Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “breach” · 7 entries

CMS reports hacking incident affecting over 100,000 records

Centers for Medicare & Medicaid Services (CMS) filed a report with HHS OCR on June 30, 2025, disclosing a hacking/IT incident that compromised the data of 107,154 individuals. The breach occurred on a network server. CMS is classified as a Health Plan under HIPAA. Healthcare administrators should note the scale of this federal breach as a benchmark for potential risks to their own systems.

Ciox Health (Datavant Group) breach: 320,702 individuals affected — email data exposed

If your organisation uses Ciox Health LLC (doing business as Datavant Group) for data services, you may be affected by a significant security incident. This Business Associate reported a hacking/IT incident to HHS OCR on 10/07/2024. The filing lists 320,702 individuals affected. Protected health information was exposed via email. Because Datavant is a Business Associate, your own compliance obligations depend on your specific contract and data flow. Verify if you share data with this entity and review your Business Associate Agreement for notification requirements.

Fieldtex Products breach filing: 104,071 individuals affected

Fieldtex Products, Inc., a Business Associate, filed an HHS OCR breach report on December 12, 2025, citing 104,071 individuals affected by a hacking/IT incident on a network server. This entry reflects the single OCR filing cited below; additional related filings have been reported elsewhere but are not covered by this record. If your organization uses Fieldtex services, review your contracts to understand notification obligations and monitor the OCR portal for further filings.

Nacogdoches Memorial Hospital breach: 2.5M affected per federal record

Nacogdoches Memorial Hospital, a healthcare provider in Texas, filed a breach report with HHS OCR on March 30, 2026, regarding a hacking/IT incident. The OCR portal lists 2,507,073 individuals affected. While some secondary sources cite a lower figure of 257,073, the federal record stands at 2.5 million with no documented correction. The breach involved data stored on a network server. As a covered entity, the hospital is responsible for notifying affected individuals. Healthcare administrators should monitor official notifications from the hospital to understand the specific scope of exposure for their own patients or partners, as the federal filing does not detail the specific types of data compromised.

Radiology group reports 1.4M-record breach; second incident status unclear

Radiology Associates of Richmond, Inc., a Virginia-based healthcare provider, filed a breach notification with HHS OCR on July 1, 2025, reporting a hacking/IT incident affecting 1,419,091 individuals. The data was accessed from a network server. This entity has since disclosed a second, separate breach involving 266,183 individuals, stemming from an incident on or about July 25, 2025. This subsequent disclosure was reported to the Maine Attorney General on May 21, 2026. However, claims that this second breach has appeared on HHS OCR's public breach portal are unsupported by primary sources and contradicted by contemporaneous reporting stating it had not yet appeared. The HHS OCR record for the initial filing indicates no business associate was involved. Administrators should monitor the OCR portal for updates on both incidents.

Veradigm breach filing — settlement finalized, but check entity names

Veradigm LLC, a healthcare IT vendor classified as a Business Associate, reported a hacking/IT incident affecting 2,672,036 individuals. The HHS OCR record lists the submission date as September 22, 2025. Because Veradigm is a Business Associate, your organization’s obligations depend on your specific Business Associate Agreement and whether your patients’ data was involved. Review your contracts to understand liability and support responsibilities. Do not assume automatic notification duties; verify if your facility uses Veradigm services. Note that the related class action Goodrum v. Veradigm, Inc. has reached a final settlement. Payments for approved claims were issued on June 12, 2026, and uncashed checks void after September 10, 2026. Crucially, the OCR filing names Veradigm LLC, while the lawsuit names Veradigm, Inc.. These are distinct legal entities. Check your contracts for the exact legal entity name to ensure proper compliance.

#breach#business-associate#hacking#settlement#entity-name

Absolute Dental Group breach — $3.3M settlement, final hearing July 30

A filing for Absolute Dental Group, LLC in Nevada lists the entity as a Business Associate. The HHS OCR record, submitted on May 2, 2025, reports 1,223,635 individuals affected by a hacking/IT incident on a network server. A $3.3 million class action settlement received preliminary court approval on March 6, 2026. The Final Approval Hearing is set for Thursday, July 30, 2026, per the official settlement administrator site. (The court docket entry, Doc. 92, reads "Thursday, July 31" — July 31 is a Friday, and every other source gives July 30, so the docket appears to contain a clerical error.) If your organization contracts with this dental group, confirm the date with the settlement administrator.

#breach#business-associate#class-action-settlement#dental-services#hacking-incident
← Back to AI Health Regulator News