Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “business-associate” · 22 entries

CareCloud breach: 3.7 million records exposed in hacking incident

CareCloud, Inc., a business associate based in New Jersey, reported a hacking/IT incident to HHS OCR on July 24, 2026. The breach affected 3,756,469 individuals, with data compromised on a network server. Because CareCloud is a business associate, any healthcare providers, health plans, or other covered entities that use its services may need to verify if their patient data was included in this incident. Organizations should review their contracts and communications from CareCloud to determine exposure. This filing date is when the report was submitted to the regulator, not necessarily when the breach occurred or was discovered.

Persante Health Care reports hacking incident affecting 111,815 individuals

Persante Health Care, a business associate operating in New Jersey, filed a breach notification with HHS OCR on November 26, 2025. The filing reports a hacking/IT incident involving a network server that exposed the protected health information of 111,815 individuals. Because Persante is a business associate, this incident likely impacts the covered entities—such as hospitals, clinics, or health plans—that rely on its services. Healthcare administrators should check whether their organization uses Persante’s services and review any communications from the vendor regarding next steps for affected patients. The submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered.

Business associate Xsolis reports massive hacking incident affecting 1.4 million records

A business associate named Xsolis, Inc. filed a breach report with HHS OCR on June 5, 2026, disclosing a hacking/IT incident that compromised the data of 1,396,519 individuals. The unauthorized access occurred on a network server. Because Xsolis is a business associate, its clients—likely healthcare providers or health plans—may also have reporting obligations to their own patients or members. Administrators should verify if their organization uses Xsolis services and review internal protocols for handling third-party breach notifications. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered.

HealthEquity breach affects 4.3 million — Business Associate filing

HealthEquity, Inc., a Business Associate based in Utah, filed a report with HHS OCR on August 9, 2024, disclosing a hacking/IT incident. The breach impacted the protected health information of 4.3 million individuals. The compromised data was located on a network server. Because HealthEquity is a Business Associate, your organization may be affected if you use its services for health savings accounts or related benefits administration. Review your contracts and incident response plans to understand your obligations when a vendor experiences a security incident. This filing date reflects when the report was submitted to the regulator, not necessarily when the breach occurred.

Business associate breach affects 134,918 individuals — HHS OCR filing

A business associate named Kerber, Eck & Braeckel LLP filed a breach report with HHS OCR on August 16, 2024. The filing covers a hacking/IT incident that compromised data for 134,918 individuals. The breached information was located on a network server. Because this entity is a business associate, your organization may be affected if you contract with them for services handling protected health information. Review your vendor contracts and security logs to determine if you are among the impacted covered entities. This submission date reflects when the report was filed with HHS, not necessarily when the breach occurred or was discovered.

Business associate breach affects 3.8 million records — Ohio

A Business Associate named Unlimited Technology Systems, LLC reported a hacking/IT incident to HHS OCR on July 21, 2026. The filing indicates that 3,803,750 individuals were affected. The unauthorized access occurred on a network server. Because the entity is a Business Associate, your organization may be impacted if you contract with this vendor for services involving protected health information. Review your vendor contracts and security logs to determine if you are among the affected clients. This submission date is when the report was filed, not necessarily when the breach occurred or was discovered.

Florida business associate reports massive hacking breach affecting 279,275 individuals

A Florida-based business associate, Zumpano Patricios, P.A., filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 279,275 individuals, with unauthorized access occurring on a network server. The filing was submitted on July 3, 2025. As a business associate, this entity is bound by HIPAA obligations through its contracts with covered entities. Healthcare administrators should review their vendor contracts to ensure business associates have adequate security measures and breach notification protocols in place. This filing highlights the scale of potential exposure when network servers are compromised.

Modernizing Medicine reports hacking incident affecting nearly 200,000 patients

Business Associate Modernizing Medicine, Inc. filed a breach report with HHS OCR on October 17, 2025, describing a hacking/IT incident involving data on a network server. The filing covers 198,795 individuals. As a Business Associate, Modernizing Medicine provides services to covered entities; if your organisation uses their software, you should verify whether your patient data was among those affected. The submission date is when the report was filed with HHS, not necessarily when the breach occurred or was discovered. This is a reportable event under HIPAA breach notification rules.

