (UnitedHealth Group subsidiary) \u2014 California Provider Impact",
    "organization_type": "Healthcare clearinghouse / payment processing (business associate to thousands of CA providers)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Nashville, TN (Change Healthcare); Note: CA providers widely affected",
    "hq_county": "NOT_APPLICABLE (Tennessee HQ; CA impact via provider relationships)",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-02-21",
    "executive_summary": "On February 21, 2024, Change Healthcare \u2014 the nation's largest healthcare clearinghouse processing 15 billion transactions annually \u2014 detected a ransomware attack by ALPHV/BlackCat. Attackers first accessed the network on February 12 via a Citrix remote access portal lacking multi-factor authentication. Change disconnected its systems, causing weeks-long outages that disrupted claims processing, eligibility verification, pharmacy transactions, and prior authorization for California and national providers. UnitedHealth CEO confirmed a $22 million ransom payment. Later updated notifications reflect 192.7 million individuals affected nationally (as of July 2025) \u2014 the largest healthcare data breach in US history. California providers and patients were extensively impacted given Change's dominant market position.",
    "attack_type": "Ransomware with data exfiltration (ALPHV/BlackCat + subsequent RansomHub extortion)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat (primary); RansomHub (secondary extortion)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 192700000,
    "residents_affected_in_state": 24000000,
    "financial_impact": "{'ransom_paid': 22000000, 'total_disclosed': 2457000000, 'notes': '$22M ransom paid in Bitcoin (confirmed by CEO Witty to Congress, April 30, 2024); $2.457B total cyberattack impacts through Sept 30, 2024 per UHG filings; $3.3B advanced to providers nationwide; litigation MDL consolidated in MN federal court.'}",
    "operational_impact": "Claims processing halted nationwide for weeks; pharmacy transactions disrupted; eligibility verification offline; provider revenue cycles severely disrupted; California hospitals, physician practices, labs, and pharmacies lost revenue and faced cash-flow crises. AMA survey found 4 in 5 clinicians lost revenue. Multiple CA provider lawsuits.",
    "remediation_disclosed": "Systems disconnected Feb 21, 2024; FBI and federal authorities engaged; OCR investigation opened March 2024; provider advance payment program launched; gradual system restoration over months. Notifications sent from July 2024; 100M notices by October 2024; 192.7M by July 2025.",
    "primary_source_url": "https://krebsonsecurity.com/2024/10/change-healthcare-breach-hits-100m-americans/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/payers/100m-people-impacted-massive-change-healthcare-cyberattack-ocr",
      "https://jamanetwork.com/journals/jama-health-forum/fullarticle/2823757",
      "https://www.nixonpeabody.com/insights/alerts/2025/11/12/change-healthcare-cybersecurity-breach-impact-on-healthcare-providers",
      "https://hyperproof.io/resource/understanding-the-change-healthcare-breach/"
    ],
    "confidence_notes": "Change Healthcare is headquartered in Tennessee but is included because of massive CA provider and patient impact. This is the largest healthcare data breach in US history. UHG disclosed first 500 individuals to OCR in July 2024 (provisional), later revised to 100M (October 2024), then 190M (January 2025), then 192.7M (July 2025). Root cause: Citrix portal without MFA.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00545",
    "year": 2024,
    "lat": 36.92153339712868,
    "lng": -120.72953307508003,
    "is_multistate": true,
    "hq_outside_state": "Nashville",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Change Healthcare (UnitedHealth Group)",
    "organization_type": "Business Associate / Health Technology",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TN",
    "hq_city": "Nashville",
    "hq_county": "Davidson",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-04-22",
    "executive_summary": "Change Healthcare, a UnitedHealth Group subsidiary processing claims for ~50% of US patients, was struck by ALPHV/BlackCat ransomware on February 21, 2024. The attack affected virtually all US healthcare organizations including extensive NE hospital systems. UHG paid a $22M ransom; attackers retained data and a second ransom was demanded by RansomHub. Approximately 190 million Americans were affected\u2014the largest US healthcare breach ever. NJ, NY, MA, PA, MD, CT, and other NE state providers were all operationally disrupted.",
    "attack_type": "Ransomware (ALPHV/BlackCat) with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat; RansomHub (second extortion)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 190000000,
    "residents_affected_in_state": "All NE states affected; not separately reported by state",
    "financial_impact": "$22 million ransom paid; UHG losses exceeding $872 million",
    "operational_impact": "Nationwide pharmacy and claims processing outage lasting weeks; hospitals and providers unable to bill; NE providers significantly disrupted",
    "remediation_disclosed": "FBI investigation; ransom paid ($22M) without data return; congressional testimony; notifications mailed to millions",
    "primary_source_url": "https://techcrunch.com/2025/01/27/how-the-ransomware-attack-at-change-healthcare-went-down-a-timeline/",
    "secondary_source_urls": [
      "https://www.aha.org/change-healthcare-cyberattack-underscores-urgent-need-strengthen-cyber-preparedness-individual-health-care-organizations-and",
      "https://energycommerce.house.gov/posts/what-we-learned-change-healthcare-cyber-attack",
      "https://www.ibm.com/think/news/change-healthcare-22-million-ransomware-payment"
    ],
    "confidence_notes": "UHG confirmed; congressional testimony; OCR breach report; 190M affected confirmed January 2025",
    "sources_used": [
      "TechCrunch",
      "AHA",
      "House Energy & Commerce Committee",
      "IBM"
    ],
    "id": "INC-00546",
    "year": 2024,
    "lat": 36.1627,
    "lng": -86.7816,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Change Healthcare / UnitedHealth Group / Optum",
    "organization_type": "Healthcare Technology / Clearinghouse / Health Insurer",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MN",
    "hq_city": "Eden Prairie",
    "hq_county": "Hennepin",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-02-22",
    "executive_summary": "BlackCat/ALPHV ransomware affiliate breached Change Healthcare (UnitedHealth Group subsidiary) using stolen credentials on a Citrix remote access portal lacking MFA. Ransomware was deployed Feb. 21, 2024, forcing disconnection of 100+ systems and causing a multi-week nationwide outage of healthcare payment/claims processing. UHG paid a $22 million ransom; data was not deleted. RansomHub subsequently attempted additional extortion. Ultimately 190 million+ individuals were affected \u2014 the largest known healthcare data breach ever reported. Nebraska AG filed suit (Dec. 2024). Fairview Health sued for $7M+ in losses.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV (and RansomHub secondary extortion)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 192700000,
    "residents_affected_in_state": 900000,
    "financial_impact": "UHG estimated $1.5B+ total impact; $22M ransom paid; UHG reported $872M in direct losses rising to $1B+; Fairview sued for $7M; IU Health claimed $66M in damages; dozens of provider lawsuits pending",
    "operational_impact": "Multi-week nationwide outage of claims processing; 94% of surveyed hospitals reported financial impact; 74% reported direct patient care delays; pharmacies unable to process prescriptions; widespread revenue cycle disruption across thousands of providers",
    "remediation_disclosed": "Yes \u2014 MFA implemented, system segmentation improved, third-party forensic investigation completed, substitute breach notice July 2024, individual notifications rolling from July 2024 onward",
    "primary_source_url": "https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/",
    "secondary_source_urls": [
      "https://www.blackfog.com/change-healthcare-landmark-cybersecurity-breach/",
      "https://www.ibm.com/think/news/change-healthcare-22-million-ransomware-payment",
      "https://www.aha.org/change-healthcare-cyberattack-underscores-urgent-need-strengthen-cyber-preparedness-individual-health-care-organizations-and",
      "https://ago.nebraska.gov/news/court-allows-attorney-general-hilgers-case-against-change-healthcare-proceed-citing-impact",
      "https://www.healthcaredive.com/news/change-healthcare-cyberattack-affects-190-million-unitedhealth/738351/",
      "https://www.finance.senate.gov/chairmans-news/wyden-hearing-statement-on-change-healthcare-cyberattack-and-unitedhealth-groups-response",
      "https://hyperproof.io/resource/understanding-the-change-healthcare-breach/",
      "https://techcrunch.com/2024/02/29/unitedhealth-change-healthcare-ransomware-alphv-blackcat-pharmacy-outages/",
      "https://www.aha.org/news/headline/2025-01-27-reports-change-healthcare-cyberattack-exposed-data-190-million-people",
      "https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0000731766&type=8-K&dateb=&owner=include&count=40"
    ],
    "confidence_notes": "High confidence. CEO congressional testimony, HHS OCR breach portal, multiple state AG filings, extensive media coverage. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "AHA",
      "AHA News",
      "BlackFog",
      "Congressional testimony",
      "HHS press releases",
      "HIPAA Journal",
      "Healthcare Dive",
      "House Energy & Commerce hearing",
      "Hyperproof",
      "IBM Think",
      "Nebraska AG",
      "SEC 8-K/10-Q filings (UnitedHealth Group)",
      "Senate Finance Committee hearing transcript",
      "TechCrunch",
      "fairtprm.com"
    ],
    "id": "INC-00547",
    "year": 2024,
    "lat": 44.8546856,
    "lng": -93.470786,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Change Healthcare Inc.",
    "organization_type": "Healthcare Business Associate / Clearinghouse (Multistate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Nashville, TN (national) / CA operations impacted statewide",
    "hq_county": "N/A \u2014 national / multistate",
    "discovery_date": "2024-02-12",
    "disclosure_date": "2024-08-03",
    "executive_summary": "On February 21, 2024, CHC found activity in our computer system that happened without our permission. We quickly took steps to stop that activity. We began investigating right away, and hired a special team to help us. We also called law enforcement. We also turned off CHC\u2019s systems to help protect our customers and their individuals. On March 7, 2024, we learned a cybercriminal was able to see and take copies of some data in our computer system. This happened between February 17, 2024 and February 20, 2024. We received files that were safe to look at on March 13, 2024.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat; RansomHub subsequently claimed exploitation",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 100000000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "UHG reported over $872M in response/remediation costs (Q1 2024); ongoing claims settlements",
    "operational_impact": "Massive nationwide disruption to prescription processing, claims submissions, prior authorizations for weeks; UnitedHealth Group subsidiary; ~$872M in immediate response costs reported",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/July%2029%202024%20Change%20Healthcare%20Individual%20Notification.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/change-healthcare-cyberattack/",
      "https://www.bleepingcomputer.com/tag/change-healthcare/",
      "https://www.hhs.gov/about/news/2024/02/26/hhs-statement-regarding-the-cyberattack-on-change-healthcare.html"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00548",
    "year": 2024,
    "lat": 36.22074151113038,
    "lng": -119.16121440947708,
    "is_multistate": true,
    "hq_outside_state": "Nashville",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Change Healthcare \u2014 Florida hospital impact",
    "organization_type": "Business Associate / Healthcare Clearinghouse",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "FL",
    "hq_city": "Nashville",
    "hq_county": "Davidson County (TN-based)",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-06-21",
    "executive_summary": "Change Healthcare (UnitedHealth Group subsidiary), one of the largest healthcare payment clearinghouses, suffered a catastrophic ransomware attack by ALPHV/BlackCat beginning February 12, 2024. The attack disrupted claims processing and payment operations nationwide. Florida had over 100 hospitals that directly contracted with Change Healthcare. The total breach affected 192.7 million individuals nationally. Florida providers experienced severe cash flow disruptions.",
    "attack_type": "Ransomware (ALPHV/BlackCat)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat (RansomHub also claimed)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 192700000,
    "residents_affected_in_state": "Not separately reported (national breach)",
    "financial_impact": "$22M ransom paid; total cost to UnitedHealth Group exceeded $2.457 billion through Q3 2024; >$2.55B in advance Medicare payments issued to affected providers",
    "operational_impact": "All claims processing and payment operations disrupted for weeks; >100 FL hospitals directly impacted; 94% of US hospitals reported financial impact; 74% reported direct patient care impact",
    "remediation_disclosed": "100+ systems disconnected; Citrix portal MFA implemented; $22M ransom paid to ALPHV; advance payment programs established by CMS; patient notification initiated July 2024",
    "primary_source_url": "https://www.wusf.org/health-news-florida/2024-06-21/change-healthcare-to-start-notifying-customers-who-had-data-exposed-in-cyberattack",
    "secondary_source_urls": [
      "https://www.aha.org/news/news/2024-03-15-aha-survey-change-healthcare-cyberattack-having-significant-disruptions-patient-care-hospitals-finances",
      "https://hyperproof.io/resource/understanding-the-change-healthcare-breach/"
    ],
    "confidence_notes": "High confidence \u2014 WUSF/NPR reporting specifically covers FL hospital impact; AHA survey data; UnitedHealth Group earnings. FL entry added for FL-specific impact documentation even though HQ is TN.",
    "sources_used": [
      "WUSF Public Media",
      "American Hospital Association",
      "Hyperproof",
      "Nixon Peabody LLP"
    ],
    "id": "INC-00549",
    "year": 2024,
    "lat": 28.5447786,
    "lng": -81.3993516,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Children's Mercy Kansas City (via Change Healthcare 2024)",
    "organization_type": "Pediatric Children's Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "Kansas City",
    "hq_county": "Jackson",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-04-01",
    "executive_summary": "Children's Mercy Kansas City, a major pediatric hospital serving Kansas City, Missouri and Kansas City, Kansas, was significantly affected by the February 2024 Change Healthcare ransomware attack. Children's Mercy relied on Change Healthcare for insurance verification, prior authorizations, and claims processing. The attack disrupted these critical administrative functions for an extended period, causing revenue cycle impacts and delays in accessing payer information. Children's Mercy did not experience a direct data breach but was among the Kansas City healthcare organizations hardest hit by the Change Healthcare outage.",
    "attack_type": "Third-Party Operational Impact (Change Healthcare ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV (Change Healthcare attacker)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately reported \u2014 operational impact only",
    "residents_affected_in_state": "Missouri and Kansas pediatric patients experienced billing and authorization delays",
    "financial_impact": "Not separately quantified; part of nationwide $1.5B+ Change Healthcare losses",
    "operational_impact": "Insurance verification, prior authorization, and claims processing disrupted for extended period",
    "remediation_disclosed": "Yes \u2014 workarounds implemented; see Change Healthcare disclosure (MW-001)",
    "primary_source_url": "https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. Children's Mercy is confirmed Change Healthcare client; operational impact well-documented through AHA reporting.",
    "sources_used": [
      "HIPAA Journal",
      "AHA (American Hospital Association)"
    ],
    "id": "INC-00550",
    "year": 2024,
    "lat": 39.0997,
    "lng": -94.5786,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "City of Hope National Medical Center",
    "organization_type": "Nonprofit cancer treatment and research center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Duarte",
    "hq_county": "Los Angeles County",
    "discovery_date": "2023-10-13",
    "disclosure_date": "2024-04-02",
    "executive_summary": "Between September 19 and October 12, 2023, an unauthorized third party accessed City of Hope's systems and exfiltrated copies of files. City of Hope detected suspicious activity on October 13, 2023, and immediately launched an investigation with a leading cybersecurity firm. The breach affected 827,149 individuals, exposing names, SSNs, financial account numbers, health insurance information, medical records, and diagnoses. City of Hope agreed to an $8.5 million class-action settlement in 2025.",
    "attack_type": "Hacking / unauthorized network access with data exfiltration (attack type not publicly specified)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 827149,
    "residents_affected_in_state": 250,
    "financial_impact": "{'litigation_settlement': 8500000, 'notes': '$8.5M class-action settlement; California class members eligible for additional $250 statutory payment. Two years of free credit monitoring offered.'}",
    "operational_impact": "No reported patient care disruption or EHR downtime publicly disclosed.",
    "remediation_disclosed": "Mitigation measures implemented October 13, 2023; investigation launched with cybersecurity firm; law enforcement notified; regulatory agencies notified. Individual email notifications sent December 14, 2023. Mail notifications sent April 2, 2024. Two years of free identity monitoring offered.",
    "primary_source_url": "https://www.hipaajournal.com/city-of-hope-cyberattack-affects-827000-individuals/",
    "secondary_source_urls": [
      "https://www.fiercehealthcare.com/health-tech/city-hope-discloses-data-breach-impacting-827k-patients-personal-and-health-information",
      "https://www.bleepingcomputer.com/news/security/us-cancer-center-data-breach-exposes-info-of-827-000-patients/",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/8-5m-city-of-hope-data-breach-settlement/"
    ],
    "confidence_notes": "Notification delay: nearly 6 months from detection to public disclosure (Oct 13, 2023 to Apr 2, 2024). Specific attack type (e.g., ransomware) not publicly confirmed; no ransomware group claimed credit publicly. Maine AG filing confirmed 827,149 nationally. Settlement claim deadline Jan 13, 2026.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00551",
    "year": 2024,
    "lat": 34.1395,
    "lng": -117.9773,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Cogdell Memorial Hospital (Scurry County Hospital District)",
    "organization_type": "Healthcare Provider (Critical Access Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Snyder",
    "hq_county": "Scurry",
    "discovery_date": "2024-01-01",
    "disclosure_date": "2024-02-24",
    "executive_summary": "Cogdell Memorial Hospital (Scurry County Hospital District) reported a hacking/IT incident to HHS that affected 86,981 individuals. A critical access hospital in West Texas, this breach was among several at smaller Texas healthcare facilities reported in 2024.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 86981,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://lubbocklights.com/umc-paid-ransom-with-insurance-data-was-restored-not-sold-on-dark-web/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; cited in Lubbock Lights article referencing HHS OCR data; limited additional sources found",
    "sources_used": [
      "Lubbock Lights"
    ],
    "id": "INC-00552",
    "year": 2024,
    "lat": 32.7180803,
    "lng": -100.918231,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Community Clinic of Maui (Malama I Ke Ola Health Center)",
    "organization_type": "Healthcare Provider (Community Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Wailuku",
    "hq_county": "Maui",
    "discovery_date": "2024-05-07",
    "disclosure_date": "2024-09-27",
    "executive_summary": "The Community Clinic of Maui (also known as Malama I Ke Ola Health Center), a non-profit healthcare organization in Hawaii, suffered a LockBit ransomware attack between May 4 and May 7, 2024. The attack caused a two-week operational shutdown. Data stolen included names, Social Security numbers, dates of birth, driver's license numbers, passport numbers, bank and payment card information, login credentials, and a wide range of sensitive medical information. The clinic did not publicly disclose whether a ransom was paid.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit ransomware group",
    "attribution_status": "claimed",
    "individuals_affected_reported": 123882,
    "residents_affected_in_state": "Majority HI-based (Maui County)",
    "financial_impact": "Not publicly disclosed; operations shut down for ~2 weeks",
    "operational_impact": "Two-week clinic closure; scheduling and clinical systems disrupted",
    "remediation_disclosed": "Systems restored; law enforcement notified; credit monitoring offered",
    "primary_source_url": "https://www.securityweek.com/hawaii-health-center-discloses-data-breach-after-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.scworld.com/brief/over-123k-impacted-by-community-clinic-of-maui-hack"
    ],
    "confidence_notes": "Maine AG notification confirmed 123,882 individuals; LockBit claimed responsibility in June 2024",
    "sources_used": [
      "SecurityWeek",
      "SC Media"
    ],
    "id": "INC-00553",
    "year": 2024,
    "lat": 20.8893,
    "lng": -156.504,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Community Health Center Inc. (CT FQHC)",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "Middletown",
    "hq_county": "Middlesex",
    "discovery_date": "2023-01-02",
    "disclosure_date": "2024-01-08",
    "executive_summary": "Community Health Center Inc. (CHC), one of Connecticut's largest federally qualified health centers serving over 145,000 patients annually, reported a data breach that occurred on January 2, 2023. The breach involved unauthorized access to its systems by a skilled criminal hacker who obtained names, dates of birth, diagnoses, and Social Security numbers. Approximately 318,440 individuals were affected.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 318440,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "CT community health center patient PHI compromised; SSNs and diagnoses exposed",
    "remediation_disclosed": "HHS OCR and patients notified; security enhanced",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "HHS OCR breach portal confirms 318,440 affected; major CT FQHC; well documented",
    "sources_used": [
      "HHS OCR",
      "HIPAA Journal"
    ],
    "id": "INC-00554",
    "year": 2024,
    "lat": 41.5623178,
    "lng": -72.6509061,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Community Health Network (Indiana) via Change Healthcare 2024",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2024-02-17",
    "disclosure_date": "2024-02-21",
    "executive_summary": "Community Health Network (CHN) and other Indiana healthcare providers were severely disrupted as downstream victims of the February 2024 Change Healthcare ransomware attack. An Indianapolis-area incident involving a cyber criminal who claimed to have stolen data from a health provider serving central Indiana \u2014 with billing documents exposed affecting 316,802 individuals \u2014 was reported to HHS. The hacker did not access medical records but billing documents were exposed.",
    "attack_type": "Data Exfiltration / Hacking",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 316802,
    "residents_affected_in_state": "Indiana (central Indiana) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Billing data exposed; medical records not accessed; operations impacted by downstream Change Healthcare outage",
    "remediation_disclosed": "Yes \u2014 investigation launched; notifications sent",
    "primary_source_url": "https://www.indystar.com/story/news/health/2024/06/27/cyber-attacks-indiana-in-2023-and-2024/74216228007/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. IndyStar reporting citing government HHS data; specific organization not named in available summary.",
    "sources_used": [
      "IndyStar"
    ],
    "id": "INC-00555",
    "year": 2024,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Concentra Health Services (via PJ&A breach)",
    "organization_type": "Occupational / Physical Health Services Provider",
    "organization_type_bucket": "Healthcare provider (other)",
    "state": "TX",
    "hq_city": "Addison, TX (national; operates in all Midwest states)",
    "hq_county": "Dallas",
    "discovery_date": "2023-09-29",
    "disclosure_date": "2024-01-09",
    "executive_summary": "Concentra Health Services confirmed on January 9, 2024 that it was affected by the Perry Johnson & Associates (PJ&A) cyberattack (March 27 \u2013 May 2, 2023). As the largest single reporting entity in the PJ&A breach, Concentra confirmed 3,998,162 patients had their PHI compromised. Concentra operates occupational health centers throughout the Midwest and other regions. Compromised data included names, DOBs, addresses, medical record numbers, hospital account numbers, admission diagnoses, dates/times of service, and for some, SSNs, insurance information, and clinical transcription files.",
    "attack_type": "Third-Party Vendor Breach (medical transcription)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (PJ&A breach)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3998162,
    "residents_affected_in_state": "Multistate including all Midwest states where Concentra operates",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Concentra's own systems not breached; transcription vendor's data compromised",
    "remediation_disclosed": "Yes \u2014 PJ&A services terminated; patient notifications issued; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/pja-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal with Concentra-specific victim count from HHS OCR portal.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00556",
    "year": 2024,
    "lat": 32.9601193,
    "lng": -96.8300029,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Concentra Health Services, Inc.",
    "organization_type": "BA / Vendor affected via PJ&A",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Addison",
    "hq_county": "Dallas",
    "discovery_date": "2023-10-10",
    "disclosure_date": "2024-01-09",
    "executive_summary": "Concentra, a large Texas-based occupational and urgent care provider, confirmed January 9, 2024, that it was affected by the PJ&A (Perry Johnson & Associates) cyberattack, with 3,998,162 of its patients' data compromised between March 27 and May 2, 2023. Concentra chose to report the breach separately to HHS OCR rather than relying on PJ&A's filing. The compromised data included names, dates of birth, addresses, medical record numbers, hospital account numbers, clinical information from transcriptions, and some Social Security numbers.",
    "attack_type": "Third-Party / Business Associate Breach (via PJ&A)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (PJ&A attacker)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3998162,
    "residents_affected_in_state": "Nationwide; not separately broken out",
    "financial_impact": "Not publicly disclosed. Joined in class action suits against PJ&A.",
    "operational_impact": "No operational disruption to Concentra operations. Data held by PJ&A was compromised.",
    "remediation_disclosed": "Terminated PJ&A transcription services. Separate HHS OCR notification filed January 2024. Notification letters to affected patients.",
    "primary_source_url": "https://www.concentra.com/privacy/notice-of-data-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/pja-data-breach/",
      "https://www.hipaajournal.com/biggest-healthcare-data-breaches-2024/"
    ],
    "confidence_notes": "High confidence. Concentra filed directly with HHS OCR as 3,998,162 individuals. Source from HIPAA Journal tracking client-side reports. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Concentra official breach notice",
      "HIPAA Journal"
    ],
    "id": "INC-00557",
    "year": 2024,
    "lat": 32.9601193,
    "lng": -96.8300029,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Consulting Radiologists, Ltd.",
    "organization_type": "Physician-Owned Radiology Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2024-02-12",
    "disclosure_date": "2024-06-14",
    "executive_summary": "Consulting Radiologists detected suspicious network activity on February 12, 2024. An unauthorized actor accessed files and data within its network, affecting 583,824 individuals. Data exposed included names, addresses, DOBs, Social Security numbers, health insurance information, and medical records. Two ransomware groups \u2014 LockBit and Qilin \u2014 both claimed in April 2024 to have stolen data. Qilin claimed to have exfiltrated more than 70 GB covering 94,667 files. A $2.2 million class action settlement was reached in January 2026.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit and Qilin (both claimed responsibility)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 583824,
    "residents_affected_in_state": "Primarily Minnesota residents",
    "financial_impact": "$2.2 million class action settlement (January 2026)",
    "operational_impact": "Patient data exfiltrated; 19,346 SSNs compromised; radiology practice operations impacted",
    "remediation_disclosed": "Yes \u2014 forensic investigation; HHS OCR notified June 14, 2024; patients notified; $2.2M settlement",
    "primary_source_url": "https://www.hipaajournal.com/consulting-radiologists-data-breach/",
    "secondary_source_urls": [
      "https://minnlawyer.com/2026/01/16/consulting-radiologists-data-breach-settlement/",
      "https://www.theregister.com/2024/06/20/radiology_information_loss/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, Minnesota Lawyer, The Register, HHS OCR portal.",
    "sources_used": [
      "HIPAA Journal",
      "Minnesota Lawyer",
      "The Register"
    ],
    "id": "INC-00558",
    "year": 2024,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Delta Dental of California and affiliates",
    "organization_type": "Health Plan / Dental Insurer",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "San Francisco, CA",
    "hq_county": "San Francisco County",
    "discovery_date": "2023-05-27",
    "disclosure_date": "2024-03-14",
    "executive_summary": "What Happened? Progress Software announced a previously unknown vulnerability within their widely used MOVEit file-transfer software program. This vulnerability led to a global data security incident that is reported to have impacted many organizations, including corporations, government agencies, insurance providers, pension funds, financial institutions, state education systems and more. On June 1, 2023, the Company learned unauthorized actors exploited a vulnerability affecting the MOVEit file transfer software application. Immediately after being alerted of the incident, we launched a thor",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Cl0p",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 6928932,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; class action lawsuits filed",
    "operational_impact": "MOVEit file transfer software exploited; data accessed without encryption",
    "remediation_disclosed": "['Identity protection services offered', 'Law enforcement notified', 'Forensic investigation conducted', 'Passwords reset']",
    "primary_source_url": "https://oag.ca.gov/system/files/California%20Supplemental%20Regulatory%20Notification%204891-4706-1419%20v.5_0.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/delta-dental-of-california-data-breach/",
      "https://www.bleepingcomputer.com/news/security/delta-dental-of-california-exposes-data-of-69m-patients/"
    ],
    "confidence_notes": "Second CA AG filing for the same MOVEit/Cl0p breach (original filed 12/14/2023); additional individuals identified",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00559",
    "year": 2024,
    "lat": 37.7749,
    "lng": -122.4194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Designed Receivable Solutions (DRS) - Initial 2024 Report",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Cypress",
    "hq_county": "Orange",
    "discovery_date": "2024-01-18 (access); 2024-01-22 (detected)",
    "disclosure_date": "2024-03-23",
    "executive_summary": "Initial HHS OCR filing (subsequently revised upward to 585,035 in updated record ID 20). This is the initial submission record.",
    "attack_type": "Hacking/IT Incident \u2014 Data exfiltration / network intrusion",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 129584,
    "residents_affected_in_state": "Majority",
    "financial_impact": "See record ID 20",
    "operational_impact": "See record ID 20",
    "remediation_disclosed": "See record ID 20",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://thelyonfirm.com/blog/designed-receivable-solutions-data-breach-investigation/"
    ],
    "confidence_notes": "Initial OCR report (129,584); amended to 585,035 (see record ID 20). Kept as separate record to show progression.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00560",
    "year": 2024,
    "lat": 33.8169,
    "lng": -118.0373,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Designed Receivable Solutions, Inc. (DRS)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Cypress",
    "hq_county": "Orange",
    "discovery_date": "2024-01-18 (unauthorized access; detected Jan 22)",
    "disclosure_date": "2024-03-23",
    "executive_summary": "Revenue cycle management company DRS experienced unauthorized access and data theft from its systems. Clients affected included Cedars-Sinai Medical Center, USC Arcadia Hospital, and multiple other California healthcare providers.",
    "attack_type": "Hacking/IT Incident \u2014 Data exfiltration / network intrusion",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "claimed",
    "individuals_affected_reported": 585035,
    "residents_affected_in_state": "Majority (most clients are CA-based healthcare providers)",
    "financial_impact": "Class action lawsuits filed; settlement amounts not confirmed",
    "operational_impact": "No direct clinical operational disruption (business associate)",
    "remediation_disclosed": "Third-party cybersecurity specialists engaged; policies and procedures reviewed; 12-month identity protection services offered; data breach notifications sent April 26, 2024",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/designed-receivable-solutions-data-breach/",
      "https://www.securityweek.com/designed-receivable-solutions-data-breach-impacts-585000-people/"
    ],
    "confidence_notes": "Multiple California healthcare organizations affected as DRS clients: Cedars-Sinai, CHA Hollywood Presbyterian, USC Arcadia, Ridgecrest Regional, Marshall Medical, Redlands Community, and others. PHI included names, addresses, DOBs, SSNs, health insurance data, dates of service.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00561",
    "year": 2024,
    "lat": 33.8169,
    "lng": -118.0373,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "DocGo Inc.",
    "organization_type": "Mobile Health / EMS Provider",
    "organization_type_bucket": "Ambulance / EMS",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2024-04-01",
    "disclosure_date": "2024-05-07",
    "executive_summary": "DocGo Inc., a New York-based mobile urgent care and ambulance services company operating in 30+ U.S. states, discovered a cyberattack in April 2024 in which an unauthorized party stole sensitive patient health data, including protected health information. DocGo notified the SEC via 8-K on May 7, 2024, and subsequently filed a breach report with HHS OCR. The company stated the incident was limited to its Transportation Services segment (ambulance operations) and no evidence of continued unauthorized activity was found. DocGo reported no material impact on operations or financial condition. The exact number of affected individuals was not prominently disclosed in public sources reviewed.",
    "attack_type": "Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Company stated no material impact on operations or financial condition (per SEC 8-K). Ongoing litigation possible.",
    "operational_impact": "Limited to Transportation Services segment. No evidence of continued unauthorized access. Healthcare mobile services operations continued.",
    "remediation_disclosed": "Incident contained. Law enforcement notified. SEC 8-K filed May 7, 2024. HHS OCR breach report filed. No evidence of misuse of stolen data or significant ongoing impact as of disclosure.",
    "primary_source_url": "https://www.sec.gov/Archives/edgar/data/1822359/000182235924000015/0001822359-24-000015-index.htm",
    "secondary_source_urls": [
      "https://www.bankinfosecurity.com/hacking-docgo-ambulance-service-exposes-patient-data-a-25150",
      "https://www.techradar.com/pro/security/mobile-medical-service-docgo-confirms-it-suffered-a-major-cyberattack",
      "https://www.mobihealthnews.com/tag/docgo"
    ],
    "confidence_notes": "Moderate confidence on facts. SEC 8-K confirmed breach and stated no material impact. HHS OCR breach count not confirmed in sources reviewed. Limited public reporting on individual count.",
    "sources_used": [
      "DocGo SEC 8-K filing",
      "BankInfoSecurity",
      "TechRadar",
      "MobiHealthNews"
    ],
    "id": "INC-00562",
    "year": 2024,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Eastern Radiologists, Inc.",
    "organization_type": "Healthcare Provider (Radiology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Greenville",
    "hq_county": "Pitt",
    "discovery_date": "2023-11-24",
    "disclosure_date": "2024-02-29",
    "executive_summary": "Eastern Radiologists (NC-based radiology practice) experienced a network server hacking incident discovered on November 24, 2023. The breach was reported to HHS OCR on February 29, 2024 as affecting 886,746 individuals. A $3.25 million class action settlement was reached. Data included names, addresses, DOBs, SSNs, health insurance, and medical information.",
    "attack_type": "Network Server Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 886746,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3.25 million class action settlement",
    "operational_impact": "Network server compromised; PHI of 886K+ individuals exposed",
    "remediation_disclosed": "Investigation launched; HHS OCR notified; $3.25M settlement",
    "primary_source_url": "https://www.claimdepot.com/settlements/eastern-radiologists-settlement",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/eastern-radiologists-inc-february-2024",
      "https://www.newsweek.com/eastern-radiologist-pay-325-million-settlement-cyberattack-lawsuit-2135121"
    ],
    "confidence_notes": "HHS OCR lists 886,746 affected. Settlement confirmed by Newsweek and ClassAction.org.",
    "sources_used": [
      "Claim Depot",
      "ClassAction.org",
      "Newsweek"
    ],
    "id": "INC-00563",
    "year": 2024,
    "lat": 35.613224,
    "lng": -77.3724593,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Emergency Medical Services Authority (EMSA)",
    "organization_type": "Healthcare Provider (Emergency Medical Services \u2013 State Authority)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2024-02-13",
    "disclosure_date": "2024-04-01",
    "executive_summary": "The Emergency Medical Services Authority (EMSA), Oklahoma's primary provider of pre-hospital emergency medical care, experienced a cybersecurity incident involving unauthorized access to its network between February 10 and February 13, 2024. 611,743 individuals were affected. Compromised data included names, addresses, dates of birth, dates of service, primary care provider names, and Social Security numbers.",
    "attack_type": "Hacking/IT Incident \u2013 Network Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 611743,
    "residents_affected_in_state": "Primarily Oklahoma residents",
    "financial_impact": "$1.5M class action settlement (2026)",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Law enforcement notified; forensic investigation; notifications sent; class action settlement",
    "primary_source_url": "https://www.compliancehome.com/emergency-medical-services-authority-settles-class-action-lawsuit-for-1-5-million/",
    "secondary_source_urls": [
      "https://www.caffertyclobes.com/blog/emsa-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 611,743; class action settlement documents available",
    "sources_used": [
      "ComplianceHome, Cafferty Clobes law firm"
    ],
    "id": "INC-00564",
    "year": 2024,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Fairview Health Services",
    "organization_type": "Nonprofit Integrated Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Minneapolis",
    "hq_county": "Hennepin",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-04-15",
    "executive_summary": "Fairview Health Services suffered approximately $7 million in operational and financial losses as a downstream victim of the Change Healthcare ransomware attack (Feb. 21, 2024). The prolonged outage of Change Healthcare's claims processing systems prevented Fairview from billing for anesthesia and other clinical services for more than six months, resulting in $7M+ in uncollected revenue and bad debt. Fairview filed a lawsuit against Change Healthcare (UnitedHealth Group) in Ramsey County District Court in April 2025, later moved to U.S. District Court of Minnesota. This entry captures Fairview's downstream victimization separately from the primary Change Healthcare incident.",
    "attack_type": "Indirect / Downstream Victim (Change Healthcare ransomware outage)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV (primary attacker of Change Healthcare)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Patient data potentially compromised via Change Healthcare; Fairview-specific count not separately reported",
    "residents_affected_in_state": "Minnesota residents",
    "financial_impact": "$7M+ in lost revenue (anesthesia billing); litigation seeking damages; ongoing",
    "operational_impact": "Claims processing unavailable 6+ months for anesthesia services; cash flow virtually stopped; overtime costs; temporary vendor contracts; revenue cycle severely impacted",
    "remediation_disclosed": "Yes \u2014 third-party vendors engaged for billing; manual payment posting; lawsuit filed for recovery",
    "primary_source_url": "https://www.hipaajournal.com/fairview-health-services-sues-change-healthcare-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.startribune.com/fairview-says-it-lost-more-than-7-million-from-cyberattack-at-unitedhealth-group-subsidiary/601332511"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, Star Tribune, Ramsey County/Federal court filings.",
    "sources_used": [
      "HIPAA Journal",
      "Star Tribune"
    ],
    "id": "INC-00565",
    "year": 2024,
    "lat": 44.9778,
    "lng": -93.265,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Foundation Health Partners / Fairbanks Memorial Hospital",
    "organization_type": "Healthcare Provider (Regional Hospital / Health System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Fairbanks",
    "hq_county": "Fairbanks North Star Borough",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-04-01",
    "executive_summary": "Foundation Health Partners (FHP), which operates Fairbanks Memorial Hospital \u2014 Interior Alaska's largest healthcare provider \u2014 was significantly impacted by the nationwide Change Healthcare ransomware attack of February 21, 2024. FHP confirmed disruptions to backend insurance billing processes and delays in care coordination due to the attack on Change Healthcare's systems. While FHP stated it was able to adapt most workflows and minimize direct patient impact, the attack severed the ability to access patient payer information and process insurance, Medicare, and Medicaid payments for an extended period.",
    "attack_type": "Third-party ransomware attack (Change Healthcare/UHG upstream)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat ransomware group (via Change Healthcare)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 190000000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed (billing delays; operational disruption for extended period)",
    "operational_impact": "Insurance billing severed; payer information inaccessible; backend processes disrupted for multiple weeks",
    "remediation_disclosed": "Workflow adaptations implemented; operations gradually restored as Change Healthcare systems recovered",
    "primary_source_url": "https://fm.kuac.org/health/2024-04-01/alaska-healthcare-business-damaged-by-national-cyberattack",
    "secondary_source_urls": [
      "https://techcrunch.com/2025/01/27/how-the-ransomware-attack-at-change-healthcare-went-down-a-timeline/"
    ],
    "confidence_notes": "Foundation Health Partners / Fairbanks Memorial Hospital impact confirmed per KUAC FM reporting; distinct from AK-008 (Change Healthcare AK \u2014 that entry covers a small home health provider, Nurses Diversified Systems). FHP is a separate, distinct Alaska healthcare organization impacted. Confidence high for operational impact; individual patient count not separately reported.",
    "sources_used": [
      "KUAC FM Alaska Public Radio",
      "TechCrunch (Change Healthcare timeline)"
    ],
    "id": "INC-00566",
    "year": 2024,
    "lat": 64.8378,
    "lng": -147.7164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Gaia Software, LLC (Americare Renal Center \u2013 Colorado dialysis)",
    "organization_type": "Business Associate / Healthcare Software",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2024-02-05",
    "disclosure_date": "2024-06-28",
    "executive_summary": "Gaia Software, an EHR/billing software provider for Americare Renal Center dialysis facilities in Colorado, was targeted in a ransomware/extortion cyberattack on February 5, 2024. 56,676 individuals affected. Data included names, addresses, DOB, SSNs, health insurance and health information.",
    "attack_type": "Ransomware / Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 56676,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Dialysis patient records exposed",
    "remediation_disclosed": "Network secured; cybersecurity experts engaged; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/data-breaches-gaia-software-pinnacle-orthopaedics-sports-medicine-specialists/",
    "secondary_source_urls": [
      "https://gaiasoftware.com/wp-content/uploads/2024/06/Notice-of-Secutiry-Incident.pdf"
    ],
    "confidence_notes": "High confidence; 56,676 per HHS OCR; HIPAA Journal confirmed; Gaia breach notice confirmed CO dialysis connection",
    "sources_used": [
      "HIPAA Journal",
      "Gaia Software breach notice"
    ],
    "id": "INC-00567",
    "year": 2024,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Geisinger Health / Nuance Communications",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Danville",
    "hq_county": "Montour",
    "discovery_date": "2023-11-29",
    "disclosure_date": "2024-06-24",
    "executive_summary": "Geisinger Health discovered on November 29, 2023 that a recently terminated Nuance Communications employee (Max Vance/Andre J. Burk) had accessed patient data two days after his termination. Over 1.2 million patient records were accessed including names, DOBs, SSNs, and medical information. Nuance failed to revoke the former employee's access promptly. Geisinger and Nuance settled resulting litigation for $5 million.",
    "attack_type": "Insider threat / unauthorized access by former vendor employee",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Andre J. Burk (a/k/a Max Vance)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1276026,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$5 million settlement (2026)",
    "operational_impact": "1.27M patient records accessed/exfiltrated; delayed notification at law enforcement request",
    "remediation_disclosed": "Access immediately revoked upon discovery; FBI investigation; perpetrator arrested; $5M settlement",
    "primary_source_url": "https://www.hipaajournal.com/geisinger-former-business-associate-employee-1m-records/",
    "secondary_source_urls": [
      "https://shublawyers.com/news/geisinger-settlement-final-approval/",
      "https://www.yahoo.com/news/articles/judge-oks-5-million-settlement-195224616.html"
    ],
    "confidence_notes": "OCR breach report confirmed; perpetrator arrested; $5M settlement final approval March 2026",
    "sources_used": [
      "HIPAA Journal",
      "Shub Johns & Holbrook LLP",
      "Centre Daily Times"
    ],
    "id": "INC-00568",
    "year": 2024,
    "lat": 40.9626,
    "lng": -76.6133,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Geisinger Health System (via Nuance Communications)",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Danville",
    "hq_county": "Montour",
    "discovery_date": "2023-11-29",
    "disclosure_date": "2024-06-24",
    "executive_summary": "On November 29, 2023, Geisinger Health System discovered that a former employee of Nuance Communications (a Microsoft subsidiary providing IT services to Geisinger) had accessed Geisinger patient data two days after being terminated. The former employee, Max Vance, used his still-active Nuance credentials to access Geisinger's systems, ran queries against patient databases, and exfiltrated data for approximately 1,276,026 patients into his personal Microsoft Azure account before downloading to a personal device. Data compromised included names, dates of birth, addresses, medical record numbers, admission/discharge codes, race, gender, phone numbers, and facility names \u2014 but not Social Security numbers, financial data, or insurance claims. Vance was arrested and charged federally. Geisinger delayed notification at law enforcement's request. A $5 million class action settlement received final approval in March 2026.",
    "attack_type": "Insider Threat / Unauthorized Access by Former Employee",
    "attack_category": "Insider threat",
    "threat_actor_name": "Max Vance (former Nuance Communications employee)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1276026,
    "residents_affected_in_state": "PA: majority (Geisinger serves central and northeast Pennsylvania); exact count not separately disclosed",
    "financial_impact": "$5M class action settlement (final approval March 2026). Remediation costs not separately disclosed.",
    "operational_impact": "No system encryption or EHR outage. Pure data exfiltration by insider. Access delayed notification approximately 7 months at law enforcement request.",
    "remediation_disclosed": "Former employee's access permanently disconnected. Law enforcement engaged; federal charges filed. Notifications mailed June 24, 2024. Credit monitoring offered. $5M class action settlement.",
    "primary_source_url": "https://www.geisinger.org/about-geisinger/news-and-media/news-releases/2024/06/24/18/17/geisinger-provides-notice-of-nuances-data-security-incident",
    "secondary_source_urls": [
      "https://news.bloomberglaw.com/litigation/geisinger-nuance-reach-5-million-settlement-after-data-breach",
      "https://www.docontrol.io/blog/former-employee-stealing-patient-records",
      "https://www.hipaajournal.com/biggest-healthcare-data-breaches-2024/"
    ],
    "confidence_notes": "Extremely high confidence. Geisinger published official breach notice. Federal criminal charges filed and guilty plea confirmed. Bloomberg Law documented settlement. Perpetrator's name (Max Vance) publicly documented.",
    "sources_used": [
      "Geisinger official breach notice",
      "Bloomberg Law",
      "DoControl blog (citing court records)",
      "HIPAA Journal 2024 breach report"
    ],
    "id": "INC-00569",
    "year": 2024,
    "lat": 40.9626,
    "lng": -76.6133,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Golden Age Nursing Home (Guthrie, OK)",
    "organization_type": "Skilled Nursing / Rehabilitation Facility",
    "organization_type_bucket": "Home health / Long-term care",
    "state": "OK",
    "hq_city": "Guthrie",
    "hq_county": "Logan",
    "discovery_date": "2024-10-01",
    "disclosure_date": "2024-10-11",
    "executive_summary": "Rhysida ransomware group breached Golden Age Nursing Home in Guthrie, Oklahoma, demanding 10 BTC ransom. Claimed 102 GB stolen including medical records and discharge reports. Ransom not paid; data leaked on Rhysida dark web site.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; ransom not paid",
    "operational_impact": "Medical records and discharge reports leaked on dark web",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.bankinfosecurity.com/rhysida-threats-a-26516",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; Rhysida dark web listing confirmed; BankInfoSecurity confirmed 102GB data leak; OCR filing not found at time of research",
    "sources_used": [
      "BankInfoSecurity"
    ],
    "id": "INC-00570",
    "year": 2024,
    "lat": 35.8789231,
    "lng": -97.4252772,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Great Plains Regional Medical Center",
    "organization_type": "Healthcare Provider (Critical Access Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Elk City",
    "hq_county": "Beckham",
    "discovery_date": "2024-09-08",
    "disclosure_date": "2024-11-18",
    "executive_summary": "Great Plains Regional Medical Center in Elk City, Oklahoma suffered a ransomware attack on September 8, 2024 after attackers gained access September 5. Files were encrypted and data exfiltrated. Systems were quickly restored, but a limited amount of patient data could not be recovered. 133,149 individuals were affected. Compromised data included names, demographic information, health insurance information, driver's license numbers, diagnosis and medication information, and Social Security numbers.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 133149,
    "residents_affected_in_state": "Primarily western Oklahoma patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems encrypted; operations impacted; systems quickly restored; limited data permanently lost",
    "remediation_disclosed": "Cybersecurity firm engaged; systems restored; credit monitoring offered for SSN-affected individuals",
    "primary_source_url": "https://www.hipaajournal.com/great-plains-regional-medical-center-ransomware/",
    "secondary_source_urls": [
      "https://securityaffairs.com/171156/data-breach/great-plains-regional-medical-center-data-breach.html",
      "https://www.kecofm.com/featured/great-plains-regional-medical-center-victim-of-ransomware-attack/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 133,149; Security Affairs and HIPAA Journal consistent",
    "sources_used": [
      "HIPAA Journal, Security Affairs, KECO FM (Elk City)"
    ],
    "id": "INC-00571",
    "year": 2024,
    "lat": 35.4140081,
    "lng": -99.4138648,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Gulf Coast Pain Consultants dba Clearway Pain Solutions Institute (Texas operations)",
    "organization_type": "Healthcare Provider / Pain Management",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-01-01",
    "disclosure_date": "2024-01-01",
    "executive_summary": "Gulf Coast Pain Consultants (dba Clearway Pain Solutions Institute), which operates in Texas, received a $1.19 million OCR civil monetary penalty in 2024 for HIPAA Security Rule violations. The enforcement action followed a data breach investigation. Included for OCR enforcement significance and TX healthcare presence.",
    "attack_type": "Unauthorized Access (HIPAA enforcement)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$1,190,000 OCR civil monetary penalty (2024)",
    "operational_impact": "Patient data security compromised",
    "remediation_disclosed": "OCR corrective action plan",
    "primary_source_url": "https://www.hipaajournal.com/2024-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for enforcement action; $1.19M OCR CMP confirmed in HIPAA Journal 2024 report; TX healthcare provider; specific breach details limited",
    "sources_used": [
      "HIPAA Journal 2024 Annual Report"
    ],
    "id": "INC-00572",
    "year": 2024,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "HMG Healthcare, LLC",
    "organization_type": "Healthcare Provider (Nursing Facility Management)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2024-01-08",
    "executive_summary": "HMG Healthcare, LLC, a Texas-based healthcare services provider managing approximately 40 affiliated nursing facilities in Texas and Kansas, detected a potential data security incident in November 2023. The breach was confirmed to involve unauthorized access to an HMG network server in August 2023. Approximately 75,000\u201380,000 individuals (patients and employees at affiliated facilities) had their personal and health information compromised. A breach notice was filed with the Texas Attorney General on January 8, 2024. Data compromised included names, Social Security numbers, dates of birth, medical treatment details, and employee records.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Hacking",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 80000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "40 affiliated nursing facilities impacted",
    "remediation_disclosed": "Third-party cybersecurity experts engaged; Texas AG breach notice filed January 8, 2024",
    "primary_source_url": "https://www.jdsupra.com/legalnews/hmg-healthcare-notifies-75k-patients-7316730/",
    "secondary_source_urls": [
      "https://www.securityweek.com/hmg-healthcare-says-data-breach-impacts-40-facilities/"
    ],
    "confidence_notes": "HHS OCR and Texas AG breach notice confirmed; JD Supra and SecurityWeek reported 75K-80K affected",
    "sources_used": [
      "JD Supra, SecurityWeek, MedicalRecords.com"
    ],
    "id": "INC-00573",
    "year": 2024,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Harvard Pilgrim Health Care",
    "organization_type": "Health Plan (Multistate)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Wellesley, MA (multistate health plan)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2023-03-28",
    "disclosure_date": "2024-02-15",
    "executive_summary": "On April 17, 2023, Harvard Pilgrim discovered it was the victim of a cybersecurity ransomware incident that impacted systems used to service members, accounts, brokers and providers. After detecting the unauthorized party, we proactively took our systems offline to contain the threat. We notified law enforcement and regulators and are working with third-party cybersecurity experts to conduct a thorough investigation into this incident and remediate the situation. We take the privacy and security of the data entrusted to us seriously. Unfortunately, the investigation identified signs that data",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2550922,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; multiple class action lawsuits filed",
    "operational_impact": "Systems taken offline; member data accessed; ongoing litigation",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/Harvard%20Pilgrim%20Health%20Care%20-%20Supplemental%20Notice%20of%20Data%20Event%20-%20CA_0_0.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/harvard-pilgrim-health-care-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/harvard-pilgrim-health-care-discloses-ransomware-attack-data-theft/",
      "https://oag.ca.gov/system/files/Harvard%20Pilgrim%20Health%20Care%20-%20Sample%20Notice_1.pdf"
    ],
    "confidence_notes": "Supplemental/additional CA AG filing for the same April 2023 breach incident (original filed 08/25/2023) Supplemental CA AG filing for same April 2023 breach. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00574",
    "year": 2024,
    "lat": 37.19504040677855,
    "lng": -119.80070737182281,
    "is_multistate": true,
    "hq_outside_state": "Wellesley",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Harvard Pilgrim Health Care (additional notification rounds)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MA",
    "hq_city": "Canton",
    "hq_county": "Norfolk",
    "discovery_date": "2023-03-28",
    "disclosure_date": "2024-02-15",
    "executive_summary": "Harvard Pilgrim Health Care filed multiple supplemental notifications with state AGs as additional affected individuals were identified from its April 2023 ransomware attack. The Delaware AG database shows Harvard Pilgrim filing notifications on multiple dates through early 2025, with ongoing identification of affected individuals as investigation progressed.",
    "attack_type": "Ransomware (supplemental notification)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2860795,
    "residents_affected_in_state": 1,
    "financial_impact": "See primary entry; $16M settlement",
    "operational_impact": "See primary entry",
    "remediation_disclosed": "See primary entry; multiple supplemental filings through 2025",
    "primary_source_url": "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/harvard-pilgrim-health-care-increases-ransomware-attack-2023/"
    ],
    "confidence_notes": "Delaware AG database shows multiple Harvard Pilgrim filings; supplemental to primary entry",
    "sources_used": [
      "Delaware AG database",
      "HIPAA Journal"
    ],
    "id": "INC-00575",
    "year": 2024,
    "lat": 42.1584324,
    "lng": -71.1447732,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Hawaii Medical Service Association (HMSA) / Navvis & Company",
    "organization_type": "Health Plan (BCBS affiliate)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "Honolulu",
    "discovery_date": "2023-07-25",
    "disclosure_date": "2024-01-18",
    "executive_summary": "Navvis & Company, a health management service vendor for Hawaii Medical Service Association (HMSA), was breached between July 12 and July 25, 2023. Unauthorized access exposed HMSA member and former employee personal and protected health information. The Hawaii DCCA recorded 765,370 Hawaii residents impacted as of January 9, 2024. Compromised data included names, dates of birth, health plan information, medical treatment information, medical record numbers, patient account numbers, case identification numbers, SSNs, diagnoses, individual health insurance policy numbers, and physician information.",
    "attack_type": "Hacking / Unauthorized network access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 462000,
    "residents_affected_in_state": 765370,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "HMSA member and employee PHI exposed via vendor breach",
    "remediation_disclosed": "Navvis secured systems; HMSA members notified",
    "primary_source_url": "https://www.hipaajournal.com/462000-hawaiians-navvis-company-breach/",
    "secondary_source_urls": [
      "https://databreaches.net/2024/01/18/hmsa-member-data-possibly-compromised-after-data-breach/",
      "https://cca.hawaii.gov/ocp/notices/security-breach/"
    ],
    "confidence_notes": "Hawaii DCCA confirmed 765,370 HI residents (January 9, 2024 notification); HIPAA Journal listed 462,000 nationally for HMSA specifically",
    "sources_used": [
      "HIPAA Journal",
      "DataBreaches.net",
      "Hawaii DCCA Security Breach Notices"
    ],
    "id": "INC-00576",
    "year": 2024,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "HealthEquity, Inc.",
    "organization_type": "Healthcare Business Associate / HSA Administrator (Multistate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Draper, UT",
    "hq_county": "N/A \u2014 national",
    "discovery_date": "2024-03-09",
    "disclosure_date": "2024-07-26",
    "executive_summary": "After receiving an alert, on March 25, 2024, HealthEquity became aware of a systems anomaly requiring extensive technical investigation and ultimately resulting in data forensics until June 10, 2024. Through this work, we discovered some unauthorized access to and potential disclosure of protected health information and/or personally identifiable information stored in an unstructured data repository outside our core systems. On June 26, 2024, after validating the data, we unfortunately determined that some of your personal information was involved.",
    "attack_type": "Hacking / Credential-based Attack via Compromised Vendor Account",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4500000,
    "residents_affected_in_state": "Not separately reported by state",
    "financial_impact": "Not publicly disclosed. Class action lawsuits filed. Remediation and notification costs not separately disclosed.",
    "operational_impact": "Third-party vendor account compromised; HSA/benefits data accessed",
    "remediation_disclosed": "['Forensic investigation conducted', 'Passwords reset']",
    "primary_source_url": "https://oag.ca.gov/system/files/Individual%20Member%20Notification%20Non%20HIPAA%20exemplar.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthequity-data-breach-4-5-million-people/",
      "https://www.bleepingcomputer.com/news/security/healthequity-says-data-breach-impacted-45-million-people/",
      "https://www.accountablehq.com/post/healthequity-data-breach-2024-what-we-know-who-may-be-affected-and-how-to-protect-yourself",
      "https://www.hipaajournal.com/biggest-healthcare-data-breaches-2024/",
      "https://www.foxnews.com/tech/4-3-million-americans-exposed-massive-health-savings-account-data-breach",
      "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
      "https://www.prnewswire.com/news-releases/privacy-alert-healthequity-under-investigation-for-data-breach-of-4-3-million-members-health-savings-account-records-302215929.html",
      "https://techcrunch.com/2024/07/30/healthequity-data-breach-affects-4-3-million-people/"
    ],
    "confidence_notes": "Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "Accountable HQ",
      "California AG Breach Notification",
      "Fox News",
      "HIPAA Journal 2024 breach report",
      "TechCrunch, HIPAA Journal, PR Newswire"
    ],
    "id": "INC-00577",
    "year": 2024,
    "lat": 37.31949991954536,
    "lng": -119.6351230829918,
    "is_multistate": true,
    "hq_outside_state": "Draper",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Hypertension-Nephrology Associates (Michigan)",
    "organization_type": "Specialty Medical Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "MI",
    "hq_city": "Michigan (specific city not confirmed)",
    "hq_county": "Wayne",
    "discovery_date": "2024-02-06",
    "disclosure_date": "2024-05-16",
    "executive_summary": "Hypertension-Nephrology Associates in Michigan was targeted by a ransomware/extortion attack. An unknown threat actor dropped a ransom note on its computer systems demanding payment to prevent publication of stolen patient data. Investigation confirmed unauthorized access between January 20 and February 6, 2024, with files containing PHI exfiltrated. The practice assumed all PHI on the affected network portion was compromised \u2014 including names, DOBs, diagnosis and treatment information, SSNs, and health insurance IDs.",
    "attack_type": "Ransomware / Data Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 715,
    "residents_affected_in_state": "Michigan patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Ransom note discovered; PHI potentially exfiltrated",
    "remediation_disclosed": "Yes \u2014 investigation launched; third-party forensics; patients notified May 2024",
    "primary_source_url": "https://www.hipaajournal.com/hypertension-nephrology-associates-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. HIPAA Journal confirmed incident; patient count not confirmed from HHS OCR.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00578",
    "year": 2024,
    "lat": 42.33136,
    "lng": -83.0520837,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "IU Health (Indiana University Health) \u2014 2024 Email Breach",
    "organization_type": "Nonprofit Academic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2024-11-08",
    "disclosure_date": "2024-12-17",
    "executive_summary": "Indiana University Health detected unusual activity linked to a team member's email account on November 8, 2024. Investigation confirmed an unauthorized recipient had access to the email account between August 27 and October 2, 2024 \u2014 a period of over a month. The breach involved a limited number of SSNs and other PHI including names, addresses, ages, medical record numbers, and medical information. Those with exposed SSNs received 12 months of credit monitoring. Notifications sent January 2, 2025.",
    "attack_type": "Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly disclosed (limited based on reporting)",
    "residents_affected_in_state": "Indiana residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Single email account; limited PHI access",
    "remediation_disclosed": "Yes \u2014 account secured; forensics completed; notifications January 2, 2025; credit monitoring for SSN-affected patients",
    "primary_source_url": "https://www.jdsupra.com/legalnews/indiana-university-health-announces-4822238/",
    "secondary_source_urls": [
      "https://www.healthcarefinancenews.com/news/iu-health-says-data-compromised-cyberattack"
    ],
    "confidence_notes": "High confidence. JD Supra (December 2024), Healthcare Finance News.",
    "sources_used": [
      "JD Supra",
      "Healthcare Finance News"
    ],
    "id": "INC-00579",
    "year": 2024,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Inova Health Care Services (Meta Pixel Tracking)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Falls Church",
    "hq_county": "Fairfax",
    "discovery_date": "2022-04-29",
    "disclosure_date": "2024-01-01",
    "executive_summary": "Inova Health agreed to pay $3.1 million to settle a class action lawsuit over claims it collected and shared patient information through tracking pixels (Facebook, Google) on its websites between approximately April 29, 2022 and April 29, 2024. Patients who visited Inova public-facing websites and had MyChart accounts may have had PHI transmitted to third parties without authorization.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (tracking pixels)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$3.1 million class action settlement",
    "operational_impact": "Patient PHI transmitted to Facebook and Google without consent",
    "remediation_disclosed": "Tracking pixels removed; $3.1M settlement",
    "primary_source_url": "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/3-1m-inova-health-privacy-class-action-settlement/",
    "secondary_source_urls": [],
    "confidence_notes": "Settlement confirmed by Top Class Actions. Number of affected individuals not specified in available sources.",
    "sources_used": [
      "Top Class Actions"
    ],
    "id": "INC-00580",
    "year": 2024,
    "lat": 38.8823,
    "lng": -77.1711,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kaiser Foundation Health Plan, Inc.",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Oakland",
    "hq_county": "Alameda",
    "discovery_date": "2017-11 to 2024-05 (tracking tools active period)",
    "disclosure_date": "2024-04-12",
    "executive_summary": "Kaiser Foundation Health Plan notified 13.4 million individuals that online tracking technologies previously installed on its websites and mobile applications may have transmitted personal information to third-party vendors including Google, Microsoft Bing, and X (Twitter).",
    "attack_type": "Unauthorized Access/Disclosure \u2014 Website pixel/tracking technology impermissible disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (tracking technology misconfiguration)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13400000,
    "residents_affected_in_state": "Not separately reported (majority of members are CA residents)",
    "financial_impact": "Up to $47.5 million class action settlement (preliminary agreement 2025); $47.5M settlement announced Dec 2025",
    "operational_impact": "No clinical operational disruption; tracking tools removed from websites and mobile apps",
    "remediation_disclosed": "Tracking technologies removed from websites and mobile apps; additional safeguards implemented; notifications sent May 2024; engaged outside security experts",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/kaiser-permanente-website-tracker-breach-affects-13-4-million-individuals/",
      "https://www.bankinfosecurity.com/kaiser-big-breach-a-24945",
      "https://kffhealthnews.org/morning-breakout/kaiser-permanente-entity-reports-breach-of-data-for-13-million/",
      "https://www.hipaajournal.com/kaiser-foundation-health-plan-data-breach/",
      "https://oag.ca.gov/system/files/Affected%20Individuals%20Notification%20Letter%20FINAL.pdf",
      "https://www.latimes.com/california/story/2024-04-26/kaiser-permanente-notifies-13-4-million-members-of-data-breach",
      "https://www.securityweek.com/kaiser-permanente-discloses-data-breach-impacting-13-4-million-patients/",
      "https://healthy.kaiserpermanente.org/health-wellness/health-encyclopedia/he.notice-of-data-breach.abk1734"
    ],
    "confidence_notes": "Reported to HHS OCR as largest healthcare data breach of 2024 at time of disclosure. Ranked #5 largest healthcare breach of all time. No SSNs, financial data, or passwords disclosed. | Cross-referenced across multiple authoritative sources. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BankInfoSecurity",
      "California AG Breach Notification",
      "HHS OCR Breach Portal",
      "HIPAA Journal",
      "Kaiser Permanente official breach notice",
      "LA Times",
      "SecurityWeek"
    ],
    "id": "INC-00581",
    "year": 2024,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Kaiser Foundation Hospitals",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Oakland, CA",
    "hq_county": "Alameda County",
    "discovery_date": "2024-08-02",
    "disclosure_date": "2024-11-01",
    "executive_summary": "On September 3, 2024, Kaiser Permanente discovered that an unauthorized party gained access to the Kaiser Permanente email accounts of two members of our workforce. Upon learning of the incident, we terminated the unauthorized access and immediately began an investigation to determine the scope of the access. After validating the email contents, we determined that some of your protected health information was involved. We apologize that this incident occurred. We take the trust you place in us very seriously and work to ensure that trust is upheld in every interaction.",
    "attack_type": "Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Multiple incidents (see individual notices)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Passwords reset']",
    "primary_source_url": "https://oag.ca.gov/system/files/Individual%20Notice%20Letter%20FINAL.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/kaiser-foundation-health-plan-data-breach/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00582",
    "year": 2024,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Kaiser Permanente / Kaiser Foundation Health Plan",
    "organization_type": "Integrated managed care health plan and hospital system (largest US HMO)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Oakland",
    "hq_county": "Alameda County",
    "discovery_date": "2023-10-25",
    "disclosure_date": "2024-04-12",
    "executive_summary": "Kaiser Permanente disclosed in April 2024 that tracking technologies (cookies/pixels from Google, Microsoft Bing, and X/Twitter) installed on its member-authenticated websites and mobile applications had been transmitting member health data to third-party advertisers without consent, potentially since November 2017. The disclosure affected an estimated 13.4 million current and former members, making it the second-largest healthcare data breach reported in 2024. Kaiser removed the tracking tools, denied wrongdoing, and agreed to a settlement of up to $47.5 million in December 2025.",
    "attack_type": "Tracking pixel / third-party data disclosure (not a network intrusion)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "NOT_APPLICABLE",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13400000,
    "residents_affected_in_state": "California is Kaiser's largest market; CA subclass included in settlement",
    "financial_impact": "{'litigation_settlement': 47500000, 'notes': 'Up to $47.5M settlement (preliminary approval granted; final approval hearing April 30, 2026). Additionally, separate 2022 email breach affecting 69,589 patients.'}",
    "operational_impact": "No operational disruption. Data shared via marketing analytics; no evidence of misuse or care delivery impact.",
    "remediation_disclosed": "Tracking technologies removed from websites and mobile apps. Additional safeguards implemented. Notifications sent to 13.4 million members starting May 2024.",
    "primary_source_url": "https://www.hipaajournal.com/kaiser-permanente-website-tracker-breach-affects-13-4-million-individuals/",
    "secondary_source_urls": [
      "https://www.securityweek.com/kaiser-permanente-discloses-data-breach-impacting-13-4-million-patients/",
      "https://www.fiercehealthcare.com/providers/kaiser-permanente-says-134m-impacted-data-breach",
      "https://www.healthleadersmedia.com/technology/kaiser-permanente-pay-46m-patient-data-breach",
      "https://www.reflectiz.com/blog/kaiser-permanente-data-breach-settlement/"
    ],
    "confidence_notes": "Kaiser OCR filing date: April 12, 2024. Disclosure internally determined Oct 25, 2023. Separate 2022 email breach (69,589 patients) documented independently. Settlement class includes CA, GA, MD, OR, WA, and DC subclasses. Kaiser is headquartered in Oakland, CA.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00583",
    "year": 2024,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "LA County Department of Health Services (DHS)",
    "organization_type": "County public health system (public hospitals and clinics; second-largest municipal health system in US after NYC H+H)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles County",
    "discovery_date": "2024-02-06",
    "disclosure_date": "2024-06-21",
    "executive_summary": "On February 6, 2024, a threat actor used push notification spamming (MFA fatigue) to bypass multi-factor authentication on a single DHS employee's Microsoft 365 account. The compromised account contained personal and health information of approximately 47,000 individuals. Data potentially exposed included SSNs, government IDs, medical record numbers, health insurance information, diagnoses, medications, and treatment dates. Law enforcement directed DHS to delay notifications to protect an ongoing criminal investigation. DHS publicly disclosed the breach June 21, 2024.",
    "attack_type": "MFA fatigue / push notification spamming attack on Microsoft 365 account",
    "attack_category": "Other / Unspecified",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 47000,
    "residents_affected_in_state": 47000,
    "financial_impact": "{'notes': 'No financial penalties disclosed. Free identity monitoring services through identity monitoring provider offered.'}",
    "operational_impact": "Single email account compromised; no reported clinical service disruption.",
    "remediation_disclosed": "Impacted email account disabled; device reset and re-imaged; suspicious websites blocked; suspicious emails quarantined; workforce phishing awareness enhanced; additional technical security measures implemented. Law enforcement and CA DPH notified.",
    "primary_source_url": "https://lacounty.gov/2024/06/21/la-county-department-of-health-services-responding-to-privacy-breach/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/phishing-la-county-dhs-23-accounts-breached/",
      "https://securityaffairs.com/162494/data-breach/los-angeles-county-department-of-health-services-data-breach.html"
    ],
    "confidence_notes": "Note: This is a separate incident from the LA County DPH phishing (also February 2024). HHS OCR breach filing: 6,085 individuals (smaller than the initially disclosed ~47,000 \u2014 OCR figure may reflect confirmed PHI exposure vs. total at-risk). OCR HIPAA Journal reported 6,085; LA County DHS press release said ~47,000.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00584",
    "year": 2024,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Legacy Health (2024 RCM vendor breach)",
    "organization_type": "Healthcare Provider (Regional Health System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2024-05-01",
    "disclosure_date": "2024-07-01",
    "executive_summary": "Legacy Health, one of Oregon's largest regional health systems operating hospitals and clinics throughout the Portland metro area and Southwest Washington, experienced a data breach through a revenue cycle management (RCM) vendor in May 2024. The breach potentially affected approximately 38,000 patients at Legacy Health facilities. This vendor-related breach is distinct from Legacy Health's earlier 2018 phishing incident and its 2019 involvement in the OR-005 RCM ransomware event. The breach involved unauthorized access to patient data including names, dates of birth, medical information, health insurance details, and for some patients, Social Security numbers.",
    "attack_type": "Third-party vendor breach / Unauthorized access",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 38000,
    "residents_affected_in_state": "Not separately reported (majority OR-based patients)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI exposed via vendor; medical and insurance data affected",
    "remediation_disclosed": "Vendor relationship reviewed; patient notifications; credit monitoring offered",
    "primary_source_url": "https://www.thelundreport.org/search?page=834",
    "secondary_source_urls": [
      "https://www.healthcareitnews.com/news/phishing-attack-breaches-38000-patient-records-legacy-health"
    ],
    "confidence_notes": "Lund Report snippet references Legacy Health breach of 38,000 patients; distinct from 2018 phishing incident. Confidence MODERATE \u2014 specific 2024 vendor breach details not fully confirmed from primary source; parent agent should verify against HHS OCR portal. NOTE: May actually be the 2018 phishing breach. If unable to confirm a distinct 2024 breach, this entry should be removed.",
    "sources_used": [
      "The Lund Report",
      "Healthcare IT News (2018 reference)"
    ],
    "id": "INC-00585",
    "year": 2024,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Legacy Treatment Services",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Mount Holly",
    "hq_county": "Burlington",
    "discovery_date": "2024-01-01",
    "disclosure_date": "2024-04-15",
    "executive_summary": "Legacy Treatment Services, a New Jersey-based behavioral health and substance abuse treatment organization, reported a data security incident affecting patient health and personal information. The breach involved unauthorized access to systems containing protected health information of clients receiving mental health and addiction treatment services.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Behavioral health patient data potentially compromised",
    "remediation_disclosed": "OCR and patients notified; cybersecurity improvements implemented",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Partial record from initial JSON write; confirmed NJ behavioral health provider",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00586",
    "year": 2024,
    "lat": 39.9928898,
    "lng": -74.7876624,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "LivaNova USA, Inc.",
    "organization_type": "Medical Device Manufacturer / Healthcare",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Houston",
    "hq_county": "Harris",
    "discovery_date": "2023-11-19",
    "disclosure_date": "2024-04-25",
    "executive_summary": "LockBit ransomware attack on LivaNova USA IT systems in October 2023, exfiltrating 2.2 TB. Patient notification began April 2024 after investigation confirmed individual PHI exposure. 180,000 patients affected with names, SSNs, medical and health insurance information.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit",
    "attribution_status": "claimed",
    "individuals_affected_reported": 180000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "IT systems disrupted; 2.2 TB exfiltrated",
    "remediation_disclosed": "Third-party cybersecurity experts engaged; law enforcement notified; 2-year identity protection offered",
    "primary_source_url": "https://www.securityweek.com/livanova-usa-discloses-data-breach-impacting-130000-individuals/",
    "secondary_source_urls": [
      "https://www.scworld.com/brief/almost-130k-hit-by-livanova-usa-breach",
      "https://databreaches.net/2024/04/26/livanova-to-notify-u-s-patients-of-october-2023-ransomware-incident/"
    ],
    "confidence_notes": "High confidence; 180,000 patients per HHS OCR; LockBit claimed December 2023; SecurityWeek and SC Media confirmed",
    "sources_used": [
      "SecurityWeek",
      "SC Media",
      "DataBreaches.net"
    ],
    "id": "INC-00587",
    "year": 2024,
    "lat": 29.7604,
    "lng": -95.3698,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Los Angeles County Department of Health Services (DHS)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles",
    "discovery_date": "2024-02-06 (cyberattack date); 2024-02-19 to 2024-02-20 (phishing campaign)",
    "disclosure_date": "2024-06-21",
    "executive_summary": "Hacker circumvented multi-factor authentication via push notification spamming attack, accessing one employee's Microsoft 365 account. Approximately 47,000 individuals potentially affected.",
    "attack_type": "Hacking/IT Incident \u2014 MFA bypass via push notification spamming (fatigue attack) / phishing",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 47000,
    "residents_affected_in_state": 47000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Affected email account disabled; device reset and re-imaged; websites blocked",
    "remediation_disclosed": "MFA-compromised account disabled; device re-imaged; phishing websites blocked; suspicious emails quarantined; law enforcement notified (investigation delayed public notification); workforce awareness notifications distributed; additional email compliance controls implemented; forensic firm engaged",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://lacounty.gov/2024/06/21/la-county-department-of-health-services-responding-to-privacy-breach/",
      "https://securityaffairs.com/162494/data-breach/los-angeles-county-department-of-health-services-data-breach.html",
      "https://www.hipaajournal.com/phishing-la-county-dhs-23-accounts-breached/"
    ],
    "confidence_notes": "DHS is the US's second largest municipal health system. February 6 MFA bypass attack compromised single account. A separate February 19-20 phishing campaign compromised 23 employee accounts (6,085 individuals per HHS OCR). This record covers the Feb 6 MFA bypass affecting ~47,000.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00588",
    "year": 2024,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Los Angeles County Department of Public Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles",
    "discovery_date": "2024-02-19 to 2024-02-20",
    "disclosure_date": "2024-06-14",
    "executive_summary": "Phishing attack at LA County Department of Public Health compromised login credentials of 53 employees. Over 200,000 residents' personal data potentially compromised.",
    "attack_type": "Hacking/IT Incident \u2014 Phishing / mass employee credential compromise (53 accounts)",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 200000,
    "residents_affected_in_state": 200000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Affected accounts disabled; devices reset",
    "remediation_disclosed": "Affected email accounts disabled; devices reset and re-imaged; phishing websites blocked; suspicious emails quarantined; enhanced employee training; Kroll identity monitoring offered",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.latimes.com/california/story/2024-06-14/la-county-public-health-data-breach-possibly-affects-200-000-are-you-one-of-them"
    ],
    "confidence_notes": "PHI/PII exposed: names, DOBs, diagnoses, prescriptions, medical record numbers, health insurance info, SSNs, and financial data. Same attack timeframe as DHS incident.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00589",
    "year": 2024,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Los Angeles County Department of Public Health (DPH)",
    "organization_type": "County public health agency (serves ~10 million residents; second-largest municipal health dept in US)",
    "organization_type_bucket": "Other healthcare entity",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles County",
    "discovery_date": "2024-02-19",
    "disclosure_date": "2024-06-14",
    "executive_summary": "Between February 19 and 20, 2024, a threat actor sent phishing emails to Los Angeles County Department of Public Health employees, compromising the login credentials of 53 employees. The attacker accessed email accounts containing personally identifiable and protected health information of more than 200,000 individuals, including clients, employees, and other persons. Exposed data included diagnoses, prescription details, medical record numbers, SSNs, and financial data. Law enforcement requested a notification delay to protect the criminal investigation; DPH publicly disclosed the breach June 14, 2024.",
    "attack_type": "Phishing / credential compromise (push notification spamming noted in DHS notice; phishing in DPH notice)",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": 200000,
    "residents_affected_in_state": 200000,
    "financial_impact": "{'notes': 'No financial penalties or settlements announced. Free identity monitoring through Kroll offered to affected individuals.'}",
    "operational_impact": "Email accounts compromised; no reported disruption to public health services or clinical operations.",
    "remediation_disclosed": "Compromised accounts disabled; devices reset and re-imaged; suspicious websites blocked; phishing awareness notifications sent to all DPH staff; enhanced email compliance controls; law enforcement notified. Kroll identity monitoring provided.",
    "primary_source_url": "https://lacounty.gov/2024/06/14/public-health-responds-to-privacy-breach/",
    "secondary_source_urls": [
      "https://securityaffairs.com/162494/data-breach/los-angeles-county-department-of-health-services-data-breach.html",
      "https://www.latimes.com/california/story/2024-06-14/la-county-public-health-data-breach-possibly-affects-200-000-are-you-one-of-them",
      "https://www.securityweek.com/200000-impacted-by-data-breach-at-los-angeles-county-public-health-agency/"
    ],
    "confidence_notes": "Note: Task listed 'LA County Department of Health Services (DHS)' and also LA County DPH. Both had phishing incidents in early 2024. DPH (Feb 19-20, 2024): 53 employees compromised, 200,000+ affected. DHS (Feb 6, 2024, per DHS notice): 1 email account compromised via 'push notification spamming,' ~47,000 individuals affected (OCR filing: 6,085). Both are included in this entry for clarity; the DPH breach is the larger one.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00590",
    "year": 2024,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Mass General Brigham Health Plan",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MA",
    "hq_city": "Somerville",
    "hq_county": "Middlesex",
    "discovery_date": "2024-04-02",
    "disclosure_date": "2024-06-28",
    "executive_summary": "Mass General Brigham Health Plan discovered on April 2, 2024 that member personal information had been accessible to unauthorized individuals via a data exposure linked to the MOVEit vulnerability via PBI Research Services. The exposure occurred between July 31, 2023 and April 2, 2024 through an employee's unauthorized access. Two separate breach reports were filed: one for 3,659 individuals (Health Plan) and one for 655 individuals (MGB Incorporated).",
    "attack_type": "Unauthorized access (employee) / Supply chain MOVEit",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4314,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member PHI exposed; two employees terminated",
    "remediation_disclosed": "Two employees terminated; HHS OCR breach reports filed; members notified",
    "primary_source_url": "https://www.mass.gov/doc/assigned-data-breach-number-2024-1221-mass-general-brigham-health-plan-inc/download",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/mass-general-brigham-terminates-two-employees-privacy-violations/",
      "https://databreach.com/breach/massgeneralbrighamhealthplan.org-2024"
    ],
    "confidence_notes": "MA AG filing; OCR breach reports filed; HIPAA Journal reporting",
    "sources_used": [
      "Massachusetts AG",
      "HIPAA Journal",
      "DataBreach.com"
    ],
    "id": "INC-00591",
    "year": 2024,
    "lat": 42.3875968,
    "lng": -71.0994968,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Medical Management Resource Group, LLC (American Vision Partners)",
    "organization_type": "Healthcare Provider (Eye Care Management)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2023-11-14",
    "disclosure_date": "2024-01-01",
    "executive_summary": "Medical Management Resource Group (MMRG), doing business as American Vision Partners, detected unauthorized activity in its network on November 14, 2023. Investigation confirmed on December 6, 2023 that the breach involved unauthorized access and removal of files containing patient data. 2,350,236 individuals were ultimately affected. Compromised data included names, contact information, dates of birth, Social Security numbers, medical information (services received, clinical records, medications), and health insurance information.",
    "attack_type": "Hacking/IT Incident \u2013 Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2350236,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; class action lawsuit filed in D. Arizona federal court",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Forensic investigation; notifications sent; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/mmrgamerican-vision-partners-breach-2-35m-patients/",
    "secondary_source_urls": [
      "https://news.bloomberglaw.com/privacy-and-data-security/eye-clinic-servicer-sued-over-data-breach-affecting-2-million",
      "https://www.globenewswire.com/news-release/2024/02/22/2834016/0/en/Lynch-Carpenter-Investigates-Claims-in-Medical-Management-Resource-Group-LLC-Data-Breach.html"
    ],
    "confidence_notes": "High confidence; OCR confirmed 2,350,236; Bloomberg Law class action suit documented",
    "sources_used": [
      "HIPAA Journal, Bloomberg Law, GlobeNewswire"
    ],
    "id": "INC-00592",
    "year": 2024,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Medical Management Resource Group, LLC (d/b/a American Vision Partners)",
    "organization_type": "BA/Vendor (Ophthalmology Practice Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2023-12-06",
    "disclosure_date": "2024-02-06",
    "executive_summary": "Medical Management Resource Group (MMRG), doing business as American Vision Partners, provides administrative services, IT infrastructure, and management systems to approximately 12 ophthalmology practices across Arizona, Texas, New Mexico, and California. In November 2023, an unauthorized party accessed MMRG's network server and obtained the protected health information of patients of its affiliated ophthalmology practices. The investigation confirmed on December 6, 2023, that data had been exfiltrated. MMRG reported the breach to HHS OCR in February 2024 as affecting 2,350,236 individuals. Compromised data included names, contact information, dates of birth, medical information including services received and clinical records, medications, and for some individuals Social Security numbers and health insurance information.",
    "attack_type": "Hacking / Network Server Compromise / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2350236,
    "residents_affected_in_state": 20415,
    "financial_impact": "Class action lawsuits filed. Settlement amount not publicly disclosed as of research date.",
    "operational_impact": "Practice management and administrative services disrupted. Patient care at 12 affiliated ophthalmology practices affected. Shared IT infrastructure across practices amplified breach scope.",
    "remediation_disclosed": "Third-party forensics engaged. HHS OCR breach reported February 2024. Notification letters mailed to 2.35M individuals.",
    "primary_source_url": "https://www.hipaajournal.com/mmrgamerican-vision-partners-breach-2-35m-patients/",
    "secondary_source_urls": [
      "https://www.bankinfosecurity.com/hack-at-services-firm-hits-24-million-eye-doctor-patients-a-24418",
      "https://www.classaction.org/news/american-vision-partners-data-breach-lawsuit-says-cyberattack-impacted-2.35m-people",
      "https://www.securityweek.com/eye-care-services-firm-faces-lawsuit-over-data-breach-impacting-2-3-million/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report is primary source of 2,350,236 count. Maine AG filing corroborates. Multiple news outlets confirmed data theft and scope.",
    "sources_used": [
      "HIPAA Journal",
      "BankInfoSecurity",
      "ClassAction.org",
      "SecurityWeek"
    ],
    "id": "INC-00593",
    "year": 2024,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Memorial Hospital of Sweetwater County",
    "organization_type": "Healthcare Provider (Community Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WY",
    "hq_city": "Rock Springs",
    "hq_county": "Sweetwater",
    "discovery_date": "2024-05-01",
    "disclosure_date": "2024-07-19",
    "executive_summary": "Memorial Hospital of Sweetwater County experienced a devastating cyberattack approximately two months before a July 2024 news report. The hospital and the Southwest Wyoming Regional Airport were both affected. The full extent of the attack and patient data compromised was not publicly detailed in available sources.",
    "attack_type": "Hacking/IT Incident \u2013 Cyberattack (type unspecified)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Wyoming patients",
    "financial_impact": "Described as 'devastating'",
    "operational_impact": "Significant operational impact; hospital and airport both affected",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.facebook.com/sweetwaternow/posts/the-southwest-wyoming-regional-airport-and-memorial-hospital-of-sweetwater-count/1003737468422102/",
    "secondary_source_urls": [],
    "confidence_notes": "Low-moderate confidence; Facebook post (SweetwaterNow news) documented; limited additional detail",
    "sources_used": [
      "SweetwaterNow (Facebook)"
    ],
    "id": "INC-00594",
    "year": 2024,
    "lat": 41.5860557,
    "lng": -109.2194544,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Memorial Sloan Kettering Cancer Center",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2024-06-01",
    "disclosure_date": "2024-07-19",
    "executive_summary": "Memorial Sloan Kettering Cancer Center disclosed a phishing attack that compromised the PHI of 12,274 individuals. Attackers gained access to email accounts containing patient information. Data exposed was limited to email accounts; medical records were not accessed. SSNs and driver's license numbers were not involved.",
    "attack_type": "Phishing / email account compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 12274,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee email accounts compromised; patient PHI in email accounts exposed",
    "remediation_disclosed": "Email accounts secured; affected individuals notified; HHS OCR report filed",
    "primary_source_url": "https://www.hipaajournal.com/memorial-sloan-kettering-cancer-center-phishing-attack/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach report; HIPAA Journal reporting",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00595",
    "year": 2024,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Michigan Medicine (University of Michigan Health) \u2014 2024 July MFA Bypass",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Ann Arbor",
    "hq_county": "Washtenaw",
    "discovery_date": "2024-07-30",
    "disclosure_date": "2024-09-26",
    "executive_summary": "Michigan Medicine's second data breach in four months occurred July 30, 2024 when a single employee accepted an unsolicited MFA prompt, allowing attackers to access the employee's email account. Analysis conducted August 21\u201329 confirmed PHI of approximately 57,891 patients was potentially exposed \u2014 names, medical record numbers, and diagnostic/treatment information. No SSNs, credit cards, or bank account numbers were exposed. This was the second cyberattack within four months.",
    "attack_type": "MFA Bypass / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 57891,
    "residents_affected_in_state": "Primarily Michigan patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Single email account compromised; PHI potentially accessed",
    "remediation_disclosed": "Yes \u2014 account disabled immediately; investigation August 21\u201329; patients notified September 26, 2024",
    "primary_source_url": "https://www.michiganmedicine.org/news-release/michigan-medicine-notifies-patients-health-information-breach-3",
    "secondary_source_urls": [
      "https://www.freep.com/story/news/health/2024/09/26/cybersecurity-breach-university-of-michigan-medicine-email-attack/75392949007/",
      "https://healthexec.com/topics/health-it/cybersecurity/lone-michigan-medicine-employee-responsible-breach-impacted-58k-patients"
    ],
    "confidence_notes": "High confidence. Michigan Medicine official press release, Detroit Free Press, HealthExec.",
    "sources_used": [
      "Michigan Medicine",
      "Detroit Free Press",
      "HealthExec"
    ],
    "id": "INC-00596",
    "year": 2024,
    "lat": 42.2808,
    "lng": -83.743,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Michigan Medicine (University of Michigan Health) \u2014 2024 May Phishing",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Ann Arbor",
    "hq_county": "Washtenaw",
    "discovery_date": "2024-05-29",
    "disclosure_date": "2024-07-22",
    "executive_summary": "Michigan Medicine discovered that employee email accounts had been hacked between May 23 and May 29, 2024, in a phishing attack. The investigation confirmed PHI of approximately 56,953 individuals was potentially exposed including names, addresses, DOBs, medical record numbers, diagnostic and treatment information, and health insurance details. Four patients' SSNs were exposed. Financial information (credit cards, bank accounts) was not compromised.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 56953,
    "residents_affected_in_state": "Primarily Michigan (Ann Arbor area) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Email accounts compromised; PHI potentially accessed; no financial data (credit cards/bank accounts) exposed",
    "remediation_disclosed": "Yes \u2014 accounts secured; investigation completed; patients notified July 22, 2024; credit monitoring for 4 patients with SSN exposure",
    "primary_source_url": "https://www.securityweek.com/57000-patients-impacted-by-michigan-medicine-data-breach/",
    "secondary_source_urls": [
      "https://www.freep.com/story/news/health/2024/09/26/cybersecurity-breach-university-of-michigan-medicine-email-attack/75392949007/"
    ],
    "confidence_notes": "High confidence. SecurityWeek, Detroit Free Press, Michigan Medicine official statement.",
    "sources_used": [
      "SecurityWeek",
      "Detroit Free Press"
    ],
    "id": "INC-00597",
    "year": 2024,
    "lat": 42.2808,
    "lng": -83.743,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Midlands Regional Rehabilitation Hospital",
    "organization_type": "Healthcare Provider / Rehabilitation Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Columbia",
    "hq_county": "Richland",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2024-04-02",
    "executive_summary": "Midlands Regional Rehabilitation Hospital, LLC reported a data security incident to the South Carolina Attorney General in April 2024 affecting 2,200 SC residents. This incident was reported on the same date as Spartanburg Rehabilitation Institute, suggesting a possible shared vendor or network breach.",
    "attack_type": "Unauthorized Access / Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2200,
    "residents_affected_in_state": 2200,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Rehabilitation patient PHI potentially accessed",
    "remediation_disclosed": "SC AG notified April 2024",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00598",
    "year": 2024,
    "lat": 34.0007,
    "lng": -81.0348,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Monument Health (via Change Healthcare 2024)",
    "organization_type": "Regional Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Rapid City",
    "hq_county": "Pennington",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-07-01",
    "executive_summary": "Monument Health, the Rapid City, South Dakota-based regional health system serving western South Dakota and surrounding states, was affected by the February 2024 Change Healthcare ransomware attack. Monument Health's operations relied on Change Healthcare for claims adjudication and prior authorizations. According to regional reporting, approximately 26,000 Monument Health patients were notified of potential data exposure from the Change Healthcare breach. This entry tracks the Monument Health-specific disclosure component of the broader Change Healthcare incident (MW-001).",
    "attack_type": "Third-Party Vendor Breach (Change Healthcare ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV (Change Healthcare attacker)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 26000,
    "residents_affected_in_state": 26000,
    "financial_impact": "Not separately quantified",
    "operational_impact": "Claims processing disrupted; billing and prior authorization functions affected",
    "remediation_disclosed": "Yes \u2014 patients notified; workarounds implemented",
    "primary_source_url": "https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/",
    "secondary_source_urls": [
      "https://www.kdsj980.com/2023/09/18/monument-health-and-sanford-health-data-breach/"
    ],
    "confidence_notes": "Medium confidence. Monument Health confirmed as Change Healthcare client; ~26,000 patient notification count from regional reporting.",
    "sources_used": [
      "HIPAA Journal",
      "KDSJ Radio (Black Hills)"
    ],
    "id": "INC-00599",
    "year": 2024,
    "lat": 44.0805,
    "lng": -103.231,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Mower County, Minnesota \u2014 Ransomware (healthcare data component)",
    "organization_type": "County Government / Health Services",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Austin",
    "hq_county": "Mower",
    "discovery_date": "2024-06-01",
    "disclosure_date": "2024-08-01",
    "executive_summary": "Mower County in Minnesota confirmed that HIPAA-protected data was compromised in a June 2024 ransomware attack on county systems. The attack disrupted county government including health-related services. Specific patient count and health data types affected were not detailed in available sources beyond HIPAA Journal headlines.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly confirmed",
    "residents_affected_in_state": "Minnesota (Mower County) residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "County systems including health services disrupted",
    "remediation_disclosed": "Not publicly confirmed in detail",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence on details. HIPAA Journal headline only; limited specific information available.",
    "sources_used": [
      "HIPAA Journal (headline reference)"
    ],
    "id": "INC-00600",
    "year": 2024,
    "lat": 43.6679992,
    "lng": -92.9746498,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "NYC Health + Hospitals (Change Healthcare vendor impact)",
    "organization_type": "Health System",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2024-02-28",
    "executive_summary": "NYC Health + Hospitals experienced telephone and call center difficulties as a result of the Change Healthcare national cybersecurity incident in February 2024, which affected its vendor. Call center hours were reduced and the main contact numbers experienced disruptions. NYC H+H advised patients to use MyChart for physician communications during the disruption.",
    "attack_type": "Supply chain (Change Healthcare ransomware impact)",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately disclosed",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Call center and phone system disruptions; reduced hours for main contact numbers",
    "remediation_disclosed": "Reduced hours communicated; MyChart alternative provided",
    "primary_source_url": "https://www.nychealthandhospitals.org/statement-on-national-cyber-incident/",
    "secondary_source_urls": [],
    "confidence_notes": "NYC H+H official statement; operational impact only; distinct from the 2025-2026 data breach at NYC H+H",
    "sources_used": [
      "NYC Health + Hospitals"
    ],
    "id": "INC-00601",
    "year": 2024,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "North Kansas City Hospital / Meritas Health (via PJ&A breach)",
    "organization_type": "Community Hospital / Physician Group",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "North Kansas City",
    "hq_county": "Clay",
    "discovery_date": "2023-07-21",
    "disclosure_date": "2024-01-03",
    "executive_summary": "Perry Johnson & Associates (PJ&A), a medical transcription vendor serving North Kansas City Hospital (NKCH) and its subsidiary Meritas Health Corporation, was hacked between March 27 and May 2, 2023. NKCH was notified on July 21, 2023. After review completed November 7, 2023, NKCH confirmed that PHI of 502,438 individuals was compromised, including demographic information (name, DOB, gender, phone, address), health insurance information, and clinical information. SSNs were not affected. Data belonging to Clay County Public Health Center was also identified. Notification letters were sent beginning January 3, 2024.",
    "attack_type": "Third-Party Vendor Breach (transcription service)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown (PJ&A breach; global 9M-patient hack)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 502438,
    "residents_affected_in_state": "Missouri residents (Kansas City area and Clay County)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "NKCH's own systems not directly breached; PJ&A services terminated",
    "remediation_disclosed": "Yes \u2014 additional safeguards implemented; PJ&A relationship terminated; patients notified January 2024",
    "primary_source_url": "https://www.nkchealth.org/pja-data-event",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/north-kansas-city-hospital-confirms-1343084/",
      "https://bell-law-kc.com/have-you-ever-been-a-patient-at-north-kansas-city-hospital-or-a-meritas-health-corporation-facility-if-so-your-personal-information-has-been-compromised-and-may-have-been-put-on-the-dark-web/"
    ],
    "confidence_notes": "High confidence. NKC Health official website notice, JD Supra, Bell Law KC.",
    "sources_used": [
      "NKC Health",
      "JD Supra",
      "Bell Law KC"
    ],
    "id": "INC-00602",
    "year": 2024,
    "lat": 39.1432057,
    "lng": -94.5733988,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "North Kansas City Hospital / NKC Health (via Perry Johnson & Associates)",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "North Kansas City",
    "hq_county": "Clay",
    "discovery_date": "2023-07-21",
    "disclosure_date": "2024-01-03",
    "executive_summary": "North Kansas City Hospital (NKCH) and its subsidiary Meritas Health Corporation were affected by a data breach at transcription services vendor Perry Johnson & Associates (PJ&A). An unauthorized party gained access to PJ&A's network between March 27 and May 2, 2023, accessing patient records. NKCH learned of the incident on July 21, 2023, but did not notify patients until January 3, 2024 \u2014 more than five months later. The breach affected over 500,000 individuals associated with NKCH and Meritas. Compromised data included patient names, dates of birth, gender, phone numbers, addresses, health insurance information, and clinical information. Social Security numbers were not affected.",
    "attack_type": "Hacking / Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 500000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class-action lawsuits filed; settlement amount not publicly disclosed",
    "operational_impact": "NKCH systems were not directly impacted; breach was at vendor PJ&A",
    "remediation_disclosed": "PJ&A services discontinued; additional safeguards implemented; policies and procedures reviewed",
    "primary_source_url": "https://www.nkchealth.org/pja-data-event",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/north-kansas-city-hospital-confirms-1343084/",
      "https://thebeaconnews.org/stories/2024/01/25/how-ransomware-attacks-at-kansas-city-hospitals-threaten-your-privacy/"
    ],
    "confidence_notes": "High confidence. NKCH published official notice. JD Supra confirmed breach and OCR report filed January 3, 2024 with 500,000+ individuals placeholder. Part of the broader PJ&A breach affecting multiple hospitals (PJ&A total was 8.9 million affected).",
    "sources_used": [
      "NKC Health official notice",
      "JD Supra",
      "Beacon Kansas City",
      "HHS OCR breach portal"
    ],
    "id": "INC-00603",
    "year": 2024,
    "lat": 39.1432057,
    "lng": -94.5733988,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Numotion (United Seating and Mobility) \u2013 Email Breach",
    "organization_type": "Healthcare Provider (Mobility Equipment DME)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Brentwood",
    "hq_county": "Williamson",
    "discovery_date": "2024-09-06",
    "disclosure_date": "2024-11-01",
    "executive_summary": "Numotion reported a separate email data breach detected on September 6, 2024. Multiple employee email accounts were compromised between August 23 and September 6, 2024. The email breach was reported to HHS OCR as affecting 529,004 individuals. Combined with the March 2024 ransomware attack, Numotion agreed to a $4M class action settlement covering both incidents.",
    "attack_type": "Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 529004,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Included in $4 million combined class action settlement",
    "operational_impact": "Multiple employee email accounts compromised",
    "remediation_disclosed": "Accounts secured; HHS OCR notified; $4M combined settlement",
    "primary_source_url": "https://www.hipaajournal.com/numotion-email-data-breach-494k/",
    "secondary_source_urls": [
      "https://compliancejunction.com/numotion-to-settle-2024-data-breaches-lawsuit-for-4-million/"
    ],
    "confidence_notes": "HHS OCR lists 529,004 for email incident. Separate from ransomware incident (#56). Both covered by $4M settlement.",
    "sources_used": [
      "HIPAA Journal",
      "ComplianceJunction"
    ],
    "id": "INC-00604",
    "year": 2024,
    "lat": 36.0325687,
    "lng": -86.7825235,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Oklahoma Spine Hospital",
    "organization_type": "Healthcare Provider (Specialty Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2024-07-01",
    "disclosure_date": "2024-09-01",
    "executive_summary": "Oklahoma Spine Hospital experienced a data incident in July 2024 in which certain files containing private information were potentially accessed. Affected information included names, Social Security numbers, dates of birth, financial account numbers and routing numbers, health insurance information, medical information, payment card information, and/or driver's license numbers. A class action settlement was reached.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 38000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; class action lawsuit filed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Notifications sent; class action settlement in progress",
    "primary_source_url": "https://oshdataincidentsettlement.com",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/hipaa-breaches/"
    ],
    "confidence_notes": "Moderate confidence; class action settlement site confirms July 2024 incident; HIPAA Journal mentions ~38,000+ affected",
    "sources_used": [
      "OSH Data Incident Settlement website, HIPAA Journal"
    ],
    "id": "INC-00605",
    "year": 2024,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "OnePoint Patient Care",
    "organization_type": "Healthcare Provider (Hospice Pharmacy)",
    "organization_type_bucket": "Pharmacy",
    "state": "AZ",
    "hq_city": "Tempe",
    "hq_county": "Maricopa",
    "discovery_date": "2024-08-08",
    "disclosure_date": "2024-10-14",
    "executive_summary": "OnePoint Patient Care, a Tempe, AZ-based hospice pharmacy serving over 40,000 patients daily, detected suspicious network activity on August 8, 2024. Investigation confirmed that between August 6-8, the INC Ransom group accessed and exfiltrated files. 795,916 individuals were initially reported; later updated to 1,741,152. Compromised data included names, residence information, medical record numbers, diagnosis and prescription information, and Social Security numbers. Data was published on INC Ransom's leak site after ransom was not paid.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware (INC Ransom)",
    "attack_category": "Ransomware",
    "threat_actor_name": "INC Ransom",
    "attribution_status": "claimed",
    "individuals_affected_reported": 1741152,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not reported to impact business operations",
    "remediation_disclosed": "Law enforcement notified; forensic investigation; credit monitoring offered for SSN-affected individuals",
    "primary_source_url": "https://www.hipaajournal.com/onepoint-patient-care-data-breach/",
    "secondary_source_urls": [
      "https://www.securityweek.com/onepoint-patient-care-data-breach-impacts-nearly-800000-people/"
    ],
    "confidence_notes": "High confidence; OCR updated count to 1,741,152; INC Ransom group confirmed; data leaked publicly",
    "sources_used": [
      "HIPAA Journal, SecurityWeek"
    ],
    "id": "INC-00606",
    "year": 2024,
    "lat": 33.4255,
    "lng": -111.94,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "PIH Health (Downey Hospital, Good Samaritan Hospital, Whittier Hospital)",
    "organization_type": "Nonprofit community health system (3 hospitals, urgent care, home health, hospice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Whittier",
    "hq_county": "Los Angeles County",
    "discovery_date": "2024-12-01",
    "disclosure_date": "2024-12-08",
    "executive_summary": "On December 1, 2024, PIH Health detected a ransomware attack that disrupted computer systems, phone systems, and patient care workflows across its three hospitals and related outpatient facilities in Southern California. Threat actor 'Dreamer2000' claimed responsibility on December 13, 2024, alleging exfiltration of approximately 2 TB of data including 17 million patient records \u2014 a figure PIH could not verify. Forensic investigation determined unauthorized access occurred November 14 \u2013 December 23, 2024. Patient notifications were mailed February 25, 2026, after a year-long data review.",
    "attack_type": "Ransomware with claimed data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Dreamer2000 (claimed)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 17000000,
    "residents_affected_in_state": "Predominantly CA residents (LA and Orange County patient base)",
    "financial_impact": "{'ransom_paid': 'NOT_DISCLOSED', 'notes': 'Ransom amount and payment status not disclosed. Multiple class-action lawsuits filed. At least one individual lawsuit filed (Pasadena Star-News, Jan 2025).'}",
    "operational_impact": "Phone systems disrupted or rerouted. Computer systems offline. Staff recording patient information manually, causing delays. Scheduling systems unavailable. Some procedures/surgeries canceled. Care continued with downtime procedures.",
    "remediation_disclosed": "Systems secured upon detection; forensic investigators engaged; FBI and local police notified. Complimentary identity protection via Experian IdentityWorks offered. Notification letters mailed Feb 25, 2026.",