Alera Group reports hacking incident affecting 155,567 records

Alera Group, Inc., a business associate in Illinois, reported a hacking/IT incident to HHS OCR on July 29, 2025. The breach involved unauthorized access to a network server, exposing the protected health information of 155,567 individuals. As a business associate, Alera Group is required to notify its covered entity clients, who in turn must notify affected patients. Healthcare administrators should verify if their organization contracts with Alera Group and review any notifications received. This filing date reflects when the report was submitted to the government, not necessarily when the breach occurred or was discovered. Monitor communications from vendors to ensure compliance with notification timelines.

Florida business associate reports hacking incident affecting 145,714 individuals

A Florida-based business associate, Operation PAR, Inc., filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on June 25, 2026, indicates that 145,714 individuals were affected. The breach occurred on a network server. Because this entity is a business associate, its covered entities (such as health plans or providers) may need to verify their own notification obligations. Administrators should check if they contract with this vendor and review their business associate agreements for specific reporting requirements.

Cierant Corporation reports major data breach affecting 232,506 individuals

Cierant Corporation, a Business Associate based in Connecticut, filed a breach report with HHS OCR on July 3, 2025. The filing describes a hacking/IT incident involving a network server that exposed the protected health information of 232,506 individuals. Because Cierant is a Business Associate, this incident likely impacts the healthcare providers and health plans that contract with them. Your organisation should check whether you have a business relationship with Cierant Corporation. If you do, contact their compliance team immediately to understand the specific data involved and any required next steps for your own breach notification obligations.

TriZetto Provider Solutions reports massive data breach affecting 3.4 million records

TriZetto Provider Solutions, a business associate serving healthcare providers, reported a hacking/IT incident to HHS OCR. The filing, submitted on February 6, 2026, states that 3,433,965 individuals were affected. The breach occurred on a network server. Because TriZetto is a business associate, your organization may be impacted if you use their services for claims processing or other administrative functions. Review your contracts and contact your vendor management team to confirm whether your entity is among those affected and to understand any required next steps.

Insightin Health reports massive data breach affecting nearly 2 million records

Insightin Health, Inc., a business associate based in Maryland, filed a report with HHS OCR on January 16, 2026, disclosing a hacking/IT incident. The breach compromised the protected health information of 1,949,534 individuals. The unauthorized access occurred on a network server. Because Insightin Health is a business associate, your organization may be impacted if you contract with them for services such as claims processing or data analytics. Review your vendor contracts and assess whether you receive data from this entity. If so, contact your legal and compliance teams to determine if you need to notify your own patients or take additional risk mitigation steps.

Ciox Health (Datavant Group) breach: 320,702 individuals affected — email data exposed

If your organisation uses Ciox Health LLC (doing business as Datavant Group) for data services, you may be affected by a significant security incident. This Business Associate reported a hacking/IT incident to HHS OCR on 10/07/2024. The filing lists 320,702 individuals affected. Protected health information was exposed via email. Because Datavant is a Business Associate, your own compliance obligations depend on your specific contract and data flow. Verify if you share data with this entity and review your Business Associate Agreement for notification requirements.

Fieldtex Products breach filing: 104,071 individuals affected

Fieldtex Products, Inc., a Business Associate, filed an HHS OCR breach report on December 12, 2025, citing 104,071 individuals affected by a hacking/IT incident on a network server. This entry reflects the single OCR filing cited below; additional related filings have been reported elsewhere but are not covered by this record. If your organization uses Fieldtex services, review your contracts to understand notification obligations and monitor the OCR portal for further filings.

Philadelphia Corporation for Aging reports massive data breach affecting over 400,000 individuals

A significant security incident has been reported by Philadelphia Corporation for Aging (PCA), a Business Associate operating in Pennsylvania. The organization filed a report with HHS OCR on September 23, 2025, disclosing a hacking/IT incident that compromised data stored on a network server. This breach affects a substantial number of individuals, with 410,491 people impacted. Because PCA is a Business Associate, this incident likely involves the health data of patients from various covered entities, such as clinics or health plans, that contract with them. Healthcare administrators should review their vendor contracts and security protocols to ensure their own Business Associates are maintaining adequate safeguards against cyber threats.