    "primary_source_url": "https://www.hipaajournal.com/pih-health-data-breach-ransomware/",
    "secondary_source_urls": [
      "https://www.netsec.news/pih-health-ransomware-incident/",
      "https://www.claimdepot.com/data-breach/pih-health-2026",
      "https://thehipaaetool.com/ransomware-attack-on-regional-california-health-system/",
      "https://www.healthcarefacilitiestoday.com/posts/PIH-Health-Facing-Lawsuit-Over-December-2024-Ransomware-Attack--29986"
    ],
    "confidence_notes": "Unusual timeline: attack Dec 1, 2024; notifications Feb 25, 2026 \u2014 over 14-month delay. Threat actor claims 17M records; this is unverified by PIH. Dreamer2000 also appeared on open web forum. CA AG, OR AG, and TX AG all received breach disclosures. TX residents: 8,434; OR residents: 2,351 reported separately.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00607",
    "year": 2024,
    "lat": 33.9792,
    "lng": -118.0328,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Pacific Cataract & Laser Institute (PCLI)",
    "organization_type": "Healthcare Provider (Ophthalmology / Eye Care)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Chehalis",
    "hq_county": "Lewis",
    "discovery_date": "2023-11-14",
    "disclosure_date": "2024-03-05",
    "executive_summary": "Pacific Cataract & Laser Institute (PCLI), a Washington-based eyecare facility performing cataract corrections, LASIK, and other eye procedures, suffered a cyberattack between November 13 and November 14, 2023. The LockBit ransomware group claimed responsibility for the attack. Hackers accessed systems containing patient PHI including names, dates of birth, Social Security numbers, medical record numbers, health insurance policy numbers, medical history, health insurance claims information, and financial account information. The breach was reported to HHS OCR as affecting 9,967 individuals. A $400,000 class-action settlement was reached, with final approval in December 2024.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit ransomware group (claimed)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 9967,
    "residents_affected_in_state": "Not separately reported (WA-based practice)",
    "financial_impact": "$400,000 class-action settlement (December 2024)",
    "operational_impact": "Patient PHI including SSNs, medical histories, and financial data exposed",
    "remediation_disclosed": "Individual notifications March 2024; $400K settlement; up to $5,000 documented loss reimbursement for class members",
    "primary_source_url": "https://www.hipaajournal.com/oak-valley-hospital-pacific-cataract-laser-institute-data-breach-settlements/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/pacific-cataract-and-laser-institute-inc.-p.c-march-2024",
      "https://topclassactions.com/lawsuit-settlements/privacy/data-breach/400k-pacific-cataract-laser-institute-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "HIPAA Journal confirmed HHS OCR filing (9,967 individuals); LockBit claim per DataBreaches.net; $400K settlement per Top Class Actions; case: Wix v. Pacific Cataract & Laser Institute, No. 24-2-06283-1-SEA, King County WA Superior Court; high confidence",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "Top Class Actions",
      "DataBreaches.net",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00608",
    "year": 2024,
    "lat": 46.6599653,
    "lng": -122.963432,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Pacific Guardian Life Insurance Company",
    "organization_type": "Health Plan / Life Insurance",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "City and County of Honolulu",
    "discovery_date": "2023-08-25",
    "disclosure_date": "2024-03-08",
    "executive_summary": "Pacific Guardian Life Insurance Company, a Hawaii-based life and health insurance company, experienced a cybersecurity incident on or about August 25, 2023, in which cybercriminals accessed its systems and exposed the personal and financial information of more than 167,000 individuals. Compromised data included names, Social Security numbers, dates of birth, financial account details, payment card information, and medical information. The Hawaii DCCA Security Breach Notices table lists this event (notified March 8, 2024 with Case No. 2024-0281) as affecting 61,500 Hawaii residents. A $2 million class-action settlement was reached in 2025.",
    "attack_type": "Hacking / Unauthorized network access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 167000,
    "residents_affected_in_state": 61500,
    "financial_impact": "$2 million class-action settlement (2025)",
    "operational_impact": "Customer SSNs, financial account data, and medical information compromised",
    "remediation_disclosed": "Systems secured; $2M settlement fund; credit monitoring offered to affected individuals",
    "primary_source_url": "https://cca.hawaii.gov/ocp/notices/security-breach/",
    "secondary_source_urls": [
      "https://www.claimdepot.com/settlements/pgli-data-breach",
      "https://hipaatimes.com/settlement-announced-in-pacific-guardian-life-cybersecurity-lawsuit"
    ],
    "confidence_notes": "High confidence: Hawaii DCCA breach notice table confirms Case 2024-0281 with 61,500 HI residents; Claim Depot and HIPAA Times confirm $2M settlement; 167,000 total from settlement documentation",
    "sources_used": [
      "Hawaii DCCA Breach Notices",
      "Claim Depot",
      "HIPAA Times (Paubox)"
    ],
    "id": "INC-00609",
    "year": 2024,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Parkland Health (Dallas County Hospital District)",
    "organization_type": "Healthcare Provider (Public Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Dallas",
    "hq_county": "Dallas",
    "discovery_date": "2024-06-01",
    "disclosure_date": "2024-10-01",
    "executive_summary": "Parkland Health (Dallas County Hospital District) reported a data breach in 2024. The HIPAA Journal referenced Parkland Health in breach coverage alongside Wichita County. Limited additional details are publicly available from the research conducted.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence; HIPAA Journal headline reference only; limited detail",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00610",
    "year": 2024,
    "lat": 32.7767,
    "lng": -96.797,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Piedmont Healthcare (tracking pixel \u2013 lawsuit dismissed)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Atlanta",
    "hq_county": "Fulton",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2024-08-24",
    "executive_summary": "Piedmont Healthcare faced a class action lawsuit alleging it used advertising technology on its MyChart patient portal to disclose patients' private information. The lawsuit claimed invasion of privacy, breach of fiduciary duty, negligence, breach of contract, unjust enrichment, and Federal Wiretap Act violations. The U.S. District Court for the Northern District of Georgia dismissed all claims on August 24, 2024, finding plaintiffs failed to sufficiently allege invasion of privacy damages or a wiretap violation.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure (alleged; lawsuit dismissed)",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (tracking pixels)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Lawsuit dismissed; no settlement",
    "operational_impact": "Alleged unauthorized transmission of patient data via advertising technology",
    "remediation_disclosed": "Lawsuit dismissed August 24, 2024",
    "primary_source_url": "https://blogs.duanemorris.com/classactiondefense/2024/08/29/georgia-federal-court-dismisses-data-privacy-class-action-against-healthcare-company-for-failure-to-sufficiently-allege-any-invasion-of-privacy-damages-or-wiretap-violation/",
    "secondary_source_urls": [],
    "confidence_notes": "Court dismissal order confirmed by Duane Morris blog. No confirmed HHS OCR breach report.",
    "sources_used": [
      "Duane Morris LLP"
    ],
    "id": "INC-00611",
    "year": 2024,
    "lat": 33.749,
    "lng": -84.388,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Planned Parenthood of Montana (Intermountain Planned Parenthood)",
    "organization_type": "Healthcare Provider / Reproductive Health",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MT",
    "hq_city": "Billings",
    "hq_county": "Yellowstone",
    "discovery_date": "2024-08-28",
    "disclosure_date": "2024-09-06",
    "executive_summary": "RansomHub ransomware breached Planned Parenthood of Montana August 24\u201328, 2024, exfiltrating 93 GB. Initially 18,003 patients; class action settlement covered ~60,402 individuals. PHI included names, addresses, DOB, medical record numbers, health insurance, diagnosis and treatment information. $400K class action settlement.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "RansomHub",
    "attribution_status": "claimed",
    "individuals_affected_reported": 60402,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$400,000 class action settlement",
    "operational_impact": "Systems partially offline; patient data stolen",
    "remediation_disclosed": "Law enforcement notified; security enhanced; $400K settlement (approved September 2025)",
    "primary_source_url": "https://www.hipaajournal.com/planned-parenthood-ransomware-2024/",
    "secondary_source_urls": [
      "https://www.classaction.org/news/400k-planned-parenthood-of-montana-settlement-resolves-class-action-over-august-2024-data-breach"
    ],
    "confidence_notes": "High confidence; HIPAA Journal confirmed 18,003 initially; $400K settlement documents confirmed ~60,402 class members; RansomHub claimed 93GB",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org"
    ],
    "id": "INC-00612",
    "year": 2024,
    "lat": 45.7833,
    "lng": -108.5007,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "PruittHealth",
    "organization_type": "Healthcare Provider (Long-Term Care/Nursing Homes)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Norcross",
    "hq_county": "Gwinnett",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2024-05-01",
    "executive_summary": "Norcross, GA-based PruittHealth (180 care centers in FL, GA, NC, SC) suffered a ransomware attack attributed to the NoEscape group in November 2023. NoEscape claimed 1.5 TB of data was stolen and uploaded to its dark web site on December 7, 2023; however, the site was taken down before forensic verification. The confirmed breach report to HHS OCR listed 56,405 individuals. Data included names, DOBs, SSNs, bank account numbers, health insurance, and medical information.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "NoEscape",
    "attribution_status": "claimed",
    "individuals_affected_reported": 56405,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; ransom not paid",
    "operational_impact": "1.5 TB of data allegedly stolen; dark web posting unverifiable",
    "remediation_disclosed": "File server reviewed; notifications mailed May 2024; class action lawsuit filed",
    "primary_source_url": "https://www.hipaajournal.com/class-action-lawsuit-alleges-pruitt-health-ransomware-attack-due-to-negligence/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/cyberattack-pruitthealth-easterseals-central-illinois/",
      "https://www.comparitech.com/news/pruitthealth-notifies-5217-people-of-data-breach-that-leaked-ssns-medical-records-and-more/"
    ],
    "confidence_notes": "HHS OCR lists 56,405 affected. NoEscape claim reported by HIPAA Journal and Comparitech.",
    "sources_used": [
      "HIPAA Journal",
      "Comparitech"
    ],
    "id": "INC-00613",
    "year": 2024,
    "lat": 33.9412127,
    "lng": -84.2135309,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Rebound Orthopedics & Neurosurgery P.C.",
    "organization_type": "Healthcare Provider (Orthopedics / Neurosurgery Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Vancouver",
    "hq_county": "Clark",
    "discovery_date": "2024-02-01",
    "disclosure_date": "2024-04-10",
    "executive_summary": "Rebound Orthopedics & Neurosurgery, a healthcare provider serving Washington and Oregon, suffered a targeted cyberattack on approximately February 1, 2024. Unauthorized actors accessed systems and potentially viewed or stole certain files containing protected health information. The breach affected 426,536 individuals \u2014 one of the largest orthopedics-related breaches in the Pacific Northwest. Compromised data included full names, dates of birth, Social Security numbers, driver's license numbers, medical information, health insurance information, and financial account information. The breach was reported to HHS OCR on April 10, 2024. A class-action lawsuit was settled for $2.5 million in December 2025 (preliminary approval).",
    "attack_type": "Unauthorized network access / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 426536,
    "residents_affected_in_state": "Not separately reported (serves WA and OR; majority WA-based)",
    "financial_impact": "$2.5 million class-action settlement (December 2025 preliminary approval)",
    "operational_impact": "426,536 individuals' PHI and PII potentially accessed; SSNs, financial data, medical records at risk",
    "remediation_disclosed": "Forensic investigation; individual notifications April 2024; $2.5M settlement; credit monitoring (CyEx Medical Shield) offered",
    "primary_source_url": "https://www.classaction.org/news/2.5m-rebound-orthopedics-and-neurosurgery-ends-class-action-lawsuit-over-february-2024-data-breach",
    "secondary_source_urls": [
      "https://rebounddatasettlement.com",
      "https://www.healthcaredive.com/news/tracking-healthcare-data-breaches-cybersecurity-hacking-hospitals/696184/"
    ],
    "confidence_notes": "HHS OCR breach portal confirmed 426,536 individuals per Healthcare Dive tracker; settlement at ReboundDataSettlement.com; case: Cooper v. Rebound Orthopedics, No. 25-2-00545-06, Clark County WA Superior Court; high confidence",
    "sources_used": [
      "ClassAction.org",
      "Rebound Data Settlement website",
      "Healthcare Dive breach tracker",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00614",
    "year": 2024,
    "lat": 45.6387,
    "lng": -122.6615,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Rhode Island RIBridges System (Brain Cipher Ransomware)",
    "organization_type": "State Government Health Benefits Portal",
    "organization_type_bucket": "Hospital / Health system",
    "state": "RI",
    "hq_city": "Providence",
    "hq_county": "Providence",
    "discovery_date": "2024-12-05",
    "disclosure_date": "2024-12-13",
    "executive_summary": "Rhode Island's RIBridges online portal, operated by Deloitte for health and social services benefits (Medicaid, SNAP, CHIP, and others), was breached on December 5, 2024 by the Brain Cipher ransomware group. Hundreds of thousands of Rhode Islanders' highly sensitive data including SSNs, banking information, names, addresses, and DOBs were stolen. Brain Cipher threatened to publish the data unless a ransom was paid. The state took the system offline; Brain Cipher subsequently leaked some data.",
    "attack_type": "Ransomware/extortion (Brain Cipher)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Brain Cipher",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Hundreds of thousands (exact number not confirmed)",
    "residents_affected_in_state": "Hundreds of thousands of RI residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "RIBridges system taken offline; Medicaid, SNAP, CHIP, and other benefit systems disrupted",
    "remediation_disclosed": "System taken offline; state offered free credit monitoring; FBI involved; Deloitte investigated",
    "primary_source_url": "https://www.hipaajournal.com/rhode-island-ri-bridges-system-hack/",
    "secondary_source_urls": [
      "https://statescoop.com/ransomware-attack-rhode-island-health-services-personal-data-2024/",
      "https://www.nytimes.com/2024/12/14/us/cyberattack-rhode-island-ribridges-snap-medicaid.html",
      "https://www.ibm.com/think/x-force/ransomware-attack-on-rhode-island-health-system-exposes-data-of-hundreds-of-thousands"
    ],
    "confidence_notes": "RI governor confirmed; Brain Cipher confirmed; NY Times reporting; Deloitte statement",
    "sources_used": [
      "HIPAA Journal",
      "StateScoop",
      "NY Times",
      "IBM"
    ],
    "id": "INC-00615",
    "year": 2024,
    "lat": 41.824,
    "lng": -71.4128,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "River Region Cardiology Associates",
    "organization_type": "Healthcare Provider (Cardiology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AL",
    "hq_city": "Montgomery",
    "hq_county": "Montgomery",
    "discovery_date": "2024-09-16",
    "disclosure_date": "2024-12-11",
    "executive_summary": "Montgomery, AL-based River Region Cardiology detected unauthorized access on September 16, 2024 stemming from 'a cyber-attack against a remote connection utilized by a vendor.' 500,000 individuals were reported to HHS OCR. The BianLian cyber threat group reportedly claimed responsibility. Exposed data included patient names, SSNs, DOBs, height, weight, and sex.",
    "attack_type": "Vendor Remote Connection Exploit / Network Intrusion",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "BianLian",
    "attribution_status": "claimed",
    "individuals_affected_reported": 500000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data including SSNs accessed via vendor remote connection",
    "remediation_disclosed": "Vendor access taken offline; investigation ongoing; HHS OCR notified December 11, 2024",
    "primary_source_url": "https://www.hipaajournal.com/river-region-cardiology-cyberattack-500000/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/river-region-cardiology-december-2024",
      "https://www.pittmandutton.com/firm-news/river-region-cardiology-associates-data-breach"
    ],
    "confidence_notes": "HHS OCR lists 500,000. BianLian claim reported by ClassAction.org. HIPAA Journal provides comprehensive details.",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org",
      "Pittman Dutton"
    ],
    "id": "INC-00616",
    "year": 2024,
    "lat": 32.3792,
    "lng": -86.3077,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sav-Rx (A&A Services) - Delaware/NE Healthcare Clients",
    "organization_type": "Business Associate / Pharmacy",
    "organization_type_bucket": "Pharmacy",
    "state": "NE",
    "hq_city": "Omaha",
    "hq_county": "Douglas",
    "discovery_date": "2023-10-08",
    "disclosure_date": "2024-05-03",
    "executive_summary": "Sav-Rx (operating as A&A Services), a pharmacy benefit management company, suffered a cyberattack October 3-10, 2023, exposing data of over 2.8 million individuals. The Delaware AG filing confirms 3,162 Delaware residents affected. Multiple NE state residents were included among victims. Data compromised included names, DOBs, SSNs, and prescription information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2800000,
    "residents_affected_in_state": 3162,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "2.8M individuals' pharmacy data compromised",
    "remediation_disclosed": "Multiple state AG notifications; HHS OCR breach filed",
    "primary_source_url": "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/database/",
    "secondary_source_urls": [],
    "confidence_notes": "Delaware AG database confirms filing; significant NE resident impact",
    "sources_used": [
      "Delaware AG database"
    ],
    "id": "INC-00617",
    "year": 2024,
    "lat": 41.2565,
    "lng": -95.9345,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Singing River Health System (additional filing)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MS",
    "hq_city": "Pascagoula",
    "hq_county": "Jackson",
    "discovery_date": "2024-03-06",
    "disclosure_date": "2024-05-01",
    "executive_summary": "Singing River Health System reported a second security event: on March 6, 2024, unusual activity was detected in its computer network again. This second incident was disclosed May 2024 when the total from the original August 2023 breach was revised to 895,204. The second event involved unauthorized access to network files including additional patient data categories (medical imaging, prescription, and insurance data).",
    "attack_type": "Unauthorized Network Access (second incident)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 895204,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Additional patient data categories potentially accessed",
    "remediation_disclosed": "Third-party cybersecurity specialists engaged; network secured",
    "primary_source_url": "https://www.hipaajournal.com/singing-river-health-system-895000-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Described in HIPAA Journal May 2024 update. Second incident details within same article as primary breach.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00618",
    "year": 2024,
    "lat": 30.3658,
    "lng": -88.5561,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Singing River Health System and its wholly owned subsidiary, Singing River Gulfport",
    "organization_type": "Hospital / Health System (Multistate)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Pascagoula, MS (Gulf Coast) / CA residents affected",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2023-08-19",
    "disclosure_date": "2024-05-13",
    "executive_summary": "We promptly took steps to secure our systems and, with the assistance of third-party forensic specialists, conducted an investigation to confirm the nature and scope of the incident. Through the investigation, we identified unauthorized access within our environment between August 16 and August 18, 2023. Following this determination, we are notifying all individuals whose information may have been included in the impacted files. Although we have no indication of any misuse of your personal information as a result of this event, out of an abundance of caution, we are providing notice to",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 895204,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuits filed",
    "operational_impact": "Hospital EHR systems disrupted; staff used paper records; services diverted",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Forensic investigation conducted']",
    "primary_source_url": "https://oag.ca.gov/system/files/SRHS%20-%20Notice%20of%20Data%20Event%20-%20CA_0.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/singing-river-health-system-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/singing-river-health-system-ransomware-attack-affects-895k-people/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00619",
    "year": 2024,
    "lat": 35.4571035098987,
    "lng": -120.30002386154203,
    "is_multistate": true,
    "hq_outside_state": "Pascagoula, Mississippi",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Somerset Dental Las Vegas",
    "organization_type": "Healthcare Provider / Dental Practice",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NV",
    "hq_city": "Las Vegas",
    "hq_county": "Clark",
    "discovery_date": "2024-02-16",
    "disclosure_date": "2024-04-01",
    "executive_summary": "Unauthorized third party accessed Somerset Dental Las Vegas's network server on or around February 16, 2024. 11,321 individuals affected per HHS OCR breach report.",
    "attack_type": "Hacking / Network Server Access",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11321,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network server compromised",
    "remediation_disclosed": "HHS OCR notified; patients notified",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/somerset-dental-las-vegas-april-2024",
    "secondary_source_urls": [
      "https://www.classaction.org/media/somerset-dental-las-vegas-online-data-breach-notice.pdf"
    ],
    "confidence_notes": "High confidence; 11,321 per HHS OCR; ClassAction.org confirmed; Las Vegas NV dental practice",
    "sources_used": [
      "ClassAction.org",
      "HHS OCR"
    ],
    "id": "INC-00620",
    "year": 2024,
    "lat": 36.1699,
    "lng": -115.1398,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "South Broward Hospital District (Memorial Healthcare System, FL)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Hollywood",
    "hq_county": "Broward",
    "discovery_date": "2023-01-01",
    "disclosure_date": "2024-01-15",
    "executive_summary": "Memorial Healthcare System (Hollywood, FL) settled with HHS OCR in January 2024 for a $60,000 civil monetary penalty related to an OCR investigation into HIPAA violations. The investigation found MHS failed to provide timely patient access to medical records (HIPAA Right of Access initiative). This is separate from MHS's 2017 $5.5M settlement for employee insider access breach. Noted as OCR's 52nd Right of Access enforcement action.",
    "attack_type": "HIPAA Right of Access Violation (not a hacking incident)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not applicable",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$60,000 OCR civil monetary penalty",
    "operational_impact": "HIPAA compliance failure; patient denied record access",
    "remediation_disclosed": "Settlement with corrective action; $60,000 penalty paid",
    "primary_source_url": "https://www.hunton.com/privacy-and-cybersecurity-law-blog/hhs-ocr-issues-fine-against-memorial-healthcare-system-under-right-of-access-initiative2",
    "secondary_source_urls": [],
    "confidence_notes": "Hunton Andrews Kurth reporting on OCR enforcement action. Not a hacking incident\u2014included for completeness as cyber compliance action.",
    "sources_used": [
      "Hunton Andrews Kurth LLP"
    ],
    "id": "INC-00621",
    "year": 2024,
    "lat": 26.0112,
    "lng": -80.1495,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "South Texas Oncology and Hematology",
    "organization_type": "Healthcare Provider (Oncology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "San Antonio",
    "hq_county": "Bexar",
    "discovery_date": "2024-06-01",
    "disclosure_date": "2024-08-01",
    "executive_summary": "South Texas Oncology and Hematology reported a cyberattack in which protected health information was compromised. The HIPAA Journal referenced this in 2024 breach coverage. Limited additional details are publicly available.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence; HIPAA Journal headline-level reference only; limited confirmable details",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00622",
    "year": 2024,
    "lat": 29.4241,
    "lng": -98.4936,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "SouthCoast Health (Privia Medical Group of Georgia)",
    "organization_type": "Healthcare Provider / Multi-Specialty Medical Group",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Savannah",
    "hq_county": "Chatham",
    "discovery_date": "2023-06-18",
    "disclosure_date": "2024-07-05",
    "executive_summary": "SouthCoast Medical Group (dba SouthCoast Health) in Georgia detected unauthorized activity on June 18, 2023. Forensic investigation confirmed an unauthorized actor accessed and potentially copied files between June 15-18, 2023. The exposed information included an extensive range of PII and PHI. SC Consumer Affairs listed 32,835 SC residents affected. Total individuals affected: 10,434 (HHS OCR reporting). The breach also affected affiliated Privia Medical Group of Georgia.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 10434,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Extensive PII and PHI exfiltrated including SSNs, passport numbers, payment card info, medical records, electronic signatures",
    "remediation_disclosed": "Systems secured; third-party forensic specialists engaged; patient notification letters sent approximately one year after breach",
    "primary_source_url": "https://www.hipaajournal.com/southcoast-health-call-4-health-notify-patients-about-cyberattacks/",
    "secondary_source_urls": [
      "https://databreaches.net/2024/07/06/southcoast-medical-group-and-privia-medical-group-notify-patients-of-june-2023-cyberattack/",
      "https://www.classaction.org/data-breach-lawsuits/southcoast-health-july-2024"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal, DataBreaches.Net, ClassAction.org, SC Consumer Affairs (32,835 SC residents).",
    "sources_used": [
      "HIPAA Journal",
      "DataBreaches.Net",
      "ClassAction.org",
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00623",
    "year": 2024,
    "lat": 32.0809,
    "lng": -81.0912,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Spartanburg Rehabilitation Institute",
    "organization_type": "Healthcare Provider / Rehabilitation Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Spartanburg",
    "hq_county": "Spartanburg",
    "discovery_date": "2023-11-01",
    "disclosure_date": "2024-04-02",
    "executive_summary": "Spartanburg Rehabilitation Institute reported a data security incident to the South Carolina Attorney General in April 2024 affecting 4,335 SC residents. Patient PHI was exposed in an unauthorized access incident.",
    "attack_type": "Unauthorized Access / Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4335,
    "residents_affected_in_state": 4335,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Rehabilitation patient PHI potentially accessed",
    "remediation_disclosed": "SC AG notified April 2024",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00624",
    "year": 2024,
    "lat": 34.9498007,
    "lng": -81.9320157,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Stanford University Department of Public Safety \u2014 Akira Ransomware",
    "organization_type": "University department (health/medical data involved; affiliated with Stanford Health Care)",
    "organization_type_bucket": "Other healthcare entity",
    "state": "CA",
    "hq_city": "Stanford (unincorporated Santa Clara County)",
    "hq_county": "Santa Clara County",
    "discovery_date": "2023-09-27",
    "disclosure_date": "2024-03-01",
    "executive_summary": "Between May 12 and September 27, 2023, the Akira ransomware group gained unauthorized access to Stanford University's Department of Public Safety (DPS) network, exfiltrating approximately 430 GB of data. Stanford discovered the breach on September 27, 2023, and took immediate steps to secure the network. The forensic investigation identified approximately 27,000 individuals whose PII (including SSNs, DOBs, passport numbers, driver's license numbers, government IDs, biometric data, and in some cases medical information) was potentially compromised. Notification letters were sent in early 2024.",
    "attack_type": "Ransomware with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Akira",
    "attribution_status": "claimed",
    "individuals_affected_reported": 27000,
    "residents_affected_in_state": "Primarily CA given Stanford's CA campus and CA-based individuals",
    "financial_impact": "{'notes': 'No publicly disclosed ransom payment or financial penalties. Akira reportedly demanded ~$1M.'}",
    "operational_impact": "Limited to DPS network; not affecting Stanford Health Care, Stanford Medicine, or hospital operations. Isolated to DPS systems per university statement.",
    "remediation_disclosed": "Unauthorized access terminated; law enforcement notified; forensic investigator engaged; notification letters sent with complimentary identity protection services.",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/stanford-university-march-2024",
    "secondary_source_urls": [
      "https://sentrybay.com/27000-individuals-hit-by-data-breach-at-stanford-university/",
      "https://www.linkedin.com/pulse/stanford-university-hacked-attackers-breached-internal-p96qc"
    ],
    "confidence_notes": "Note: Akira (first appeared March 2023) targets Windows and Linux. Claimed 430 GB stolen. Attack dwell time was ~4.5 months (May 12 \u2013 Sept 27, 2023). Not a Stanford Health Care breach per se, but DPS records included medical/biometric data for some individuals. Maine AG filing used to confirm 27,000 individuals.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00625",
    "year": 2024,
    "lat": 37.4275,
    "lng": -122.1697,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Summit Pathology and Summit Pathology Laboratories, Inc.",
    "organization_type": "Lab / Pathology",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "CO",
    "hq_city": "Loveland",
    "hq_county": "Larimer",
    "discovery_date": "2024-04-18",
    "disclosure_date": "2024-10-18",
    "executive_summary": "On approximately April 18, 2024, a Summit Pathology employee opened a malicious email attachment, providing the Medusa ransomware group access to the company's network. Summit Pathology and Summit Pathology Laboratories, Colorado-based pathology service providers, reported the breach to HHS OCR in October 2024 as affecting 1,813,538 patients. Data stolen included names, addresses, medical billing and insurance information, diagnoses, dates of birth, Social Security numbers, and financial information. While data was exfiltrated, no public leak occurred on Medusa's site as of the time of the lawsuits, suggesting ransom may have been paid. The company was sued within 48 hours of its breach notification.",
    "attack_type": "Ransomware / Phishing / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Medusa",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1813538,
    "residents_affected_in_state": "CO: majority; exact state-level counts not separately disclosed",
    "financial_impact": "Class action lawsuits filed immediately. Ransom payment status: Not publicly confirmed but suggested by absence of data leak. Settlement amounts not yet disclosed.",
    "operational_impact": "Pathology services disrupted. Patient data exfiltrated. No public data dump on Medusa's leak site at time of notification, suggesting payment or negotiation.",
    "remediation_disclosed": "Third-party forensics. HHS OCR breach reported October 18, 2024. Notification letters mailed. Legal response to class action commenced.",
    "primary_source_url": "https://www.hipaajournal.com/summit-pathology-data-breach/",
    "secondary_source_urls": [
      "https://databreaches.net/2024/10/30/summit-pathology-laboratories-notified-1-8-million-patients-of-a-breach-less-than-48-hours-later-they-were-sued/",
      "https://securityboulevard.com/2024/11/how-proactive-security-could-have-stopped-the-summit-pathology-data-breach/",
      "https://www.cybersecurity-insiders.com/medusa-ransomware-attack-impacts-1-8-million-patients/",
      "https://www.compliancehome.com/1-8-million-individuals-impacted-by-ransomware-attack-on-summit-pathology/"
    ],
    "confidence_notes": "High confidence. HHS OCR breach report is primary source. HIPAA Journal and DataBreaches.Net corroborate. Medusa attribution confirmed by company's legal counsel to ISMG. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "DataBreaches.Net",
      "HIPAA Journal",
      "HIPAA Journal, Cybersecurity Insiders, ComplianceHome",
      "Security Boulevard"
    ],
    "id": "INC-00626",
    "year": 2024,
    "lat": 40.3977612,
    "lng": -105.07498,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Texas Tech University Health Sciences Center (Interlock Ransomware)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Lubbock",
    "hq_county": "Lubbock",
    "discovery_date": "2024-09-29",
    "disclosure_date": "2024-11-14",
    "executive_summary": "Texas Tech University Health Sciences Center (Lubbock campus) suffered a ransomware attack detected in late September 2024. Unauthorized access occurred between September 17 and September 29, 2024. The Interlock ransomware group claimed responsibility and leaked 2.6 TB of data (including 2.1M files) after the ransom was not paid. 650,000 patients at the Lubbock campus were affected. Compromised data included names, addresses, dates of birth, SSNs, driver's license numbers, financial account information, health insurance information, and diagnosis and treatment information.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware + Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock",
    "attribution_status": "claimed",
    "individuals_affected_reported": 650000,
    "residents_affected_in_state": "Primarily West Texas patients",
    "financial_impact": "Not publicly disclosed; multiple class action lawsuits filed",
    "operational_impact": "Computer systems and applications disrupted; patient portal and communication platforms offline",
    "remediation_disclosed": "Systems isolated; third-party cybersecurity firms engaged; FBI involved; notifications mailed by December 2024",
    "primary_source_url": "https://www.hipaajournal.com/texas-tech-university-health-sciences-center-ransomware-data-breach/",
    "secondary_source_urls": [
      "https://www.blackfog.com/texas-tech-cyberattack-1-4m-records-compromised/",
      "https://insider.govtech.com/texas/news/tech-health-sciences-center-cyber-attack-impacted-1-4m-patients"
    ],
    "confidence_notes": "High confidence; OCR confirmed 650,000 (Lubbock) separately from El Paso campus; Interlock confirmed via leak site",
    "sources_used": [
      "HIPAA Journal, BlackFog, GovTech Insider Texas"
    ],
    "id": "INC-00627",
    "year": 2024,
    "lat": 33.5779,
    "lng": -101.8552,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Texas Tech University Health Sciences Center El Paso",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "El Paso",
    "hq_county": "El Paso",
    "discovery_date": "2024-09-29",
    "disclosure_date": "2024-11-14",
    "executive_summary": "Texas Tech University Health Sciences Center El Paso was simultaneously affected with the Lubbock campus by the Interlock ransomware group. The El Paso campus reported 815,000 patients affected \u2014 more than the Lubbock campus. Systems and applications shared between TTUHSC, Texas Tech Physicians, and UMC Health System were disrupted. Combined Lubbock+El Paso total was 1,465,000 patients.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware + Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock",
    "attribution_status": "claimed",
    "individuals_affected_reported": 815000,
    "residents_affected_in_state": "Primarily West Texas (El Paso region) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Computer systems and applications disrupted; shared systems with UMC Health System affected",
    "remediation_disclosed": "Systems isolated; FBI engaged; Interlock data leak (2.6 TB) released publicly after ransom not paid",
    "primary_source_url": "https://www.hipaajournal.com/texas-tech-university-health-sciences-center-ransomware-data-breach/",
    "secondary_source_urls": [
      "https://lubbocklights.com/umc-paid-ransom-with-insurance-data-was-restored-not-sold-on-dark-web/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 815,000 (El Paso) separately; UMC Health System also affected (500+ placeholder)",
    "sources_used": [
      "HIPAA Journal, Lubbock Lights"
    ],
    "id": "INC-00628",
    "year": 2024,
    "lat": 31.7619,
    "lng": -106.485,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "The Lash Group \u2014 SC impact",
    "organization_type": "Business Associate / Patient Support Services",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "SC",
    "hq_city": "Charlotte",
    "hq_county": "Mecklenburg County (NC-based)",
    "discovery_date": "2024-01-01",
    "disclosure_date": "2024-05-24",
    "executive_summary": "The Lash Group, LLC, a healthcare patient support services company (subsidiary of AmerisourceBergen, headquartered in Charlotte, NC), reported a data breach affecting 249,033 South Carolina residents per the SC AG. The Lash Group provides patient access and adherence programs for pharmaceutical manufacturers across the Southeast.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 249033,
    "residents_affected_in_state": 249033,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient support program data including PHI and PII exposed",
    "remediation_disclosed": "SC AG notified May 2024",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing with 249,033 SC residents May 2024. Major SE healthcare-adjacent breach.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00629",
    "year": 2024,
    "lat": 32.7919443,
    "lng": -79.9262938,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Tri-City Healthcare District",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Oceanside, CA (San Diego County)",
    "hq_county": "San Diego County",
    "discovery_date": "2024-02-11",
    "disclosure_date": "2024-10-12",
    "executive_summary": "Upon discovering this activity, we took steps to secure our digital environment. We also engaged leading cybersecurity experts to assist with an investigation and to determine whether personal information may have been accessed or acquired without authorization. The investigation revealed that an unknown actor gained access to and obtained certain data from the Tri-City network on or about November 8, 2023. Tri-City then worked with additional experts to conduct a comprehensive review of the impacted data to determine what personal information was involved. On or about September 27, 2",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "INC Ransom",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 108149,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuits filed",
    "operational_impact": "Oceanside, CA hospital; emergency services diverted; systems taken offline",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified', 'Additional security measures implemented']",
    "primary_source_url": "https://oag.ca.gov/system/files/10.1.24%20Tri-City%20-%20Adult%20Template%20Notification%20Letter%2811832080.1%29_v2__Static_Proof_R2.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/tri-city-medical-center-lockbit-ransomware-attack/",
      "https://www.bleepingcomputer.com/news/security/lockbit-claims-attack-on-california-hospital-tri-city-medical-center/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00630",
    "year": 2024,
    "lat": 33.1959,
    "lng": -117.3795,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "TriHealth Physician Partners \u2014 2024 Vendor Breach",
    "organization_type": "Primary Care / OB-GYN Provider Group",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OH",
    "hq_city": "Cincinnati",
    "hq_county": "Hamilton",
    "discovery_date": "2024-10-23",
    "disclosure_date": "2024-11-18",
    "executive_summary": "TriHealth learned on October 23, 2024 that a vendor experienced unauthorized access to electronic documents related to care provided by For Women, an OB/GYN group that joined TriHealth in January 2020. The breach affected only historical documents predating For Women's integration with TriHealth. PHI of 27,426 individuals was exposed including names, addresses, DOBs, SSNs, claims information, medical conditions, medications, lab results, and detailed treatment histories.",
    "attack_type": "Hacking / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 27426,
    "residents_affected_in_state": "Ohio (Cincinnati area) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Historical OB/GYN records only; TriHealth's current network not breached",
    "remediation_disclosed": "Yes \u2014 vendor relationship reviewed; patients notified November 2024",
    "primary_source_url": "https://www.hipaajournal.com/trihealth-physician-partners-cyberattack/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/trihealth-november-2024"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, HHS OCR breach portal (27,426), ClassAction.org.",
    "sources_used": [
      "HIPAA Journal",
      "ClassAction.org"
    ],
    "id": "INC-00631",
    "year": 2024,
    "lat": 39.1031,
    "lng": -84.512,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Trustpoint Rehabilitation Hospital of Lubbock",
    "organization_type": "Healthcare Provider (Rehabilitation Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Lubbock",
    "hq_county": "Lubbock",
    "discovery_date": "2024-01-01",
    "disclosure_date": "2024-03-29",
    "executive_summary": "Trustpoint Rehabilitation Hospital of Lubbock reported a hacking/IT incident that affected 9,014 individuals. The breach was reported to HHS on March 29, 2024.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 9014,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://lubbocklights.com/umc-paid-ransom-with-insurance-data-was-restored-not-sold-on-dark-web/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; cited in Lubbock Lights article referencing HHS OCR data",
    "sources_used": [
      "Lubbock Lights"
    ],
    "id": "INC-00632",
    "year": 2024,
    "lat": 33.5779,
    "lng": -101.8552,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UC San Diego Health Hillcrest - Hillcrest Medical Center",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Diego, CA",
    "hq_county": "San Diego County",
    "discovery_date": "2024-01-09",
    "disclosure_date": "2024-03-08",
    "executive_summary": "On January 9, 2024, we identified a phishing attack against UC San Diego Health employees, which resulted in unauthorized access to two employee email accounts. \u201cPhishing\u201d occurs when an email is sent that looks like it is from a trustworthy source, but it is not. The email misleads the recipient to share or provide access to their email login information. When UC San Diego Health discovered the event, we immediately secured the email accounts and enhanced our security controls. We also began an",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 495949,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "[]",
    "primary_source_url": "https://oag.ca.gov/system/files/UCSDH_CA_AG_Appendix_3_8_24_Prism_Redacted.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "Separate filing for UCSD Hillcrest campus phishing incident; distinct from prior UCSD Health filing",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00633",
    "year": 2024,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "UNC Health (UNC School of Medicine / UNC Hospitals) \u2013 2024 Phishing",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "Chapel Hill",
    "hq_county": "Orange",
    "discovery_date": "2024-02-02",
    "disclosure_date": "2024-04-02",
    "executive_summary": "A UNC School of Medicine faculty member fell victim to a social engineering phishing attack on February 1, 2024. The threat actor tricked the user into sharing an MFA code, accessing the university email account. UNC discovered and contained the breach within 24 hours on February 2. The compromised account contained patient names, DOBs, diagnoses, SSNs, driver's licenses, financial account information, and health insurance IDs.",
    "attack_type": "Phishing / Social Engineering / MFA Bypass",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Single email account compromised; resolved within 24 hours",
    "remediation_disclosed": "Email account secured; additional email security measures implemented; credit monitoring offered; notifications mailed April 2, 2024",
    "primary_source_url": "https://www.unchealthcare.org/news-media/notice-of-a-data-security-incident/",
    "secondary_source_urls": [],
    "confidence_notes": "UNC Health official notice is primary source. Exact number of affected individuals not disclosed.",
    "sources_used": [
      "UNC Health (official website)"
    ],
    "id": "INC-00634",
    "year": 2024,
    "lat": 35.9132,
    "lng": -79.0558,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UT Southwestern Medical Center (2024 \u2013 calendar tool)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Dallas",
    "hq_county": "Dallas",
    "discovery_date": "2024-10-10",
    "disclosure_date": "2024-12-16",
    "executive_summary": "UT Southwestern Medical Center discovered on October 10, 2024 that workforce members were using a third-party calendar management tool that allowed the vendor to access employee calendars \u2014 some of which contained PHI. 43,048 patients were affected. This was UTSW's third breach of 2024 and sixth since 2020. Compromised data included names, dates of birth, medical record numbers, phone numbers, dates of planned services, diagnoses, lab results, medications, insurance benefits, and partial SSNs.",
    "attack_type": "Hacking/IT Incident \u2013 Third-Party Software Unauthorized Data Access",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 43048,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Processes implemented to limit third-party data sharing; monitoring for sensitive data leaving network",
    "primary_source_url": "https://www.hipaajournal.com/ut-southwestern-medical-center-data-breach-43000/",
    "secondary_source_urls": [
      "https://hipaatimes.com/university-of-texas-southwestern-files-3rd-data-breach-notice-of-2024"
    ],
    "confidence_notes": "High confidence; HIPAA Journal documented; OCR confirmed 43,048",
    "sources_used": [
      "HIPAA Journal, Paubox/HIPAA Times"
    ],
    "id": "INC-00635",
    "year": 2024,
    "lat": 32.7767,
    "lng": -96.797,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "United Seating and Mobility (Numotion) \u2013 Ransomware",
    "organization_type": "Healthcare Provider (Mobility Equipment DME)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Brentwood",
    "hq_county": "Williamson",
    "discovery_date": "2024-03-02",
    "disclosure_date": "2024-04-01",
    "executive_summary": "Brentwood, TN-based Numotion (wheelchair and mobility equipment provider) suffered a ransomware attack by the Black Basta group. Attackers had network access between February 29 and March 2, 2024, stealing data and encrypting files. Initial reports indicated few thousand affected; final HHS OCR report listed 602,265 individuals. Data included names, DOBs, SSNs, equipment order information, supporting medical records, and health insurance details.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Black Basta",
    "attribution_status": "reported",
    "individuals_affected_reported": 602265,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$4 million class action settlement (consolidated with second breach)",
    "operational_impact": "Files stolen and encrypted; initially understated to a few thousand affected",
    "remediation_disclosed": "Systems restored; HHS OCR notified; $4M settlement (combined with email breach)",
    "primary_source_url": "https://www.hipaajournal.com/numotion-email-data-breach-494k/",
    "secondary_source_urls": [
      "https://www.securityweek.com/numotion-data-breach-impacts-nearly-500000-people/",
      "https://compliancejunction.com/numotion-to-settle-2024-data-breaches-lawsuit-for-4-million/"
    ],
    "confidence_notes": "HHS OCR lists 602,265 for ransomware incident. Black Basta attribution via SecurityWeek.",
    "sources_used": [
      "HIPAA Journal",
      "SecurityWeek",
      "ComplianceJunction"
    ],
    "id": "INC-00636",
    "year": 2024,
    "lat": 36.0325687,
    "lng": -86.7825235,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "University Medical Center (UMC) Health System",
    "organization_type": "Healthcare Provider (Teaching Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Lubbock",
    "hq_county": "Lubbock",
    "discovery_date": "2024-09-26",
    "disclosure_date": "2024-11-22",
    "executive_summary": "University Medical Center (UMC) Health System in Lubbock experienced a ransomware attack starting September 16, 2024 \u2014 linked to the same Interlock attack that hit TTUHSC. UMC paid a ransom using insurance coverage (except for the deductible), and data was reportedly restored and not sold on the dark web. UMC separately disclosed the breach to HHS with 500+ as a placeholder. UMC is the primary teaching hospital affiliated with TTUHSC.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock (likely shared with TTUHSC attack)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 500,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Ransom paid (amount undisclosed); insurance covered ransom and recovery costs minus deductible",
    "operational_impact": "Recovery took approximately two months; all clinical aspects restored by November 22, 2024",
    "remediation_disclosed": "Ransom paid; passwords changed; new technical safeguards implemented; FBI engaged; third-party forensic firm",
    "primary_source_url": "https://lubbocklights.com/umc-paid-ransom-with-insurance-data-was-restored-not-sold-on-dark-web/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; HHS filing confirmed but placeholder used; ransomware payment confirmed via Lubbock Lights investigation",
    "sources_used": [
      "Lubbock Lights (investigative journalism)"
    ],
    "id": "INC-00637",
    "year": 2024,
    "lat": 33.5779,
    "lng": -101.8552,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "University of Maryland Medical Center (UMMC) - Insider Spyware Campaign",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Baltimore",
    "hq_county": "Baltimore City",
    "discovery_date": "2024-09-01",
    "disclosure_date": "2024-10-01",
    "executive_summary": "The University of Maryland Medical Center disclosed in October 2024 that a former pharmacist (Matthew Bathula) had installed keylogger spyware on approximately 400 hospital computers over a decade, gaining access to credentials of at least 80 staff members. Bathula remotely activated cameras to record women in private spaces. UMMC sent an October 2024 group email to staff warning about the 'sophisticated and very difficult to detect cyberattack.' A class action lawsuit was filed in April 2025.",
    "attack_type": "Insider threat / malicious spyware/keylogger installation",
    "attack_category": "Malware",
    "threat_actor_name": "Matthew Bathula (former UMMC pharmacist)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 80,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; class action pending",
    "operational_impact": "10-year spyware campaign; 400 computers compromised; credentials of 80 staff stolen; privacy violations including camera surveillance",
    "remediation_disclosed": "400 computers replaced; cameras removed; credentials reset; software installation restricted; FBI investigation; perpetrator terminated",
    "primary_source_url": "https://www.hipaajournal.com/lawsuit-teaching-hospital-pharmacist-cyber-spying-campaign/",
    "secondary_source_urls": [
      "https://www.gelaw.com/insights/university-of-maryland-medical-center-faces-class-action-lawsuit-concerning-decade-long-cyber-spying-incident/",
      "https://www.wmar2news.com/local/lawsuit-alleges-ummc-pharmacist-hacked-hundreds-of-computers-to-watch-women-undress"
    ],
    "confidence_notes": "UMMC confirmed via October 2024 staff email; class action filed April 2025; FBI investigation; technically cyber intrusion involving spyware",
    "sources_used": [
      "HIPAA Journal",
      "Grant & Eisenhofer",
      "WMAR2"
    ],
    "id": "INC-00638",
    "year": 2024,
    "lat": 39.2904,
    "lng": -76.6122,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "WebTPA Employer Services, LLC",
    "organization_type": "Business Associate (Health Insurance Benefits Administrator)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "TX",
    "hq_city": "Grand Prairie",
    "hq_county": "Dallas",
    "discovery_date": "2023-12-28",
    "disclosure_date": "2024-05-08",
    "executive_summary": "WebTPA, a Texas-based company providing health insurance and benefit plan administration, detected suspicious activity on December 28, 2023. Investigation revealed unauthorized access to its network between April 18 and April 23, 2023 \u2014 approximately 8 months before detection. 2,429,175 individuals were affected. Compromised data included names, contact information, dates of birth, dates of death, Social Security numbers, and insurance information. No financial account or treatment/diagnostic information was affected.",
    "attack_type": "Hacking/IT Incident \u2013 Network Server Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2429175,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Forensic investigation; affected benefit plans notified; breach reported to HHS on May 8, 2024",
    "primary_source_url": "https://techcrunch.com/2024/05/17/healthcare-company-webtpa-discloses-breach-affecting-2-5-million-people/",
    "secondary_source_urls": [
      "https://thehipaaetool.com/webtpa-announces-breach-affecting-2-4-million/"
    ],
    "confidence_notes": "High confidence; OCR confirmed 2,429,175; TechCrunch and HIPAA E-Tool documented",
    "sources_used": [
      "TechCrunch, The HIPAA E-Tool"
    ],
    "id": "INC-00639",
    "year": 2024,
    "lat": 32.7459645,
    "lng": -96.9977846,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Weirton Medical Center",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WV",
    "hq_city": "Weirton",
    "hq_county": "Brooke",
    "discovery_date": "2024-01-18",
    "disclosure_date": "2024-03-01",
    "executive_summary": "Weirton Medical Center suffered a ransomware attack between January 14-18, 2024, resulting in the theft and encryption of patient data. The breach affected 26,793 individuals, exposing names, dates of birth, SSNs, health insurance details, and treatment records. Four class action lawsuits were filed, later consolidated. A class action settlement was reached in 2025.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 26793,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action settlement reached; $5,000 cap per class member for documented losses or $50 flat payment",
    "operational_impact": "Patient data stolen and encrypted; multi-system disruption",
    "remediation_disclosed": "Incident response engaged; law enforcement notified; class action settlement reached with credit monitoring and identity theft protection",
    "primary_source_url": "https://www.paubox.com/blog/weirton-medical-center-settles-ransomware-data-breach-case",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 Paubox reporting, court records, HHS OCR filing.",
    "sources_used": [
      "Paubox",
      "Court records",
      "HHS OCR"
    ],
    "id": "INC-00640",
    "year": 2024,
    "lat": 40.4002396,
    "lng": -80.5899788,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wichita County (Texas health data breach)",
    "organization_type": "Government / Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Wichita Falls",
    "hq_county": "Wichita",
    "discovery_date": "2024-01-01",
    "disclosure_date": "2024-01-01",
    "executive_summary": "Wichita County, Texas reported a health data breach in 2024. Referenced by HIPAA Journal alongside Parkland Health in the same headline. Limited details available.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence; HIPAA Journal headline reference only",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00641",
    "year": 2024,
    "lat": 33.9004572,
    "lng": -98.5020777,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wisconsin Physicians Service Insurance Corporation (WPS) / CMS MOVEit breach",
    "organization_type": "Medicare Administrative Contractor / Health Insurance",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WI",
    "hq_city": "Madison",
    "hq_county": "Dane",
    "discovery_date": "2023-05-31",
    "disclosure_date": "2024-09-09",
    "executive_summary": "Wisconsin Physicians Service Insurance Corporation (WPS), a Medicare Administrative Contractor for CMS, was affected by the May 2023 Cl0p group exploitation of the MOVEit file transfer software zero-day vulnerability. WPS used MOVEit for transferring files for Medicare claims services provided to CMS. The breach occurred between May 27\u201331, 2023, before the vulnerability was patched. Investigation revealed files containing PHI and PII of Medicare beneficiaries were exfiltrated. CMS and WPS jointly disclosed the breach in September 2024, confirming 946,801 Medicare beneficiaries were affected. Data exposed included names, Social Security/TIN numbers, mailing addresses, dates of birth, gender, hospital account numbers, dates of service, Medicare Beneficiary Identifiers, and health insurance claim numbers.",
    "attack_type": "MOVEit Zero-Day Exploitation / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Cl0p (CL0P)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 946801,
    "residents_affected_in_state": "Medicare beneficiaries across multiple states; Wisconsin residents \u2014 not separately quantified",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Medicare data exposed; no clinical operational disruption reported",
    "remediation_disclosed": "Yes \u2014 MOVEit patched, investigation completed, CMS/WPS notified HHS, credit monitoring offered to affected individuals",
    "primary_source_url": "https://www.hipaajournal.com/cms-wisconsin-physicians-service-moveit-hack/",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/cms-wisconsin-physicians-service-insurance-corporation-moveit-data-breach/726416/"
    ],
    "confidence_notes": "High confidence. CMS official disclosure, HIPAA Journal, Healthcare Dive.",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare Dive",
      "CMS official announcement"
    ],
    "id": "INC-00642",
    "year": 2024,
    "lat": 43.0731,
    "lng": -89.4012,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Young Consulting LLC (dba Connexure)",
    "organization_type": "Business Associate (Stop-Loss Insurance Software)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "GA",
    "hq_city": "Atlanta",
    "hq_county": "Fulton",
    "discovery_date": "2024-04-13",
    "disclosure_date": "2024-08-26",
    "executive_summary": "Atlanta-based Young Consulting (Connexure), providing software solutions for the employer stop-loss insurance marketplace, suffered a BlackSuit ransomware attack between April 10 and April 13, 2024. BlackSuit added Young Consulting to its leak site on May 7, 2024, claiming data theft. When negotiations reportedly failed, BlackSuit published a 324 GB compressed file of stolen data. 954,177 individuals were affected, including members of Blue Shield of California and other HIPAA-covered entities.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackSuit",
    "attribution_status": "claimed",
    "individuals_affected_reported": 954177,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; ransom demand reported but amount unknown",
    "operational_impact": "324 GB of stolen data published on dark web",
    "remediation_disclosed": "FBI and CISA engaged; 12-month credit monitoring offered; notifications mailed August 26, 2024",
    "primary_source_url": "https://www.hipaajournal.com/young-consulting-ransomware-attack/",
    "secondary_source_urls": [
      "https://hipaatimes.com/blacksuit-targets-young-consulting-exposing-954000-individuals",
      "https://compliancejunction.com/ransomware-attack-on-young-consulting-impacts-954k-individuals/"
    ],
    "confidence_notes": "HHS OCR lists 954,177. BlackSuit attribution well-documented. HIPAA Journal and Paubox corroborate.",
    "sources_used": [
      "HIPAA Journal",
      "Paubox/HIPAA Times",
      "ComplianceJunction"
    ],
    "id": "INC-00643",
    "year": 2024,
    "lat": 33.749,
    "lng": -84.388,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Academic Urology & Urogynecology of Arizona",
    "organization_type": "Healthcare Provider / Urology Practice",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2025-05-01",
    "disclosure_date": "2025-08-01",
    "executive_summary": "INC ransomware group breached Academic Urology & Urogynecology of Arizona in May 2025; claimed responsibility on dark web in June 2025. 73,281 individuals notified of exposure of SSNs, financial information, and medical information. Organization disclosed breach in August 2025.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "INC",
    "attribution_status": "claimed",
    "individuals_affected_reported": 73281,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient and financial data exposed",
    "remediation_disclosed": "Breach disclosed on website; notifications mailed",
    "primary_source_url": "https://www.comparitech.com/news/arizona-urologist-warns-73000-people-of-data-breach-that-leaked-ssns-medical-and-financial-info/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; Comparitech confirmed 73,281 patients; INC ransomware claimed June 2025; organization disclosed August 2025",
    "sources_used": [
      "Comparitech"
    ],
    "id": "INC-00644",
    "year": 2025,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Alabama Ophthalmology Associates (AOA)",
    "organization_type": "Healthcare Provider / Eye Care",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Birmingham",
    "hq_county": "Jefferson",
    "discovery_date": "2025-01-30",
    "disclosure_date": "2025-04-10",
    "executive_summary": "Alabama Ophthalmology Associates suffered a targeted cyberattack between January 22 and January 30, 2025, attributed to the BianLian ransomware group. Unauthorized actors gained access to systems and extracted large amounts of sensitive data including patient health records, HR and vendor data. The company agreed to an $850,000 class action settlement.",
    "attack_type": "Ransomware (BianLian) / Data Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "BianLian",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not publicly disclosed (class action filed)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$850,000 class action settlement agreed",
    "operational_impact": "Patient health records, HR data, vendor data, and biometric data potentially compromised",
    "remediation_disclosed": "$850K settlement; credit monitoring offered; improved cybersecurity measures committed",
    "primary_source_url": "https://www.pittmandutton.com/firm-news/alabama-ophthalmology-associates-data-breach",
    "secondary_source_urls": [
      "https://www.classaction.org/news/850k-alabama-ophthalmology-associates-settlement-ends-class-action-lawsuit-over-january-2025-data-breach",
      "https://aoasettlement.com"
    ],
    "confidence_notes": "High confidence \u2014 multiple law firm reports, settlement website, SecurityWeek coverage.",
    "sources_used": [
      "Pittman Dutton Hellums Bradley & Mann",
      "ClassAction.org",
      "AOA Settlement Website",
      "SecurityWeek"
    ],
    "id": "INC-00645",
    "year": 2025,
    "lat": 33.5186,
    "lng": -86.8104,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Albany College of Pharmacy and Health Sciences",
    "organization_type": "Healthcare Education",
    "organization_type_bucket": "Pharmacy",
    "state": "NY",
    "hq_city": "Albany",
    "hq_county": "Albany",
    "discovery_date": "2024-09-14",
    "disclosure_date": "2025-06-16",
    "executive_summary": "Albany College of Pharmacy and Health Sciences discovered unauthorized activity in its computer systems on September 14, 2024. A cybercriminal stole personal information between August 31 and September 14, 2024. The breach ultimately affected 166,953 individuals. Data compromised included names, DOBs, SSNs, and other PII.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 166953,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "166K+ individuals' data stolen",
    "remediation_disclosed": "HHS OCR breach filed; affected individuals notified; law enforcement notified",
    "primary_source_url": "https://www.hipaajournal.com/albany-college-pharmacy-health-sciences-data-breach/",
    "secondary_source_urls": [
      "https://classlawdc.com/2025/06/17/albany-college-data-breach-investigation/"
    ],
    "confidence_notes": "OCR breach report confirmed 166,953; HIPAA Journal and class action investigation",
    "sources_used": [
      "HIPAA Journal",
      "Migliaccio & Rathod"
    ],
    "id": "INC-00646",
    "year": 2025,
    "lat": 42.6526,
    "lng": -73.7562,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Albany Medical College (Albany Med) - Change Healthcare",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Albany",
    "hq_county": "Albany",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2025-01-01",
    "executive_summary": "Albany Medical Center was among the NY health systems affected by the Change Healthcare ransomware attack in February 2024, which disrupted its pharmacy and billing operations. Additionally, Albany Medical College was breached by a ransomware attack in fall 2024. The Change Healthcare breach affected pharmacy claims processing system-wide.",
    "attack_type": "Supply chain ransomware (Change Healthcare); separate institutional ransomware 2024",
    "attack_category": "Ransomware",
    "threat_actor_name": "ALPHV/BlackCat (Change Healthcare); Unknown (Albany Med 2024)",
    "attribution_status": "reported",
    "individuals_affected_reported": "Not separately disclosed",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Pharmacy and billing disruptions from Change Healthcare; Albany Med College ransomware in fall 2024",
    "remediation_disclosed": "Systems restored; security improvements",
    "primary_source_url": "https://www.reddit.com/r/Albany/comments/1i8lzut/anyone_here_about_this_data_breach_from_albany/",
    "secondary_source_urls": [],
    "confidence_notes": "Reddit community report on Albany Med College ransomware fall 2024; Change Healthcare broadly confirmed",
    "sources_used": [
      "Reddit/Albany community",
      "General Change Healthcare reporting"
    ],
    "id": "INC-00647",
    "year": 2025,
    "lat": 42.6526,
    "lng": -73.7562,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "AltaMed Health Services Corporation",
    "organization_type": "Federally Qualified Health Center (FQHC)",
    "organization_type_bucket": "FQHC / Community health",
    "state": "CA",
    "hq_city": "Los Angeles, CA",
    "hq_county": "Los Angeles County",
    "discovery_date": "2024-08-05",
    "disclosure_date": "2025-06-13",
    "executive_summary": "On August 9, 2024, AltaMed became aware of suspicious activity on its computer systems. AltaMed quickly took steps to stop the activity, disconnect the systems to prevent further impact, and investigate the matter. Further, AltaMed launched a detailed investigation to determine the nature and scope of certain suspicious email related activity. The investigation determined that an unauthorized individual gained access to a certain email account between August 5 and August 9, 2024. AltaMed then undertook a comprehensive and time-intensive review of the potentially impacted data with the assistan",
    "attack_type": "Hacking / Security Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered']",
    "primary_source_url": "https://oag.ca.gov/system/files/AltaMed%20Health%20Services%20Corporation%20-%20Notice%20of%20Data%20Event%20%20-%20CA_0.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00648",
    "year": 2025,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Anchorage Neighborhood Health Center (ANHC)",
    "organization_type": "Healthcare Provider (Federally Qualified Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Anchorage",
    "hq_county": "Anchorage Municipality",
    "discovery_date": "2025-08-26",
    "disclosure_date": "2025-09-05",
    "executive_summary": "Anchorage Neighborhood Health Center suffered a criminal cyberattack in late August 2025 that disrupted appointment scheduling and phone systems for more than a week. An anonymous hacking group claimed to have stolen 10,000 patient records initially, later increasing the claim to 60,000 and then leaking data including names, Social Security numbers, driver's license numbers, dates of birth, medical treatment information, and health insurance information. The FBI's Anchorage Field Office confirmed it was aware of the incident. Final victim count confirmed at 70,555 individuals per Oregon AG notification.",
    "attack_type": "Cyberattack / Data theft and extortion",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Anonymous hacking group (23 TB claimed stolen)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 70555,
    "residents_affected_in_state": "AK-based community health center patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Appointment scheduling and phone systems disrupted for 8+ days",
    "remediation_disclosed": "Network security reviewed; forensic investigation with third-party experts; law enforcement notified; 12-month Experian credit monitoring offered",
    "primary_source_url": "https://www.comparitech.com/news/anchorage-clinic-notifies-70000-patients-of-data-breach-that-leaked-ssns-medical-info/",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/anchorage-neighborhood-health-center-september-2025",
      "https://databreaches.net/2025/09/16/fbi-aware-of-anchorage-health-clinic-data-breach-as-hackers-claim-60k-patients-impacted/"
    ],
    "confidence_notes": "Oregon AG confirmed 70,555 individuals notified; FBI confirmed awareness; hackers claimed 23 TB stolen",
    "sources_used": [
      "Comparitech",
      "ClassAction.org",
      "DataBreaches.net"
    ],
    "id": "INC-00649",
    "year": 2025,
    "lat": 61.2181,
    "lng": -149.9003,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Anchorage Neighborhood Health Center (ANHC-2)",
    "organization_type": "Healthcare Provider (Federally Qualified Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AK",
    "hq_city": "Anchorage",
    "hq_county": "Anchorage Municipality",
    "discovery_date": "2025-10-10",
    "disclosure_date": "2025-11-19",
    "executive_summary": "Anchorage Neighborhood Health Center (ANHC) suffered a significant data breach on August 24\u201325, 2025, discovered October 10, 2025. A hacker group claimed to have stolen patient records and initially published 10,000 records online in early September 2025. By September 15, hackers claimed to have leaked an additional 50,000 patient records, bringing the total to at least 60,000 affected individuals. Compromised data included names, addresses, Social Security numbers, driver's license numbers, dates of birth, email addresses, phone numbers, and health insurance details. ANHC took affected systems offline, notified federal law enforcement, and engaged third-party cybersecurity experts. Notifications to affected individuals were issued November 19, 2025 per Maine AG filing (disclosure to Maine AG with 54 Maine residents).",
    "attack_type": "Unauthorized network access / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown hacker group (not publicly identified)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 60000,
    "residents_affected_in_state": "Majority Alaska-based (not separately reported)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Affected systems taken offline; 60,000 patient records allegedly leaked publicly; class action investigation opened",
    "remediation_disclosed": "Systems taken offline; FBI and law enforcement notified; third-party forensic investigation; credit monitoring and identity protection offered",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/anchorage-neighborhood-health-center-september-2025",
    "secondary_source_urls": [
      "https://dataprivacyjustice.com/anchorage-neighborhood-health-center-data-breach-investigation/",
      "https://thelyonfirm.com/blog/anchorage-neighborhood-health-center-data-breach/",
      "https://eksm.com/active-case/anchorage-neighborhood-health-center-announces-data-breach/",
      "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/55524267-0a55-4829-b637-93002b4240d4.html"
    ],
    "confidence_notes": "Maine AG filing confirms breach dates Aug 24-25, 2025 and discovery Oct 10, 2025; 54 Maine residents affected per filing; ~60,000 total estimated from news reports; ANHC confirmed investigation. Note: This ANHC differs from AK-004 (ANHC 2022 breach \u2014 that was Anchorage Neighborhood Health Center's earlier breach). Different incident.",
    "sources_used": [
      "ClassAction.org",
      "Data Privacy Justice",
      "The Lyon Firm",
      "EKSM",
      "Maine AG Breach Notifications"
    ],
    "id": "INC-00650",
    "year": 2025,
    "lat": 61.2181,
    "lng": -149.9003,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Arch Health Partners, Inc. d/b/a Palomar Health Medical Group",
    "organization_type": "Medical Group (Palomar Health Affiliated)",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "Escondido, CA (San Diego County)",
    "hq_county": "San Diego County",
    "discovery_date": "2024-05-05",
    "disclosure_date": "2025-10-15",
    "executive_summary": "PHMG immediatelylaunched an investigation to determine thenature and scope of theactivity. The investigation determined that an unauthorized actor gained access to certain files within PHMG\u2019s network fromApril 23, 2024, to May 5, 2024, and may have copied those files. Following the investigation, PHMG undertook a detailed review of all the files potentiallyimpacted todetermine",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Largest public healthcare district in CA; multiple hospitals affected; operations disrupted",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/Palamor%20Health%20Medical%20Group%20-%20CA%20-%20Exhibit%20A-B_0.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/palomar-health-ransomware-attack/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00651",
    "year": 2025,
    "lat": 33.1192,
    "lng": -117.0864,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Arizona Arthritis and Rheumatology Associates",
    "organization_type": "Healthcare Provider (Rheumatology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2025-01-01",
    "disclosure_date": "2025-02-01",
    "executive_summary": "Arizona Arthritis and Rheumatology Associates reported a phishing incident that compromised patient PHI. The HIPAA Journal referenced this as a 2025 phishing incident. Limited additional details publicly available.",
    "attack_type": "Hacking/IT Incident \u2013 Phishing",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence; HIPAA Journal reference only; limited detail",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00652",
    "year": 2025,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Arizona Health Care Cost Containment System (AHCCCS)",
    "organization_type": "State Health Agency / Medicaid",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2025-09-01",
    "disclosure_date": "2025-09-25",
    "executive_summary": "Arizona AHCCCS (Arizona's Medicaid program) reported a data breach affecting 3,177 members in September 2025. The breach revealed limited personal information of Medicaid members. Corrective actions were underway as of the announcement.",
    "attack_type": "Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3177,
    "residents_affected_in_state": 3177,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Limited personal information of Medicaid members exposed",
    "remediation_disclosed": "Corrective actions underway; members guided on protective steps",
    "primary_source_url": "https://www.facebook.com/kvoa4/posts/a-data-breach-at-ahcccs-has-impacted-3177-members-in-arizona-revealing-limited-p/1225829826238947/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence; KVOA4 Tucson news confirmed AHCCCS breach affecting 3,177 members September 2025; limited detail on breach mechanism",
    "sources_used": [
      "KVOA4 News Tucson"
    ],
    "id": "INC-00653",
    "year": 2025,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Ascension Health \u2014 2024-2025 Third-Party (Cleo/Cl0p) Breach",
    "organization_type": "Nonprofit Catholic Health System",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MO",
    "hq_city": "St. Louis",
    "hq_county": "St. Louis",
    "discovery_date": "2025-01-21",
    "disclosure_date": "2025-04-28",
    "executive_summary": "Ascension Health inadvertently disclosed patient data to a former business partner during July 17 \u2013 August 6, 2024. That former business partner subsequently experienced a cyberattack by the Cl0p ransomware gang targeting Cleo software (December 2024). Investigation confirmed on January 21, 2025 that hackers had accessed the data shared with the former business partner. Approximately 437,000 patients across five states \u2014 Alabama, Michigan, Indiana, Tennessee, and Texas \u2014 were affected. Compromised data included full names, addresses, phone numbers, DOBs, race/gender, SSNs, and detailed clinical information (admission/discharge dates, diagnoses, billing codes, insurance company names).",
    "attack_type": "Third-Party Vendor Breach (Cleo software exploitation by Cl0p)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p ransomware (Cleo campaign)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 437000,
    "residents_affected_in_state": "Indiana and Michigan among the five affected states; specific counts not separated by state",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Ascension's own systems not directly compromised in this specific incident; patient data shared with former business partner was stolen",
    "remediation_disclosed": "Yes \u2014 new measures to prevent similar data sharing incidents; 2 years credit monitoring offered; notifications April 28, 2025",
    "primary_source_url": "https://www.hipaajournal.com/ascension-data-breach-former-business-partner/",
    "secondary_source_urls": [
      "https://cohenandmalad.com/alerts/ascension-data-breach"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, CohenMalad law firm investigation announcement.",
    "sources_used": [
      "HIPAA Journal",
      "CohenMalad LLP"
    ],
    "id": "INC-00654",
    "year": 2025,
    "lat": 38.627,
    "lng": -90.1994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Ascension St. Vincent / Ascension Health \u2014 2025 Former Business Partner Breach (Indiana component)",
    "organization_type": "Nonprofit Catholic Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2025-01-21",
    "disclosure_date": "2025-04-28",
    "executive_summary": "Ascension St. Vincent (Indiana component) was among the five-state systems affected by the Ascension inadvertent disclosure/Cleo breach of December 2024 (see MW-049). A hospital spokesperson confirmed that patient information was 'likely stolen' from a former business partner, affecting Indiana patients. Notification to Indiana patients indicated compromised data included names, addresses, phone numbers, SSNs, and medical records.",
    "attack_type": "Third-Party Vendor Breach (Cleo/Cl0p)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Cl0p ransomware",
    "attribution_status": "unknown",
    "individuals_affected_reported": 437000,
    "residents_affected_in_state": "Indiana residents",
    "financial_impact": "Not separately disclosed for Indiana",
    "operational_impact": "Patient data stolen via former business partner; 2 years credit monitoring offered",
    "remediation_disclosed": "Yes \u2014 same as MW-049",
    "primary_source_url": "https://www.youtube.com/watch?v=nEftgDcQ1d0",
    "secondary_source_urls": [
      "https://cohenandmalad.com/alerts/ascension-data-breach"
    ],
    "confidence_notes": "High confidence. Local TV report (WRTV YouTube), CohenMalad law firm announcement.",
    "sources_used": [
      "WRTV/YouTube",
      "CohenMalad LLP"
    ],
    "id": "INC-00655",
    "year": 2025,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Baylor Scott & White Texas Spine & Joint Hospital",
    "organization_type": "Healthcare Provider (Specialty Hospital \u2013 Orthopedics)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Tyler",
    "hq_county": "Smith",
    "discovery_date": "2025-01-15",
    "disclosure_date": "2025-03-14",
    "executive_summary": "Baylor Scott & White Texas Spine & Joint Hospital discovered on January 15, 2025 that an unauthorized party had gained access to a company email account hosted on Microsoft 365 for approximately four days (January 10-14, 2025). The compromised account contained sensitive patient information including names, dates of birth, medical information, and billing and claims information. Breach notification letters were sent to affected individuals on March 14, 2025.",
    "attack_type": "Hacking/IT Incident \u2013 Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal; isolated to single email account",
    "remediation_disclosed": "Account contained; investigation launched; notifications sent March 14; additional security measures implemented",
    "primary_source_url": "https://www.jdsupra.com/legalnews/baylor-scott-white-texas-spine-joint-6021202/",
    "secondary_source_urls": [
      "https://databreachclassaction.io/blog/baylor-scott-white-texas-spine-joint-hospital-data-breach-class-action-investigation"
    ],
    "confidence_notes": "High confidence; JD Supra and class action investigation both documented; Texas AG notification",
    "sources_used": [
      "JD Supra, Console & Associates"
    ],
    "id": "INC-00656",
    "year": 2025,
    "lat": 32.3512601,
    "lng": -95.3010624,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Behavioral Health Resources (BHR)",
    "organization_type": "Healthcare Provider (Behavioral & Mental Health Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Olympia",
    "hq_county": "Thurston",
    "discovery_date": "2024-11-20",
    "disclosure_date": "2025-01-17",
    "executive_summary": "Behavioral Health Resources, a Washington state behavioral and mental health services provider, suffered unauthorized access to its computer systems on or before November 20, 2024. A forensic investigation confirmed that an unauthorized actor gained access to systems containing sensitive patient information and likely exfiltrated data. The breach affected 50,083 current and former patients. BHR notified HHS OCR on January 17, 2025 and sent individual notifications in April 2025. A class-action lawsuit was filed and settled for $1.1 million in December 2025.",
    "attack_type": "Unauthorized network access / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 50083,
    "residents_affected_in_state": "Not separately reported (majority WA-based)",
    "financial_impact": "$1.1 million class-action settlement (December 2025)",
    "operational_impact": "PHI and PII of 50,083 patients likely exfiltrated; patients at increased risk for identity theft",
    "remediation_disclosed": "Forensic investigation; HHS OCR notification; individual notifications April 2025; $1.1M settlement",
    "primary_source_url": "https://databreaches.net/2025/04/20/behavioral-health-resources-of-washington-state-updates-its-data-breach-disclosure/",
    "secondary_source_urls": [
      "https://www.netsec.news/behavioral-health-resources-data-breach-lawsuit/",
      "https://www.claimdepot.com/data-breach/behavioral-health-resources",
      "https://www.justice4you.com/behavioral-health-resources-data-breach/"
    ],
    "confidence_notes": "HHS OCR breach report filed Jan 17, 2025 (50,083 individuals confirmed); DataBreaches.net reporting; $1.1M settlement confirmed",
    "sources_used": [
      "DataBreaches.net",
      "NetSec News",
      "Claim Depot",
      "Arnold Law Firm",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00657",
    "year": 2025,
    "lat": 47.0379,
    "lng": -122.9007,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Blue Cross Blue Shield of Montana (Conduent breach)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MT",
    "hq_city": "Helena",
    "hq_county": "Lewis and Clark",
    "discovery_date": "2025-01-13",
    "disclosure_date": "2025-09-01",
    "executive_summary": "BCBS Montana confirmed it was affected by the Conduent Business Services ransomware breach (SafePay, October 2024\u2013January 2025). BCBS Montana notified 462,000 individuals whose data was processed through Conduent's systems.",
    "attack_type": "Ransomware (via Business Associate)",
    "attack_category": "Ransomware",
    "threat_actor_name": "SafePay",
    "attribution_status": "claimed",
    "individuals_affected_reported": 462000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member data exposed via third-party data processor",
    "remediation_disclosed": "Notification letters mailed; Conduent network secured January 2025",
    "primary_source_url": "https://www.hipaajournal.com/conduent-business-solutions-data-breach/",
    "secondary_source_urls": [
      "https://freedomforallamericans.org/conduent-data-breach/"
    ],
    "confidence_notes": "High confidence; HIPAA Journal confirmed BCBS Montana 462,000 notifications; Montana Conduent investigation referenced",
    "sources_used": [
      "HIPAA Journal",
      "Freedom For All Americans"
    ],
    "id": "INC-00658",
    "year": 2025,
    "lat": 46.5891,
    "lng": -112.0391,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Blue Cross and Blue Shield of New Mexico (BCBSNM)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "NM",
    "hq_city": "Albuquerque",
    "hq_county": "Bernalillo",
    "discovery_date": "2025-02-01",
    "disclosure_date": "2025-02-01",
    "executive_summary": "Blue Cross and Blue Shield of New Mexico (BCBSNM) identified suspicious activity in its Blue Access for Members (BAM) portal in February 2025. Investigation revealed that between November 8, 2024, and March 5, 2025, unauthorized actors may have accessed personal data of BCBSNM members through the member portal, including names, addresses, dates of birth, phone numbers, email addresses, policy numbers, billing information, and details of health services received. BCBSNM stated it had no reason to believe the information was misused, and offered affected members one year of complimentary identity-protection services through Experian IdentityWorks. This is a separate incident from the Conduent/BCBS breach also reported in 2025.",
    "attack_type": "Hacking/IT Incident \u2013 Unauthorized Portal Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member portal access compromised for approximately four months",
    "remediation_disclosed": "Suspicious activity investigated; member portal secured; Experian IdentityWorks monitoring offered to affected members",
    "primary_source_url": "https://ardham.com/lessons-from-the-blue-cross-and-blue-shield-of-new-mexico-breach-for-nm-businesses",
    "secondary_source_urls": [],
    "confidence_notes": "Confirmed via secondary analysis source; specific count of affected members not publicly disclosed; incident distinct from Conduent breach affecting BCBS entities",
    "sources_used": [
      "Ardham Technologies analysis article"
    ],
    "id": "INC-00659",
    "year": 2025,
    "lat": 35.0844,
    "lng": -106.6504,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Blue Shield of California",
    "organization_type": "Nonprofit health insurance plan (nearly 6 million members)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Oakland",
    "hq_county": "Alameda County",
    "discovery_date": "2025-02-11",
    "disclosure_date": "2025-04-09",
    "executive_summary": "On February 11, 2025, Blue Shield of California discovered that a Google Analytics misconfiguration had been sharing member health data with Google Ads from April 2021 through January 2024. Exposed data potentially included health plan names and group numbers, patient names, gender, zip code, family size, and 'Find a Doctor' search terms \u2014 sufficient to reveal members' health conditions or needs. SSNs and financial data were not exposed. Up to 4.7 million members were potentially affected, making it the second-largest healthcare breach reported in 2025. No bad actor was involved; the exposure was a configuration error.",
    "attack_type": "Misconfiguration / tracking pixel / third-party data disclosure (not a network intrusion)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "NOT_APPLICABLE",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4700000,
    "residents_affected_in_state": "Predominantly CA members",
    "financial_impact": "{'notes': 'No financial penalties or settlements publicly announced as of research date. Potential regulatory investigation expected.'}",
    "operational_impact": "No patient care disruption. Data shared via analytics configuration; Google may have used data for targeted ad campaigns.",
    "remediation_disclosed": "Connection between Google Analytics and Google Ads severed January 2024. Full website review conducted to identify other potential exposures. HHS OCR notified April 9, 2025.",
    "primary_source_url": "https://www.hipaajournal.com/blue-shield-of-california-google-ads-data-breach/",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/blue-shield-california-data-breach-4-7-million-google/746280/",
      "https://www.mobihealthnews.com/news/blue-shield-california-shared-private-health-data-47m-members-google-years",
      "https://www.malwarebytes.com/blog/news/2025/04/4-7-million-customers-data-accidentally-leaked-to-google-by-blue-shield-of-california",
      "https://www.hipaajournal.com/largest-healthcare-data-breaches-of-2025/",
      "https://www.techtarget.com/healthtechsecurity/feature/10-largest-healthcare-data-breaches-reported-to-OCR-in-2025",
      "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf"
    ],
    "confidence_notes": "Issue existed April 2021 \u2013 January 2024 (~3 years); discovered February 11, 2025 \u2014 over one year after the data exposure period ended. Similar pattern to Kaiser Permanente pixel disclosure. No ransom, hacker, or intentional data theft. | Ranked #22 largest healthcare breach of all time. No evidence data was misused; limited potential for harm due to nature of tracking data. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HHS OCR Breach Portal",
      "Organization notice / News / SEC"
    ],
    "id": "INC-00660",
    "year": 2025,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Boudreaux's Specialty Compounding Pharmacy (via Nationwide Recovery / Erlanger shared BA)",
    "organization_type": "Healthcare Provider (Specialty Pharmacy)",
    "organization_type_bucket": "Pharmacy",
    "state": "LA",
    "hq_city": "Shreveport",
    "hq_county": "Caddo Parish",
    "discovery_date": "2025-01-25",
    "disclosure_date": "2025-04-18",
    "executive_summary": "Boudreaux's Specialty Compounding Pharmacy in Shreveport, LA experienced a cyberattack on January 25, 2025 causing network disruption. The incident was reported by HIPAA Journal April 2025. The attack affected the pharmacy's operations and potentially exposed patient data. Both Erlanger Health and Vitruvian Health were referenced as affected by the same BA breach context.",
    "attack_type": "Network Disruption / Cyberattack",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network disruption; pharmacy operations affected",
    "remediation_disclosed": "Investigation launched; notifications pending",
    "primary_source_url": "https://www.hipaajournal.com/vitruvian-health-erlanger-health-business-associate-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal April 2025 report mentions Boudreaux's as the victim. Limited details available.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00661",
    "year": 2025,
    "lat": 32.5252,
    "lng": -93.7502,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Broad River Physicians Group (via ApolloMD)",
    "organization_type": "Healthcare Provider / Emergency Medicine",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Columbia",
    "hq_county": "Richland",
    "discovery_date": "2025-05-22",
    "disclosure_date": "2025-09-18",
    "executive_summary": "Broad River Physicians Group, LLC, specializing in emergency medicine in South Carolina, reported a data breach originating from its business associate ApolloMD Business Services. An unauthorized actor accessed ApolloMD's IT systems between May 22-23, 2025. The breach exposed patient names, dates of birth, SSNs, addresses, diagnosis information, provider names, treatment information, and health insurance data. SC Consumer Affairs lists 3,171 SC residents affected.",
    "attack_type": "Business Associate Breach (ApolloMD) / Network Intrusion",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly disclosed (thousands estimated)",
    "residents_affected_in_state": 3171,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI and PII accessed through business associate; patients notified via mail September 18, 2025",
    "remediation_disclosed": "File review completed September 11, 2025; patient notification letters sent; security improvements implemented",
    "primary_source_url": "https://www.claimdepot.com/data-breach/broad-river-physicians-group-2025",
    "secondary_source_urls": [
      "https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Broad%20River%20-%20South%20Carolina%20-%20Consumer%20Notice.pdf",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach notice PDF, Claim Depot reporting, SC Consumer Affairs listing (3,171 SC residents).",
    "sources_used": [
      "Claim Depot",
      "SC Consumer Affairs Breach Portal",
      "SC Consumer Affairs Official Notice PDF"
    ],
    "id": "INC-00662",
    "year": 2025,
    "lat": 34.0007,
    "lng": -81.0348,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CHRISTUS Health (Oracle Health / Cerner breach)",
    "organization_type": "Healthcare Provider (Catholic Health System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Irving",
    "hq_county": "Dallas",
    "discovery_date": "2025-10-01",
    "disclosure_date": "2025-12-09",
    "executive_summary": "CHRISTUS Health was among multiple healthcare providers notified in October 2025 by Oracle Health that an unauthorized third party gained access to legacy Cerner systems as early as January 22, 2025. Oracle provided CHRISTUS with a patient list on December 9, 2025. Potentially compromised data included names, Social Security numbers, and laboratory records (laboratory orders, blood bank records, medical record numbers, doctors, diagnoses, medicines, test results) from prior to February 2025. Current IT systems were not impacted.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate (Oracle Health / legacy Cerner EHR)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly disclosed (pending Oracle Health's notification process)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No impact on current CHRISTUS IT systems or clinical operations",
    "remediation_disclosed": "Oracle Health notified healthcare clients; patient list provided December 9, 2025; notifications ongoing",
    "primary_source_url": "https://www.christushealth.org/privacy-practices/oracle-health-data-incident",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; official CHRISTUS Health website notice cited; Oracle Health breach affecting multiple providers",
    "sources_used": [
      "CHRISTUS Health official website"
    ],
    "id": "INC-00663",
    "year": 2025,
    "lat": 32.814,
    "lng": -96.9489,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Capitol Region Education Council (CT)",
    "organization_type": "Healthcare Provider (School Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "Hartford",
    "hq_county": "Hartford",
    "discovery_date": "2025-04-01",
    "disclosure_date": "2025-06-09",
    "executive_summary": "Capitol Region Education Council in Connecticut reported a data security incident to the Maine AG in June 2025 involving unauthorized access to health-related information of students and staff. School-based health data including records of minors may have been compromised.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "School health data of students and staff potentially compromised",
    "remediation_disclosed": "Maine AG notified; affected individuals notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing June 9, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00664",
    "year": 2025,
    "lat": 41.7658,
    "lng": -72.6734,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CareOregon / Health Share of Oregon",
    "organization_type": "Health Plan (Medicaid Coordinated Care)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2025-10-27",
    "disclosure_date": "2025-12-22",
    "executive_summary": "CareOregon and Health Share of Oregon discovered on October 27, 2025, that one or more unauthorized individuals had accessed member personal information without permission. Potentially exposed data included member names, dates of birth, health plan information, Medicaid ID numbers, Medicare ID numbers, and primary care provider information. Social Security numbers and financial information were not accessed. CareOregon separately had a mismailing breach reported to OCR in May 2025.",
    "attack_type": "Unauthorized access / Hacking",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "OR-based Medicaid members",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member PHI and insurance data potentially exposed",
    "remediation_disclosed": "Notifications sent; members offered guidance",
    "primary_source_url": "https://www.healthshareoregon.org/databreach",
    "secondary_source_urls": [
      "https://www.paubox.com/blog/careoregon-notifies-members-after-personal-health-information-breach"
    ],
    "confidence_notes": "Official Health Share of Oregon breach page confirmed; discovered October 2025",
    "sources_used": [
      "Health Share of Oregon official breach notice",
      "Paubox"
    ],
    "id": "INC-00665",
    "year": 2025,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "CareOregon / Health Share of Oregon (Oct 2025 unauthorized access)",
    "organization_type": "Health Plan (Medicaid Coordinated Care Organization)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2025-10-27",
    "disclosure_date": "2025-12-22",
    "executive_summary": "On October 27, 2025, CareOregon and Health Share of Oregon discovered that one or more unauthorized individuals had accessed members' protected health information without permission. A total of 5,473 members were affected, including 4,415 served by CareOregon. The breach was reported to law enforcement, indicating criminal involvement. Accessed data included member names, dates of birth, health plan information, Medicaid ID numbers, Medicare ID numbers, and primary care provider office information. No Social Security numbers or financial data were accessed. The motivation appeared to be fraudulent insurance claim creation.",
    "attack_type": "Unauthorized system access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown (criminal involvement confirmed per law enforcement referral)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 5473,
    "residents_affected_in_state": 5473,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Member PHI accessed; potential use for fraudulent insurance claims; system access controls revised",
    "remediation_disclosed": "Issue investigated and fixed; access controls changed; staff retrained; law enforcement notified; individual notifications December 26, 2025",
    "primary_source_url": "https://www.careoregon.org/members/member-updates/2025/12/22/members-to-be-notified-of-recent-data-breach",
    "secondary_source_urls": [
      "https://www.paubox.com/blog/careoregon-notifies-members-after-personal-health-information-breach",
      "https://databreaches.net/2025/12/28/health-share-of-oregon-and-careoregon-notify-members-of-data-breach/",
      "https://www.thelundreport.org/content/oregon-medicaid-insurers-data-breach-could-lead-insurance-fraud-0"
    ],
    "confidence_notes": "CareOregon official member notice published; confirmed 5,473 members affected per Lund Report; law enforcement referral confirmed; separate from existing OR-008 (2020 HealthShare breach)",
    "sources_used": [
      "CareOregon official notice",
      "Paubox",
      "DataBreaches.net",
      "The Lund Report"
    ],
    "id": "INC-00666",
    "year": 2025,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Central District Health Department of Nebraska",
    "organization_type": "Public Health Department",
    "organization_type_bucket": "Other healthcare entity",
    "state": "NE",
    "hq_city": "Grand Island",
    "hq_county": "Hall",
    "discovery_date": "2025-02-01",
    "disclosure_date": "2025-04-03",
    "executive_summary": "The Central District Health Department (CDHD) of Nebraska experienced a network security incident in which an unauthorized party gained access to their network environment on February 1, 2025. The investigation was ongoing as of April 2025, seeking to determine whether patient information was accessed and acquired. CDHD serves central Nebraska with public health services. Personal and/or protected health information may have been exposed.",
    "attack_type": "Hacking / Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not yet determined (investigation ongoing)",
    "residents_affected_in_state": "Nebraska (central region) residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network access compromised; public health operations potentially disrupted",
    "remediation_disclosed": "Partial \u2014 investigation launched; cautionary notifications being issued",
    "primary_source_url": "https://www.cdhd.ne.gov/vnews/display.v/ART/67eee1850f27a",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for incident occurrence. CDHD official government website notice.",
    "sources_used": [
      "Central District Health Department Nebraska (official)"
    ],
    "id": "INC-00667",
    "year": 2025,
    "lat": 40.924271,
    "lng": -98.338685,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Central Jersey Medical Center",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Perth Amboy",
    "hq_county": "Middlesex",
    "discovery_date": "2025-08-25",
    "disclosure_date": "2025-11-05",
    "executive_summary": "Central Jersey Medical Center, a Federally Qualified Health Center with locations in Perth Amboy, Newark, and Carteret, New Jersey, suffered a ransomware attack on August 25, 2025 affecting its dental server network. The Sinobi ransomware group claimed responsibility and reported theft of 930 GB of data. Approximately 88,000 individuals were affected, with compromised data including names, addresses, SSNs, dental records, health insurance information, and treatment histories. The electronic medical record system was not affected.",
    "attack_type": "Ransomware (Sinobi)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Sinobi",
    "attribution_status": "claimed",
    "individuals_affected_reported": 88000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Dental server network encrypted; 930 GB data claimed stolen; EMR system unaffected",
    "remediation_disclosed": "HHS OCR notified; patients notified; investigation ongoing",
    "primary_source_url": "https://www.hipaajournal.com/central-jersey-medical-center-ransomware/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal confirms 88,000 HHS OCR report; Sinobi claim on leak site; August 2025",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00668",
    "year": 2025,
    "lat": 40.5133218,
    "lng": -74.2724241,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Central Texas Pediatric Orthopedics",
    "organization_type": "Healthcare Provider (Orthopedic Specialty Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Austin",
    "hq_county": "Travis",
    "discovery_date": "2025-01-25",
    "disclosure_date": "2025-03-06",
    "executive_summary": "Central Texas Pediatric Orthopedics discovered on January 25, 2025 that an unauthorized third party accessed its network between January 23 and January 26, 2025. The Qilin ransomware group claimed responsibility and data exfiltration was confirmed. 134,903 individuals were ultimately notified (90,000 Texas residents per Texas AG + additional nationwide). Compromised data included names, dates of birth, government-issued IDs (passports, state IDs), medical information (X-rays), and health insurance information.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware (Qilin)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Qilin",
    "attribution_status": "claimed",
    "individuals_affected_reported": 134903,
    "residents_affected_in_state": 90000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Third-party forensic experts engaged; OCR and Texas AG notified; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/central-texas-pediatric-orthopedics-hacking-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; HIPAA Journal documented; Texas AG and OCR reports confirmed",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00669",
    "year": 2025,
    "lat": 30.2672,
    "lng": -97.7431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Centric Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "California (exact city not confirmed)",
    "hq_county": "Unknown",
    "discovery_date": "Unknown",
    "disclosure_date": "2025-12-10",
    "executive_summary": "Hacking/IT incident at Centric Health affecting both EMR and network server. Business associate involved.",
    "attack_type": "Hacking/IT Incident \u2014 Network server and EMR compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 6855,
    "residents_affected_in_state": 6855,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal (Dec 2025).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00670",
    "year": 2025,
    "lat": 37.546579755988134,
    "lng": -120.02899475479207,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Charleston Area Medical Center (CAMC) \u2014 2024",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WV",
    "hq_city": "Charleston",
    "hq_county": "Kanawha",
    "discovery_date": "2024-10-03",
    "disclosure_date": "2025-02-14",
    "executive_summary": "Charleston Area Medical Center suffered a second phishing attack on October 2-3, 2024, compromising a small number of employee email accounts and granting unauthorized access to patient PHI for approximately 24 hours. CAMC notified ~67,413 individuals in February 2025. CAMC agreed to a $1,000,000 class action settlement including four years of free credit monitoring for all class members.",
    "attack_type": "Phishing / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 67413,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$1,000,000 class action settlement",
    "operational_impact": "Employee email accounts compromised; patient PHI (names, DOBs, SSNs, driver's licenses, medical information, health insurance) potentially exposed for ~24 hours",
    "remediation_disclosed": "$1M settlement; 4 years free credit monitoring and identity theft protection; improved data security measures committed for 4 years",
    "primary_source_url": "https://hipaatimes.com/charleston-area-medical-center-phishing-attack-exposes-patient-data",
    "secondary_source_urls": [
      "https://www.classaction.org/news/1m-charleston-area-medical-center-settlement-ends-class-action-over-october-2024-data-breach",
      "https://www.claimdepot.com/settlements/camc-data-breach-settlement"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Times, ClassAction.org settlement reporting, Claim Depot, court filings.",
    "sources_used": [
      "HIPAA Times (Paubox)",
      "ClassAction.org",
      "Claim Depot",
      "Court filings"
    ],
    "id": "INC-00671",
    "year": 2025,
    "lat": 38.3498,
    "lng": -81.6326,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "ChristianaCare / Oracle Health (Cerner)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "DE",
    "hq_city": "Wilmington",
    "hq_county": "New Castle",
    "discovery_date": "2025-01-01",
    "disclosure_date": "2025-11-01",
    "executive_summary": "ChristianaCare, Delaware's largest health system, disclosed a data breach in late November 2025 resulting from a cyberattack on its third-party vendor Oracle Health (formerly Cerner). Oracle notified ChristianaCare in April 2025 that unauthorized parties had gained access to legacy systems. The breach involved SSNs and medical records. ChristianaCare faced a class action lawsuit filed December 2025.",
    "attack_type": "Supply chain / third-party vendor breach (Oracle Health/Cerner)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient SSNs and medical records compromised via Oracle legacy system breach",
    "remediation_disclosed": "Patients notified November 2025; class action filed December 2025; Oracle Health under investigation",
    "primary_source_url": "https://spotlightdelaware.org/2026/01/23/christianacare-faces-class-action-lawsuit-after-patient-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Spotlight Delaware reporting; class action filed; Oracle Health broader breach affected multiple NE health systems",
    "sources_used": [
      "Spotlight Delaware"
    ],
    "id": "INC-00672",
    "year": 2025,
    "lat": 39.7391,
    "lng": -75.5398,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "City of St. Joseph Health Department (Missouri)",
    "organization_type": "Municipal Public Health Agency",
    "organization_type_bucket": "Other healthcare entity",
    "state": "MO",
    "hq_city": "St. Joseph",
    "hq_county": "Buchanan",
    "discovery_date": "2025-09-01",
    "disclosure_date": "2025-09-15",
    "executive_summary": "The City of St. Joseph, Missouri Health Department reported a hacking/IT incident to HHS OCR in September 2025, affecting 11,538 individuals. The incident involved a network server hacking event. The specific nature, attack type, and operational impact have not been fully publicly disclosed beyond the HHS OCR breach portal listing. This is one of two Midwest public health agency entries (alongside the Illinois IDHS breach) in this dataset.",
    "attack_type": "Network Server Hacking",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11538,
    "residents_affected_in_state": "Missouri residents \u2014 primarily Buchanan County",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not fully disclosed",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified September 2025",
    "primary_source_url": "https://www.hipaajournal.com/september-2025-healthcare-data-breach-report/",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. HIPAA Journal September 2025 report cites HHS OCR data. Limited additional details available.",
    "sources_used": [
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00673",
    "year": 2025,
    "lat": 39.7686055,
    "lng": -94.8466322,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Columbia Medical Practice (Qilin ransomware)",
    "organization_type": "Healthcare Provider (Multispecialty Medical Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Vancouver",
    "hq_county": "Clark",
    "discovery_date": "2025-11-05",
    "disclosure_date": "2025-11-24",
    "executive_summary": "Columbia Medical Practice, a multispecialty healthcare practice, suffered a ransomware attack on November 5, 2025. The Qilin ransomware group installed ransomware, locked files, and copied data before systems were recovered. The attack was posted on the dark web on November 24, 2025. Compromised information included names, addresses, Social Security numbers, driver's licenses, passport numbers, diagnoses, prescriptions, medical history, financial account numbers, and health insurance data for at least 3,000 individuals. Reported to HHS December 5, 2025.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Qilin ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 3000,
    "residents_affected_in_state": "WA-based patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Files locked; data exfiltrated; ransomware deployed",
    "remediation_disclosed": "Systems recovered; toll-free assistance line 1-833-974-3375 established; notification letters mailed",
    "primary_source_url": "https://www.claimdepot.com/data-breach/columbia-medical-practice-2026",
    "secondary_source_urls": [
      "https://www.teiss.co.uk/news/columbia-medical-practice-confirms-november-ransomware-attack-exposed-patient-data-16998"
    ],
    "confidence_notes": "HHS OCR notification December 5, 2025; Qilin claimed responsibility via dark web posting",
    "sources_used": [
      "Claim Depot",
      "TEISS"
    ],
    "id": "INC-00674",
    "year": 2025,
    "lat": 45.6387,
    "lng": -122.6615,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Community Health Network (Indiana) \u2014 2025 Email Breach",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2025-02-26",
    "disclosure_date": "2025-07-07",
    "executive_summary": "Community Health Network discovered on February 25\u201326, 2025 that an unknown actor accessed an employee email account between those dates. The investigation concluded July 15, 2025, confirming that accessed information included patient names, medical information, and health insurance information for approximately 13,939 individuals.",
    "attack_type": "Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13939,
    "residents_affected_in_state": "Indiana residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal \u2014 email account only; investigation completed",
    "remediation_disclosed": "Yes \u2014 account secured; investigation completed; patient notifications mailed September 2025",
    "primary_source_url": "https://www.paubox.com/blog/community-health-network-of-indiana-announces-data-breach-linked-to-email",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Paubox/HIPAA Times reporting, CHN website notice.",
    "sources_used": [
      "Paubox/HIPAA Times"
    ],
    "id": "INC-00675",
    "year": 2025,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Community Health Network (via employee email 2025)",
    "organization_type": "Healthcare Provider / Hospital Network",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2025-02-25",
    "disclosure_date": "2025-09-12",
    "executive_summary": "Community Health Network in Indianapolis, Indiana disclosed that an unknown actor accessed an employee email account between February 25 and February 26, 2025. Once discovered, it was immediately contained and investigated. The investigation concluded on July 15, 2025, determining that protected health information had been involved including patient names, medical information, and health insurance information. Community Health Network notified 13,939 affected individuals. This is separate from Community Health Network's 2022 tracking technology breach (MW-016 or similar in the database) that affected 1.5 million.",
    "attack_type": "Email Account Compromise / Unauthorized Access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 13939,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal \u2014 single employee email account compromised",
    "remediation_disclosed": "Account immediately contained upon discovery; investigation completed; breach notifications issued September 2025",
    "primary_source_url": "https://www.paubox.com/blog/community-health-network-of-indiana-announces-data-breach-linked-to-email",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Community Health Network published the breach notice September 12, 2025. Paubox reported on the disclosure. 13,939 individuals confirmed affected.",
    "sources_used": [
      "Paubox",
      "Community Health Network official notice"
    ],
    "id": "INC-00676",
    "year": 2025,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Conduent Business Services (NJ healthcare clients)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NJ",
    "hq_city": "Florham Park",
    "hq_county": "Morris",
    "discovery_date": "2025-01-13",
    "disclosure_date": "2025-10-01",
    "executive_summary": "Conduent Business Services, a Florham Park NJ-based business process outsourcing company serving healthcare organizations and government agencies, suffered a major breach when a threat actor (reportedly Safepay ransomware group) gained access to its network between October 21, 2024 and January 13, 2025. The breach affected more than 10.5 million individuals nationally, exposing names, Social Security numbers, medical information, and health insurance data. Notifications did not begin until October 2025, approximately one year after initial access. Multiple class action lawsuits were consolidated in the District of New Jersey.",
    "attack_type": "Ransomware/Hacking with data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Safepay (reported)",
    "attribution_status": "reported",
    "individuals_affected_reported": 10515849,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Texas AG investigation; multiple class action lawsuits consolidated in NJ federal court; regulatory scrutiny ongoing",
    "operational_impact": "Systems disrupted briefly; PHI of 10.5M+ individuals exfiltrated across multiple healthcare and government clients",
    "remediation_disclosed": "SEC 8-K filed January 2025; systems restored; individual notifications mailed October 2025; TX AG investigation opened",
    "primary_source_url": "https://www.hipaajournal.com/conduent-business-solutions-data-breach/",
    "secondary_source_urls": [
      "https://www.nj.com/healthfit/2026/02/nj-company-faces-lawsuits-texas-attorney-general-investigation-over-massive-data-breach.html",
      "https://freedomforallamericans.org/conduent-data-breach/"
    ],
    "confidence_notes": "HIPAA Journal confirms 10.5M+ affected; SEC 8-K filed; TX AG confirmed ~4M Texans; OR DOJ confirmed 10.5M; NJ HQ confirmed; ranked #3 largest healthcare breach ever",
    "sources_used": [
      "HIPAA Journal",
      "NJ.com",
      "SEC filings"
    ],
    "id": "INC-00677",
    "year": 2025,
    "lat": 40.7881643,
    "lng": -74.3891647,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Conduent Business Services (Premera Blue Cross / Washington Covered)",
    "organization_type": "Business Associate (Healthcare IT / Claims Processing) \u2014 serving WA health plans",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2025-01-13",
    "disclosure_date": "2025-03-24",
    "executive_summary": "Conduent Business Services, a major healthcare IT and business process outsourcing firm, suffered a significant data breach between October 21, 2024 and January 13, 2025. The breach is among the largest healthcare business associate breaches of 2025, ultimately affecting an estimated 14.79 million individuals nationally. Conduent serves Premera Blue Cross and other Washington state health plans as a business associate. Washington state AG received disclosure March 24, 2026. The breach exposed names, SSNs, financial account information, and health insurance data of health plan members whose data Conduent processed.",