Major Data Breach at ATSG, Inc. — Nearly 1 Million Records Compromised

A significant data breach has been reported involving ATSG, Inc., a business associate operating in New York. This incident, classified as a hacking/IT event, compromised the protected health information of 909,469 individuals. The breach occurred on a network server and was reported to the HHS Office for Civil Rights on October 4, 2024. Hospital administrators should review their own business associate agreements to ensure vendors have robust cybersecurity measures. While this specific incident affects ATSG, it serves as a stark reminder of the risks associated with third-party data handling. Monitor your own systems for unusual activity and verify that your partners are compliant with security standards.

Navia Benefit Solutions Breach — 2.15 Million in OCR Filing, ~2.7 Million Total

Navia Benefit Solutions, Inc., a Washington-based business associate for employee benefits (FSA, HSA, HRA, COBRA, DCAP), reported a hacking/IT incident to HHS OCR on March 18, 2026. The filing lists 2,151,330 individuals affected, but external reports from the Maine Attorney General and other sources cite a total of approximately 2,697,540 individuals. The breach involved data on a network server and other locations. Because Navia serves employers rather than hospitals, health plans, self-insured employers, and benefits administrators should verify if they use Navia. If so, review your vendor contracts and assess potential exposure to your members or employees. This filing date is when the report was submitted to OCR, not when the breach occurred.

Veradigm breach filing — settlement finalized, but check entity names

Veradigm LLC, a healthcare IT vendor classified as a Business Associate, reported a hacking/IT incident affecting 2,672,036 individuals. The HHS OCR record lists the submission date as September 22, 2025. Because Veradigm is a Business Associate, your organization’s obligations depend on your specific Business Associate Agreement and whether your patients’ data was involved. Review your contracts to understand liability and support responsibilities. Do not assume automatic notification duties; verify if your facility uses Veradigm services. Note that the related class action Goodrum v. Veradigm, Inc. has reached a final settlement. Payments for approved claims were issued on June 12, 2026, and uncashed checks void after September 10, 2026. Crucially, the OCR filing names Veradigm LLC, while the lawsuit names Veradigm, Inc.. These are distinct legal entities. Check your contracts for the exact legal entity name to ensure proper compliance.

#breach#business-associate#hacking#settlement#entity-name

Absolute Dental Group breach — $3.3M settlement, final hearing July 30

A filing for Absolute Dental Group, LLC in Nevada lists the entity as a Business Associate. The HHS OCR record, submitted on May 2, 2025, reports 1,223,635 individuals affected by a hacking/IT incident on a network server. A $3.3 million class action settlement received preliminary court approval on March 6, 2026. The Final Approval Hearing is set for Thursday, July 30, 2026, per the official settlement administrator site. (The court docket entry, Doc. 92, reads "Thursday, July 31" — July 31 is a Friday, and every other source gives July 30, so the docket appears to contain a clerical error.) If your organization contracts with this dental group, confirm the date with the settlement administrator.

#breach#business-associate#class-action-settlement#dental-services#hacking-incident

Major Data Breach at Specialty Networks — Over 411,000 Records Compromised

A significant hacking/IT incident has been reported involving Specialty Networks, Inc., a business associate located in Tennessee. The breach affected the personal health information of 411,037 individuals. The compromised data was stored on a network server. This incident was reported to the HHS Office for Civil Rights on August 15, 2024. Hospital administrators should review their contracts with business associates to ensure robust cybersecurity measures are in place. If your facility uses Specialty Networks, verify their security protocols and confirm that any shared data was protected. This is a confirmed breach, not a proposal, highlighting the ongoing risks of digital health records.

Massive Data Breach at Conduent Business Services — 62 Million Records Compromised

A major breach has been reported involving Conduent Business Services LLC, a business associate operating in New Jersey. This incident, classified as a hacking/IT incident, compromised the data of approximately 62.2 million individuals. The unauthorized access occurred on a network server. Hospital administrators should verify if their organization uses Conduent for services such as billing, claims processing, or other administrative support. If you do, contact your vendor management team immediately to assess potential risks to your patient data. Even if you are not a direct client, the scale of this breach highlights the critical need to review your own cybersecurity protocols and ensure all business associates have robust security measures in place to protect sensitive health information.

← Back to AI Health Regulator News