    "attack_type": "Hacking / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14791500,
    "residents_affected_in_state": "Not separately reported (WA health plan members included as clients of Conduent)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "14.79M individuals nationally affected; health plan member data including SSNs and financial data exposed across multiple clients",
    "remediation_disclosed": "Individual notifications; credit monitoring offered; AG disclosures to multiple states",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [
      "https://healthsource.premera.com/our-perspective/news/conduent-data-security-incident/"
    ],
    "confidence_notes": "Conduent is ranked #3 all-time largest healthcare data breach per HIPAA Journal (14,791,500 individuals); Premera Blue Cross confirmed as client affected per prior research (WA-013 entry covers the specific Premera/Conduent breach notification to WA members \u2014 this entry covers Conduent's national filing). Note: may overlap with WA-013; confirm with parent agent whether to retain or merge.",
    "sources_used": [
      "HIPAA Journal",
      "Premera Blue Cross official notice",
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00678",
    "year": 2025,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Conduent Business Services LLC (Blue Cross Blue Shield of Texas / Texas Medicaid)",
    "organization_type": "Business Associate / Health Plan Administrator",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "TX",
    "hq_city": "Austin",
    "hq_county": "Travis",
    "discovery_date": "2025-01-13",
    "disclosure_date": "2025-09-01",
    "executive_summary": "SafePay ransomware group breached Conduent October 21, 2024 to January 13, 2025, exfiltrating ~8 TB. Over 4 million Texans affected including Texas Medicaid recipients and BCBS Texas members. Total nationwide: 14,791,500+. Texas AG launched investigation. Data included names, SSNs, dates of birth, medical and health insurance information.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "SafePay",
    "attribution_status": "claimed",
    "individuals_affected_reported": 14791500,
    "residents_affected_in_state": 4000000,
    "financial_impact": "Not publicly disclosed; multiple class actions filed",
    "operational_impact": "Mailroom and payment processing impacted; notifications delayed months",
    "remediation_disclosed": "Network secured January 2025; forensic investigation; identity monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/conduent-business-solutions-data-breach/",
    "secondary_source_urls": [
      "https://compliancejunction.com/conduent-business-services-data-breach-investigation-by-texas-attorney-general/",
      "https://healthselect.bcbstx.com/pdf/conduent-incident-faq.pdf"
    ],
    "confidence_notes": "High confidence; TX AG confirmed 4M Texans; HIPAA Journal confirmed 14.7M+ nationwide; BCBS TX confirmed via FAQ; ranked #3 all-time breach",
    "sources_used": [
      "HIPAA Journal",
      "ComplianceJunction",
      "BCBS Texas"
    ],
    "id": "INC-00679",
    "year": 2025,
    "lat": 30.2672,
    "lng": -97.7431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Conduent Business Services \u2014 SC/SE impact",
    "organization_type": "Business Associate / Business Process Outsourcing",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "SC",
    "hq_city": "Florham Park",
    "hq_county": "Morris County (NJ-based)",
    "discovery_date": "2025-01-01",
    "disclosure_date": "2025-10-25",
    "executive_summary": "Conduent Business Services, a major business process outsourcing firm serving healthcare and government clients, reported a massive data breach affecting 664,012 South Carolina residents per the SC AG. Total affected individuals are 14,791,500 nationally. Conduent provides technology services including Medicaid claims processing in multiple SE states. This is the third-largest healthcare data breach of 2025.",
    "attack_type": "Network Hacking / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 14791500,
    "residents_affected_in_state": 664012,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare and government service recipient data exposed across multiple SE states; Medicaid processing disruption",
    "remediation_disclosed": "SC AG notified October 2025; individual notifications sent",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthcare-data-breach-statistics/"
    ],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing with 664,012 SC residents; HIPAA Journal identifies this as third-largest 2025 healthcare breach nationally.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal",
      "HIPAA Journal Healthcare Data Breach Statistics"
    ],
    "id": "INC-00680",
    "year": 2025,
    "lat": 40.7881643,
    "lng": -74.3891647,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Cooper Health System (Cooper University Health Care)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NJ",
    "hq_city": "Camden",
    "hq_county": "Camden",
    "discovery_date": "2024-05-14",
    "disclosure_date": "2025-05-28",
    "executive_summary": "Cooper Health System, a three-hospital Southern New Jersey health system, detected unusual network activity on May 14, 2024 and engaged cybersecurity experts. An investigation concluded on March 26, 2025, confirming that an unauthorized actor accessed and exfiltrated certain data from Cooper's systems. Approximately 57,412 patients were affected, with compromised data including names, dates of birth, Social Security numbers, health insurance information, medical record numbers, treatment information, and medical history.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 57412,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Class action lawsuit filed (Bloomberg Law, May 2025)",
    "operational_impact": "Patient PHI including SSNs and medical records exfiltrated; no confirmed system disruption",
    "remediation_disclosed": "FBI notified; cybersecurity measures enhanced; Maine AG notified; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/cooper-health-system-data-breach/",
    "secondary_source_urls": [
      "https://www.mobihealthnews.com/news/cooper-health-system-reports-data-security-breach",
      "https://news.bloomberglaw.com/litigation/cooper-health-system-hit-with-class-action-over-2024-data-breach"
    ],
    "confidence_notes": "Maine AG filing confirms 57,412 affected; HIPAA Journal and Bloomberg Law corroborate; widely reported 2025",
    "sources_used": [
      "HIPAA Journal",
      "Mobi Health News",
      "Bloomberg Law"
    ],
    "id": "INC-00681",
    "year": 2025,
    "lat": 39.9259,
    "lng": -75.1196,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Coos County Family Health Services (NH)",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NH",
    "hq_city": "Berlin",
    "hq_county": "Coos",
    "discovery_date": "2025-07-01",
    "disclosure_date": "2025-10-09",
    "executive_summary": "Coos County Family Health Services, a federally qualified health center in Berlin, New Hampshire, reported a data security incident to the Maine AG in October 2025. The breach involved unauthorized access to patient health information at the rural NH healthcare provider.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Rural NH community health patient data potentially compromised",
    "remediation_disclosed": "Maine AG notified; patients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing October 9, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00682",
    "year": 2025,
    "lat": 44.4696602,
    "lng": -71.1810703,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Covenant Health (Maine/New England)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Tewksbury",
    "hq_county": "Middlesex",
    "discovery_date": "2025-05-01",
    "disclosure_date": "2025-05-29",
    "executive_summary": "Covenant Health, which operates St. Mary's Health System in Lewiston, ME and St. Joseph's Hospital in Bangor, ME among other New England facilities, was impacted by a cyberattack in May 2025. Maine AG filings and Maine news coverage confirm impact to Maine facilities. St. Mary's and St. Joseph's hospitals were affected. The attack disrupted health system operations across New England.",
    "attack_type": "Cyberattack (nature unconfirmed)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "St. Mary's Lewiston and St. Joseph's Bangor (ME) impacted; other New England Covenant facilities also affected",
    "remediation_disclosed": "Maine AG notified; systems restoration underway",
    "primary_source_url": "https://www.youtube.com/watch?v=HsssTmzE3Po",
    "secondary_source_urls": [
      "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html"
    ],
    "confidence_notes": "Maine AG filing (Covenant Health, Inc. - Dec 2025 listing); YouTube news report confirms Maine hospitals; limited public details",
    "sources_used": [
      "Maine AG Viewer",
      "Maine News Video"
    ],
    "id": "INC-00683",
    "year": 2025,
    "lat": 43.6337644,
    "lng": -70.2867452,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Covenant Health (Maine/New Hampshire - Qilin ransomware)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Tewksbury",
    "hq_county": "Middlesex",
    "discovery_date": "2025-05-26",
    "disclosure_date": "2025-07-01",
    "executive_summary": "Covenant Health, a Catholic healthcare organization, suffered a ransomware attack on May 26, 2025 affecting its hospitals in Maine (St. Joseph Hospital, Waterville; St. Mary's Health System, Lewiston) and New Hampshire (St. Joseph Hospital, Nashua). The Qilin ransomware group claimed responsibility and reported theft of 850 GB of sensitive data. The organization shut down all data systems across hospitals, clinics, and practices. Approximately 478,188 individuals were ultimately identified as affected after an initial estimate of 7,800.",
    "attack_type": "Ransomware (Qilin)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Qilin",
    "attribution_status": "claimed",
    "individuals_affected_reported": 478188,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "All data systems across ME and NH hospitals shut down; care disruptions at three hospital campuses; 850 GB data stolen",
    "remediation_disclosed": "Systems restored; individuals notified; law enforcement engaged",
    "primary_source_url": "https://therecord.media/maine-new-hampshire-cyberattacks-hospital",
    "secondary_source_urls": [
      "https://securityaffairs.com/186439/data-breach/covenant-health-data-breach-after-ransomware-attack-impacted-over-478000-people.html"
    ],
    "confidence_notes": "The Record confirmed May 26 attack; Security Affairs confirms Qilin claim and 478,188 total; widely reported",
    "sources_used": [
      "The Record",
      "Security Affairs"
    ],
    "id": "INC-00684",
    "year": 2025,
    "lat": 43.6337644,
    "lng": -70.2867452,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "DaVita Inc.",
    "organization_type": "Healthcare Provider (Dialysis Services)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CO",
    "hq_city": "Denver",
    "hq_county": "Denver",
    "discovery_date": "2025-04-12",
    "disclosure_date": "2025-04-14",
    "executive_summary": "DaVita Inc., a Denver-based kidney dialysis provider operating 2,600+ outpatient centers nationwide, detected and eradicated a ransomware attack on April 12, 2025. The Interlock ransomware group claimed responsibility and posted leaked data including 1.5 TB publicly (claiming 20+ TB stolen). 2,689,826 individuals were ultimately affected. Compromised data from DaVita's dialysis labs database included names, addresses, dates of birth, SSNs, health insurance, clinical information (treatment details, dialysis lab results), and in some cases tax identification numbers. DaVita reported $13.5M in Q2 2025 expenses from the incident.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware (Interlock)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock",
    "attribution_status": "claimed",
    "individuals_affected_reported": 2689826,
    "residents_affected_in_state": "Not separately reported (nationwide dialysis centers)",
    "financial_impact": "$13.5M Q2 2025 expenses ($1M patient care + $12.5M G&A); SEC 8-K filing April 14",
    "operational_impact": "Patient care continued; major impacted servers and systems restored; all major systems restored by August 2025",
    "remediation_disclosed": "Threat actor eradicated same day of detection; SEC 8-K filed; all systems restored; OCR notified",
    "primary_source_url": "https://www.hipaajournal.com/davita-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.blackfog.com/davita-ransomware-attack-major-data-breach/",
      "https://www.medtechdive.com/news/davita-ransomware-attack-data-breach-2-7-million/758416/",
      "https://www.hipaajournal.com/davita-ransomware-attack/",
      "https://www.reuters.com/business/healthcare-pharmaceuticals/ransomware-attack-davita-impacted-27-million-people-us-health-dept-website-shows-2025-08-21/",
      "https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=DVA&type=8-K&dateb=&owner=include&count=40"
    ],
    "confidence_notes": "High confidence; OCR confirmed 2,689,826; SEC 8-K filed; MedTech Dive confirmed | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "BlackFog",
      "DaVita SEC 8-K filing (April 14, 2025)",
      "HIPAA Journal",
      "HIPAA Journal, BlackFog, MedTech Dive",
      "MedTech Dive",
      "Reuters"
    ],
    "id": "INC-00685",
    "year": 2025,
    "lat": 39.7392,
    "lng": -104.9903,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "DaVita Inc. (OR dialysis patients \u2014 Interlock ransomware)",
    "organization_type": "Healthcare Provider (Dialysis / Kidney Care)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Denver",
    "hq_county": "Unknown",
    "discovery_date": "2025-04-12",
    "disclosure_date": "2025-04-14",
    "executive_summary": "Cross-reference entry for Oregon's DaVita Interlock ransomware impact. DaVita operates dialysis facilities across Oregon. The Oregon AG breach notification system received notices for this incident, which is the same April 2025 Interlock ransomware attack affecting DaVita's national network. See WA-039 for primary entry details. The Oregon DOJ published advisories about the Change Healthcare attack that also disrupted DaVita's Oregon billing operations separately in 2024.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock ransomware group",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not publicly disclosed (OR-specific subset)",
    "residents_affected_in_state": "Oregon dialysis patients at DaVita facilities",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Dialysis operations disrupted; OR patient PHI potentially compromised",
    "remediation_disclosed": "Same as WA-039",
    "primary_source_url": "https://www.hipaajournal.com/davita-ransomware-attack-interlock/",
    "secondary_source_urls": [],
    "confidence_notes": "Cross-reference to WA-039. Separate entry for OR tracking purposes based on OR AG notification of DaVita breach.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00686",
    "year": 2025,
    "lat": 45.5712523,
    "lng": -122.6873183,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "DaVita Inc. (WA/OR dialysis patients \u2014 Interlock ransomware)",
    "organization_type": "Healthcare Provider (Dialysis / Kidney Care)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Denver",
    "hq_county": "Unknown",
    "discovery_date": "2025-04-12",
    "disclosure_date": "2025-04-14",
    "executive_summary": "DaVita Inc., a large dialysis provider that operates multiple facilities in Washington and Oregon, disclosed a ransomware attack beginning April 12, 2025. The Interlock ransomware group claimed responsibility and encrypted portions of DaVita's network and stole data. DaVita operates dozens of dialysis facilities across WA and OR. The Washington AG breach notification system received notices affecting WA residents. The Oregon AG also received notifications. DaVita's SEC 8-K filing confirmed the attack on April 14, 2025. Patient data including PHI for dialysis patients \u2014 a highly vulnerable population \u2014 was potentially exposed. The Interlock group published samples of allegedly stolen data.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock ransomware group",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not publicly disclosed (investigation ongoing)",
    "residents_affected_in_state": "WA dialysis patients at multiple DaVita facilities",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "DaVita network encrypted; dialysis operations disrupted; highly sensitive PHI of kidney disease patients potentially compromised",
    "remediation_disclosed": "Law enforcement notified; SEC 8-K filed; containment measures implemented; investigation ongoing",
    "primary_source_url": "https://www.hipaajournal.com/davita-ransomware-attack-interlock/",
    "secondary_source_urls": [
      "https://therecord.media/davita-ransomware-attack-interlock"
    ],
    "confidence_notes": "High confidence: DaVita SEC 8-K confirmed attack; Interlock claimed responsibility; DaVita has significant WA/OR footprint. This entry is also referenced as OR incident via OR AG notification; note WA as primary state (DaVita national operations; WA has most facilities in the Pacific Northwest). See also OR cross-reference.",
    "sources_used": [
      "HIPAA Journal",
      "The Record"
    ],
    "id": "INC-00687",
    "year": 2025,
    "lat": 42.6713752,
    "lng": -92.3372158,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "DaVita Inc. \u2014 SC Dialysis Patients",
    "organization_type": "Healthcare Provider / Dialysis",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Denver",
    "hq_county": "Denver County (CO-based)",
    "discovery_date": "2025-04-01",
    "disclosure_date": "2025-08-01",
    "executive_summary": "DaVita Inc., a major dialysis provider with numerous centers throughout the Southeast including South Carolina, reported a data security incident affecting 11,570 South Carolina residents. DaVita operates dialysis centers across FL, GA, NC, SC, VA, TN, and other SE states. The SC AG filing shows DaVita affected 11,570 SC residents.",
    "attack_type": "Network Intrusion / Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11570,
    "residents_affected_in_state": 11570,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Dialysis patient PHI and PII potentially exposed across SE centers",
    "remediation_disclosed": "SC AG notified August 2025",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing DaVita Inc. with 11,570 SC residents August 2025. HQ is Colorado but major SE healthcare provider.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00688",
    "year": 2025,
    "lat": 34.5753839,
    "lng": -82.7365261,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "David A. Nover M.D. P.C. (psychiatry practice)",
    "organization_type": "Healthcare Provider (Psychiatry)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "PA",
    "hq_city": "Warrington",
    "hq_county": "Bucks",
    "discovery_date": "2025-06-03",
    "disclosure_date": "2025-11-05",
    "executive_summary": "David A. Nover M.D. P.C., a psychiatry and psychotherapy practice in Warrington, Pennsylvania, reported a data security incident on June 3, 2025. An investigation confirmed unauthorized access to the network and copying of files containing patient information including names, SSNs, payment card data, medical record numbers, Medicare numbers, health insurance IDs, diagnostic information, treatment records, and lab results. The number of affected individuals had not been publicly disclosed as of November 2025.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Psychiatric patient PHI including SSNs and payment card data exfiltrated",
    "remediation_disclosed": "Cybersecurity and legal counsel engaged; credit monitoring offered to affected individuals",
    "primary_source_url": "https://www.hipaajournal.com/central-jersey-medical-center-ransomware/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal November 2025 breach report; psychiatric patient data particularly sensitive; HHS OCR not yet shown due to government shutdown",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00689",
    "year": 2025,
    "lat": 40.2492741,
    "lng": -75.1340604,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Delta Dental of Virginia",
    "organization_type": "Health Plan / Dental Insurer (Multistate)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "CA",
    "hq_city": "Richmond, VA (multistate insurer, CA members affected)",
    "hq_county": "N/A \u2014 multistate",
    "discovery_date": "2025-03-21",
    "disclosure_date": "2025-11-21",
    "executive_summary": "DDVA engaged independent cybersecurity experts to assist with the process. As a result of the investigation, DDVA determined that certain emails and attachments may have been accessed and acquired without authorization between March 21, 2025 and April 23, 2025. DDVA undertook a comprehensive review of those files and upon completion of that review, learned that some of your personal information was contained within the potentially affected data. That is the reason for this notification. Please note that DDVA has no evidenc",
    "attack_type": "Hacking / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/%28CA%29%20DDVA%20notice.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00690",
    "year": 2025,
    "lat": 36.01058953216646,
    "lng": -119.19462886922399,
    "is_multistate": true,
    "hq_outside_state": "Richmond, Contra Costa",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Deschutes County Health Services / Best Care / La Pine Community Health Center (via TriZetto Provider Solutions)",
    "organization_type": "Healthcare Provider (County Health / Community Health Centers)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Bend",
    "hq_county": "Deschutes",
    "discovery_date": "2025-10-02",
    "disclosure_date": "2025-12-10",
    "executive_summary": "TriZetto Provider Solutions (TPS), a healthcare insurance verification vendor, suffered a breach beginning November 2024 in which an unauthorized actor accessed historical eligibility reports. The threat was not eliminated until October 2, 2025, potentially exposing PHI of 700,000+ people nationwide. Three Central Oregon healthcare providers were notified December 10, 2025: Deschutes County Health Services (~1,300 patients), La Pine Community Health Center (~1,200 patients), and Best Care (~1,650 patients). Exposed data included names, addresses, dates of birth, Social Security numbers, health insurer names, and health insurance member numbers.",
    "attack_type": "Hacking / Unauthorized database access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4150,
    "residents_affected_in_state": 4150,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Eligibility and insurance data exposed for nearly a year",
    "remediation_disclosed": "TPS eliminated threat; providers notified; guidance provided to affected patients",
    "primary_source_url": "https://www.theregister.com/2026/01/30/trizetto_health_data_stolen/",
    "secondary_source_urls": [
      "https://ktvz.com/news/crime-courts/2026/01/29/contractor-data-breach-may-have-exposed-the-protected-health-info-of-thousands-of-central-oregonians/",
      "https://www.bestcaretreatment.org/incident/"
    ],
    "confidence_notes": "Breach began Nov 2024, discovered/notified Dec 2025; three OR providers confirmed individually",
    "sources_used": [
      "The Register",
      "KTVZ (Bend, OR)",
      "Best Care official notice"
    ],
    "id": "INC-00691",
    "year": 2025,
    "lat": 44.0582,
    "lng": -121.3153,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Dignity Health Lassen Medical Clinic",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Susanville",
    "hq_county": "Lassen",
    "discovery_date": "2024",
    "disclosure_date": "01/2025",
    "executive_summary": "Data breach at Dignity Health Lassen Medical Clinic affecting over 65,000 individuals.",
    "attack_type": "Hacking/IT Incident \u2014 Hacking / network intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 65000,
    "residents_affected_in_state": 65000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://x.com/California_Laws/status/1877075873075179716"
    ],
    "confidence_notes": "Reported via California Law News January 2025. Dignity Health is CA-based health system with operations statewide.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00692",
    "year": 2025,
    "lat": 40.4163,
    "lng": -120.653,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Doctors Imaging Group (DIG)",
    "organization_type": "Healthcare Provider (Radiology/Imaging)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Miami",
    "hq_county": "Miami-Dade",
    "discovery_date": "2024-11-05",
    "disclosure_date": "2025-08-29",
    "executive_summary": "Miami-based Doctors Imaging Group confirmed a cyberattack in which attackers copied data from its internal network between November 5 and November 11, 2024. The breach was not fully confirmed until August 29, 2025\u2014nearly a year later. 170,000+ individuals were affected. Stolen data included names, addresses, DOBs, medical record numbers, diagnoses, treatment details, claims, health insurance, financial account numbers, and SSNs.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 170000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient medical and financial data stolen; ~1 year notification delay",
    "remediation_disclosed": "Network security assessed; forensic review; notifications mailed August/September 2025",
    "primary_source_url": "https://www.bitdefender.com/en-us/blog/hotforsecurity/florida-x-ray-clinic-year-tell-patients-hackers-stole-medical-data",
    "secondary_source_urls": [],
    "confidence_notes": "Bitdefender Hot for Security reports 170,000+ affected. Nearly 1-year notification delay noted as a significant compliance concern.",
    "sources_used": [
      "Bitdefender Hot for Security"
    ],
    "id": "INC-00693",
    "year": 2025,
    "lat": 25.7617,
    "lng": -80.1918,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Doctors' Memorial Hospital (via Nationwide Recovery Services)",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Perry",
    "hq_county": "Taylor",
    "discovery_date": "2024-07-05",
    "disclosure_date": "2025-05-27",
    "executive_summary": "Perry, FL-based Doctors' Memorial Hospital was notified on May 27, 2025 that its debt collection provider, Nationwide Recovery Services, experienced a cyberattack from July 5\u201311, 2024. Files containing patient names, DOBs, SSNs, financial details, and medical information were potentially accessed. Doctors' Memorial Hospital's own systems were not affected.",
    "attack_type": "Business Associate Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data exposed via debt collection vendor",
    "remediation_disclosed": "Notifications mailed by USPS; hospital systems not affected",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/doctors-memorial-hospital-july-2025",
    "secondary_source_urls": [],
    "confidence_notes": "ClassAction.org provides breach details. Number of affected individuals not yet disclosed.",
    "sources_used": [
      "ClassAction.org"
    ],
    "id": "INC-00694",
    "year": 2025,
    "lat": 30.1174351,
    "lng": -83.5818147,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Episource LLC (UnitedHealth Group / Optum)",
    "organization_type": "BA / Vendor (Medical Coding & Risk Adjustment)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "El Segundo",
    "hq_county": "Los Angeles",
    "discovery_date": "2025-02-06",
    "disclosure_date": "2025-04-23",
    "executive_summary": "Episource LLC, a UnitedHealth Group (Optum) subsidiary providing medical coding and risk adjustment services, discovered unusual network activity on February 6, 2025, consistent with a ransomware-type attack. Unauthorized access had occurred between January 27 and February 6, 2025. Systems were immediately shut down. Preliminary notifications went to clients April 23, 2025. The HHS OCR portal confirmed 5,418,866 individuals affected \u2014 the second-largest healthcare data breach of 2025 at time of reporting. Compromised data included names, contact info, SSNs, medical diagnoses, prescriptions, test results, insurance information, and Medicaid/Medicare IDs. No ransomware group claimed responsibility publicly.",
    "attack_type": "Ransomware (suspected) / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5418866,
    "residents_affected_in_state": "Nationwide; not broken out by state",
    "financial_impact": "Not publicly disclosed. Two years of free credit monitoring and identity theft protection offered to affected individuals.",
    "operational_impact": "Episource IT systems powered down. Impact on medical coding and risk adjustment services for health plan and provider clients.",
    "remediation_disclosed": "All systems shut down immediately upon detection. External cybersecurity experts and law enforcement engaged. Preliminary client notifications April 23, 2025. Full notifications sent June 2025 onward. Security posture strengthened.",
    "primary_source_url": "https://www.episource.com/data-security-notice/",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/episource-data-breach/",
      "https://healthexec.com/topics/health-it/cybersecurity/unitedhealth-subsidiary-exposes-55m-patient-records-hackers",
      "https://cybernews.com/security/unitedhealth-data-breach-episource/",
      "https://technijian.com/cyber-security/episource-data-breach-affects-5-4-million-patients/"
    ],
    "confidence_notes": "High confidence. HHS OCR portal confirms 5,418,866 (per HIPAA Journal). Episource published official breach notice. No threat actor confirmed.",
    "sources_used": [
      "Episource official security notice",
      "HIPAA Journal",
      "Health Exec",
      "Cybernews",
      "Technijian"
    ],
    "id": "INC-00695",
    "year": 2025,
    "lat": 33.917028,
    "lng": -118.4156337,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Episource, LLC",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Los Angeles County (UnitedHealth/Optum subsidiary)",
    "hq_county": "Unknown",
    "discovery_date": "2025-01-27 to 2025-02-06",
    "disclosure_date": "Reported to OCR in 2025",
    "executive_summary": "Hackers accessed and copied files from Episource systems between January 27 and February 6, 2025. Data included names, contact details, dates of birth, SSNs, Medicaid IDs, and full medical histories.",
    "attack_type": "Hacking/IT Incident \u2014 Data exfiltration / network intrusion",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5418866,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Systems shut down to contain breach after detection on Feb 6, 2025",
    "remediation_disclosed": "Systems shut down immediately upon detection; notifications sent to affected individuals from April 2025; IDX identity theft protection offered; additional state-specific notices to California and Vermont",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://therecord.media/5-million-affected-episource-data-breach",
      "https://www.securityweek.com/data-breach-at-healthcare-services-firm-episource-impacts-5-4-million-people/"
    ],
    "confidence_notes": "Ranked #19 largest healthcare breach of all time. Episource is a subsidiary of UnitedHealth's Optum division providing healthcare data analytics and coding services.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00696",
    "year": 2025,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Esse Health",
    "organization_type": "Healthcare Provider / Independent Physician Group",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "St. Louis",
    "hq_county": "St. Louis",
    "discovery_date": "2025-04-21",
    "disclosure_date": "2025-07-03",
    "executive_summary": "Missouri-based Esse Health, an independent physician group operating in the Greater St. Louis area, detected unusual network activity on April 21, 2025. An investigation confirmed that threat actors gained access and stole files containing personal information of 263,601 patients. Compromised data included names, Social Security numbers, and health insurance details. The company stated that attackers did not download or directly access electronic medical records, but the nature of the information raised concerns about identity theft and medical fraud. Esse Health notified affected individuals by mail and reported the breach to the Maine Attorney General's Office.",
    "attack_type": "Hacking / Data Exfiltration (probable ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 263601,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; complimentary identity protection services offered",
    "operational_impact": "Communication systems disrupted; cybersecurity specialists and law enforcement engaged",
    "remediation_disclosed": "Enhanced cybersecurity protocols implemented; law enforcement notified; identity protection services offered to affected individuals",
    "primary_source_url": "https://www.bitdefender.com/en-us/blog/hotforsecurity/missouri-healthcare-provider-cyberattack-exposes-data-of-over-260-000-patients",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/tracking-healthcare-data-breaches-cybersecurity-hacking-hospitals/696184/"
    ],
    "confidence_notes": "High confidence. Esse Health submitted a breach report to the Maine AG confirming 263,601 affected. Bitdefender's Hot for Security reported directly from the breach notification.",
    "sources_used": [
      "Bitdefender Hot for Security",
      "Healthcare Dive",
      "Maine AG breach portal"
    ],
    "id": "INC-00697",
    "year": 2025,
    "lat": 38.627,
    "lng": -90.1994,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Excelsior Orthopaedics LLP",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "NY",
    "hq_city": "Amherst",
    "hq_county": "Erie",
    "discovery_date": "2025-07-01",
    "disclosure_date": "2025-08-29",
    "executive_summary": "Excelsior Orthopaedics LLP, a New York orthopedic practice, reported a data security incident to the Maine AG in August 2025. The breach involved unauthorized access to systems containing patient PHI. The Maine AG listing confirms the breach as reportable in 2025.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI compromised",
    "remediation_disclosed": "Maine AG notified; patients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing August 29, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00698",
    "year": 2025,
    "lat": 42.9783924,
    "lng": -78.7997616,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Frederick Health Medical Group, Inc.",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MD",
    "hq_city": "Frederick",
    "hq_county": "Frederick",
    "discovery_date": "2025-01-27",
    "disclosure_date": "2025-01-27",
    "executive_summary": "Frederick Health Medical Group, a Maryland-based regional hospital system, suffered a ransomware attack discovered January 27, 2025, that forced its systems offline and caused ambulance diversions and an emergency department closure under a 'mini disaster' designation by the Maryland Institute for Emergency Medical Services Systems. Initial access occurred January 25, 2025. The attacker copied files from a file-sharing server. The confirmed affected count, per a March 28, 2025, breach notice, was 934,326 patients. Compromised data included names, addresses, SSNs, driver's license numbers, medical record numbers, health insurance data, and clinical information. No ransomware group claimed responsibility publicly.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 934326,
    "residents_affected_in_state": "Primarily Maryland; not separately broken out",
    "financial_impact": "Not publicly disclosed. Class action lawsuits filed. Judge denied most of dismissal motion (March 2026).",
    "operational_impact": "Systems taken offline. Ambulances diverted to other facilities. Emergency department placed under 'mini disaster' designation (unable to accept any patients temporarily). Systems restored over several weeks.",
    "remediation_disclosed": "External forensic firm engaged. Law enforcement notified. Ambulance systems restored. Notification letters mailed to 934,326 individuals (March 2025). Security posture enhanced.",
    "primary_source_url": "https://frederickhealth.org/cybersecurity-incident",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/frederick-health-medical-group-ransomware-attack/",
      "https://www.classaction.org/data-breach-lawsuits/frederick-health-march-2025",
      "https://www.paubox.com/blog/learning-from-frederick-health-hospitals-ransomware-attack",
      "https://frederickcitymedia.com/2025/01/27/frederick-health-systems-taken-offline-due-to-ransomware-attack/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal confirmed 934,326 per March 2025 breach notice. Ambulance diversions confirmed by MIEMSS designation. Threat actor unconfirmed. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "ClassAction.org",
      "Frederick City Media",
      "Frederick Health official notice",
      "Frederick News-Post (Yahoo)",
      "HIPAA Journal",
      "Paubox"
    ],
    "id": "INC-00699",
    "year": 2025,
    "lat": 39.415779,
    "lng": -77.4127562,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Fundamental Administrative Services LLC \u2014 SE impact",
    "organization_type": "Business Associate / Long-Term Care Administration",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TN",
    "hq_city": "Nashville",
    "hq_county": "Davidson",
    "discovery_date": "2025-07-01",
    "disclosure_date": "2025-10-30",
    "executive_summary": "Fundamental Administrative Services LLC, which provides administrative services to skilled nursing facilities and long-term care providers throughout the Southeast, reported a data breach affecting 11,595 South Carolina residents per the SC AG. The company supports facilities across TN, FL, GA, SC, and other SE states.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 11595,
    "residents_affected_in_state": 11595,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Long-term care patient PHI and administrative records exposed",
    "remediation_disclosed": "SC AG notified October 2025",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing with 11,595 SC residents October 2025.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00700",
    "year": 2025,
    "lat": 36.1627,
    "lng": -86.7816,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Gaylord Specialty Healthcare (CT)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "Wallingford",
    "hq_county": "New Haven",
    "discovery_date": "2025-07-01",
    "disclosure_date": "2025-09-24",
    "executive_summary": "Gaylord Specialty Healthcare, a Connecticut specialty rehabilitation hospital, reported a data security incident to the Maine AG in September 2025 involving unauthorized access to patient health information. The breach involved patient rehabilitation and specialty care records.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Specialty rehabilitation patient data compromised",
    "remediation_disclosed": "Maine AG notified; patients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing September 24, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00701",
    "year": 2025,
    "lat": 41.4564233,
    "lng": -72.8239356,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Goshen Medical Center",
    "organization_type": "Community Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Goshen",
    "hq_county": "Elkhart",
    "discovery_date": "2025-03-04",
    "disclosure_date": "2025-09-17",
    "executive_summary": "Note: Goshen Medical Center in Fayetteville, NC (not Indiana) suffered a ransomware attack discovered March 4, 2025 with access occurring February 15, 2025. BianLian ransomware group claimed responsibility, posting attack details on the Tor network. 456,385 patients were notified. This organization is in North Carolina, not Indiana. Included for verification purposes. The task list mentioned 'Goshen Health IN 2023' \u2014 separate from this NC entity. No confirmed Indiana Goshen Health 2023 incident found in available sources.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "BianLian",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 456385,
    "residents_affected_in_state": "North Carolina (NOT Midwest; included for verification only)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Financial, HR, patient data, partner data exfiltrated",
    "remediation_disclosed": "Yes \u2014 investigation; external cybersecurity experts; additional security measures implemented; notifications September 2025",
    "primary_source_url": "https://www.claimdepot.com/data-breach/goshen-medical-center-2025",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence for Goshen Medical Center (NC). CONFIRMED this is NOT an Indiana Midwest incident. North Carolina entity \u2014 included as verification note only.",
    "sources_used": [
      "Claim Depot",
      "Paubox/HIPAA Times"
    ],
    "id": "INC-00702",
    "year": 2025,
    "lat": 41.5821,
    "lng": -85.8344,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Hampton Regional Medical Center",
    "organization_type": "Healthcare Provider / General Acute Care Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Varnville",
    "hq_county": "Hampton",
    "discovery_date": "2025-07-16",
    "disclosure_date": "2025-09-12",
    "executive_summary": "Hampton Regional Medical Center in Varnville, South Carolina detected suspicious activity on July 16, 2025. Investigation with third-party cybersecurity specialists revealed unauthorized access between June 18 and July 16, 2025. Data potentially compromised includes names, SSNs, dates of birth, driver's license numbers, medical information, and demographic data. SC Consumer Affairs lists 27,609 SC residents affected.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 27609,
    "residents_affected_in_state": 27609,
    "financial_impact": "Not publicly disclosed; 24 months identity monitoring offered",
    "operational_impact": "Patient, staff, and affiliated individuals' PHI and PII potentially accessed over 28-day window",
    "remediation_disclosed": "Network secured; third-party cybersecurity specialists engaged; 24 months free identity monitoring services offered; breach reported to HHS and SC AG",
    "primary_source_url": "https://www.claimdepot.com/data-breach/hampton-regional-medical-center-2025",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/hampton-regional-medical-center-september-2025",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 Claim Depot reporting, ClassAction.org, SC Consumer Affairs listing (27,609 SC residents).",
    "sources_used": [
      "Claim Depot",
      "ClassAction.org",
      "SC Consumer Affairs Breach Portal",
      "HHS OCR"
    ],
    "id": "INC-00703",
    "year": 2025,
    "lat": 32.850471,
    "lng": -81.0792239,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "HealthEquity, Inc.",
    "organization_type": "Healthcare Business Associate / HSA Administrator (Multistate)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Draper, UT",
    "hq_county": "N/A \u2014 national",
    "discovery_date": "2024-03-09",
    "disclosure_date": "2025-05-16",
    "executive_summary": "After receiving an alert, on March 25, 2024, HealthEquity became aware of a systems anomaly requiring extensive technical investigation and ultimately resulting in data forensics until June 10, 2024. Through this work, we discovered some unauthorized access to and potential disclosure of protected health information and/or personally identifiable information stored in an unstructured data repository outside our core systems. On June 26, 2024, after validating the data, we unfortunately determined that some of your personal information was involved.",
    "attack_type": "Hacking / Credential-based Attack via Compromised Vendor Account",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4500000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Third-party vendor account compromised; HSA/benefits data accessed",
    "remediation_disclosed": "['Forensic investigation conducted', 'Passwords reset']",
    "primary_source_url": "https://oag.ca.gov/system/files/HealthEquity%20Sample%20Notice_4.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/healthequity-data-breach-4-5-million-people/",
      "https://www.bleepingcomputer.com/news/security/healthequity-says-data-breach-impacted-45-million-people/"
    ],
    "confidence_notes": "Supplemental/additional CA AG notification filing; same July 2024 breach",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00704",
    "year": 2025,
    "lat": 37.66143844456747,
    "lng": -118.82091669881129,
    "is_multistate": true,
    "hq_outside_state": "Draper",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "HealthPartners (Meta/Facebook Pixel tracking lawsuit)",
    "organization_type": "Nonprofit Health Plan / Health System",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "MN",
    "hq_city": "Bloomington",
    "hq_county": "Hennepin",
    "discovery_date": "2025-01-01",
    "disclosure_date": "2025-03-01",
    "executive_summary": "A class action lawsuit was filed against Group Health Plan, Inc. (doing business as HealthPartners) alleging that it secretly disclosed patient PII and PHI to Meta Platforms and other third parties using Facebook Pixel and Facebook Conversions API tracking technologies on its websites. The lawsuit alleged HealthPartners shared the type of medical treatment sought, specific health conditions, and appointment booking actions with Facebook without patient knowledge or consent, violating HIPAA and patient privacy expectations.",
    "attack_type": "Unauthorized Tracking Technology Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable \u2014 Meta/Facebook as data recipient",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Minnesota patients",
    "financial_impact": "Lawsuit filed; settlement not yet reached in available sources",
    "operational_impact": "No clinical disruption; privacy/regulatory compliance impact",
    "remediation_disclosed": "Not publicly confirmed in available sources",
    "primary_source_url": "https://milberg.com/news/healthpartners-meta/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. Milberg class action lawsuit filing; no HHS OCR breach report confirmed.",
    "sources_used": [
      "Milberg Class Action Law Firm"
    ],
    "id": "INC-00705",
    "year": 2025,
    "lat": 44.8408,
    "lng": -93.2983,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Healthcare Services Group Inc. (HCSG)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "PA",
    "hq_city": "Bensalem",
    "hq_county": "Bucks",
    "discovery_date": "2025-06-01",
    "disclosure_date": "2025-08-25",
    "executive_summary": "Healthcare Services Group Inc. (HCSG), a Pennsylvania-based company providing housekeeping and laundry services to healthcare facilities, reported a data security incident to the Maine AG in August 2025. The breach involved unauthorized access to employee and client healthcare facility data.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Employee and healthcare facility client data potentially compromised",
    "remediation_disclosed": "Maine AG notified; individuals notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing August 25, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00706",
    "year": 2025,
    "lat": 40.1045549,
    "lng": -74.951279,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Henry Ford Health System \u2014 2025 Insider (desktop)",
    "organization_type": "Nonprofit Academic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Detroit",
    "hq_county": "Wayne",
    "discovery_date": "2025-10-01",
    "disclosure_date": "2025-12-12",
    "executive_summary": "Henry Ford Health reported an insider data breach to HHS OCR in December 2025 affecting 1,984 patients via unauthorized access to a desktop computer. An employee was terminated. This is the same as MW-057 \u2014 combining to avoid duplication.",
    "attack_type": "Insider Unauthorized Access",
    "attack_category": "Insider threat",
    "threat_actor_name": "Henry Ford Health employee (terminated)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1984,
    "residents_affected_in_state": "Michigan patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal",
    "remediation_disclosed": "Yes \u2014 employee terminated; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/henry-ford-health-2025-insider-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal citing HHS OCR. NOTE: duplicate of MW-057; retained for completeness.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00707",
    "year": 2025,
    "lat": 42.3314,
    "lng": -83.0458,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Henry Ford Health \u2014 2025 Insider Breach",
    "organization_type": "Nonprofit Academic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Detroit",
    "hq_county": "Wayne",
    "discovery_date": "2025-10-01",
    "disclosure_date": "2025-12-12",
    "executive_summary": "Henry Ford Health reported to HHS OCR a data breach affecting 1,984 patients involving unauthorized access to a desktop computer. This appears to be an insider incident \u2014 Henry Ford confirmed that it terminated the employee responsible. The nature of the unauthorized access was not fully disclosed, nor were all data types affected.",
    "attack_type": "Insider Unauthorized Access",
    "attack_category": "Insider threat",
    "threat_actor_name": "Henry Ford Health employee (terminated)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1984,
    "residents_affected_in_state": "Michigan patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Minimal \u2014 desktop computer access; credit monitoring offered",
    "remediation_disclosed": "Yes \u2014 employee terminated; notifications sent; credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/henry-ford-health-2025-insider-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. HIPAA Journal citing HHS OCR breach portal (1,984).",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00708",
    "year": 2025,
    "lat": 42.3314,
    "lng": -83.0458,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "High Point Treatment Center",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Brockton",
    "hq_county": "Plymouth",
    "discovery_date": "2025-05-01",
    "disclosure_date": "2025-07-29",
    "executive_summary": "High Point Treatment Center, a Massachusetts behavioral health and substance use disorder treatment provider, reported a data security incident to the Maine AG in July 2025. The breach involved patient PHI including substance use disorder records with enhanced privacy protections.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Behavioral health and SUD patient records potentially compromised",
    "remediation_disclosed": "Maine AG notified; patients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing July 29, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00709",
    "year": 2025,
    "lat": 42.0834335,
    "lng": -71.0183787,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Highlands Oncology Group (Medusa Ransomware \u2013 Second Incident)",
    "organization_type": "Healthcare Provider (Oncology)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Fayetteville",
    "hq_county": "Washington",
    "discovery_date": "2025-06-02",
    "disclosure_date": "2025-08-01",
    "executive_summary": "Highlands Oncology Group suffered a second ransomware attack, this time by the Medusa ransomware group. Unauthorized access occurred beginning January 21, 2025, with intermittent access until June 2, 2025, when Medusa deployed ransomware to encrypt files and made data inaccessible. The Medusa group listed Highlands on its data leak site on June 19, 2025, demanding $700,000. The investigation confirmed 113,575 individuals were affected. PHI compromised included names, dates of birth, passport numbers, driver's license/state ID numbers, Social Security numbers, financial account data, credit/debit card numbers, medical treatment data, patient account numbers, medical record numbers, and medical insurance policy data. The Medusa listing was subsequently removed, suggesting the ransom may have been paid.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack with Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Medusa",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 113575,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$700,000 ransom demanded; payment status not confirmed; free identity theft protection offered to those with SSN/DL exposed",
    "operational_impact": "Files and systems encrypted; prolonged unauthorized access from January through June 2025",
    "remediation_disclosed": "Enhanced technical security measures; substitute notice posted; breach reported to HHS and Maine AG; identity theft protection offered",
    "primary_source_url": "https://databreaches.net/2025/08/02/highlands-oncology-group-notifies-113575-people-after-ransomware-attack-by-medusa/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/lawsuit-news/ransomware-attack-hits-highlands-oncology-exposing-over-113k-patient-info/",
      "https://www.defensorum.com/highlands-oncology-group-ransomware-attack/"
    ],
    "confidence_notes": "Maine AG breach report confirms 113,575 affected; Medusa confirmed by DataBreaches.net; listing removed from leak site suggests possible payment",
    "sources_used": [
      "DataBreaches.net, Top Class Actions, Defensorum"
    ],
    "id": "INC-00710",
    "year": 2025,
    "lat": 36.0822,
    "lng": -94.1719,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Highlands Oncology Group PA \u2013 2025 Medusa Breach",
    "organization_type": "Healthcare Provider (Oncology Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AR",
    "hq_city": "Fayetteville",
    "hq_county": "Washington",
    "discovery_date": "2025-06-02",
    "disclosure_date": "2025-08-01",
    "executive_summary": "Highlands Oncology Group suffered a second major breach when the Medusa ransomware group gained access to its network between January 21 and June 2, 2025. Medusa demanded $700,000, adding Highlands to its leak site with a countdown clock. 113,575 individuals were affected. Data included names, DOBs, SSNs, driver's licenses, passport numbers, financial data, medical treatment information, and health insurance data.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Medusa",
    "attribution_status": "claimed",
    "individuals_affected_reported": 113575,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$700,000 ransom demanded; payment status unknown",
    "operational_impact": "Files encrypted; network access for 4+ months",
    "remediation_disclosed": "Additional security measures implemented; notifications mailed August 1, 2025",
    "primary_source_url": "https://databreaches.net/2025/08/02/highlands-oncology-group-notifies-113575-people-after-ransomware-attack-by-medusa/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/lawsuit-news/ransomware-attack-hits-highlands-oncology-exposing-over-113k-patient-info/",
      "https://www.classaction.org/data-breach-lawsuits/highlands-oncology-group-august-2025"
    ],
    "confidence_notes": "HHS OCR filing confirms 113,575. Medusa attribution from DataBreaches.net and Top Class Actions.",
    "sources_used": [
      "DataBreaches.net",
      "Top Class Actions",
      "ClassAction.org"
    ],
    "id": "INC-00711",
    "year": 2025,
    "lat": 36.0822,
    "lng": -94.1719,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Hoag Memorial Hospital Presbyterian (via ALN Medical Management breach)",
    "organization_type": "Nonprofit community hospital and health system",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Newport Beach",
    "hq_county": "Orange County",
    "discovery_date": "2024-03-18",
    "disclosure_date": "2025-03-21",
    "executive_summary": "Between March 18 and 24, 2024, an unauthorized actor accessed files hosted by ALN Medical Management (ALN) \u2014 a third-party revenue cycle and billing services provider \u2014 via ALN's own third-party provider's systems. Hoag Clinic was among multiple ALN clients whose patient data was exposed. Exposed data included names, DOBs, SSNs, driver's license numbers, financial account information, payment card details, health insurance information, and medical information. ALN began notifying affected Hoag Clinic patients on March 21, 2025 \u2014 approximately one year after the breach.",
    "attack_type": "Hacking / unauthorized data access (via business associate ALN Medical Management's third-party provider)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": "NOT_PUBLICLY_DISCLOSED",
    "residents_affected_in_state": "Primarily CA (Orange County Hoag patients)",
    "financial_impact": "{'notes': '24 months of free IDX credit monitoring and identity theft protection offered.'}",
    "operational_impact": "No clinical disruption reported (billing/revenue cycle vendor breach).",
    "remediation_disclosed": "ALN investigated and notified Hoag Clinic; 24-month IDX credit monitoring offered to affected individuals.",
    "primary_source_url": "https://www.claimdepot.com/data-breach/hoag-clinic",
    "secondary_source_urls": [],
    "confidence_notes": "Note: The breach hit ALN's third-party provider's systems (not ALN's internal systems or Hoag's systems directly). One-year delay from breach (Mar 2024) to notification (Mar 2025). Enrollment deadline June 21, 2025. Hoag Clinic operates separately from Hoag Hospital main campus.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00712",
    "year": 2025,
    "lat": 33.6189,
    "lng": -117.9298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "HopeHealth, Inc.",
    "organization_type": "Healthcare Provider / Federally Qualified Health Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Florence",
    "hq_county": "Florence",
    "discovery_date": "2025-03-20",
    "disclosure_date": "2025-07-15",
    "executive_summary": "HopeHealth, a Federally-Qualified Health Center serving patients in Florence, Clarendon, Darlington, Williamsburg, Aiken, and Orangeburg Counties in South Carolina, reported a network intrusion identified on or around March 20, 2025. Investigation confirmed unauthorized access March 19-20, 2025. Exposed information included names, SSNs, DOBs, driver's license numbers, medical information, health insurance information, financial account information, and credit card information. SC Consumer Affairs listed 1,625 SC residents affected.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1625,
    "residents_affected_in_state": 1625,
    "financial_impact": "Not publicly disclosed; 12 months single bureau credit monitoring offered",
    "operational_impact": "Extensive PII and PHI potentially accessed including financial account and credit card data",
    "remediation_disclosed": "Network secured; forensic investigation; 12 months credit monitoring offered; SC AG notified July 2025",
    "primary_source_url": "https://www.hipaajournal.com/south-carolina-healthcare-providers-hacking-incidents/",
    "secondary_source_urls": [
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal reporting on SC healthcare providers; SC Consumer Affairs listing.",
    "sources_used": [
      "HIPAA Journal",
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00713",
    "year": 2025,
    "lat": 34.1984435,
    "lng": -79.7671658,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Illinois Department of Human Services \u2014 Medicaid Data Exposure",
    "organization_type": "State Government / Medicaid Program",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IL",
    "hq_city": "Springfield",
    "hq_county": "Sangamon",
    "discovery_date": "2025-09-22",
    "disclosure_date": "2025-12-31",
    "executive_summary": "The Illinois Department of Human Services (IDHS) discovered September 22, 2025 that mapping website tools had incorrect privacy settings exposing sensitive data publicly for years. Approximately 672,616 Medicaid and Medicare Savings Program recipients had addresses, case numbers, demographic information, and medical assistance plan names exposed online between January 2022 and September 2025. Additionally, approximately 32,401 Division of Rehabilitation Services customers had names, addresses, case numbers, and status exposed from April 2021 through September 2025. IDHS reported it was unaware of any misuse. HHS OCR was notified.",
    "attack_type": "Unauthorized Data Exposure (misconfigured privacy settings)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not applicable \u2014 inadvertent public exposure",
    "attribution_status": "unknown",
    "individuals_affected_reported": 704000,
    "residents_affected_in_state": 704000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Long-term public data exposure; no clinical operational disruption",
    "remediation_disclosed": "Yes \u2014 privacy settings corrected September 22, 2025; notifications mailed to affected individuals; HHS OCR notified",
    "primary_source_url": "https://www.hipaajournal.com/illinois-department-of-human-services-data-breach-2025/",
    "secondary_source_urls": [
      "https://www.nprillinois.org/illinois/2026-01-06/health-care-data-breach-affects-600-000-patients-illinois-agency-says"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, NPR Illinois (WUIS).",
    "sources_used": [
      "HIPAA Journal",
      "NPR Illinois/WUIS"
    ],
    "id": "INC-00714",
    "year": 2025,
    "lat": 39.7817,
    "lng": -89.6501,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kettering Health",
    "organization_type": "Healthcare Provider / Hospital Network",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Dayton",
    "hq_county": "Montgomery",
    "discovery_date": "2025-05-20",
    "disclosure_date": "2025-07-21",
    "executive_summary": "Interlock ransomware group gained access to Kettering Health's network on April 9, 2025, and deployed ransomware on May 20, 2025, causing a system-wide outage across all 14 medical centers and 120+ outpatient facilities in western Ohio. The attack disrupted Epic EHR access, forced ambulance diversions, and canceled elective procedures. Interlock exfiltrated 941 GB of data including 732,490 files before encrypting systems. The breach affected 1.7 million individuals per April 2026 update, exposing names, SSNs, medical information, health insurance details, financial account information, and driver's license numbers. Multiple class-action lawsuits were filed.",
    "attack_type": "Ransomware / Double Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1700000,
    "residents_affected_in_state": "Primarily Ohio; not separately broken out",
    "financial_impact": "Not publicly disclosed; class-action lawsuits filed in Montgomery County; significant operational and recovery costs",
    "operational_impact": "System-wide outage across all 14 medical centers; ambulance diversions; elective procedure cancellations; Epic EHR offline ~2 weeks; phone and patient portal disruptions",
    "remediation_disclosed": "Network segmentation enhanced; updated access controls; Epic EHR restored June 2, 2025; all systems restored by mid-June 2025; ransomware eradicated and security enhancements implemented",
    "primary_source_url": "https://www.hipaajournal.com/kettering-health-ransomware-attack/",
    "secondary_source_urls": [
      "https://ketteringhealth.org/cybersecurity-incident-faq/",
      "https://databreaches.net/2026/02/12/kettering-adventist-health-now-notifying-patients-affected-by-may-2025-ransomware-attack/",
      "https://www.paubox.com/blog/lawsuits-filed-after-kettering-health-ransomware-attack-disrupted-patient-care",
      "https://www.hipaajournal.com/kettering-health-ransomware-attack/",
      "https://databreach.com/breach/kettering-health-2025",
      "https://yourlegalhelp.com/2026/03/05/44-lawsuits-now-filed-against-kettering-health-over-2025-cyberattack/"
    ],
    "confidence_notes": "High confidence. Kettering Health confirmed the breach publicly. HIPAA Journal tracked through multiple updates. OCR breach report filed July 21, 2025. Final patient count of 1.7 million confirmed in April 2026 HIPAA Journal update. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "CNN",
      "DataBreach.com",
      "DataBreaches.net",
      "HHS OCR breach portal",
      "HIPAA Journal",
      "Kettering Health official FAQ",
      "Kettering Health official FAQ page",
      "Paubox",
      "Wright & Schulte LLC"
    ],
    "id": "INC-00715",
    "year": 2025,
    "lat": 39.7589,
    "lng": -84.1916,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Kettering Health (Kettering Adventist Healthcare)",
    "organization_type": "Nonprofit Health System (14 medical centers, western Ohio)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OH",
    "hq_city": "Dayton",
    "hq_county": "Montgomery",
    "discovery_date": "2025-05-20",
    "disclosure_date": "2025-05-21",
    "executive_summary": "The Interlock ransomware group first accessed Kettering Health's network on April 9, 2025, and maintained access until detection on May 20, 2025. On May 20, Interlock deployed ransomware causing a system-wide outage at all 14 medical centers, forcing cancellation of all scheduled procedures and activation of paper-based downtime protocols. Emergency rooms remained open. Interlock claimed to have exfiltrated ~941 GB of data (732,490 files) and published it on its dark web leak site on June 5, 2025 after no ransom was paid. Epic EHR restored June 2; normal operations resumed June 10. The breach ultimately affected 1.7 million individuals per HIPAA Journal reporting (HHS OCR placeholder of 501 as of July 2025). 44+ lawsuits filed.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Interlock",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 1700000,
    "residents_affected_in_state": "Primarily Ohio residents",
    "financial_impact": "Not publicly disclosed; 44+ lawsuits consolidated",
    "operational_impact": "System-wide outage at 14 medical centers; all scheduled procedures cancelled; ambulance diversions; call center disrupted; paper-based operations for ~3 weeks",
    "remediation_disclosed": "Yes \u2014 ransomware eradicated June 5; all patches applied; network segmentation enhanced; Epic restored June 2; normal operations June 10",
    "primary_source_url": "https://www.hipaajournal.com/kettering-health-ransomware-attack/",
    "secondary_source_urls": [
      "https://databreach.com/breach/kettering-health-2025",
      "https://www.campussafetymagazine.com/news/ransomware-attack-shuts-down-14-ohio-medical-centers/170708/",
      "https://yourlegalhelp.com/2026/03/05/44-lawsuits-now-filed-against-kettering-health-over-2025-cyberattack/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal tracking, CNN ransom note, Interlock dark web claim, 44 lawsuits filed.",
    "sources_used": [
      "HIPAA Journal",
      "DataBreach.com",
      "Campus Safety Magazine",
      "Wright & Schulte LLC"
    ],
    "id": "INC-00716",
    "year": 2025,
    "lat": 39.7589,
    "lng": -84.1916,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "LCMC Health (via Restorix Business Associate)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "LA",
    "hq_city": "New Orleans",
    "hq_county": "Orleans Parish",
    "discovery_date": "2024-05-30",
    "disclosure_date": "2025-02-14",
    "executive_summary": "Three LCMC Health hospitals (East Jefferson General Hospital, Touro Infirmary, New Orleans East Hospital) were impacted by a data breach at Restorix Health, a wound care business associate. An unauthorized actor accessed a Restorix employee email account between May 7 and May 29, 2024. PHI was discovered in the account on November 27, 2024. Data included names, DOBs, SSNs, government IDs, medical info, and health insurance data.",
    "attack_type": "Business Email Compromise / Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI of patients at 3 LCMC hospitals exposed via vendor email account",
    "remediation_disclosed": "LCMC notified December 18, 2024; notifications mailed February 14, 2025",
    "primary_source_url": "https://www.lcmchealth.org/blog/2025/february/restorix-notice-of-data-security-incident/",
    "secondary_source_urls": [],
    "confidence_notes": "Official LCMC Health notice is primary source. Number of affected individuals not yet specified in public sources.",
    "sources_used": [
      "LCMC Health (official website)"
    ],
    "id": "INC-00717",
    "year": 2025,
    "lat": 29.9511,
    "lng": -90.0715,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "LCMC Health / Oracle Health (Cerner) Legacy Servers",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "LA",
    "hq_city": "New Orleans",
    "hq_county": "Orleans Parish",
    "discovery_date": "2025-02-20",
    "disclosure_date": "2025-04-01",
    "executive_summary": "East Jefferson Hospital (LCMC Health, Metairie, LA) was identified as affected by the Oracle Health data breach involving unauthorized access to legacy Cerner server systems. Access began around January 22, 2025 and was discovered February 20, 2025. PHI including names, SSNs, medical records, and clinical information may have been exposed. Oracle Health and healthcare providers were in the process of notifying impacted patients.",
    "attack_type": "Unauthorized Access to Legacy EHR (Cerner) Servers",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Legacy Cerner systems compromised; potential patient data exposure",
    "remediation_disclosed": "Oracle Health and LCMC notifying patients; investigation ongoing",
    "primary_source_url": "https://www.stuevesiegel.com/what-investigations-lcmc-health-east-jefferson-hospital-oracle-cerner-data-breach",
    "secondary_source_urls": [],
    "confidence_notes": "Law firm investigation website confirms LCMC/East Jefferson among affected institutions. Number of affected not yet specified.",
    "sources_used": [
      "Stueve Siegel Hanson LLP"
    ],
    "id": "INC-00718",
    "year": 2025,
    "lat": 29.9511,
    "lng": -90.0715,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "LCMC Health / Willis-Knighton Health System (Meta Pixel)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "LA",
    "hq_city": "New Orleans",
    "hq_county": "Orleans Parish",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2025-06-04",
    "executive_summary": "Class action lawsuits filed in 2025 allege that LCMC Health and Willis-Knighton Health System used Meta Pixel tracking code on their websites and patient portals, transmitting patient PHI (medical conditions, prescriptions, doctor names, appointments) to Facebook/Meta without patient consent. This constitutes an impermissible disclosure of PHI in violation of HIPAA.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (Meta Pixel tracking)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Pending litigation",
    "operational_impact": "Unauthorized disclosure of patient PHI to Meta/Facebook",
    "remediation_disclosed": "Pixel code reportedly removed; litigation ongoing",
    "primary_source_url": "https://hkgclaw.com/firm/louisiana-hospitals-hit-with-class-action-lawsuits-over-sharing-patients-data/",
    "secondary_source_urls": [],
    "confidence_notes": "Class action lawsuit filed; details from plaintiff law firm. No HHS OCR breach report confirmed at time of research.",
    "sources_used": [
      "Herman, Katz, Gisleson & Cain (HKG Law)"
    ],
    "id": "INC-00719",
    "year": 2025,
    "lat": 29.9511,
    "lng": -90.0715,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Laboratory Services Cooperative (LSC)",
    "organization_type": "Healthcare Provider / Business Associate (Clinical Laboratory serving Planned Parenthood)",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2024-10-27",
    "disclosure_date": "2025-04-10",
    "executive_summary": "Laboratory Services Cooperative (LSC), a Seattle-based nonprofit independent clinical laboratory serving Planned Parenthood centers in more than 30 states, detected suspicious activity on its network on October 27, 2024. An investigation confirmed an unauthorized third party had accessed and acquired certain files containing the personal and health information of approximately 1.6 million individuals \u2014 primarily Planned Parenthood patients and some LSC employees/dependents. Compromised data included names, Social Security numbers, driver's license numbers, passport numbers, dates of birth, financial account information, medical diagnoses, insurance information, and other sensitive details. Two class-action lawsuits were filed in U.S. District Court for the Western District of Washington.",
    "attack_type": "Hacking / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1600000,
    "residents_affected_in_state": 30,
    "financial_impact": "Class action lawsuits pending; financial impact not yet publicly resolved",
    "operational_impact": "Patient and employee data exfiltrated; widespread notification required across 30+ states",
    "remediation_disclosed": "Network secured; cybersecurity experts retained; federal authorities notified; credit monitoring and identity theft protection offered",
    "primary_source_url": "https://www.hipaajournal.com/laboratory-services-cooperative-data-breach/",
    "secondary_source_urls": [
      "https://www.jdsupra.com/legalnews/laboratory-services-cooperative-data-9483682/",
      "https://www.classaction.org/data-breach-lawsuits/laboratory-services-cooperative-april-2025",
      "https://topclassactions.com/lawsuit-settlements/lawsuit-news/planned-parenthood-data-breach-exposed-1-6m-patients-info-class-actions-claim/"
    ],
    "confidence_notes": "High confidence: LSC official notice published April 10, 2025; HIPAA Journal confirms ~1.6 million affected; two class actions filed in WDWA federal court",
    "sources_used": [
      "HIPAA Journal",
      "JD Supra",
      "ClassAction.org",
      "Top Class Actions"
    ],
    "id": "INC-00720",
    "year": 2025,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Lake Region Healthcare \u2014 2025 Worldleaks Ransomware",
    "organization_type": "Regional Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Fergus Falls",
    "hq_county": "Otter Tail",
    "discovery_date": "2025-06-01",
    "disclosure_date": "2025-06-12",
    "executive_summary": "Lake Region Healthcare was listed by the Worldleaks ransomware group as a victim in June 2025, representing a second ransomware attack on the Minnesota health system following the December 2020 incident (MW-023). Details of compromised information and patient count were not publicly confirmed in available sources.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Worldleaks ransomware",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Minnesota patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly confirmed",
    "remediation_disclosed": "Not publicly confirmed",
    "primary_source_url": "https://www.hookphish.com/blog/ransomware-group-worldleaks-hits-lake-region-healthcare/",
    "secondary_source_urls": [],
    "confidence_notes": "Low-moderate confidence. HookPhish reporting of Worldleaks claim; not yet confirmed by Lake Region Healthcare or HHS OCR.",
    "sources_used": [
      "HookPhish"
    ],
    "id": "INC-00721",
    "year": 2025,
    "lat": 46.283015,
    "lng": -96.077558,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Marshfield Clinic Health System \u2014 2025 Breach",
    "organization_type": "Nonprofit Integrated Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WI",
    "hq_city": "Marshfield",
    "hq_county": "Wood",
    "discovery_date": "2025-08-27",
    "disclosure_date": "2025-11-07",
    "executive_summary": "Marshfield Clinic Health System, a major Wisconsin nonprofit health system serving Wisconsin and Michigan's Upper Peninsula, discovered that an unauthorized actor accessed certain employee email accounts on or around August 26\u201327, 2025, copying and removing emails containing patient information. The breach was disclosed to HHS on November 7, 2025. Approximately 35,952 individuals were affected. Compromised data included names, medical record numbers, health insurance information, diagnosis, and treatment information. Notification letters began in late November 2025.",
    "attack_type": "Email Account Compromise / Unauthorized Access",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 35952,
    "residents_affected_in_state": "Primarily Wisconsin residents; also Michigan Upper Peninsula patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Email accounts compromised; patient data copied and removed",
    "remediation_disclosed": "Yes \u2014 investigation launched; HHS notified November 7, 2025; patient notifications late November 2025",
    "primary_source_url": "https://www.claimdepot.com/data-breach/marshfield-clinic-2025",
    "secondary_source_urls": [
      "https://shublawyers.com/current-investigations/marshfield-clinic-health-system-data-breach-investigation/"
    ],
    "confidence_notes": "High confidence. Claim Depot citing HHS OCR breach portal (35,952), Shub Law investigation.",
    "sources_used": [
      "Claim Depot",
      "Shub Johns & Holbrook LLP"
    ],
    "id": "INC-00722",
    "year": 2025,
    "lat": 44.6688,
    "lng": -90.1718,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Mayo Clinic (email breach reported March 2025)",
    "organization_type": "Nonprofit Academic Medical Center / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MN",
    "hq_city": "Rochester",
    "hq_county": "Olmsted",
    "discovery_date": "2025-03-01",
    "disclosure_date": "2025-03-28",
    "executive_summary": "Mayo Clinic reported a data breach categorized as unauthorized email access to the HHS OCR on or about March 28, 2025. Limited details are publicly available. Additionally, in October 2025, reports indicated Mayo Clinic phone lines were affected by ransomware attacks impacting individual departments. The scale of any 2025 ransomware impact on Mayo Clinic had not been confirmed in detail as of available sources.",
    "attack_type": "Unauthorized Email Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not publicly confirmed",
    "residents_affected_in_state": "Minnesota patients primarily",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Email access breach; some phone system disruption in 2025",
    "remediation_disclosed": "Not publicly confirmed in detail",
    "primary_source_url": "https://datacentral.desmoinesregister.com/health-care-data-breaches/mayo-clinic-mn-1869-20250328-unauthorized-email/",
    "secondary_source_urls": [],
    "confidence_notes": "Low-moderate confidence. HHS OCR breach data reference in Des Moines Register health data tracker; limited detail available.",
    "sources_used": [
      "Des Moines Register HHS Data Tracker"
    ],
    "id": "INC-00723",
    "year": 2025,
    "lat": 44.0121,
    "lng": -92.4802,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "McKenzie Health System (McKenzie Memorial Hospital) \u2014 2025 Breach",
    "organization_type": "Critical Access Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Sandusky",
    "hq_county": "Sanilac",
    "discovery_date": "2025-04-15",
    "disclosure_date": "2025-07-24",
    "executive_summary": "McKenzie Memorial Hospital suffered a second significant cyber incident, detected on or about April 15, 2025. An unauthorized actor accessed certain files on the hospital's network between April 14\u201315, 2025. Approximately 54,016 individuals were affected, with exposed data including names, Social Security numbers, and financial account information. The disclosure was submitted to the Maine AG on July 24, 2025. This was the second breach in three years for this critical access hospital, raising significant concerns about the persistent vulnerability of small rural hospitals.",
    "attack_type": "Unauthorized Network Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 54016,
    "residents_affected_in_state": "Michigan residents primarily",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not fully disclosed; network security measures strengthened",
    "remediation_disclosed": "Yes \u2014 third-party forensic investigation, network security strengthened, credit monitoring offered",
    "primary_source_url": "https://cybernews.com/privacy/mckenzie-memorial-hospital-data-breach/",
    "secondary_source_urls": [
      "https://databreaches.net/2025/07/28/two-data-breaches-in-three-years-mckenzie-health/",
      "https://hipaatimes.com/michigan-hospital-hack-exposes-over-54000-patient-records"
    ],
    "confidence_notes": "High confidence. Cybernews, DataBreaches.Net, HIPAA Times reporting. Maine AG filing confirmed.",
    "sources_used": [
      "Cybernews",
      "DataBreaches.Net",
      "HIPAA Times",
      "Maine AG"
    ],
    "id": "INC-00724",
    "year": 2025,
    "lat": 43.420299,
    "lng": -82.829657,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "McLaren Health Care Corporation \u2014 2024 Inc Ransom Attack",
    "organization_type": "Nonprofit Integrated Health System (12 hospitals)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Grand Blanc",
    "hq_county": "Genesee",
    "discovery_date": "2024-08-04",
    "disclosure_date": "2025-06-26",
    "executive_summary": "Less than a year after the 2023 BlackCat attack, McLaren Health Care suffered a second ransomware attack attributed to the Inc Ransom group. Attackers accessed systems from July 17, 2024 to August 3, 2024, affecting 743,131 individuals. The attack was described by staff as more disruptive than the first, causing outages at Karmanos Cancer Institute and 12 hospitals. McLaren did not begin notifying patients until June 2025 \u2014 10 months after discovery. The $14 million settlement covers both 2023 and 2024 incidents combined.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Inc Ransom",
    "attribution_status": "unknown",
    "individuals_affected_reported": 743131,
    "residents_affected_in_state": "Primarily Michigan residents",
    "financial_impact": "Covered under combined $14M settlement with 2023 incident",
    "operational_impact": "Major disruption at 12 hospitals and 113,000-provider network; ambulance diversions; patient care delays across Michigan, Indiana, and Ohio operations",
    "remediation_disclosed": "Yes \u2014 investigation completed May 2025; notifications issued June 2025; security enhancements mandated under settlement",
    "primary_source_url": "https://bridgemi.com/michigan-health-watch/ten-months-later-mclaren-reveals-740000-impacted-ransomware-attack/",
    "secondary_source_urls": [
      "https://www.itcpeacademy.org/blog/news-mclaren-health-care-to-pay-14-million-over-back-to-back-ransomware-attacks",
      "https://compliancejunction.com/mclaren-health-care-settles-data-breach-lawsuit-for-14-million/"
    ],
    "confidence_notes": "High confidence. Bridge Michigan investigative reporting; settlement filings confirm victim count.",
    "sources_used": [
      "Bridge Michigan",
      "ITCP Academy",
      "ComplianceJunction"
    ],
    "id": "INC-00725",
    "year": 2025,
    "lat": 42.9275,
    "lng": -83.6299,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Medical Associates of Brevard",
    "organization_type": "Healthcare Provider (Multi-Specialty Group)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "FL",
    "hq_city": "Brevard County",
    "hq_county": "Brevard",
    "discovery_date": "2025-01-17",
    "disclosure_date": "2025-09-01",
    "executive_summary": "Medical Associates of Brevard confirmed a ransomware attack by the BianLian cybercrime group on January 17, 2025. BianLian claimed to have stolen accounting/HR data, personal/health records, email correspondence, and other sensitive files. The breach affected 246,711 patients.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "BianLian",
    "attribution_status": "claimed",
    "individuals_affected_reported": 246711,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient records, HR data, and email data stolen",
    "remediation_disclosed": "Investigation launched; HHS OCR notified",
    "primary_source_url": "https://hipaatimes.com/medical-associates-of-brevard-exposes-data-of-nearly-247000-in-ransomware-attack",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Times / Paubox reports 246,711 affected. BianLian claim widely reported.",
    "sources_used": [
      "HIPAA Times / Paubox"
    ],
    "id": "INC-00726",
    "year": 2025,
    "lat": 28.2100203,
    "lng": -80.7997185,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "NFI North (ME notification)",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NH",
    "hq_city": "Woburn",
    "hq_county": "Middlesex",
    "discovery_date": "2025-09-01",
    "disclosure_date": "2025-11-13",
    "executive_summary": "NFI North, a New Hampshire-based behavioral health provider operating across New England, reported a data security incident to the Maine AG in November 2025. The breach involved unauthorized access to client behavioral health records.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Behavioral health client records across New England potentially compromised",
    "remediation_disclosed": "Maine AG notified; affected clients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing November 13, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00727",
    "year": 2025,
    "lat": 42.9214622,
    "lng": -71.4974992,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "NKC Health (North Kansas City Hospital) via Oracle Health/Cerner",
    "organization_type": "Healthcare Provider / Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "North Kansas City",
    "hq_county": "Clay",
    "discovery_date": "2025-02-20",
    "disclosure_date": "2025-12-02",
    "executive_summary": "North Kansas City Hospital (NKC Health) was identified as one of multiple healthcare providers affected by a data breach involving Oracle Health (formerly Cerner Corporation). An unauthorized third party gained access to legacy Cerner servers starting approximately January 22, 2025, with the breach discovered on February 20, 2025. The breach potentially exposed patient names, dates of birth, Cerner patient identifiers, medical record numbers, doctor information, diagnoses, medicines, test results, imaging, and details of care and treatment. The full scope of affected individuals was not specified. This is separate from the 2023 PJ&A breach at NKCH (MW-157).",
    "attack_type": "Hacking / Unauthorized Server Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Legacy Cerner server data accessed; NKC Health's own systems were not directly breached",
    "remediation_disclosed": "Oracle Health/Cerner worked with federal law enforcement; breach notifications issued; dedicated patient helpline established (1-833-990-3687)",
    "primary_source_url": "https://www.claimdepot.com/data-breach/nkc-health-2025",
    "secondary_source_urls": [
      "https://www.stuevesiegel.com/what-investigations-north-kansas-city-hospital-cerner-oracle-data-breach"
    ],
    "confidence_notes": "High confidence for the Oracle Health/Cerner breach. NKC Health published breach notice and established patient helpline. Part of the broader Oracle Health/Cerner breach affecting multiple health systems nationally. Patient count not yet confirmed.",
    "sources_used": [
      "Claim Depot breach database",
      "Stueve Siegel Hanson LLP investigation notice",
      "NKC Health patient communications"
    ],
    "id": "INC-00728",
    "year": 2025,
    "lat": 39.1432057,
    "lng": -94.5733988,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "NKC Health / North Kansas City Hospital (via Cerner breach \u2014 2025)",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MO",
    "hq_city": "North Kansas City",
    "hq_county": "Clay",
    "discovery_date": "2025-01-22",
    "disclosure_date": "2025-12-01",
    "executive_summary": "North Kansas City Hospital (NKC Health) reported that Cerner, its electronic medical record vendor, experienced unauthorized access by a third party as early as January 22, 2025. The unauthorized party obtained data including NKC Health patient identifiers, medical record numbers, doctors, diagnoses, medicines, test results, images, and other care details. Cerner/Oracle activated its critical incident response process and engaged external cybersecurity specialists. Federal law enforcement was involved. The number of affected individuals was not yet specified.",
    "attack_type": "Third-Party Vendor Breach (EHR vendor)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Missouri (North Kansas City area) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR vendor's systems breached; NKC Health patient data obtained; federal law enforcement engaged",
    "remediation_disclosed": "Yes \u2014 Cerner secured affected systems; NKC Health patient notifications initiated",
    "primary_source_url": "https://www.claimdepot.com/data-breach/nkc-health-2025",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. Claim Depot reporting; specific patient count not yet confirmed.",
    "sources_used": [
      "Claim Depot"
    ],
    "id": "INC-00729",
    "year": 2025,
    "lat": 39.1432057,
    "lng": -94.5733988,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "New Hampshire Hospital Association",
    "organization_type": "Healthcare Association",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NH",
    "hq_city": "Concord",
    "hq_county": "Mercer",
    "discovery_date": "2025-07-01",
    "disclosure_date": "2025-09-19",
    "executive_summary": "The New Hampshire Hospital Association reported a data security incident to the Maine AG in September 2025. The breach involved unauthorized access to member and employee health-related information managed by the association on behalf of NH hospitals.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Hospital association member data potentially compromised",
    "remediation_disclosed": "Maine AG notified; affected individuals notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing September 19, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00730",
    "year": 2025,
    "lat": 43.2081,
    "lng": -71.5376,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Next Step Healthcare LLC (MA/NH)",
    "organization_type": "Healthcare Provider (Post-Acute)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Woburn",
    "hq_county": "Middlesex",
    "discovery_date": "2025-03-01",
    "disclosure_date": "2025-05-30",
    "executive_summary": "Next Step Healthcare LLC, a Massachusetts-based post-acute care provider operating multiple facilities in MA and NH, reported a data security incident to the Maine AG in May 2025. The breach involved unauthorized access to patient health and financial information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Post-acute care patient data potentially compromised",
    "remediation_disclosed": "Maine AG notified; patients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing May 30, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00731",
    "year": 2025,
    "lat": 42.4792618,
    "lng": -71.1522766,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Northwell Health - Hidden Camera Incident (2022-2024)",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New Hyde Park",
    "hq_county": "Nassau",
    "discovery_date": "2024-04-23",
    "disclosure_date": "2025-05-22",
    "executive_summary": "A former Northwell Health employee (Sanjai Syamaprasad) secretly installed hidden cameras disguised as smoke detectors in restrooms at the Northwell Sleep Disorder Center and STARS Rehabilitation Center in Great Neck, NY between August 2022 and April 2024, recording over 20,000 patients and staff. The surveillance was a cyber intrusion involving unauthorized recording devices. Northwell was indicted; Nassau County DA investigated. Northwell delayed notifying over 20,000 potential victims for more than a year after evidence was secured.",
    "attack_type": "Unauthorized cyber-physical surveillance (hidden cameras/recording devices)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Sanjai Syamaprasad (former Northwell employee)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 20880,
    "residents_affected_in_state": 20880,
    "financial_impact": "Class action pending; significant reputational harm",
    "operational_impact": "Patients, employees, and minors secretly recorded in private areas; notification delayed 13+ months",
    "remediation_disclosed": "Employee terminated; Nassau County DA investigation; indictment on 5 counts unlawful surveillance; class action filed",
    "primary_source_url": "https://giannicriminallaw.com/northwell-health-lawsuit/",
    "secondary_source_urls": [],
    "confidence_notes": "Nassau County DA indictment; notification letters sent May 2025; class action filed. Note: Cyber-physical incident, included as unauthorized access/cyber",
    "sources_used": [
      "Gianni Karmily Law Firm"
    ],
    "id": "INC-00732",
    "year": 2025,
    "lat": 40.7352157,
    "lng": -73.6883239,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Northwest Radiologists / Mount Baker Imaging",
    "organization_type": "Healthcare Provider (Radiology Practice)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "WA",
    "hq_city": "Bellingham",
    "hq_county": "Whatcom",
    "discovery_date": "2025-01-25",
    "disclosure_date": "2025-03-26",
    "executive_summary": "Northwest Radiologists and its joint venture Mount Baker Imaging experienced a network disruption (confirmed as ransomware) between January 20 and January 25, 2025. Approximately 348,118 Washington State residents were affected, with data including names, addresses, Social Security numbers, driver's license numbers, dates of birth, medical record numbers, diagnosis and treatment information, health insurance data, and financial/banking details compromised. Four class-action lawsuits were filed and consolidated in Whatcom County Superior Court.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 348118,
    "residents_affected_in_state": 348118,
    "financial_impact": "Class-action settlement proposed; amount not publicly disclosed",
    "operational_impact": "Network disruption affecting radiology systems across multiple locations in Whatcom County and Ketchikan, AK",
    "remediation_disclosed": "Systems secured; law enforcement notified; credit monitoring and identity protection offered",
    "primary_source_url": "https://www.securityweek.com/northwest-radiologists-data-breach-impacts-350000-washingtonians/",
    "secondary_source_urls": [
      "https://securityaffairs.com/180772/data-breach/northwest-radiologists-data-breach-hits-350000-in-washington.html",
      "https://whatcom-news.com/bellingham-businesses-propose-settlement-in-data-breach-class-action-suit_235490/"
    ],
    "confidence_notes": "WA AG notification confirmed 348,118 WA residents; ransomware confirmed by court documents; also operates in AK",
    "sources_used": [
      "SecurityWeek",
      "Security Affairs",
      "Whatcom News"
    ],
    "id": "INC-00733",
    "year": 2025,
    "lat": 48.7544012,
    "lng": -122.478836,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Nursing Resources of Syracuse (NRS) / Albany College",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "Syracuse",
    "hq_county": "Onondaga",
    "discovery_date": "2024-07-11",
    "disclosure_date": "2025-05-12",
    "executive_summary": "Nursing Resources of Syracuse (NRS), a New York-based healthcare staffing and homecare agency, was hacked between July 5-11, 2024. Files containing PHI were copied by an unauthorized party. The breach also impacted Albany College of Pharmacy's county EMS data. Data compromised included names, SSNs, DOBs, medical information, and account balances for approximately 166,953 individuals.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 166953,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "166K+ individuals' health data compromised including county EMS data",
    "remediation_disclosed": "HHS OCR breach filed; affected individuals notified",
    "primary_source_url": "https://www.hipaajournal.com/albany-college-pharmacy-health-sciences-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "OCR breach report; HIPAA Journal reporting on NRS breach affecting Albany College EMS data",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00734",
    "year": 2025,
    "lat": 43.0481,
    "lng": -76.1474,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "OU Medicine / OU Health (2024 email breach)",
    "organization_type": "Healthcare Provider (Academic Medical Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2024-10-18",
    "disclosure_date": "2025-02-01",
    "executive_summary": "OU Medicine in Oklahoma confirmed that an unauthorized third party accessed two employee email accounts containing PHI. Detection occurred October 18, 2024; on November 18, 2024 OU Medicine learned files in the accounts had likely been viewed or acquired. 2,537 individuals were affected. Compromised data varied but may have included names, dates of birth, diagnoses, lab results, medication information, SSNs, and billing information. Credit monitoring was offered to SSN-affected individuals.",
    "attack_type": "Hacking/IT Incident \u2013 Email Account Compromise",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2537,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Accounts secured; cybersecurity professionals assisted; email security and internal controls enhanced",
    "primary_source_url": "https://www.hipaajournal.com/24400-individuals-affected-5-healthcare-data-breaches/",
    "secondary_source_urls": [
      "https://www.federmanlaw.com/blog/federman-sherwood-investigates-ou-medicine-inc-ou-health-for-data-breach/"
    ],
    "confidence_notes": "High confidence; HIPAA Journal confirmed OCR report; Federman & Sherwood investigating",
    "sources_used": [
      "HIPAA Journal, Federman & Sherwood law firm"
    ],
    "id": "INC-00735",
    "year": 2025,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Ochsner LSU Health System \u2013 Regional Urology",
    "organization_type": "Healthcare Provider (Specialty Clinic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "LA",
    "hq_city": "Shreveport",
    "hq_county": "Caddo Parish",
    "discovery_date": "2025-10-10",
    "disclosure_date": "2025-12-09",
    "executive_summary": "Ochsner LSU Health \u2013 Regional Urology disclosed that an unauthorized party accessed retired, decommissioned Cerner systems (taken offline in late 2022) between October 5 and some date in 2025. Attackers downloaded data from these legacy systems. 4,519 patients were affected. Data included names, SSNs, DOBs, medical records, medical imaging, and treatment details prior to December 31, 2022.",
    "attack_type": "Unauthorized Access to Decommissioned/Legacy Systems",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4519,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Legacy Cerner systems accessed; current systems not affected",
    "remediation_disclosed": "Retired systems secured; credit monitoring offered; HHS OCR notified December 9, 2025",
    "primary_source_url": "https://www.hipaajournal.com/wilbarger-general-hospital-ochsner-lsu-health-system-data-breaches/",
    "secondary_source_urls": [
      "https://www.federmanlaw.com/blog/ochsner-lsu-health-regional-urology-data-breach-investigated-by-federman-sherwood/"
    ],
    "confidence_notes": "HIPAA Journal December 2025 report is primary source. 4,519 confirmed via HHS OCR filing.",
    "sources_used": [
      "HIPAA Journal",
      "Federman & Sherwood"
    ],
    "id": "INC-00736",
    "year": 2025,
    "lat": 32.5252,
    "lng": -93.7502,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "OncoHealth Inc. (cancer patient data)",
    "organization_type": "Business Associate",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "NC",
    "hq_city": "Atlanta",
    "hq_county": "Fulton",
    "discovery_date": "2025-09-01",
    "disclosure_date": "2025-11-20",
    "executive_summary": "OncoHealth, a healthcare technology company providing oncology pharmacy benefit management services to health plans, reported a data security incident to Maine AG in November 2025 affecting cancer patients' treatment and insurance data across NE states.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Oncology patient PHI potentially compromised",
    "remediation_disclosed": "Maine AG notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing November 20, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00737",
    "year": 2025,
    "lat": 36.0399789,
    "lng": -79.8071875,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Penquis CAP (ME) - Dual Incidents",
    "organization_type": "Healthcare Provider (Community Action Agency)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Bangor",
    "hq_county": "Penobscot",
    "discovery_date": "2025-04-01",
    "disclosure_date": "2025-06-27",
    "executive_summary": "Penquis CAP, a Maine community action agency providing health and human services, reported data security incidents to the Maine AG in both February and June 2025. The organization provides healthcare and social services to low-income Maine residents. Both incidents involved unauthorized access to client health information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Community health service client data potentially compromised",
    "remediation_disclosed": "Maine AG notified (multiple times); patients notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database shows 2 Penquis entries: Feb 5, 2026 and June 27, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00738",
    "year": 2025,
    "lat": 44.8016,
    "lng": -68.7712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Planned Parenthood of the Great Northwest and the Hawaiian Islands",
    "organization_type": "Healthcare Provider (Reproductive Health Clinic)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Seattle",
    "hq_county": "King",
    "discovery_date": "2024-10-27",
    "disclosure_date": "2025-04-10",
    "executive_summary": "Planned Parenthood of the Great Northwest and the Hawaiian Islands, which operates clinics in Washington, Oregon, Idaho, and Hawaii, was among the Planned Parenthood affiliates whose patient data may have been compromised when Laboratory Services Cooperative (LSC) \u2014 LSC's Seattle headquarters and laboratory operations support Planned Parenthood locations across more than 30 states \u2014 suffered a cyberattack in October 2024. The breach affected up to 1.6 million individuals. WA-029 covers the LSC breach from the laboratory's perspective; this entry captures the specific Planned Parenthood affiliate's notification obligations under the breach. Affected affiliates, including PP Great Northwest, were required to notify patients served by LSC.",
    "attack_type": "Third-party vendor breach (via LSC cyberattack)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1600000,
    "residents_affected_in_state": "WA OR HI Planned Parenthood patients served by LSC",
    "financial_impact": "Class-action lawsuits filed in WDWA federal court; resolution pending",
    "operational_impact": "Reproductive health patient data \u2014 including diagnoses and procedures \u2014 exposed; notification letters sent",
    "remediation_disclosed": "Network secured; credit monitoring offered; federal authorities notified",
    "primary_source_url": "https://www.hipaajournal.com/laboratory-services-cooperative-data-breach/",
    "secondary_source_urls": [
      "https://topclassactions.com/lawsuit-settlements/lawsuit-news/planned-parenthood-data-breach-exposed-1-6m-patients-info-class-actions-claim/"
    ],
    "confidence_notes": "Moderate confidence: PP Great Northwest serves WA/OR/HI; LSC breach confirmed with WA-29 as primary LSC entry; this entry is a covered entity cross-reference for PP affiliate notification. Consider consolidating with WA-029.",
    "sources_used": [
      "HIPAA Journal",
      "Top Class Actions"
    ],
    "id": "INC-00739",
    "year": 2025,
    "lat": 47.6062,
    "lng": -122.3321,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Premera Blue Cross (via Conduent Business Services)",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Mountlake Terrace",
    "hq_county": "Snohomish",
    "discovery_date": "2025-01-13",
    "disclosure_date": "2025-10-23",
    "executive_summary": "Conduent Business Services, a third-party document processing and payment services vendor, suffered a cyberattack in which hackers accessed its network from October 21, 2024 through January 13, 2025. Files containing Premera Blue Cross member information were among the data obtained. Compromised data may include names, Social Security numbers, dates of birth, treatment/diagnosis codes, treatment costs, admission/discharge dates, member ID numbers, and claim numbers. This incident is separate from Premera's 2014 mega-breach. Notification letters were sent to affected Premera members in mid-November 2025.",
    "attack_type": "Data theft / Hacking (via business associate)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Safepay ransomware group (alleged)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 10500000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "$25 million direct costs incurred by Conduent",
    "operational_impact": "Member PHI and insurance claim data exposed",
    "remediation_disclosed": "Two years complimentary credit monitoring and identity protection offered; Conduent systems secured",
    "primary_source_url": "https://healthsource.premera.com/our-perspective/news/conduent-data-security-incident/",
    "secondary_source_urls": [
      "https://www.prnewswire.com/news-releases/premera-blue-cross-responds-to-conduent-data-security-incident-302592987.html",
      "https://www.hipaajournal.com/conduent-business-solutions-data-breach/"
    ],
    "confidence_notes": "Confirmed by Premera official notice and PR Newswire press release; Conduent total impact estimated at 10.5M+ individuals across all clients",
    "sources_used": [
      "Premera Blue Cross official notice",
      "PR Newswire",
      "HIPAA Journal"
    ],
    "id": "INC-00740",
    "year": 2025,
    "lat": 47.7909667,
    "lng": -122.3066395,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Primary Health \u2013 SMMPP / U.S. Healthworks \u2013 SMMPP (Arizona)",
    "organization_type": "Business Associate (Healthcare Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "AZ",
    "hq_city": "Phoenix",
    "hq_county": "Maricopa",
    "discovery_date": "2024-12-13",
    "disclosure_date": "2025-03-04",
    "executive_summary": "Primary Health-SMMPP and U.S. Healthworks-SMMPP, two HIPAA business associates based in Arizona, detected unusual server activity on December 13, 2024. A third-party digital forensics firm confirmed an unauthorized third party may have accessed or copied stored data. Primary Health-SMMPP reported 67,567 individuals affected, U.S. Healthworks-SMMPP reported 10,673. Compromised data included names, dates of birth, dates of service, and in some cases SSNs.",
    "attack_type": "Hacking/IT Incident \u2013 Server Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 78240,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Systems secured; forensic review completed January 7, 2025; OCR notified",
    "primary_source_url": "https://hipaatimes.com/over-70k-records-exposed-in-recent-arizona-data-breach",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; Paubox/HIPAA Times documented; OCR notifications confirmed",
    "sources_used": [
      "Paubox/HIPAA Times"
    ],
    "id": "INC-00741",
    "year": 2025,
    "lat": 33.4484,
    "lng": -112.074,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Providence Mutual Fire Insurance Company (RI) - healthcare data",
    "organization_type": "Health Plan",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "RI",
    "hq_city": "North Scituate",
    "hq_county": "Providence",
    "discovery_date": "2025-05-01",
    "disclosure_date": "2025-07-03",
    "executive_summary": "Providence Mutual Fire Insurance Company in Rhode Island reported a data security incident to the Maine AG in July 2025 affecting policyholder health and personal information. The breach involved unauthorized access to insurance records containing health data.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "RI health insurance policyholder data potentially compromised",
    "remediation_disclosed": "Maine AG notified; policyholders notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing July 3, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00742",
    "year": 2025,
    "lat": 41.8317661,
    "lng": -71.5872858,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Richmond Behavioral Health Authority (RBHA)",
    "organization_type": "Healthcare Provider (Public Mental Health Authority)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "VA",
    "hq_city": "Richmond",
    "hq_county": "Richmond City",
    "discovery_date": "2025-09-30",
    "disclosure_date": "2025-12-18",
    "executive_summary": "Richmond Behavioral Health Authority discovered unauthorized access to its computer systems on approximately September 30, 2025. A forensic investigation confirmed ransomware was deployed on September 29, 2025, encrypting files. The Qilin ransomware group claimed responsibility and published 192 GB of data. 113,232 individuals were affected. Data included names, passport numbers, SSNs, financial account information, and health information.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Qilin",
    "attribution_status": "claimed",
    "individuals_affected_reported": 113232,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Files encrypted; 192 GB of data published on dark web",
    "remediation_disclosed": "Additional safeguards implemented; HHS OCR notified; notifications issued December 2025",
    "primary_source_url": "https://www.hipaajournal.com/richmond-behavioral-health-authority-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "HIPAA Journal December 2025 report. Qilin claim confirmed via leak site screenshots mentioned in article.",
    "sources_used": [
      "HIPAA Journal"
    ],
    "id": "INC-00743",
    "year": 2025,
    "lat": 37.5407,
    "lng": -77.436,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "River City Eye Care",
    "organization_type": "Healthcare Provider (Ophthalmology/Eye Care)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2025-09-08",
    "disclosure_date": "2025-10-16",
    "executive_summary": "River City Eye Care in Oregon detected unusual activity indicating unauthorized network access around September 8, 2025. An investigation revealed that the Genesis hacking group had infiltrated the network and exfiltrated approximately 200 GB of patient data including names, addresses, email addresses, phone numbers, and in some cases, Social Security numbers. Notifications to affected patients began October 16, 2025. The breach had not yet been listed on the HHS OCR breach portal at time of reporting.",
    "attack_type": "Unauthorized network access / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Genesis hacking group",
    "attribution_status": "claimed",
    "individuals_affected_reported": 2025,
    "residents_affected_in_state": "Not separately reported (OR-based practice)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "~200 GB of patient data exfiltrated; names, addresses, SSNs (some) compromised",
    "remediation_disclosed": "Patient notifications Oct 16, 2025; forensic investigation ongoing",
    "primary_source_url": "https://www.hipaajournal.com/hipaa-breaches/",
    "secondary_source_urls": [
      "https://www.reddit.com/r/pwnhub/comments/1odobn2/oregon_eye_care_provider_and_new_york_childrens/"
    ],
    "confidence_notes": "Reported by HIPAA Journal and pwnhub/Reddit; Genesis group claim; specific affected count not yet reported to OCR at time of breach announcement; confidence moderate pending OCR filing",
    "sources_used": [
      "HIPAA Journal",
      "pwnhub (security news aggregator)",
      "Genesis group claim"
    ],
    "id": "INC-00744",
    "year": 2025,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Rockhill Women's Care",
    "organization_type": "OB/GYN Medical Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "MO",
    "hq_city": "Lee's Summit",
    "hq_county": "Jackson",
    "discovery_date": "2025-02-26",
    "disclosure_date": "2025-09-30",
    "executive_summary": "Rockhill Women's Care, an OB/GYN medical practice with locations in Overland Park, Kansas, and Lee's Summit, Missouri, discovered a network security incident on February 26, 2025. An unauthorized party accessed systems containing patient PHI and PII. The Qilin ransomware group claimed responsibility on March 4, 2025, alleging it had stolen approximately 20 GB of data and threatening to release it. A data mining vendor completed its review on August 13, 2025. Approximately 70,129 patients were affected. Exposed data included names, addresses, dates of birth, Social Security numbers, medical treatment information, and health insurance information. Notification letters were mailed beginning September 30, 2025.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Qilin",
    "attribution_status": "claimed",
    "individuals_affected_reported": 70129,
    "residents_affected_in_state": "Missouri and Kansas residents (Lee's Summit MO and Overland Park KS locations)",
    "financial_impact": "Not publicly disclosed; class action investigation filed",
    "operational_impact": "IT systems compromised; patient data exfiltrated; specialized cybersecurity responders engaged",
    "remediation_disclosed": "Yes \u2014 cybersecurity experts engaged immediately, law enforcement notified, data mining review completed August 2025, notifications mailed September 2025, additional security measures implemented",
    "primary_source_url": "https://hipaatimes.com/rockhill-womens-care-reports-data-breach-involving-patient-information",
    "secondary_source_urls": [
      "https://www.claimdepot.com/data-breach/rockhill-womens-care-2025",
      "https://www.barnowlaw.com/rockhill-womens-care-data-breach-investigation/",
      "https://www.hipaajournal.com/september-2025-healthcare-data-breach-report/"
    ],
    "confidence_notes": "High confidence. HIPAA Times, ClaimDepot, Barnow Law, HIPAA Journal September 2025 breach report. HHS OCR confirmed 70,129 individuals.",
    "sources_used": [
      "HIPAA Times",
      "Claim Depot",
      "Barnow Law",
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00745",
    "year": 2025,
    "lat": 38.9107156,
    "lng": -94.3821295,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Rural Health Services (RHS)",
    "organization_type": "Healthcare Provider / Federally Qualified Health Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SC",
    "hq_city": "Aiken",
    "hq_county": "Aiken",
    "discovery_date": "2025-02-13",
    "disclosure_date": "2025-06-20",
    "executive_summary": "Rural Health Services, serving patients in Aiken County, South Carolina, detected a network intrusion on February 13, 2025. Investigation confirmed unauthorized access from January 15 to February 13, 2025. Up to 36,542 patients had their information exposed, including names, SSNs, DOBs, driver's license numbers, passport numbers, financial account numbers, medical records, and health insurance information.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 36542,
    "residents_affected_in_state": 32948,
    "financial_impact": "Not publicly disclosed; 12 months credit monitoring offered",
    "operational_impact": "Patient data including medical history, financial accounts, and SSNs potentially accessed over 29-day intrusion window",
    "remediation_disclosed": "Network secured; law enforcement notified; third-party forensic specialists engaged; 12-month credit monitoring offered",
    "primary_source_url": "https://www.hipaajournal.com/south-carolina-healthcare-providers-hacking-incidents/",
    "secondary_source_urls": [
      "https://ruralhs.org/wp-content/uploads/2025/06/Notice-of-Data-Security-Incident-0625.pdf",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 HIPAA Journal reporting, RHS official breach notice PDF, SC Consumer Affairs listing (32,948 SC residents).",
    "sources_used": [
      "HIPAA Journal",
      "Rural Health Services Official Notice",
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00746",
    "year": 2025,
    "lat": 33.5723191,
    "lng": -81.6182086,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Sacopee Valley Personal Care Agency (ME)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "South Hiram",
    "hq_county": "Oxford",
    "discovery_date": "2025-10-01",
    "disclosure_date": "2025-12-03",
    "executive_summary": "Sacopee Valley Personal Care Agency, a Maine home healthcare provider, reported a data security incident to the Maine AG in December 2025. The breach involved unauthorized access to client personal health information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Home healthcare client data compromised",
    "remediation_disclosed": "Maine AG notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing December 3, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00747",
    "year": 2025,
    "lat": 43.8130358,
    "lng": -70.8771897,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Saint Anthony Hospital (Chicago, IL)",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2025-02-01",
    "disclosure_date": "2025-04-01",
    "executive_summary": "Saint Anthony Hospital in Chicago, Illinois reported an email security incident to HHS OCR in 2025 in which two employee email accounts were compromised, exposing the personal and health information of approximately 146,000 patients. The intrusion occurred in February 2025. Notably, Saint Anthony Hospital had previously been listed on LockBit's dark web data leak site in January 2024, indicating prior targeting by ransomware groups. The 2025 email breach appears to be a separate incident from the 2024 LockBit listing.",
    "attack_type": "Email Account Compromise (two accounts)",
    "attack_category": "Phishing/BEC",
    "threat_actor_name": "Unknown (2025 email breach); LockBit (2024 separate listing)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 146000,
    "residents_affected_in_state": "Illinois residents \u2014 primarily Chicago/Cook County",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient PHI exposed through two compromised employee email accounts",
    "remediation_disclosed": "Partial \u2014 HHS OCR notified; patients notified",
    "primary_source_url": "https://www.securityweek.com/data-breaches-at-healthcare-organizations-in-illinois-and-texas-affect-600000/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. SecurityWeek confirmed via HHS OCR breach tracker. 146,000 individuals confirmed.",
    "sources_used": [
      "SecurityWeek",
      "HHS OCR"
    ],
    "id": "INC-00748",
    "year": 2025,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sanford Health (via Cerner/Oracle Health breach \u2014 2025)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2024-11-01",
    "disclosure_date": "2025-01-22",
    "executive_summary": "Sanford Health, headquartered in Sioux Falls, South Dakota, was among the healthcare organizations affected by the January 2025 Cerner/Oracle Health security incident. Cerner, the EHR vendor used by Sanford Health, experienced an unauthorized access event in which legacy data was compromised during a server migration. Oracle Health confirmed the breach in late January 2025. Sanford Health patients' historical data may have been affected. The exact number of Sanford patients affected was not separately disclosed. This entry tracks the Sanford-specific component of the Oracle/Cerner breach.",
    "attack_type": "Third-Party EHR Vendor Breach (Cerner/Oracle server migration data exposure)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately quantified for Sanford patients",
    "residents_affected_in_state": "South Dakota North Dakota Minnesota and other states served by Sanford",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Legacy patient data potentially compromised during server migration; Sanford EHR operations not disrupted",
    "remediation_disclosed": "Partial \u2014 Oracle notified covered entities January 2025; Sanford notifying affected patients",
    "primary_source_url": "https://www.claimdepot.com/data-breach/nkc-health-2025",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence. Cerner/Oracle breach documented; Sanford Health's use of Cerner well-established. Specific Sanford patient count not confirmed.",
    "sources_used": [
      "Claim Depot (NKC Health context)",
      "MercyOne statement on Cerner breach",
      "Oracle Health breach reporting"
    ],
    "id": "INC-00749",
    "year": 2025,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Sanford Health (via Cerner/Oracle breach \u2014 2025)",
    "organization_type": "Rural Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "SD",
    "hq_city": "Sioux Falls",
    "hq_county": "Minnehaha",
    "discovery_date": "2025-01-22",
    "disclosure_date": "2025-12-27",
    "executive_summary": "Sanford Health reported that patient information from its systems may be uncompromised after its EHR vendor Cerner/Oracle experienced a security breach as early as January 22, 2025. Lake Regional Health System also reported similarly. Sanford Health confirmed it was reviewing the situation and conducting its own investigation. As of late December 2025, Sanford indicated patient information appeared uncompromised, though the investigation was ongoing.",
    "attack_type": "Third-Party Vendor Breach (EHR vendor)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not confirmed; investigation ongoing",
    "residents_affected_in_state": "South Dakota patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "EHR vendor breached; Sanford's own patient data status uncertain",
    "remediation_disclosed": "Partial \u2014 investigation ongoing as of late 2025 reporting",
    "primary_source_url": "https://www.facebook.com/krmsnews/posts/lake-regional-health-system-says-patient-information-uncompromised-after-reported/1460007679464657/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence for patient data compromise. Facebook/KRMS news indicates Sanford/Lake Regional may be unaffected; included for completeness given Cerner breach scope.",
    "sources_used": [
      "KRMS News/Facebook"
    ],
    "id": "INC-00750",
    "year": 2025,
    "lat": 43.546,
    "lng": -96.7313,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Share Ourselves",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Costa Mesa",
    "hq_county": "Orange",
    "discovery_date": "Unknown",
    "disclosure_date": "2025-12-26",
    "executive_summary": "Hacking/IT incident at Share Ourselves, a community health center in Orange County.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2864,
    "residents_affected_in_state": 2864,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal (Dec 2025).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00751",
    "year": 2025,
    "lat": 33.6411,
    "lng": -117.9187,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sharp Community Medical Group (SCMG)",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "CA",
    "hq_city": "San Diego, CA",
    "hq_county": "San Diego County",
    "discovery_date": "2025-01-27",
    "disclosure_date": "2025-09-11",
    "executive_summary": "On February 6, 2025, we found unusual activity in our computer systems. We quickly took steps to stop the activity. We began investigating right away and hired a special team to help us. We also called law enforcement. We turned off our computer systems to help protect our customers and their patients and members. We learned that a criminal was able to see and take copies of some data in our computer systems. This happened between January 27, 2025 and February 6, 2025. To date, we are not aware of any misuse of the data.",
    "attack_type": "Hacking / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Unknown",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/Episource%20Individual%20Notice%20Letter%20Template%20No%20SSN%205-21-25_v2%20%28Static%20Proof%29_0_0.pdf",
    "secondary_source_urls": [],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00752",
    "year": 2025,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Sharp HealthCare",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Diego, CA",
    "hq_county": "San Diego County",
    "discovery_date": "2025-01-27",
    "disclosure_date": "2025-06-06",
    "executive_summary": "On February 6, 2025, we found unusual activity in our computer systems. We quickly took steps to stop the activity. We began investigating right away and hired a special team to help us. We also called law enforcement. We turned off our computer systems to help protect our customers and their patients and members. We learned that a criminal was able to see and take copies of some data in our computer systems. This happened between January 27, 2025 and February 6, 2025. To date, we are not aware of any misuse of the data.",
    "attack_type": "Hacking / Third-Party Vendor Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": 62777,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Web server (sharp.com) breached for a few hours on Jan 12, 2023; billing payment file accessed; FollowMyHealth portal not affected",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered', 'Law enforcement notified']",
    "primary_source_url": "https://oag.ca.gov/system/files/Episource%20Individual%20Notice%20Letter%20Template%20No%20SSN%205-21-25_v2%20%28Static%20Proof%29.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/sharp-healthcare-data-breach/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00753",
    "year": 2025,
    "lat": 32.7157,
    "lng": -117.1611,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Skagit Regional Health",
    "organization_type": "Healthcare Provider (Regional Hospital / Health System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Mount Vernon",
    "hq_county": "Skagit",
    "discovery_date": "2025-05-01",
    "disclosure_date": "2025-09-30",
    "executive_summary": "Skagit Regional Health (Skagit County Public Hospital District No. 1), which operates Skagit Regional Hospital in Mount Vernon, Washington, disclosed that it had installed Meta Pixel and other tracking technologies on its patient portal website. These tools transmitted protected health information to third-party advertising platforms (including Meta/Facebook) without patient authorization over an extended period from at least May 2021 through approximately September 2025. A class-action lawsuit was filed alleging negligence, invasion of privacy, and related claims. The case settled for approximately $400,000. The incident involves unauthorized disclosure of PHI through third-party tracking pixels \u2014 a widespread healthcare industry issue.",
    "attack_type": "Unauthorized disclosure via third-party tracking pixel",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not applicable (third-party tracking technology)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2021,
    "residents_affected_in_state": "Skagit County and surrounding WA regions",
    "financial_impact": "~$400,000 class-action settlement",
    "operational_impact": "Patient health information transmitted to Meta and other ad platforms without authorization",
    "remediation_disclosed": "Tracking pixels removed; $400K settlement fund; OCR notification",
    "primary_source_url": "https://www.hipaajournal.com/skagit-regional-health-pixel-settlement/",
    "secondary_source_urls": [
      "https://www.defensorum.com/skagit-regional-health-data-breach-use-of-tracking-technologies/"
    ],
    "confidence_notes": "Moderate confidence: pixel tracking incidents are classified as hacking/IT incidents by HHS OCR (unauthorized access to PHI); settlement confirmed; exact affected count not disclosed",
    "sources_used": [
      "HIPAA Journal",
      "Defensorum"
    ],
    "id": "INC-00754",
    "year": 2025,
    "lat": 48.4200462,
    "lng": -122.32642,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Sturgis Hospital",
    "organization_type": "Rural Emergency Hospital / Critical Access Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Sturgis",
    "hq_county": "St. Joseph",
    "discovery_date": "2024-12-01",
    "disclosure_date": "2025-09-18",
    "executive_summary": "Sturgis Hospital, a rural emergency hospital in Sturgis, Michigan (Michigan's first Rural Emergency Hospital), reported two separate cyberattacks. The first incident occurred in December 2024 (discovered approximately December 1, lasting through December 17, 2024). While that investigation was still underway, a second wave of unauthorized activity was discovered in June 2025. Both investigations confirmed that unauthorized third parties accessed or acquired files containing patient and employee PHI and PII. Approximately 77,771 individuals were affected across both incidents. Exposed data included names, contact details, Social Security numbers, bank account numbers, health insurance details, prescriptions, treatment records, and clinical data. Disclosure was made to HHS OCR in September 2025, nine months after the initial breach.",
    "attack_type": "Network Server Hacking (two incidents)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 77771,
    "residents_affected_in_state": "Michigan residents \u2014 primarily St. Joseph County area",
    "financial_impact": "Not publicly disclosed; class action investigation filed",
    "operational_impact": "Patient data accessed; rural hospital operations potentially disrupted during both incidents",
    "remediation_disclosed": "Yes \u2014 third-party cybersecurity experts engaged for both incidents; HHS OCR notified September 2025; credit monitoring offered",
    "primary_source_url": "https://hipaatimes.com/sturgis-hospital-reports-dual-cyberattacks-affecting-over-77000-patients",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/sturgis-hospital-september-2025",
      "https://www.hipaajournal.com/september-2025-healthcare-data-breach-report/"
    ],
    "confidence_notes": "High confidence. HIPAA Times, ClassAction.org, HIPAA Journal September 2025 report. HHS OCR breach portal confirms 77,771 individuals.",
    "sources_used": [
      "HIPAA Times",
      "ClassAction.org",
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00755",
    "year": 2025,
    "lat": 41.799217,
    "lng": -85.4191482,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Sunflower Medical Group",
    "organization_type": "Multi-Specialty Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "KS",
    "hq_city": "Kansas City (Lenexa/Roeland Park)",
    "hq_county": "Johnson",
    "discovery_date": "2025-01-07",
    "disclosure_date": "2025-03-10",
    "executive_summary": "Sunflower Medical Group, with four care centers in the Kansas City area (Kansas City, Lenexa, and Roeland Park, KS), detected suspicious network activity on January 7, 2025. Forensic investigation confirmed an unauthorized actor had accessed its network from December 15, 2024 through January 7, 2025, exfiltrating patient data. The Rhysida ransomware group claimed responsibility, posting Sunflower on its dark web leak site and threatening to release a 3-terabyte SQL database allegedly containing ~400,000 records. Final confirmed count: 220,968 individuals affected. Data exposed included names, addresses, DOBs, SSNs, driver's license numbers, medical information, and health insurance information. A class action settlement was reached in early 2026.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 220968,
    "residents_affected_in_state": "Primarily Kansas residents (Kansas City area)",
    "financial_impact": "Class action settlement reached 2026 (terms not publicly disclosed in available sources)",
    "operational_impact": "Patient data exfiltrated over ~3 weeks; no confirmed operational shutdown reported",
    "remediation_disclosed": "Yes \u2014 forensic investigation completed; patients notified March 2025; federal health regulators reviewed and closed inquiry",
    "primary_source_url": "https://www.hipaajournal.com/cyberattack-on-sunflower-medical-group-affects-221000-patients/",
    "secondary_source_urls": [
      "https://therecord.media/kansas-healthcare-provider-data-breach",
      "https://www.paubox.com/blog/sunflower-medical-group-agrees-to-settlement-after-ransomware-attack",
      "https://sunflowermed.com/data-security-incident/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, The Record, HHS OCR breach portal (220,968), Paubox/Paubox settlement report. | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HIPAA Journal",
      "Maine AG breach portal",
      "Paubox",
      "Sunflower Medical Group official notice",
      "The Record"
    ],
    "id": "INC-00756",
    "year": 2025,
    "lat": 39.1142,
    "lng": -94.6275,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Susan B. Allen Memorial Hospital",
    "organization_type": "Community Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "KS",
    "hq_city": "El Dorado",
    "hq_county": "Butler",
    "discovery_date": "2025-07-18",
    "disclosure_date": "2025-07-22",
    "executive_summary": "Susan B. Allen Memorial Hospital, a Joint Commission-accredited community hospital in El Dorado, Kansas, confirmed it was investigating a potential cyberattack on July 18, 2025 after experiencing a system outage. Ransomware gang Kawa4096 claimed responsibility on July 22, 2025, alleging it had stolen 210 GB of data from the hospital. HHS OCR breach reports record approximately 12,097 individuals as affected. Exposed data types included patient protected health information and personally identifiable information.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Kawa4096",
    "attribution_status": "claimed",
    "individuals_affected_reported": 12097,
    "residents_affected_in_state": "Kansas residents \u2014 Butler County and surrounding areas",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "System outage reported; hospital operations disrupted during attack",
    "remediation_disclosed": "Partial \u2014 investigating as of July 2025; cybersecurity experts engaged; law enforcement notified",
    "primary_source_url": "https://www.comparitech.com/news/ransomware-gang-claims-cyber-attack-on-susan-b-allen-memorial-hospital/",
    "secondary_source_urls": [
      "https://www.breachsense.com/breaches/susan-b-allen-memorial-hospital-data-breach/",
      "https://www.hipaajournal.com/september-2025-healthcare-data-breach-report/"
    ],
    "confidence_notes": "High confidence. Comparitech confirmed attack; Kawa4096 claimed responsibility; HHS OCR September 2025 breach report (12,097 individuals).",
    "sources_used": [
      "Comparitech",
      "BreachSense",
      "HIPAA Journal",
      "HHS OCR"
    ],
    "id": "INC-00757",
    "year": 2025,
    "lat": 37.8173015,
    "lng": -96.8537388,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Texas Health and Human Services Commission (HHSC) \u2013 Insider Access Breach",
    "organization_type": "Government Health Agency",
    "organization_type_bucket": "Other healthcare entity",
    "state": "TX",
    "hq_city": "Austin",
    "hq_county": "Travis",
    "discovery_date": "2024-11-21",
    "disclosure_date": "2025-01-15",
    "executive_summary": "Multiple HHSC employees improperly accessed records of 61,104 individuals without authorization from June 2021 to December 2024. Seven employees fired; Texas OIG investigation opened. Data included names, addresses, SSNs, Medicaid/Medicare numbers, financial information, and health records.",
    "attack_type": "Insider Threat / Unauthorized Access",
    "attack_category": "Insider threat",
    "threat_actor_name": "Insider (multiple employees)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 61104,
    "residents_affected_in_state": 61104,
    "financial_impact": "Not publicly disclosed; criminal charges sought",
    "operational_impact": "Employee access revoked; criminal investigation launched",
    "remediation_disclosed": "Employees fired; OIG investigation; additional monitoring",
    "primary_source_url": "https://www.hipaajournal.com/texas-hhsc-insider-breach-2024/",
    "secondary_source_urls": [
      "https://statescoop.com/texas-health-agency-privacy-breach-2025/"
    ],
    "confidence_notes": "High confidence; HIPAA Journal and StateScoop confirmed; HHSC officially announced; 61,104 per HHSC notification",
    "sources_used": [
      "HIPAA Journal",
      "StateScoop"
    ],
    "id": "INC-00758",
    "year": 2025,
    "lat": 30.2672,
    "lng": -97.7431,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "UI Community HomeCare / University of Iowa Health Care",
    "organization_type": "Home Health Care Agency / Academic Medical Center Affiliate",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Iowa City",
    "hq_county": "Johnson",
    "discovery_date": "2025-07-03",
    "disclosure_date": "2025-08-29",
    "executive_summary": "UI Community HomeCare, an affiliate company of University of Iowa Health Care (UIHC), had its computer system accessed without authorization on July 3, 2025. The cybercriminal copied data files containing patient information, including a group of UIHC patients whose data was shared with the affiliate. Servers were shut down quickly and restored within one business day. Electronic health record systems were not affected. Approximately 211,000 individuals were affected, including both UI Community HomeCare patients and some UIHC patients.",
    "attack_type": "Unauthorized Network Access / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 211000,
    "residents_affected_in_state": 211000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Servers shut down; restored within one business day; no EHR impact",
    "remediation_disclosed": "Yes \u2014 cybersecurity experts engaged, servers restored, notification letters mailed to all affected individuals",
    "primary_source_url": "https://uihealthcare.org/article/ui-community-homecare-and-ui-health-care-notify-individuals-potentially-impacted-data",
    "secondary_source_urls": [
      "https://cbs2iowa.com/news/local/patient-information-of-over-200000-people-leaked-after-data-breach-at-uihc-affiliate-ui-community-homecare-cybercrime-cybersecurity-cybercriminal-university-of-iowa-hospitals-and-clinics-computer-systems"
    ],
    "confidence_notes": "High confidence. University of Iowa Health Care official statement and KGAN/CBS2 Iowa news reporting.",
    "sources_used": [
      "University of Iowa Health Care",
      "CBS2 Iowa / KGAN"
    ],
    "id": "INC-00759",
    "year": 2025,
    "lat": 41.6611,
    "lng": -91.5302,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Union Health (via Oracle Health/Cerner)",
    "organization_type": "Healthcare Provider / Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Terre Haute",
    "hq_county": "Vigo",
    "discovery_date": "2025-02-20",
    "disclosure_date": "2025-05-08",
    "executive_summary": "Union Health, which operates two hospitals and a medical group in Terre Haute, Indiana, disclosed that approximately 262,786 individuals were affected by a hacking incident involving data being migrated on the Oracle Health (formerly Cerner) platform. The unauthorized access to legacy Cerner servers began around January 22, 2025, and was discovered on February 20, 2025. Compromised data included patient names, Social Security numbers, medical records, and clinical information.",
    "attack_type": "Hacking / Unauthorized Server Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 262786,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Data exfiltration via vendor system; Union Health's internal systems not directly compromised",
    "remediation_disclosed": "Oracle Health/Cerner worked with law enforcement; notifications issued to affected patients",
    "primary_source_url": "https://www.bankinfosecurity.com/indiana-health-system-notifies-263000-oracle-hack-a-28353",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. BankInfoSecurity reported Union Health was notifying approximately 263,000 individuals. Part of the broader Oracle Health/Cerner breach disclosed in 2025.",
    "sources_used": [
      "BankInfoSecurity",
      "Oracle Health breach notifications"
    ],
    "id": "INC-00760",
    "year": 2025,
    "lat": 39.4667025,
    "lng": -87.4139119,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "University of Chicago Medicine (via Nationwide Recovery Services breach)",
    "organization_type": "Academic Medical Center",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2025-04-01",
    "disclosure_date": "2025-05-28",
    "executive_summary": "UChicago Medicine was notified in April 2025 that a cybersecurity incident at Nationwide Recovery Services (NRS), a debt collection/financial services vendor, had occurred July 5\u201311, 2024, exposing patient data. The Rhysida ransomware group claimed responsibility for the NRS attack and attempted to sell stolen data for $3M+. UChicago Medicine's UCM Medical Group \u2014 not the University of Chicago Medical Center \u2014 had approximately 38,000 patients affected. Compromised data included names, addresses, DOBs, SSNs, financial account information, and medical information. UChicago ended its relationship with NRS.",
    "attack_type": "Third-Party Vendor Breach (debt collection company)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Rhysida (claimed responsibility for Nationwide Recovery Services breach)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 38000,
    "residents_affected_in_state": "Primarily Illinois (Chicago area) patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "UCM Medical Group patient data exposed via vendor; UChicago Medical Center not directly affected",
    "remediation_disclosed": "Yes \u2014 NRS relationship terminated; patients notified May/June 2025",
    "primary_source_url": "https://www.cbsnews.com/chicago/news/uchicago-medicine-patients-data-breach/",
    "secondary_source_urls": [
      "https://abc7chicago.com/post/uchicago-med-confirms-data-breach-patient-information-latest-nationwide-recovery-services-cyber-security-incident/16574581/"
    ],
    "confidence_notes": "High confidence. CBS Chicago, ABC7 Chicago, UChicago Medicine statement.",
    "sources_used": [
      "CBS Chicago",
      "ABC7 Chicago"
    ],
    "id": "INC-00761",
    "year": 2025,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Veradigm (MercyOne Iowa component) \u2014 2024 Credential Breach",
    "organization_type": "Nonprofit Hospital System (Iowa)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2024-12-01",
    "disclosure_date": "2025-12-10",
    "executive_summary": "MercyOne patients in Iowa were specifically identified as victims notified about the Veradigm (formerly Allscripts) data breach of December 2024 in local Iowa news coverage. A KCCI News (Iowa) report in December 2025 confirmed MercyOne patients were being notified about the breach. This is the Iowa-specific component of the Veradigm breach (see MW-053), warranting a separate entry for Iowa patient tracking.",
    "attack_type": "Third-Party Vendor Breach (cloud storage credential theft)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately quantified for Iowa MercyOne patients",
    "residents_affected_in_state": "Iowa (MercyOne) patients",
    "financial_impact": "Covered under Veradigm $10.5M settlement",
    "operational_impact": "MercyOne's own systems not affected; vendor breach",
    "remediation_disclosed": "Yes \u2014 patients notified December 2025 via vendor",
    "primary_source_url": "https://www.mercyone.org/press-releases/mercyone-statement-regarding-january-22-cerneroracle-security-incident",
    "secondary_source_urls": [
      "https://www.facebook.com/kcci8/posts/mercyone-patients-are-being-informed-of-a-data-breach-involving-their-third-part/1300017598832468/"
    ],
    "confidence_notes": "High confidence. MercyOne official statement; KCCI Iowa reporting confirmed.",
    "sources_used": [
      "MercyOne",
      "KCCI8/Facebook"
    ],
    "id": "INC-00762",
    "year": 2025,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Veradigm Inc. (Allscripts \u2014 Illinois HQ)",
    "organization_type": "Healthcare Technology Company (EHR/Practice Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "IL",
    "hq_city": "Chicago",
    "hq_county": "Cook",
    "discovery_date": "2024-12-01",
    "disclosure_date": "2025-09-29",
    "executive_summary": "Veradigm Inc. (formerly Allscripts), an Illinois-based healthcare technology company, suffered a data breach in December 2024 when attackers used stolen credentials to access a Veradigm storage account. Patient information from multiple healthcare provider clients was exposed. At least 2.5 million patients were affected. Compromised data included names, contact information, DOBs, health records (diagnoses, medications, test results, treatments), health insurance information, payment details, SSNs, and driver's license numbers. At least 70,000 confirmed affected in two states (TX and SC). A $10.5 million class action settlement was announced January 2026. MercyOne (Iowa) was among clients whose patients were notified.",
    "attack_type": "Credential Theft / Cloud Storage Breach",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2500000,
    "residents_affected_in_state": "Multistate including MercyOne (Iowa) patients; IL-headquartered vendor",
    "financial_impact": "$10.5 million class action settlement (January 2026); up to $5,000 per documented claim; 2 years identity theft protection",
    "operational_impact": "Storage account compromised; multiple healthcare provider client patient data exposed",
    "remediation_disclosed": "Yes \u2014 storage account secured; vendor notified clients; HHS and state AGs notified; $10.5M settlement",
    "primary_source_url": "https://www.hipaajournal.com/veradigm-data-breach/",
    "secondary_source_urls": [
      "https://www.paubox.com/blog/veradigm-agrees-to-10.5-million-settlement-after-2024-data-breach",
      "https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/10-5m-veradigm-data-breach-class-action-settlement/"
    ],
    "confidence_notes": "High confidence. HIPAA Journal, Paubox, Top Class Actions settlement coverage.",
    "sources_used": [
      "HIPAA Journal",
      "Paubox",
      "Top Class Actions"
    ],
    "id": "INC-00763",
    "year": 2025,
    "lat": 41.8781,
    "lng": -87.6298,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Veradigm LLC \u2014 SC impact",
    "organization_type": "Business Associate / Healthcare Technology",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "SC",
    "hq_city": "Chicago",
    "hq_county": "Cook County (IL-based)",
    "discovery_date": "2025-06-01",
    "disclosure_date": "2025-09-22",
    "executive_summary": "Veradigm LLC (formerly Allscripts Healthcare Solutions), a major healthcare IT vendor serving practices throughout the Southeast, reported a data breach affecting 23,491 South Carolina residents per the SC AG. Veradigm provides EHR, practice management, and analytics services to healthcare providers across the SE states.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 23491,
    "residents_affected_in_state": 23491,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare provider patient data exposed through EHR/practice management systems",
    "remediation_disclosed": "SC AG notified September 2025",
    "primary_source_url": "https://consumer.sc.gov/identity-theft-unit/security-breach-notices",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence \u2014 SC Consumer Affairs breach portal listing with 23,491 SC residents September 2025.",
    "sources_used": [
      "SC Consumer Affairs Breach Portal"
    ],
    "id": "INC-00764",
    "year": 2025,
    "lat": 35.0626811,
    "lng": -82.1836628,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Washington Gastroenterology (WAGI)",
    "organization_type": "Healthcare Provider (Gastroenterology Group)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Tacoma",
    "hq_county": "Pierce",
    "discovery_date": "2025-03-10",
    "disclosure_date": "2025-05-23",
    "executive_summary": "Washington Gastroenterology (WAGI), a major gastroenterology group in Tacoma, Washington, discovered on March 10, 2025 that an unknown third party had accessed and exposed data from a legacy system. The forensic investigation confirmed that sensitive personal information including names, Social Security numbers, and medical information may have been compromised. WAGI began notifying affected individuals on May 23, 2025, with additional notifications issued August 22, 2025 after further individuals were identified. The incident was disclosed to multiple state attorneys general including Washington.",
    "attack_type": "Unauthorized network access / Data exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately disclosed (under review)",
    "residents_affected_in_state": "Not separately reported (WA-based practice; majority WA residents)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Legacy system compromised; SSNs, medical information exposed; multiple AG notifications required",
    "remediation_disclosed": "Legacy system secured; forensic investigation; credit monitoring via IDX offered; notifications to multiple state AGs",
    "primary_source_url": "https://www.federmanlaw.com/blog/washington-gastroenterology-wagi-data-breach-investigated-by-federman-sherwood/",
    "secondary_source_urls": [
      "https://www.almeidalawgroup.com/washington-gastroenterology-data-breach/",
      "https://www.barnowlaw.com/washington-gastroenterology-data-breach-investigation/",
      "https://www.claimdepot.com/data-breach/washington-gastroenterology"
    ],
    "confidence_notes": "Confirmed ransomware/hacking incident per multiple law firm reports; notification to WA AG confirmed; IDX enrollment URL (response.idx.us/wagi) published; total affected individuals not yet published in OCR portal at time of research",
    "sources_used": [
      "Federman & Sherwood law firm",
      "Almeida Law Group",
      "Barnow and Associates",
      "Claim Depot"
    ],
    "id": "INC-00765",
    "year": 2025,
    "lat": 47.2529,
    "lng": -122.4443,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Watsonville Community Hospital",
    "organization_type": "Hospital / Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Watsonville, CA (Santa Cruz County)",
    "hq_county": "Santa Cruz County",
    "discovery_date": "2024-11-25",
    "disclosure_date": "2025-10-16",
    "executive_summary": "In response, we promptly took portions of our network offline, isolated the affected systems, and began an investigation into the activity. The investigation determined there was unauthorized access to a limited subset of our network between November 25, 2024 and November 30, 2024, and that certain files within the network were accessed or downloaded without authorization during that time. While our investigation was ongoing, we began notifying potentially affected individuals via our website and media notice. As part of our response efforts, we performed a comprehensive",
    "attack_type": "Hacking / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not publicly attributed",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Community hospital in Santa Cruz County disrupted; systems taken offline",
    "remediation_disclosed": "['Credit monitoring offered to affected individuals', 'Identity protection services offered']",
    "primary_source_url": "https://oag.ca.gov/system/files/Exhibit%20A_15_0.pdf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/watsonville-community-hospital-cyber-attack/"
    ],
    "confidence_notes": "",
    "sources_used": [
      "California AG Breach Notification"
    ],
    "id": "INC-00766",
    "year": 2025,
    "lat": 36.9102,
    "lng": -121.7569,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Wellpath (formerly Correct Care Solutions) \u2014 SE prisons/jails",
    "organization_type": "Healthcare Provider / Correctional Healthcare",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Nashville",
    "hq_county": "Davidson",
    "discovery_date": "2024-11-01",
    "disclosure_date": "2025-03-01",
    "executive_summary": "Wellpath LLC, a major provider of correctional healthcare services with operations in detention facilities across the Southeast (FL, GA, NC, SC, TN, VA, AL, MS), disclosed a data breach affecting incarcerated individuals and former patients. Wellpath provides healthcare in jails, prisons, and civil commitment facilities throughout the SE region. The breach exposed patient PHI and PII.",
    "attack_type": "Ransomware / Network Intrusion",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Correctional healthcare patient data exposed across SE detention facilities",
    "remediation_disclosed": "Breach notifications sent; third-party forensics engaged",
    "primary_source_url": "https://www.hipaajournal.com/healthcare-data-breach-statistics/",
    "secondary_source_urls": [],
    "confidence_notes": "Low confidence \u2014 General HIPAA Journal reference. Wellpath has significant SE correctional healthcare operations. Verify against HHS OCR portal.",
    "sources_used": [
      "HIPAA Journal Healthcare Data Breach Statistics"
    ],
    "id": "INC-00767",
    "year": 2025,
    "lat": 36.1627,
    "lng": -86.7816,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "West Virginia Primary Care Association",
    "organization_type": "Healthcare Provider / Community Health Association",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WV",
    "hq_city": "Charleston",
    "hq_county": "Kanawha",
    "discovery_date": "2025-07-31",
    "disclosure_date": "2025-08-01",
    "executive_summary": "On July 31, 2025, the ransomware group Incransom publicly claimed responsibility for a cyberattack against the West Virginia Primary Care Association (WVPCA). The group posted an extortion notice threatening to leak sensitive data. WVPCA provides support to community health centers throughout West Virginia. No formal breach notification has been publicly confirmed as of the research date.",
    "attack_type": "Ransomware / Data Extortion (Incransom)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Incransom",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Data exfiltration claimed; threat to leak sensitive data; community health center operations potentially affected",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://www.dexpose.io/incransom-strikes-west-virginia-primary-care-association/",
    "secondary_source_urls": [],
    "confidence_notes": "Medium confidence \u2014 DeXpose threat intelligence reporting on Incransom claim; no formal HHS filing confirmed as of research date.",
    "sources_used": [
      "DeXpose Threat Intelligence"
    ],
    "id": "INC-00768",
    "year": 2025,
    "lat": 38.3498,
    "lng": -81.6326,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Whitman Hospital & Medical Clinics (WHMC)",
    "organization_type": "Healthcare Provider (Rural Hospital / Multispecialty Clinics)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Colfax",
    "hq_county": "Whitman",
    "discovery_date": "2025-02-28",
    "disclosure_date": "2025-04-10",
    "executive_summary": "Whitman Hospital & Medical Clinics, which operates a hospital and clinics in Colfax, St. John, Tekoa, and Garfield in eastern Washington, suffered unauthorized access to its IT environment between December 26, 2024, and February 28, 2025. An intruder accessed or acquired files containing sensitive information for approximately 64,401 individuals, including patients and members of WHMC's group health plan. Compromised data included names, dates of birth, addresses, Social Security numbers, financial account information, medical diagnoses, lab results, medications, health insurance information, provider names, and dates of treatment. A $500,000 class-action settlement was reached.",
    "attack_type": "Hacking / Unauthorized network access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 64401,
    "residents_affected_in_state": "Majority WA-based (eastern Washington rural communities)",
    "financial_impact": "$500,000 class-action settlement (preliminary approval February 2026)",
    "operational_impact": "Patient portal access disrupted; IT environment compromised for approximately 2 months",
    "remediation_disclosed": "Systems secured; cybersecurity experts engaged; $500K settlement fund; credit monitoring offered",
    "primary_source_url": "https://www.classaction.org/news/500k-whitman-hospital-and-medical-clinics-settlement-wraps-up-class-action-lawsuit-over-data-breach",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/whitman-hospital-and-medical-clinics-april-2025",
      "https://thelyonfirm.com/blog/whitman-hospital-medical-clinics-cyberattack-investigation/",
      "https://www.claimdepot.com/data-breach/whitman-hospital"
    ],
    "confidence_notes": "High confidence: court documents confirm 64,401 affected individuals; $500K settlement received preliminary court approval February 2026; multiple sources corroborate details",
    "sources_used": [
      "ClassAction.org",
      "The Lyon Firm",
      "Claim Depot"
    ],
    "id": "INC-00769",
    "year": 2025,
    "lat": 46.8801655,
    "lng": -117.364349,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Wood River Health (RI)",
    "organization_type": "Healthcare Provider (FQHC)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "RI",
    "hq_city": "Hope Valley",
    "hq_county": "Washington",
    "discovery_date": "2025-06-01",
    "disclosure_date": "2025-07-28",
    "executive_summary": "Wood River Health, a Rhode Island federally qualified health center, reported a data security incident to the Maine AG in July 2025. The breach involved unauthorized access to patient and employee health information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient and employee data potentially compromised",
    "remediation_disclosed": "Maine AG notified; affected individuals notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing July 28, 2025",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00770",
    "year": 2025,
    "lat": 41.5098682,
    "lng": -71.7196508,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Yale New Haven Health System",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CT",
    "hq_city": "New Haven",
    "hq_county": "New Haven",
    "discovery_date": "2025-03-08",
    "disclosure_date": "2025-04-11",
    "executive_summary": "Yale New Haven Health identified unusual activity on its IT systems on March 8, 2025, leading to engagement of Mandiant as cybersecurity investigator. An unauthorized third party accessed the network and obtained copies of data including demographic information, SSNs, patient types, and medical record numbers. The incident affected approximately 5,556,702 individuals\u2014the largest healthcare breach of 2025 at the time\u2014though the EHR system was not accessed. An $18 million settlement was announced.",
    "attack_type": "Hacking/IT Incident (data exfiltration)",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 5556702,
    "residents_affected_in_state": "CT NY RI \u2014 breakdown not separately published",
    "financial_impact": "$18 million settlement (preliminary)",
    "operational_impact": "Phone and internet connection disruptions; patient care maintained; EHR not affected",
    "remediation_disclosed": "Mandiant engaged; federal law enforcement notified; enhanced security measures",
    "primary_source_url": "https://www.ynhhs.org/news/yale-new-haven-health-notifies-patients-of-data-security-incident",
    "secondary_source_urls": [
      "https://www.healthcaredive.com/news/yale-new-haven-health-data-breach-5-6-million/746236/",
      "https://www.hipaajournal.com/yale-new-haven-health-system-data-breach/",
      "https://techcrunch.com/2025/04/25/data-breach-at-connecticut-yale-new-haven-health-affects-over-5-million/",
      "https://sentrybay.com/yale-new-haven-health-system-data-breach-exposes-5-5-million-records/",
      "https://topclassactions.com/lawsuit-settlements/lawsuit-news/yale-new-haven-health-announces-massive-data-breach-affecting-5-5m-patients/",
      "https://www.ynhhs.org/cybersecurity-incident"
    ],
    "confidence_notes": "YNHHS official notice; OCR breach report; $18M settlement announced | Cross-referenced across multiple authoritative sources.",
    "sources_used": [
      "HIPAA Journal",
      "Healthcare Dive",
      "SentryBay",
      "TechCrunch",
      "Top Class Actions",
      "YNHHS official press release",
      "Yale New Haven Health System"
    ],
    "id": "INC-00771",
    "year": 2025,
    "lat": 41.3083,
    "lng": -72.9279,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Adapt Integrated Health Care (via TriZetto/OCHIN breach)",
    "organization_type": "Healthcare Provider (Community Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OR",
    "hq_city": "Roseburg",
    "hq_county": "Douglas",
    "discovery_date": "2025-12-10",
    "disclosure_date": "2026-01-20",
    "executive_summary": "Adapt Integrated Health Care, a Roseburg, Oregon-based behavioral health and substance use treatment provider, reported a data security incident at TriZetto Provider Solutions, a vendor serving Adapt's EHR system through OCHIN. Adapt learned of the incident on December 10, 2025, when OCHIN notified them that an unauthorized individual had accessed TriZetto's systems (originally on October 2, 2025). Adapt's own internal systems were not breached. Beginning February 2026, TriZetto planned to send notification letters to affected individuals. Potentially exposed data included names, Social Security numbers, dates of birth, contact information, and health-related and insurance information. TriZetto's total breach affected 3.4 million individuals nationwide.",
    "attack_type": "Third-party vendor breach / Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3433965,
    "residents_affected_in_state": "Oregon residents receiving care at Adapt Integrated Health Care",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Adapt's internal systems not breached; third-party vendor data exposed; notification delayed pending TriZetto investigation",
    "remediation_disclosed": "TriZetto disabled affected users/IPs October 2, 2025; Mandiant engaged for forensics; identity theft monitoring via Kroll offered",
    "primary_source_url": "https://kpic.com/news/local/adapt-integrated-health-care-reports-data-breach-at-vendor-assures-patient-info-safety",
    "secondary_source_urls": [
      "https://kval.com/news/local/adapt-integrated-health-care-reports-data-breach-at-vendor-assures-patient-info-safety",
      "https://www.techradar.com/pro/security/trizetto-data-breach-health-tech-giant-reveals-personal-info-of-3-4-million-users-may-have-been-affected"
    ],
    "confidence_notes": "High confidence: KPIC local news (Roseburg) and KVAL confirmed Adapt notification; TriZetto confirmed breach with 3.4M national total via Maine AG filing; Adapt-specific count not yet disclosed",
    "sources_used": [
      "KPIC (Roseburg local TV)",
      "KVAL",
      "TechRadar"
    ],
    "id": "INC-00772",
    "year": 2026,
    "lat": 43.216505,
    "lng": -123.3417381,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "AltaMed Health Services Corporation",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Los Angeles",
    "hq_county": "Los Angeles",
    "discovery_date": "2025-11-27 (per CA AG filing)",
    "disclosure_date": "2026-02-26",
    "executive_summary": "Hacking/IT incident at AltaMed Health Services Corporation affecting network server.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 501,
    "residents_affected_in_state": 501,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "AltaMed is one of the largest FQHC networks in the US, serving Southern California.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00773",
    "year": 2026,
    "lat": 34.0522,
    "lng": -118.2437,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Aroostook Mental Health Center (Maine)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Caribou",
    "hq_county": "Aroostook",
    "discovery_date": "2026-03-01",
    "disclosure_date": "2026-04-11",
    "executive_summary": "Aroostook Mental Health Center, a Maine-based behavioral health provider, reported a data security incident to the Maine AG in April 2026. The breach involved unauthorized access to systems containing patient mental health and PHI.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Mental health patient PHI potentially compromised",
    "remediation_disclosed": "Maine AG notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing April 11, 2026",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00774",
    "year": 2026,
    "lat": 46.8606301,
    "lng": -68.0116807,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Asian Americans for Community Involvement (AACI)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Jose",
    "hq_county": "Santa Clara",
    "discovery_date": "2024-11-01 to 2025-10-02 (per CA AG filing)",
    "disclosure_date": "01/2026",
    "executive_summary": "Hacking/IT incident at AACI, a community health organization in Silicon Valley.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not confirmed from available sources",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed on both HHS OCR portal and CA AG breach list.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00775",
    "year": 2026,
    "lat": 37.3382,
    "lng": -121.8863,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Axis Community Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Pleasanton",
    "hq_county": "Alameda",
    "discovery_date": "2024-11-01 to 2025-10-02 (per CA AG filing)",
    "disclosure_date": "2026-01-16",
    "executive_summary": "Hacking/IT incident at Axis Community Health.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3579,
    "residents_affected_in_state": 3579,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal and CA AG breach notice list (Jan 2026).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00776",
    "year": 2026,
    "lat": 37.6624,
    "lng": -121.8747,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Bay Area Community Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Dublin",
    "hq_county": "Alameda",
    "discovery_date": "2024-11-01 to 2025-10-02 (per CA AG filing)",
    "disclosure_date": "2026-01-16",
    "executive_summary": "Hacking/IT incident affecting Bay Area Community Health network server. Business associate involved.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 9912,
    "residents_affected_in_state": 9912,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal (currently under investigation) and CA AG breach notice list.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00777",
    "year": 2026,
    "lat": 37.7022,
    "lng": -121.9358,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Bay Area Community Health (Second Record - LifeLong/Axis cluster)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Dublin",
    "hq_county": "Alameda",
    "discovery_date": "2024-11-01 (per CA AG LifeLong filing)",
    "disclosure_date": "2026-01-14",
    "executive_summary": "Related to same cyberattack cluster affecting multiple Bay Area FQHCs in late 2024.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise; same attack affecting multiple Bay Area FQHCs",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not separately confirmed (linked to same FQHC cluster as LifeLong Medical Care)",
    "residents_affected_in_state": "Not separately confirmed",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "LifeLong Medical Care filed with CA AG Jan 14, 2026, breach date Nov 1, 2024. Same cluster as Axis Community Health, AACI, Indian Health Center of Santa Clara Valley, and Santa Cruz Community Health.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00778",
    "year": 2026,
    "lat": 37.7022,
    "lng": -121.9358,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Bayside Dental",
    "organization_type": "Healthcare Provider (Dental Practice)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "WA",
    "hq_city": "Anacortes",
    "hq_county": "Skagit",
    "discovery_date": "2026-01-13",
    "disclosure_date": "2026-03-13",
    "executive_summary": "Bayside Dental in Anacortes, Washington suffered an unauthorized network intrusion by the Sinobi ransomware group between January 5 and January 13, 2026. Attackers claimed to have stolen 580 GB of sensitive patient data including Social Security numbers, dates of birth, financial account information, and patient treatment records. The breach was determined to impact patient PHI on March 13, 2026. Bayside Dental notified affected patients and offered remediation services.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Sinobi ransomware group",
    "attribution_status": "claimed",
    "individuals_affected_reported": 2026,
    "residents_affected_in_state": "Not separately reported (WA-based practice)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "580 GB patient data alleged stolen; SSNs, DOBs, financial and treatment records exposed",
    "remediation_disclosed": "Forensic investigation; patient notifications; identity protection offered",
    "primary_source_url": "https://www.beckersdental.com/dentists/washington-dental-practice-suffers-data-breach/",
    "secondary_source_urls": [
      "https://www.claimdepot.com/data-breach/bayside-dental-2026"
    ],
    "confidence_notes": "Reported by Becker's Dental and Claim Depot; Sinobi group claimed responsibility; OCR filing count not yet available at time of research (March 2026 determination)",
    "sources_used": [
      "Becker's Dental",
      "Claim Depot",
      "Sinobi group claim"
    ],
    "id": "INC-00779",
    "year": 2026,
    "lat": 48.516844,
    "lng": -122.6125717,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Cascadia Health (via TriZetto Provider Solutions)",
    "organization_type": "Healthcare Provider (Community Behavioral Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Spokane",
    "hq_county": "Spokane",
    "discovery_date": "2025-12-10",
    "disclosure_date": "2026-02-13",
    "executive_summary": "Cascadia Health, a Spokane-based community behavioral health provider, was affected by a cybersecurity breach at TriZetto Provider Solutions (TPS), a vendor providing insurance verification services. Cascadia learned of the incident on December 10, 2025, when OCHIN notified them of the breach. The TriZetto breach occurred on October 2, 2025, with unauthorized access potentially beginning as early as November 2024. Approximately 1,800 Cascadia Health patients had their information potentially compromised. Exposed data included names, addresses, dates of birth, Social Security numbers, health insurance numbers, provider names, and other demographic or insurance details. TriZetto confirmed total breach impact of 3.4 million individuals nationwide.",
    "attack_type": "Third-party vendor breach / Hacking",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1800,
    "residents_affected_in_state": 1800,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data potentially exposed via vendor system; Cascadia internal systems not breached",
    "remediation_disclosed": "TriZetto contained incident October 2, 2025; notifications sent February 2026; identity theft monitoring through Kroll offered",
    "primary_source_url": "https://cascadiahealth.org/news-trizetto-2026/",
    "secondary_source_urls": [
      "https://www.techradar.com/pro/security/trizetto-data-breach-health-tech-giant-reveals-personal-info-of-3-4-million-users-may-have-been-affected",
      "https://www.foxnews.com/tech/health-tech-breach-exposes-3-4m-patient-records"
    ],
    "confidence_notes": "High confidence: Cascadia Health official notice published; TriZetto total breach size (3.4M) confirmed via Maine AG filing; Cascadia-specific count (1,800) from official notice",
    "sources_used": [
      "Cascadia Health official notice",
      "TechRadar",
      "Fox News"
    ],
    "id": "INC-00780",
    "year": 2026,
    "lat": 47.6588,
    "lng": -117.426,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Central Maine Healthcare",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Lewiston",
    "hq_county": "Androscoggin",
    "discovery_date": "2025-06-01",
    "disclosure_date": "2026-01-12",
    "executive_summary": "Central Maine Healthcare detected unusual activity in its IT network on June 1, 2025. Investigation revealed unauthorized access between March 19 and June 1, 2025. The breach affected 145,381 individuals (including 138,800 Maine residents). Data potentially accessed included names, DOBs, treatment information, dates of service, provider names, health insurance information, and some SSNs.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 145381,
    "residents_affected_in_state": 138800,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "2.5-month unauthorized access; patient data potentially accessed/acquired",
    "remediation_disclosed": "Systems secured; investigation; patient notifications sent July-December 2025; security improvements",
    "primary_source_url": "https://www.cmhc.org/2025/12/notice-of-data-security-incident/",
    "secondary_source_urls": [
      "https://wgme.com/news/local/central-maine-healthcare-data-breach-affects-145000-more-people-than-initially-reported-central-maine-medical-center-maine-attorney-generals-office-cyberattack"
    ],
    "confidence_notes": "Maine AG filing confirmed 145,381; CMHC official notice; WGME reporting",
    "sources_used": [
      "Central Maine Healthcare official notice",
      "WGME"
    ],
    "id": "INC-00781",
    "year": 2026,
    "lat": 44.0990717,
    "lng": -70.2177099,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Coastal Carolina Health Care (CCHC)",
    "organization_type": "Healthcare Provider (Multi-Specialty Practice)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NC",
    "hq_city": "New Bern",
    "hq_county": "Craven",
    "discovery_date": "2025-03-28",
    "disclosure_date": "2026-02-26",
    "executive_summary": "New Bern, NC-based Coastal Carolina Health Care detected unusual system activity on March 28, 2025. Investigation confirmed unauthorized access to systems between March 21 and March 27, 2025 and acquisition of PHI and PII. By February 26, 2026, a third-party vendor confirmed compromised information including names and SSNs. HIPAA Journal noted 645 GB of data was claimed stolen.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown (Genesis ransomware group alleged per HIPAA Journal)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "645 GB allegedly stolen; network disruption",
    "remediation_disclosed": "Network secured; cybersecurity firm engaged; NH AG notified; notifications mailed",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/coastal-carolina-health-care-march-2026",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/six-new-healthcare-data-breaches-announced/"
    ],
    "confidence_notes": "HIPAA Journal March 2026 and ClassAction.org report. Number of affected individuals not yet disclosed.",
    "sources_used": [
      "ClassAction.org",
      "HIPAA Journal"
    ],
    "id": "INC-00782",
    "year": 2026,
    "lat": 35.1068428,
    "lng": -77.0398762,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Columbia Medical Practice (ME notification)",
    "organization_type": "Medical Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "ME",
    "hq_city": "Unknown",
    "hq_county": "Unknown",
    "discovery_date": "2026-03-01",
    "disclosure_date": "2026-04-24",
    "executive_summary": "Columbia Medical Practice reported a data security incident to the Maine AG in April 2026 involving unauthorized access to patient health information. Details are limited as this is a recent notification.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient medical data potentially compromised",
    "remediation_disclosed": "Maine AG notified",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing April 24, 2026; limited detail",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00783",
    "year": 2026,
    "geocode_note": "Exact city not resolved; placed at ME state centroid.",
    "lat": 44.546314178988695,
    "lng": -69.42326963335445,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "state_centroid_jittered"
  },
  {
    "organization_name": "Community Psychiatry Management, LLC (dba Mindpath Health)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Campbell",
    "hq_county": "Santa Clara",
    "discovery_date": "2024-11-25 (per CA AG filing)",
    "disclosure_date": "2026-04-14",
    "executive_summary": "Hacking/IT incident at Mindpath Health (Community Psychiatry Management) in November 2024.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not confirmed (listed in CA AG breach database)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Mindpath Health is a behavioral health provider with extensive CA operations. Listed in CA AG breach database.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00784",
    "year": 2026,
    "lat": 37.2872,
    "lng": -121.95,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Cookeville Regional Medical Center",
    "organization_type": "Healthcare Provider / Regional Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Cookeville",
    "hq_county": "Putnam",
    "discovery_date": "2025-07-14",
    "disclosure_date": "2026-04-14",
    "executive_summary": "Cookeville Regional Medical Center (CRMC) was targeted by the Rhysida ransomware group between July 11-14, 2025. Rhysida claimed responsibility on August 2, 2025 and demanded 10 Bitcoin (~$1.15M). The group claimed 538 GB of data stolen and posted approximately 70% publicly on the dark web. CRMC notified 337,917 affected individuals beginning April 14, 2026 \u2014 roughly nine months after discovery.",
    "attack_type": "Ransomware (Rhysida)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": 337917,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "10 Bitcoin ransom demand (~$1.15M at time); payment status unconfirmed; ~70% of stolen data leaked publicly",
    "operational_impact": "Patient names, addresses, DOBs, SSNs, driver's license numbers, financial accounts, medical records, and health insurance data compromised; significant data publicly leaked",
    "remediation_disclosed": "Third-party forensic investigation; 12 months free identity theft protection through Experian offered; breach notifications sent to 337,917 individuals",
    "primary_source_url": "https://www.infosecurity-magazine.com/news/cookeville-medical-center-data/",
    "secondary_source_urls": [
      "https://www.securityweek.com/data-breach-at-tennessee-hospital-affects-337000/",
      "https://www.corywatson.com/blog/cookeville-regional-medical-center-data-breach-what-victims-need-to-know/"
    ],
    "confidence_notes": "High confidence \u2014 Infosecurity Magazine, SecurityWeek, Cory Watson Attorneys, Maine AG filing, Rhysida dark web claim.",
    "sources_used": [
      "Infosecurity Magazine",
      "SecurityWeek",
      "Cory Watson Attorneys",
      "Maine AG",
      "Rhysida leak site"
    ],
    "id": "INC-00785",
    "year": 2026,
    "lat": 36.1623886,
    "lng": -85.4997057,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Corewell Health (via Pinnacle Holdings breach \u2014 2024)",
    "organization_type": "Nonprofit Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Grand Rapids",
    "hq_county": "Kent",
    "discovery_date": "2024-11-25",
    "disclosure_date": "2026-03-28",
    "executive_summary": "Pinnacle Holdings Ltd., a Colorado-based health care consulting firm that previously provided services to Corewell Health, experienced a 'network disruption' on November 25, 2024, potentially enabling unauthorized access to Corewell Health patient data. Corewell Health was notified and launched a data review. Approximately 19,000 Corewell Health patients were affected. Compromised data included names, phone numbers, SSNs, driver's license numbers, DOBs, health insurance information, prescription information, and dates of service.",
    "attack_type": "Hacking / Network Disruption",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 19000,
    "residents_affected_in_state": "Michigan patients",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Vendor's systems compromised; Corewell's own systems not directly affected",
    "remediation_disclosed": "Yes \u2014 Pinnacle implemented safeguards; Corewell patients notified March 2026; free credit monitoring and identity protection offered",
    "primary_source_url": "https://www.cbsnews.com/detroit/news/corewell-health-pinnacle-holdings-data-breach/",
    "secondary_source_urls": [
      "https://www.fox2detroit.com/news/thousands-corewell-health-patients-affected-2024-vendor-data-breach"
    ],
    "confidence_notes": "High confidence. CBS Detroit, FOX 2 Detroit reporting; Corewell Health press release.",
    "sources_used": [
      "CBS Detroit",
      "FOX 2 Detroit"
    ],
    "id": "INC-00786",
    "year": 2026,
    "lat": 42.9634,
    "lng": -85.6681,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Decatur Diagnostic Laboratory",
    "organization_type": "Healthcare Provider / Clinical Laboratory",
    "organization_type_bucket": "Laboratory / Diagnostic",
    "state": "AL",
    "hq_city": "Decatur",
    "hq_county": "Morgan",
    "discovery_date": "2026-04-14",
    "disclosure_date": "2026-04-14",
    "executive_summary": "On April 14, 2026, the LockBit 5.0 ransomware group publicly claimed responsibility for a cyberattack against Decatur Diagnostic Laboratory, a privately-owned medical laboratory in Decatur, Alabama. The attackers threatened to publish stolen patient data unless ransom demands were met. As of April 2026, Decatur Diagnostic Laboratory had not issued a formal public statement or filed an HHS OCR breach notification.",
    "attack_type": "Ransomware (LockBit 5.0) / Data Extortion",
    "attack_category": "Ransomware",
    "threat_actor_name": "LockBit 5.0",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not publicly disclosed (breach notification not yet filed)",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed; ransom amount not stated",
    "operational_impact": "Patient lab data potentially stolen including names, SSNs, health insurance, lab results, diagnoses, and billing information",
    "remediation_disclosed": "No formal public statement issued as of April 2026",
    "primary_source_url": "https://www.corywatson.com/blog/decatur-diagnostic-laboratory-data-breach-what-alabama-patients-need-to-know/",
    "secondary_source_urls": [
      "https://www.dexpose.io/lockbit-5-0-strikes-decatur-diagnostic-lab-in-the-usa/",
      "https://www.pittmandutton.com/firm-news/decatur-diagnostic-laboratory-data-breach"
    ],
    "confidence_notes": "Medium confidence \u2014 Cory Watson Attorneys, DeXpose threat intelligence, Pittman Dutton law firm reporting. No formal HHS notification filed as of research date; threat actor claim confirmed by multiple security sources.",
    "sources_used": [
      "Cory Watson Attorneys",
      "DeXpose Threat Intelligence",
      "Pittman Dutton Law Firm"
    ],
    "id": "INC-00787",
    "year": 2026,
    "lat": 34.6060203,
    "lng": -86.9838165,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Doctor Alliance (Texas healthcare software \u2013 home health)",
    "organization_type": "Business Associate (Healthcare Software \u2013 Home Health)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "TX",
    "hq_city": "Texas (HQ location not fully specified)",
    "hq_county": "Brazos",
    "discovery_date": "2025-11-17",
    "disclosure_date": "2026-03-26",
    "executive_summary": "Doctor Alliance, a Texas-based software platform used by home health care providers to manage and sign clinical documents, suffered a breach when an unauthorized party obtained credentials and accessed certain files via the Doctor Alliance web portal intermittently between October 31 and November 17, 2025. The attacker used a script to mass-access patient records. Doctor Alliance notified the FBI on November 16, 2025. Multiple Texas home healthcare providers then issued breach notices.",
    "attack_type": "Hacking/IT Incident \u2013 Credential Compromise / Automated Web Access",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Texas home healthcare patients primarily",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Portal access compromised; systems secured after discovery",
    "remediation_disclosed": "FBI notified November 16, 2025; systems secured; home health companies notified patients",
    "primary_source_url": "https://www.fox4news.com/news/sensitive-patient-health-information-leaked-texas-third-party-software-breach",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; FOX 4 Dallas documented; FBI notification confirmed",
    "sources_used": [
      "FOX 4 Dallas-Fort Worth"
    ],
    "id": "INC-00788",
    "year": 2026,
    "lat": 30.6108618,
    "lng": -96.3520606,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Enhabit Home Health & Hospice (Dallas TX) \u2013 Doctor Alliance/Kazu breach",
    "organization_type": "Home Health / Hospice",
    "organization_type_bucket": "Home health / Long-term care",
    "state": "TX",
    "hq_city": "Dallas",
    "hq_county": "Dallas",
    "discovery_date": "2025-12-05",
    "disclosure_date": "2026-02-05",
    "executive_summary": "Doctor Alliance (My 485 Inc.), used by Enhabit Home Health & Hospice, was breached by the Kazu ransomware group via compromised credentials in October\u2013November 2025. 22,552 Enhabit patients' PHI exposed including names, addresses, DOB, medical record numbers, clinical information, and health plan numbers. SSNs and financial data not involved.",
    "attack_type": "Credential Compromise / Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Kazu",
    "attribution_status": "claimed",
    "individuals_affected_reported": 22552,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient portal compromised",
    "remediation_disclosed": "Additional authentication implemented; HHS notified February 2026",
    "primary_source_url": "https://www.hipaajournal.com/three-healthcare-providers-ransomware-attacks/",
    "secondary_source_urls": [
      "https://www.claimdepot.com/data-breach/enhabit-home-health-hospice-2026"
    ],
    "confidence_notes": "High confidence; HIPAA Journal confirmed 22,552 patients; Kazu claimed 353 GB from Doctor Alliance; distinct from SC073 (Amedisys/Doctor Alliance)",
    "sources_used": [
      "HIPAA Journal",
      "Claim Depot"
    ],
    "id": "INC-00789",
    "year": 2026,
    "lat": 32.7767,
    "lng": -96.797,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Erlanger Health System (via TPS/TriZetto Provider Solutions)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TN",
    "hq_city": "Chattanooga",
    "hq_county": "Hamilton",
    "discovery_date": "2025-12-11",
    "disclosure_date": "2026-02-04",
    "executive_summary": "Erlanger Health System was notified on December 11, 2025 by TriZetto Provider Solutions (TPS) of a breach at TPS. Investigation determined unauthorized access to TPS systems between November 2024 and October 2025. Approximately 219 Erlanger Health patients had data contained in the TPS breach.",
    "attack_type": "Business Associate Breach (TPS/TriZetto)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 219,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "219 patient records exposed via claims management vendor",
    "remediation_disclosed": "Erlanger notified affected patients; posted substitute notice on website",
    "primary_source_url": "https://www.erlanger.org/about-us/data-breach-notice",
    "secondary_source_urls": [],
    "confidence_notes": "Erlanger official website notice is primary source. Small number of affected patients (219).",
    "sources_used": [
      "Erlanger Health (official website)"
    ],
    "id": "INC-00790",
    "year": 2026,
    "lat": 35.0456,
    "lng": -85.3097,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Healthcare Interactive, Inc. (HCIactive) \u2014 SC impact",
    "organization_type": "Business Associate / Healthcare Technology",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "SC",
    "hq_city": "Ellicott City",
    "hq_county": "Howard County (MD-based)",
    "discovery_date": "2020-07-01",
    "disclosure_date": "2026-01-07",
    "executive_summary": "Healthcare Interactive, Inc. (HCIactive), an AI-powered healthcare insurance enrollment software provider, experienced a data breach discovered in July 2020. By January 2026 the breach was confirmed to affect 3,056,950 individuals nationwide, including 103,000 South Carolina residents. The breach exposed names, addresses, DOBs, SSNs, medical information, and insurance data. SC Consumer Affairs reported this as affecting 103,000 SC residents.",
    "attack_type": "Network Intrusion / Unauthorized Access",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3056950,
    "residents_affected_in_state": 103000,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Healthcare enrollment and benefits administration data exposed; ranked 5th largest healthcare data breach of 2025",
    "remediation_disclosed": "Breach reported to SC AG January 2026; credit monitoring offered; investigation conducted",
    "primary_source_url": "https://insurancenewsnet.com/oarticle/massive-data-breach-at-healthcare-interactive-affects-over-3-million-including-103000-sc-residents",
    "secondary_source_urls": [
      "https://www.classaction.org/data-breach-lawsuits/hciactive-september-2025",
      "https://consumer.sc.gov/identity-theft-unit/security-breach-notices"
    ],
    "confidence_notes": "High confidence \u2014 InsuranceNewsNet reporting, ClassAction.org, SC Consumer Affairs listing (103,000 SC residents). Note: organization HQ is in Maryland but breach had major SC patient impact.",
    "sources_used": [
      "InsuranceNewsNet",
      "ClassAction.org",
      "SC Consumer Affairs Breach Portal",
      "WLTX News"
    ],
    "id": "INC-00791",
    "year": 2026,
    "lat": 39.2673284,
    "lng": -76.7983067,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Heart South Cardiovascular Group",
    "organization_type": "Healthcare Provider / Cardiovascular Practice",
    "organization_type_bucket": "Hospital / Health system",
    "state": "AL",
    "hq_city": "Alabaster",
    "hq_county": "Shelby",
    "discovery_date": "2025-11-10",
    "disclosure_date": "2026-04-23",
    "executive_summary": "Heart South Cardiovascular Group, a three-clinic central Alabama cardiovascular practice, disclosed its second data breach in two years. The Rhysida ransomware group claimed responsibility on November 10, 2025, demanding 6 bitcoin ($630,000) and posting sample data on its dark web leak site. The breach affected 46,666 individuals.",
    "attack_type": "Ransomware (Rhysida)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Rhysida",
    "attribution_status": "claimed",
    "individuals_affected_reported": 46666,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "6 Bitcoin ransom demand (~$630,000); payment status not confirmed",
    "operational_impact": "Patient data stolen and posted to dark web; second ransomware event within 18 months",
    "remediation_disclosed": "Free credit monitoring and identity theft restoration through Kroll offered to affected individuals",
    "primary_source_url": "https://www.paubox.com/blog/heart-south-cardiovascular-group-reports-second-ransomware-breach-in-18-months",
    "secondary_source_urls": [
      "https://www.redpacketsecurity.com/rhysida-ransomware-victim-heart-south-cardiovascular-group/"
    ],
    "confidence_notes": "High confidence \u2014 Paubox/HIPAA Times reporting, RedPacket Security threat intelligence, Comparitech data.",
    "sources_used": [
      "Paubox (HIPAA Times)",
      "RedPacket Security",
      "Comparitech"
    ],
    "id": "INC-00792",
    "year": 2026,
    "lat": 33.2442813,
    "lng": -86.8163773,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "IU Health (Indiana University Health) \u2014 Change Healthcare Impact / $66M Losses",
    "organization_type": "Academic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IN",
    "hq_city": "Indianapolis",
    "hq_county": "Marion",
    "discovery_date": "2024-02-21",
    "disclosure_date": "2026-02-19",
    "executive_summary": "Indiana University Health (IU Health), Indiana's largest health system, sustained an estimated $66 million in operational losses due to the February 2024 Change Healthcare ransomware attack (see MW-001). Although IU Health itself was not breached, the disruption to Change Healthcare's claims processing and data systems \u2014 which IU Health relied upon under a Business Associate Agreement requiring MFA for IU Health data \u2014 caused massive financial harm. IU Health was unable to process insurance claims, verify coverage, or access critical administrative data for an extended period. IU Health filed a federal lawsuit against Change Healthcare on February 19, 2026, in the Minnesota US District Court seeking $66 million in damages and alleging negligence, gross negligence, breach of contract, unjust enrichment, and fraud.",
    "attack_type": "Third-Party Operational and Financial Impact (Change Healthcare ransomware)",
    "attack_category": "Ransomware",
    "threat_actor_name": "BlackCat/ALPHV (Change Healthcare attacker)",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Not separately reported \u2014 IU Health patient data not directly breached; operational financial impact only",
    "residents_affected_in_state": "Indiana patients experienced care and billing delays",
    "financial_impact": "$66 million in damages claimed by IU Health including temporary staffing, IT workarounds, lost billing revenue, and operational disruption",
    "operational_impact": "Claims processing halted; insurance verification unavailable; billing severely disrupted; internal incident command centers established; temporary staff hired",
    "remediation_disclosed": "Yes \u2014 IU Health implemented IT workarounds, contracted temp employees, manual backlog review; filed lawsuit February 2026",
    "primary_source_url": "https://www.theindianalawyer.com/articles/iu-health-files-lawsuit-against-firm-hit-by-2024-ransomware-attack",
    "secondary_source_urls": [
      "https://www.idsnews.com/article/2026/03/iu-health-files-lawsuit-healthcare-tech-company-data-breach"
    ],
    "confidence_notes": "High confidence. Indiana Lawyer and Indiana Daily Student confirmed $66M lawsuit filing. IU Health is not a breach subject itself but a major Midwest victim of the Change Healthcare attack.",
    "sources_used": [
      "The Indiana Lawyer",
      "Indiana Daily Student",
      "IU Health"
    ],
    "id": "INC-00793",
    "year": 2026,
    "lat": 39.7684,
    "lng": -86.1581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Iowa Department of Health and Human Services \u2014 Medicaid Data Exposure",
    "organization_type": "State Government / Medicaid Program",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2026-02-20",
    "disclosure_date": "2026-04-01",
    "executive_summary": "On February 20, 2026, the Iowa Department of Health and Human Services (HHS) became aware that a file containing limited Medicaid subscriber information had been inadvertently posted to the department's website on February 16, 2026. The file was immediately removed. It contained Medicaid subscriber IDs, names of Medicaid waiver programs associated with those IDs, and dates assessments for eligibility were scheduled or conducted. It did not contain subscriber names, addresses, or other contact or health information. Approximately 6,717 individuals were affected.",
    "attack_type": "Unauthorized Data Exposure (inadvertent public posting)",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Not applicable \u2014 government error",
    "attribution_status": "unknown",
    "individuals_affected_reported": 6717,
    "residents_affected_in_state": 6717,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "No clinical operations disruption; Medicaid subscriber IDs potentially misused for medical fraud",
    "remediation_disclosed": "Yes \u2014 file removed February 20, 2026; all affected individuals notified",
    "primary_source_url": "https://hhs.iowa.gov/about/newsroom/data-breach-notifications",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. Iowa HHS official data breach notification page.",
    "sources_used": [
      "Iowa HHS",
      "Iowa DHHS data breach notifications"
    ],
    "id": "INC-00794",
    "year": 2026,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "La Clinica de La Raza, Inc.",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Oakland",
    "hq_county": "Alameda",
    "discovery_date": "2024-11-04 (per CA AG filing)",
    "disclosure_date": "2026-01-15",
    "executive_summary": "Hacking/IT incident at La Clinica de La Raza, a community health organization serving the East Bay area of Northern California.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not confirmed from available sources",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed in CA AG breach database (Jan 2026 report date). La Clinica is a major FQHC in Alameda, Contra Costa, and Solano counties.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00795",
    "year": 2026,
    "lat": 37.8044,
    "lng": -122.2712,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Legacy Health LLC (ransomware \u2014 revenue cycle)",
    "organization_type": "Business Associate (Healthcare Revenue Cycle Management)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "OR",
    "hq_city": "Portland",
    "hq_county": "Multnomah",
    "discovery_date": "2026-03-16",
    "disclosure_date": "2026-03-20",
    "executive_summary": "Note: This is Legacy Health LLC, a Dallas-based healthcare revenue cycle management company (distinct from Legacy Health hospital system in Portland). The Worldleaks ransomware group claimed responsibility for an attack disclosed March 20, 2026. Sensitive personal and financial information was accessed, including names, Social Security numbers, bank account numbers, and driver's license numbers. The number of affected individuals had not been publicly disclosed as of the investigation date.",
    "attack_type": "Ransomware",
    "attack_category": "Ransomware",
    "threat_actor_name": "Worldleaks",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI and financial data stolen from revenue cycle management systems",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://colevannote.com/2026/03/20/legacy-health-llc-data-breach-investigation-2/",
    "secondary_source_urls": [
      "https://www.reddit.com/r/pwnhub/comments/1rzbzog/worldleaks_exposes_legacy_health_llc_as_latest/"
    ],
    "confidence_notes": "This is Legacy Health LLC (TX-based RCM firm), not Legacy Health Oregon hospital system. Included because it affects Oregon healthcare providers as clients. March 2026.",
    "sources_used": [
      "Cole & Van Note",
      "Reddit/pwnhub"
    ],
    "id": "INC-00796",
    "year": 2026,
    "lat": 45.5051,
    "lng": -122.675,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "LifeLong Medical Care \u2014 TriZetto Provider Solutions Breach",
    "organization_type": "Federally qualified health center (FQHC) / community health provider (East Bay, Northern CA)",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "CA",
    "hq_city": "Richmond",
    "hq_county": "Contra Costa County",
    "discovery_date": "2025-10-02",
    "disclosure_date": "2026-01-14",
    "executive_summary": "TriZetto Provider Solutions (TPS), a business associate used by LifeLong Medical Care for insurance eligibility verification, disclosed a breach to LifeLong on October 2, 2025. TPS determined that beginning in November 2024, an unauthorized actor accessed records related to insurance eligibility verification transactions via a web portal. Data potentially including names, SSNs, DOBs, health insurance information, and other PHI was exposed. LifeLong filed a breach notice with the California Attorney General on approximately January 14, 2026.",
    "attack_type": "Hacking / unauthorized access via web portal (business associate TriZetto Provider Solutions)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "NOT_PUBLICLY_DISCLOSED",
    "attribution_status": "unknown",
    "individuals_affected_reported": "NOT_DISCLOSED",
    "residents_affected_in_state": "East Bay CA residents (LifeLong patient base)",
    "financial_impact": "{'notes': 'No financial penalties or settlements disclosed.'}",
    "operational_impact": "No clinical disruption reported.",
    "remediation_disclosed": "TPS took additional protective measures; cybersecurity experts and law enforcement engaged; LifeLong notified affected individuals; no payment card or banking data involved.",
    "primary_source_url": "https://oag.ca.gov/system/files/LifeLong%20TriZetto%20Patient%20Breach%20Notification.pdf",
    "secondary_source_urls": [
      "https://www.federmanlaw.com/blog/lifelong-medical-care-data-breach-investigated-by-federman-sherwood/",
      "https://thelyonfirm.com/class-action/data-breach/lifelong-medical-care/"
    ],
    "confidence_notes": "Earlier LifeLong breach: August 2021 (business associate, 115,448 patients; reported Aug 25, 2021 to OCR). This entry covers the more recent 2024\u20132026 TPS incident. Note: 'Valley Health Team' per the task list \u2014 no matching CA healthcare org 'Valley Health Team' was found; 'Valley Family Health Care' (Fresno area) was affected by a similar TriZetto breach (Nov 2024). Valley Health Team may refer to a specific local CA FQHC not separately documented in this period.",
    "sources_used": [
      "Organization notice / News / SEC"
    ],
    "id": "INC-00797",
    "year": 2026,
    "lat": 37.9358,
    "lng": -122.3477,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Marin Cancer Care",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Greenbrae",
    "hq_county": "Marin",
    "discovery_date": "2025-11-22 (per CA AG filing)",
    "disclosure_date": "2026-02-06",
    "executive_summary": "Hacking/IT incident at Marin Cancer Care affecting network server.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 501,
    "residents_affected_in_state": 501,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed on both HHS OCR portal and CA AG breach notice list.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00798",
    "year": 2026,
    "lat": 37.954,
    "lng": -122.5378,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "MercyOne (via Veradigm/Allscripts Cerner/Oracle incident \u2014 2025-2026)",
    "organization_type": "Nonprofit Hospital System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "IA",
    "hq_city": "Des Moines",
    "hq_county": "Polk",
    "discovery_date": "2025-12-01",
    "disclosure_date": "2026-01-22",
    "executive_summary": "MercyOne patients in Iowa were notified in January 2026 of a data breach at Veradigim (formerly Allscripts) involving unauthorized access to a storage account using stolen credentials in December 2024. Some notification letters were mailed January 22, 2026, including a vendor data-matching error (wrong names on envelopes). Compromised data included DOBs, medical records, insurance, and payment details. No evidence of misuse was found and MercyOne's own systems were not directly affected.",
    "attack_type": "Third-Party Vendor Breach (cloud storage credential theft)",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2500000,
    "residents_affected_in_state": "Iowa residents (MercyOne patients)",
    "financial_impact": "Not separately disclosed",
    "operational_impact": "MercyOne's own systems not directly affected; notification process experienced vendor data-matching error",
    "remediation_disclosed": "Yes \u2014 vendor secured storage account; patients notified January 2026",
    "primary_source_url": "https://www.mercyone.org/press-releases/mercyone-statement-regarding-january-22-cerneroracle-security-incident",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/veradigm-data-breach/"
    ],
    "confidence_notes": "High confidence. MercyOne official press release, HIPAA Journal Veradigm coverage.",
    "sources_used": [
      "MercyOne",
      "HIPAA Journal"
    ],
    "id": "INC-00799",
    "year": 2026,
    "lat": 41.5868,
    "lng": -93.625,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "NYC Health + Hospitals",
    "organization_type": "Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "NY",
    "hq_city": "New York",
    "hq_county": "New York",
    "discovery_date": "2026-02-02",
    "disclosure_date": "2026-03-24",
    "executive_summary": "NYC Health + Hospitals discovered suspicious activity on February 2, 2026. Investigation revealed that an unauthorized actor accessed systems between approximately November 25, 2025 and February 11, 2026, via a breach at a third-party vendor. Data potentially compromised included health insurance information, medical records, biometric information (fingerprints, palm prints), financial data, and PII. The exact number of affected individuals was not disclosed.",
    "attack_type": "Hacking/IT Incident via third-party vendor",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "11-week unauthorized access period; biometric and medical data potentially exfiltrated",
    "remediation_disclosed": "Network immediately secured; external cybersecurity firm engaged; 24-month credit monitoring offered to all patients/employees since 2020; enhanced detection technologies deployed",
    "primary_source_url": "https://www.nychealthandhospitals.org/pressrelease/notice-of-data-breach/",
    "secondary_source_urls": [
      "https://www.reddit.com/r/pwnhub/comments/1s3eim3/nyc_health_hospitals_faces_serious_cybersecurity_compromise/"
    ],
    "confidence_notes": "NYC H+H official notice; incident not yet on HHS OCR portal as of March 2026",
    "sources_used": [
      "NYC Health + Hospitals official notice",
      "Reddit/PwnHub"
    ],
    "id": "INC-00800",
    "year": 2026,
    "lat": 40.7128,
    "lng": -74.006,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Nacogdoches Memorial Hospital",
    "organization_type": "Healthcare Provider (Hospital)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Nacogdoches",
    "hq_county": "Nacogdoches",
    "discovery_date": "2026-01-31",
    "disclosure_date": "2026-04-02",
    "executive_summary": "Nacogdoches Memorial Hospital reported that on January 31, 2026, a threat actor hacked into its internal network and information systems from approximately January 15, 2026. 257,073 individuals were notified that their data may have been compromised. Exposed information included names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and in some cases photographs of patients.",
    "attack_type": "Hacking/IT Incident \u2013 Network Intrusion",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 257073,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network and information systems compromised",
    "remediation_disclosed": "Investigation launched; law enforcement notified; notifications sent to Maine AG",
    "primary_source_url": "https://www.securityweek.com/250000-affected-by-data-breach-at-nacogdoches-memorial-hospital/",
    "secondary_source_urls": [
      "https://www.paubox.com/blog/nacogdoches-memorial-hospital-investigates-a-250k-data-breach"
    ],
    "confidence_notes": "High confidence; SecurityWeek and Paubox documented; Maine AG notification confirmed 257,073",
    "sources_used": [
      "SecurityWeek, Paubox"
    ],
    "id": "INC-00801",
    "year": 2026,
    "lat": 31.5970503,
    "lng": -94.5927451,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Nephrology Associates Medical Group, Inc.",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "California (Central/Southern CA)",
    "hq_county": "Unknown",
    "discovery_date": "2025-05-19 to 2025-05-22 (per CA AG filing)",
    "disclosure_date": "2026-02-27",
    "executive_summary": "Email-based hacking/IT incident at Nephrology Associates Medical Group.",
    "attack_type": "Hacking/IT Incident \u2014 Email compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4631,
    "residents_affected_in_state": 4631,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed on HHS OCR portal and CA AG breach list.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00802",
    "year": 2026,
    "lat": 36.647296514856365,
    "lng": -119.0064745126956,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "New Horizons Behavioral Health",
    "organization_type": "Healthcare Provider (Behavioral Health/Non-Profit)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Columbus",
    "hq_county": "Muscogee",
    "discovery_date": "2026-01-18",
    "disclosure_date": "2026-03-18",
    "executive_summary": "Columbus, GA-based New Horizons Behavioral Health (8-county mental health services provider) disclosed that an unauthorized actor accessed its computer network between January 15 and January 18, 2026. PHI and PII of an unspecified number of individuals was potentially accessed or obtained. Data types included names, addresses, DOBs, SSNs, driver's licenses, financial account info, and medical/health insurance information.",
    "attack_type": "Network Intrusion / Data Exfiltration",
    "attack_category": "Data exfiltration",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network access and data acquisition by unauthorized actor",
    "remediation_disclosed": "Credit monitoring offered; notification mailed March 2026",
    "primary_source_url": "https://nhbh.org/data-privacy-event",
    "secondary_source_urls": [
      "https://www.ledger-enquirer.com/news/local/article315167536.html"
    ],
    "confidence_notes": "New Horizons official website notice is primary source. Ledger-Enquirer local news corroborates. Individual count not yet disclosed.",
    "sources_used": [
      "New Horizons Behavioral Health (official website)",
      "Columbus Ledger-Enquirer"
    ],
    "id": "INC-00803",
    "year": 2026,
    "lat": 32.4609,
    "lng": -84.9877,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "North East Medical Services (NEMS)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "San Francisco",
    "hq_county": "San Francisco",
    "discovery_date": "2025-10-19 (per CA AG filing)",
    "disclosure_date": "2026-02-18",
    "executive_summary": "Hacking/IT incident at North East Medical Services (NEMS), a community health center serving the Chinese-American community in San Francisco.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Not confirmed from available sources",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed in CA AG breach database (Feb 2026 report date).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00804",
    "year": 2026,
    "lat": 37.7749,
    "lng": -122.4194,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "North Texas Behavioral Health Authority",
    "organization_type": "Healthcare Provider (Behavioral Health / Mental Health Authority)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "TX",
    "hq_city": "Dallas",
    "hq_county": "Dallas",
    "discovery_date": "2025-10-01",
    "disclosure_date": "2026-01-01",
    "executive_summary": "North Texas Behavioral Health Authority, a mental health and substance abuse resource provider serving the Dallas-Fort Worth area, detected a network intrusion in October 2025. Investigation revealed that unauthorized individuals may have accessed and exfiltrated files containing personal information, including Social Security numbers, for approximately 285,000 individuals. The Insomnia ransomware group claimed responsibility, listing the organization on its leak website in February 2026 and claiming to have stolen information on 150,000 patients. The organization filed a breach report with HHS OCR.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware Attack with Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Insomnia",
    "attribution_status": "claimed",
    "individuals_affected_reported": 285000,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Network intrusion; files potentially exfiltrated",
    "remediation_disclosed": "Investigation launched; HHS OCR breach notice filed; notifications sent to affected individuals",
    "primary_source_url": "https://www.news4hackers.com/data-breaches-hit-healthcare-organizations-in-il-and-tx-impacting-600k-individuals/",
    "secondary_source_urls": [
      "https://evrimagaci.org/gpt/texas-probes-massive-health-data-breach-impacting-millions-528760"
    ],
    "confidence_notes": "HHS OCR breach report confirmed 285,000 affected; Insomnia ransomware group claimed responsibility in February 2026; SecurityWeek reported",
    "sources_used": [
      "News4Hackers/SecurityWeek, Grand Pinnacle Tribune"
    ],
    "id": "INC-00805",
    "year": 2026,
    "lat": 32.7767,
    "lng": -96.797,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "One Community Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Sacramento",
    "hq_county": "Sacramento",
    "discovery_date": "Unknown",
    "disclosure_date": "2026-01-02",
    "executive_summary": "Hacking/IT incident at One Community Health. Business associate involved.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 4309,
    "residents_affected_in_state": 4309,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal (Jan 2026).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00806",
    "year": 2026,
    "lat": 38.5816,
    "lng": -121.4944,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "PIH Health, Inc. (2024 Ransomware Attack)",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Whittier",
    "hq_county": "Los Angeles",
    "discovery_date": "2024-11-14 to 2024-12-23 (access period); 2024-12-01 (ransomware detected)",
    "disclosure_date": "2026 (pending formal notification completion Feb 25, 2026)",
    "executive_summary": "Ransomware attack disrupted systems at PIH Health Downey Hospital, Good Samaritan Hospital, Whittier Hospital, urgent care centers, and physician offices. Hackers claimed 2 TB data exfiltration including 17 million patient records.",
    "attack_type": "Hacking/IT Incident \u2014 Ransomware with claimed 2 TB data exfiltration; systems offline for extended period",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (no group claimed responsibility publicly)",
    "attribution_status": "claimed",
    "individuals_affected_reported": 17000000,
    "residents_affected_in_state": "Not separately confirmed (serves Orange County and San Gabriel Valley)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Multiple hospital systems offline; phone systems disrupted; PIH Health Downey Hospital, Good Samaritan Hospital, Whittier Hospital affected; urgent care and home health disrupted; scheduling and call centers impacted",
    "remediation_disclosed": "Systems isolated upon detection; third-party cyber forensic specialists engaged; FBI and local law enforcement notified; validated backups used for recovery; credit monitoring and identity theft protection offered; notification letters mailed Feb 25, 2026",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://www.hipaajournal.com/pih-health-data-breach-ransomware/",
      "https://www.netsec.news/pih-health-ransomware-incident/",
      "https://www.jdsupra.com/legalnews/hackers-orchestrate-cyberattack-against-6185632/"
    ],
    "confidence_notes": "Access period: Nov 14 \u2013 Dec 23, 2024. Formal notification completion: Feb 25, 2026. Investigation confirmed files accessed/potentially exfiltrated. PHI may include names, addresses, SSNs, taxpayer IDs, driver's licenses, financial account info, credit/debit card numbers, medical info, health insurance info.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00807",
    "year": 2026,
    "lat": 33.9792,
    "lng": -118.0328,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Personalis, Inc.",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Menlo Park",
    "hq_county": "San Mateo",
    "discovery_date": "Unknown",
    "disclosure_date": "2026-02-04",
    "executive_summary": "Email-based hacking/IT incident at Personalis, a genomic intelligence company providing precision oncology services.",
    "attack_type": "Hacking/IT Incident \u2014 Email compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 650,
    "residents_affected_in_state": 650,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal (Feb 2026).",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00808",
    "year": 2026,
    "lat": 37.453,
    "lng": -122.1817,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Physicians' Clinic of Iowa",
    "organization_type": "Multi-Specialty Physician Group",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "IA",
    "hq_city": "Cedar Rapids",
    "hq_county": "Linn",
    "discovery_date": "2026-02-26",
    "disclosure_date": "2026-03-01",
    "executive_summary": "Physicians' Clinic of Iowa (PCI), a multi-specialty physician group in Cedar Rapids, Iowa, was listed by ransomware group Anubis as a victim of a data exfiltration attack on February 26, 2026. According to Ransomware.Live, Anubis published images purportedly showing exfiltrated data including personal identifiers and protected health information. As of early March 2026, PCI had not confirmed the breach or issued a formal notification. This incident is currently under investigation.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Anubis ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": "Unknown \u2014 not yet confirmed",
    "residents_affected_in_state": "Iowa residents \u2014 scope not yet determined",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not yet confirmed",
    "remediation_disclosed": "Not publicly disclosed as of March 2026",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/physicians-clinic-of-iowa-february-2026",
    "secondary_source_urls": [],
    "confidence_notes": "Low-medium confidence. Ransomware.Live and ClassAction.org reporting. PCI has not confirmed. Preliminary/emerging incident.",
    "sources_used": [
      "ClassAction.org",
      "Ransomware.Live (via ClassAction.org)"
    ],
    "id": "INC-00809",
    "year": 2026,
    "lat": 41.9779,
    "lng": -91.6656,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Pit River Health Service Inc.",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Burney",
    "hq_county": "Shasta",
    "discovery_date": "Unknown",
    "disclosure_date": "2026-01-06",
    "executive_summary": "Hacking/IT incident at Pit River Health Service Inc., a tribal health facility in Northern California.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1800,
    "residents_affected_in_state": 1800,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf"
    ],
    "confidence_notes": "Tribal health facility serving Native American community in Shasta County, CA.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00810",
    "year": 2026,
    "lat": 40.8821,
    "lng": -121.6602,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Providence Health & Services (HIE Unauthorized Sharing)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "WA",
    "hq_city": "Renton",
    "hq_county": "King",
    "discovery_date": "2026-02-11",
    "disclosure_date": "2026-04-09",
    "executive_summary": "Providence Health & Services discovered on February 11, 2026, that its Health Information Exchange (HIE), managed via Health Gorilla and integrated with its Epic EHR system, had been sharing patient data with unauthorized HIE participants from August 30, 2024 through December 8, 2025. While no hacking or external theft was confirmed, sensitive clinical data including diagnoses, medications, test results, insurance, and demographic information was shared without defined business need. Providence is offering 12 months of complimentary identity protection through IDX.",
    "attack_type": "Unauthorized disclosure via HIE misconfiguration",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "N/A (configuration/access control failure)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2026,
    "residents_affected_in_state": "WA OR and other Providence states",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI shared without authorization for ~15 months",
    "remediation_disclosed": "Additional safeguards implemented; working with Health Gorilla; 12-month IDX identity protection offered",
    "primary_source_url": "https://www.dapeer.com/databreaches/providence-data-breach-ssns-exposed",
    "secondary_source_urls": [
      "https://classactionu.org/current-data-breaches/providence/"
    ],
    "confidence_notes": "Discovered and disclosed 2026; individual count not yet released; Providence HQ in Renton, WA with operations in WA and OR",
    "sources_used": [
      "Dapeer Law",
      "Class Action U"
    ],
    "id": "INC-00811",
    "year": 2026,
    "lat": 47.4829,
    "lng": -122.2171,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Providence Health & Services (Health Information Exchange breach)",
    "organization_type": "Healthcare Provider (Health System / Integrated Health Network)",
    "organization_type_bucket": "Health plan / Insurer",
    "state": "WA",
    "hq_city": "Renton",
    "hq_county": "King",
    "discovery_date": "2026-02-11",
    "disclosure_date": "2026-04-09",
    "executive_summary": "Providence Health & Services discovered on February 11, 2026 that certain participants in its Health Information Exchange (HIE), connected via Health Gorilla and the Epic EHR system, had accessed or shared patient information without a defined business need between August 30, 2024 and December 8, 2025. The issue stemmed from Health Gorilla's network configuration, which allowed some HIE participants inappropriate access to patient records. While no external hacking occurred and Providence's own systems were not breached, the unauthorized sharing of PHI across a 15+ month window constitutes a HIPAA-reportable breach. Affected data included names, dates of birth, addresses, insurance information, and clinical records. No SSNs were involved. Providence notified affected patients beginning April 9, 2026 and offered 12-month identity protection through IDX.",
    "attack_type": "Unauthorized access via third-party HIE misconfiguration",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Not applicable (internal/partner unauthorized access, not criminal hacking)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 2026,
    "residents_affected_in_state": "Not separately reported (Providence serves WA OR AK and other states)",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "PHI shared without authorization across 15-month window; clinical data including diagnoses, medications, test results potentially exposed",
    "remediation_disclosed": "Health Gorilla configuration corrected; IDX identity protection offered (12 months); enrollment deadline July 9, 2026",
    "primary_source_url": "https://www.dapeer.com/databreaches/providence-data-breach-ssns-exposed",
    "secondary_source_urls": [
      "https://classactionu.org/current-data-breaches/providence/"
    ],
    "confidence_notes": "Providence official disclosure April 9, 2026; Dapeer Law reporting confirms breach window and notification details; classified as Unauthorized Access/Disclosure not hacking \u2014 included as PHI was improperly shared via HIE partner; confidence high",
    "sources_used": [
      "Dapeer Law",
      "ClassAction U",
      "Providence Health official disclosure"
    ],
    "id": "INC-00812",
    "year": 2026,
    "lat": 47.4829,
    "lng": -122.2171,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Rocky Mountain Care",
    "organization_type": "Healthcare Provider (Senior Living / Long-Term Care)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "UT",
    "hq_city": "Salt Lake City",
    "hq_county": "Salt Lake",
    "discovery_date": "2026-02-02",
    "disclosure_date": "2026-03-27",
    "executive_summary": "Rocky Mountain Care, a Utah-based senior living and long-term care company, confirmed a cybersecurity breach occurring between January 30 and February 2, 2026. The Qilin ransomware group was linked to the breach via dark web monitoring (Ransomware.Live identified it on February 23, 2026). The company was determining the extent of patient PHI compromised and planned direct notifications.",
    "attack_type": "Hacking/IT Incident \u2013 Ransomware (Qilin)",
    "attack_category": "Ransomware",
    "threat_actor_name": "Qilin",
    "attribution_status": "claimed",
    "individuals_affected_reported": "Not publicly disclosed at time of research",
    "residents_affected_in_state": "Utah senior care residents",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Investigation ongoing; direct notifications planned",
    "primary_source_url": "https://www.classaction.org/data-breach-lawsuits/rocky-mountain-care-march-2026",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence; ClassAction.org documented; breach notice confirmed on Rocky Mountain Care website",
    "sources_used": [
      "ClassAction.org"
    ],
    "id": "INC-00813",
    "year": 2026,
    "lat": 40.7608,
    "lng": -111.891,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Santa Cruz Community Health",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "Santa Cruz",
    "hq_county": "Santa Cruz",
    "discovery_date": "2024-11-01 to 2024-10-02 (per CA AG filing)",
    "disclosure_date": "2026-01-12",
    "executive_summary": "Hacking/IT incident at Santa Cruz Community Health involving network server. Business associate present.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1487,
    "residents_affected_in_state": 1487,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf",
      "https://oag.ca.gov/privacy/databreach/list"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00814",
    "year": 2026,
    "lat": 36.9741,
    "lng": -122.0308,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "Signature Healthcare (Brockton Hospital)",
    "organization_type": "Hospital",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MA",
    "hq_city": "Brockton",
    "hq_county": "Plymouth",
    "discovery_date": "2026-04-07",
    "disclosure_date": "2026-04-08",
    "executive_summary": "Signature Healthcare in Brockton, Massachusetts diverted ambulances on April 7-8, 2026 following a cyberattack that caused significant disruptions. The organization did not confirm a ransomware attack and no threat actor had claimed responsibility as of the reporting date. This is among the most recent incidents in the dataset.",
    "attack_type": "Cyberattack (nature unconfirmed)",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Ambulances diverted; significant operational disruption",
    "remediation_disclosed": "Investigation underway as of April 2026",
    "primary_source_url": "https://www.securityweek.com/massachusetts-hospital-diverts-ambulances-as-cyberattack-causes-disruption/",
    "secondary_source_urls": [],
    "confidence_notes": "SecurityWeek reporting; very recent incident with limited details",
    "sources_used": [
      "SecurityWeek"
    ],
    "id": "INC-00815",
    "year": 2026,
    "lat": 42.0834335,
    "lng": -71.0183787,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Southern Illinois Dermatology",
    "organization_type": "Dermatology Medical Practice",
    "organization_type_bucket": "Medical group / Clinic",
    "state": "IL",
    "hq_city": "Salem",
    "hq_county": "Marion",
    "discovery_date": "2025-11-01",
    "disclosure_date": "2026-03-01",
    "executive_summary": "Southern Illinois Dermatology, a Salem, Illinois-based dermatology practice, became aware of a cybersecurity incident in late November 2025. An investigation completed in early March 2026 determined that files storing personal information were compromised. The Insomnia ransomware group listed Southern Illinois Dermatology on its leak site in February 2026, claiming to have stolen information of 150,000 patients and subsequently leaking the data. HHS OCR breach reports confirmed approximately 160,000 individuals were affected. Exposed data included personal and health information.",
    "attack_type": "Ransomware / Data Exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Insomnia ransomware group",
    "attribution_status": "confirmed",
    "individuals_affected_reported": 160000,
    "residents_affected_in_state": "Illinois residents \u2014 primarily Marion County and southern Illinois",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient files compromised; ransomware group leaked stolen data",
    "remediation_disclosed": "Partial \u2014 investigation completed March 2026; HHS OCR notified",
    "primary_source_url": "https://www.securityweek.com/data-breaches-at-healthcare-organizations-in-illinois-and-texas-affect-600000/",
    "secondary_source_urls": [],
    "confidence_notes": "High confidence. SecurityWeek confirmed via HHS OCR breach tracker. Insomnia ransomware group attribution confirmed by SecurityWeek reporting.",
    "sources_used": [
      "SecurityWeek",
      "HHS OCR"
    ],
    "id": "INC-00816",
    "year": 2026,
    "lat": 38.6269929,
    "lng": -88.9456158,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Tieu Dental Corporation",
    "organization_type": "Healthcare Provider",
    "organization_type_bucket": "Hospital / Health system",
    "state": "CA",
    "hq_city": "California (exact city not confirmed)",
    "hq_county": "Unknown",
    "discovery_date": "Unknown",
    "disclosure_date": "2026-03-05",
    "executive_summary": "Hacking/IT incident at Tieu Dental Corporation affecting network server.",
    "attack_type": "Hacking/IT Incident \u2014 Network server compromise",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 8918,
    "residents_affected_in_state": 8918,
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Not publicly disclosed",
    "remediation_disclosed": "Not publicly disclosed",
    "primary_source_url": "https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf",
    "secondary_source_urls": [
      "https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf"
    ],
    "confidence_notes": "Listed on HHS OCR breach portal (Mar 2026). Dental provider with CA operations.",
    "sources_used": [
      "HHS OCR Breach Portal"
    ],
    "id": "INC-00817",
    "year": 2026,
    "lat": 36.22147525545681,
    "lng": -119.43555903923871,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "preserved_ca"
  },
  {
    "organization_name": "TriZetto Provider Solutions (Cognizant Technology)",
    "organization_type": "Business Associate / Healthcare IT Revenue Cycle Management",
    "organization_type_bucket": "Business Associate / Vendor",
    "state": "MO",
    "hq_city": "Denver",
    "hq_county": "Worth",
    "discovery_date": "2025-10-02",
    "disclosure_date": "2026-02-06",
    "executive_summary": "TriZetto Provider Solutions (owned by Cognizant Technology Solutions) identified suspicious activity on its web portal on October 2, 2025, later determining that unauthorized actors had been active since November 2024, accessing reports on a portal used by healthcare provider clients. The breach affected 3,433,965 individuals. Compromised data included names, addresses, Social Security numbers, health insurance information, and other demographic and health details. TriZetto provides revenue cycle management and insurance verification services to numerous Midwest healthcare providers. The breach was reported to the HHS OCR and Maine AG in February 2026.",
    "attack_type": "Hacking / Unauthorized Access to Web Portal",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 3433965,
    "residents_affected_in_state": 50,
    "financial_impact": "Class-action litigation initiated; financial penalty not yet determined",
    "operational_impact": "Unauthorized access to provider web portal for approximately 11 months undetected",
    "remediation_disclosed": "Web portal secured; incident reported to law enforcement; breach notifications issued February 2026",
    "primary_source_url": "https://techcrunch.com/2026/03/06/trizetto-confirms-3-4m-peoples-health-and-personal-data-was-stolen-during-breach/",
    "secondary_source_urls": [
      "https://www.infosecurity-magazine.com/news/trizetto-provider-solutions-breach/",
      "https://www.wolfpopper.com/cases-investigations/trizetto-data-breach-litigation"
    ],
    "confidence_notes": "High confidence for the breach itself. TriZetto is headquartered in Denver but extensively serves Midwest healthcare organizations. Included as a multi-state business associate incident with Midwest healthcare provider impact. Healthcare Dive listed this under Missouri in its tracking. State attribution is per HHS OCR reporting location.",
    "sources_used": [
      "TechCrunch",
      "Infosecurity Magazine",
      "Wolf Popper LLP litigation notice",
      "Healthcare Dive",
      "Maine AG breach portal"
    ],
    "id": "INC-00818",
    "year": 2026,
    "lat": 40.397202,
    "lng": -94.324604,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "Trinity Health (via Health Gorilla HIE unauthorized access \u2014 2026)",
    "organization_type": "Nonprofit Catholic Health System",
    "organization_type_bucket": "Hospital / Health system",
    "state": "MI",
    "hq_city": "Livonia",
    "hq_county": "Wayne",
    "discovery_date": "2026-01-13",
    "disclosure_date": "2026-03-01",
    "executive_summary": "On January 13, 2026, Trinity Health's HIE partner reported a potential issue involving Health Gorilla, an interoperability platform that processes data access requests for healthcare providers. Companies obtained Trinity Health patient data through Health Gorilla for purposes that could not be confirmed as legitimate treatment. Clinical care information, demographic details, insurance data, and some driver's license numbers may have been accessed without proper authorization. The number of affected individuals had not been disclosed as of available reporting. Trinity began notifying affected individuals and offering 24 months of credit monitoring.",
    "attack_type": "Unauthorized Access via HIE Platform",
    "attack_category": "Unauthorized access / disclosure",
    "threat_actor_name": "Unknown companies accessing data via Health Gorilla",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Multistate; Michigan-headquartered",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Patient data potentially accessed without authorization via HIE; Health Gorilla suspended access for involved companies",
    "remediation_disclosed": "Yes \u2014 Health Gorilla suspended access; Trinity notifying patients; 24 months credit monitoring offered; reported to HHS OCR",
    "primary_source_url": "https://www.netsec.news/trinity-health-upmc-data-breach/",
    "secondary_source_urls": [],
    "confidence_notes": "Moderate confidence. NetSec.News reporting; HHS OCR not yet showing count as of reporting.",
    "sources_used": [
      "NetSec.News"
    ],
    "id": "INC-00819",
    "year": 2026,
    "lat": 42.36837,
    "lng": -83.3527097,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "nominatim"
  },
  {
    "organization_name": "University of Hawaii Cancer Center (Epidemiology Division)",
    "organization_type": "Healthcare Provider / Research Institution",
    "organization_type_bucket": "Hospital / Health system",
    "state": "HI",
    "hq_city": "Honolulu",
    "hq_county": "Honolulu",
    "discovery_date": "2025-08-31",
    "disclosure_date": "2026-02-27",
    "executive_summary": "The University of Hawaii Cancer Center's Epidemiology Division suffered a ransomware attack discovered on August 31, 2025, isolating servers supporting research operations. Attackers encrypted data and potentially exfiltrated research files. The university engaged with threat actors, paid a ransom, obtained a decryption tool, and secured assurances that exfiltrated data was destroyed. Approximately 87,493 Multiethnic Cohort Study participants were directly affected, plus approximately 1.15 million additional individuals from historical Hawaii driver's license and voter registration records (collected 1998\u20132000) which contained Social Security numbers. Total potential impact: ~1.24 million individuals.",
    "attack_type": "Ransomware / Data exfiltration",
    "attack_category": "Ransomware",
    "threat_actor_name": "Unknown (ransomware group)",
    "attribution_status": "unknown",
    "individuals_affected_reported": 1237493,
    "residents_affected_in_state": 1240000,
    "financial_impact": "Ransom paid (amount undisclosed)",
    "operational_impact": "Research servers encrypted; research data potentially exfiltrated; clinical operations unaffected",
    "remediation_disclosed": "Decryption tool obtained; affirmation of data destruction secured; 12-month credit monitoring; extensive security overhaul including new governance council and information security task force",
    "primary_source_url": "https://www.hawaii.edu/news/2026/02/27/notice-of-cyberattack-uh-cancer-center/",
    "secondary_source_urls": [
      "https://www.securityweek.com/1-2-million-affected-by-university-of-hawaii-cancer-center-data-breach/",
      "https://thecyberexpress.com/uh-cancer-center-cyberattack/",
      "https://www.civilbeat.org/2026/02/uh-cyber-hack-exposed-social-security-numbers-of-up-to-1-15-million/"
    ],
    "confidence_notes": "Official UH system announcement; attack Aug 2025, disclosure Feb 2026; ransom paid confirmed; full scope still under investigation",
    "sources_used": [
      "University of Hawaii official news",
      "SecurityWeek",
      "The Cyber Express",
      "Honolulu Civil Beat"
    ],
    "id": "INC-00820",
    "year": 2026,
    "lat": 21.3099,
    "lng": -157.8581,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Variety Care",
    "organization_type": "Healthcare Provider (Community Health Center)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "OK",
    "hq_city": "Oklahoma City",
    "hq_county": "Oklahoma",
    "discovery_date": "2025-10-02",
    "disclosure_date": "2026-01-01",
    "executive_summary": "Variety Care, an Oklahoma City-based federally qualified community health center, was affected by a data breach at its business associate TriZetto Provider Solutions (TPS). TPS discovered suspicious activity in a web portal on October 2, 2025; investigation revealed unauthorized access had begun as early as November 2024. The breach affected approximately 17,163 Variety Care patients. Compromised data included names, addresses, dates of birth, Social Security numbers, health insurance member numbers, health insurer names, provider names, and other demographic, health, and insurance information. TPS, which provides insurance eligibility verification services, notified affected providers on December 9, 2025.",
    "attack_type": "Hacking/IT Incident \u2013 Business Associate Web Portal Breach",
    "attack_category": "Supply chain / third party",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": 17163,
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Insurance eligibility verification services disrupted",
    "remediation_disclosed": "TPS eliminated threat to environment; physical letters mailed to affected individuals in January 2026",
    "primary_source_url": "https://www.paubox.com/blog/variety-care-notifies-17k-of-data-breach",
    "secondary_source_urls": [
      "https://varietycare.org/notice-of-data-breach",
      "https://www.foxnews.com/tech/health-tech-breach-exposes-3-4m-patient-records"
    ],
    "confidence_notes": "Variety Care official breach notice confirms 17,163 affected; TPS breach confirmed by multiple sources as affecting 3.4M total across customers",
    "sources_used": [
      "Paubox, Variety Care official notice, Fox News"
    ],
    "id": "INC-00821",
    "year": 2026,
    "lat": 35.4676,
    "lng": -97.5164,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "WellStar Health System (tracking pixel \u2013 investigation)",
    "organization_type": "Healthcare Provider (Hospital System)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "GA",
    "hq_city": "Marietta",
    "hq_county": "Cobb",
    "discovery_date": "2022-01-01",
    "disclosure_date": "2026-02-04",
    "executive_summary": "Attorneys investigating WellStar Health System allege the Marietta, GA-based health system (11 hospitals, Atlanta metro) used Meta Pixel tracking technology on its website (wellstar.org) and patient portal (MyChart.Wellstar.org) to transmit patient health data to Facebook for advertising purposes. The alleged conduct may violate federal wiretapping laws and HIPAA. Class action investigation launched in 2026.",
    "attack_type": "Website Tracking Pixel / Unauthorized PHI Disclosure (alleged)",
    "attack_category": "Tracking pixel disclosure",
    "threat_actor_name": "Not applicable (tracking pixels)",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Pending litigation",
    "operational_impact": "Alleged unauthorized transmission of patient health data to Meta/Facebook",
    "remediation_disclosed": "Investigation ongoing; no formal breach notice issued as of research date",
    "primary_source_url": "https://www.classaction.org/wellstar-privacy-lawsuit",
    "secondary_source_urls": [],
    "confidence_notes": "Class action investigation only; no confirmed breach notice or HHS OCR filing identified at time of research.",
    "sources_used": [
      "ClassAction.org"
    ],
    "id": "INC-00822",
    "year": 2026,
    "lat": 33.9526,
    "lng": -84.5499,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  },
  {
    "organization_name": "Woodfords Family Services (ME)",
    "organization_type": "Healthcare Provider (Behavioral Health)",
    "organization_type_bucket": "Hospital / Health system",
    "state": "ME",
    "hq_city": "Portland",
    "hq_county": "Cumberland",
    "discovery_date": "2026-01-01",
    "disclosure_date": "2026-03-27",
    "executive_summary": "Woodfords Family Services, a Maine nonprofit providing behavioral health and developmental disability services, reported a data security incident to the Maine AG in March 2026 (with an amended notice in April 2026). The breach involved unauthorized access to client health information.",
    "attack_type": "Hacking/IT Incident",
    "attack_category": "Hacking / IT incident",
    "threat_actor_name": "Unknown",
    "attribution_status": "unknown",
    "individuals_affected_reported": "Unknown",
    "residents_affected_in_state": "Not separately reported",
    "financial_impact": "Not publicly disclosed",
    "operational_impact": "Behavioral health and developmental disability client data compromised",
    "remediation_disclosed": "Maine AG notified; amended notice submitted April 7, 2026",
    "primary_source_url": "https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/list.html",
    "secondary_source_urls": [],
    "confidence_notes": "Maine AG database listing March 27, 2026; amended notice April 7, 2026",
    "sources_used": [
      "Maine AG database"
    ],
    "id": "INC-00823",
    "year": 2026,
    "lat": 43.6591,
    "lng": -70.2568,
    "is_multistate": false,
    "hq_outside_state": "",
    "geocode_source": "builtin"
  }
]