Data breaches have increasingly become one of the most alarming threats to both individuals and organizations, posing significant risks to privacy, security, and financial well-being. Sensitive personal and health information, including Social Security numbers, medical records, financial data, and login credentials, is often stored electronically, making it a prime target for hackers and cybercriminals. These cyberattacks lead to identity theft, fraudulent transactions, unauthorized access to confidential systems, and a whole host of other problems that come with devastating consequences for victims.
High-profile cases, such as healthcare data breaches and ransomware attacks on large corporations, are getting more common. Our defenses are not keeping up with the vulnerability of electronic records and the growing sophistication of cybercriminals. Too often, companies do not make the investment needed to protect our privacy.
Whether targeting small businesses, major institutions, or individuals, these breaches underscore the critical importance of robust cybersecurity measures and immediate legal recourse for those affected. Protecting personal and medical information from cyberattacks has never been more crucial, as data breaches continue to grow in scale and impact.
Recent data breach investigations involving Change Healthcare, Center for Vein Restoration, Iowa Radiologic Medical Services, Atlantic Orthopaedic Specialists, Rocky Mountain Gastroenterology, Liberty First Credit Union, Anna Jaques Hospital, and an employment-related investigation at Channahon Lion Electric highlight the significant legal and financial repercussions organizations face when cybersecurity measures fail.
Change Healthcare Data Breach
A class action lawsuit has been filed by dozens of individuals, alleging that the Change Healthcare data breach last year was the result of inadequate cybersecurity measures, which left millions unnecessarily vulnerable to identity theft and fraud.
The complaint, filed on January 15 in the U.S. District Court for the District of Minnesota, seeks class action status against UnitedHealth Group Incorporated, Optum, Inc., OptumInsight, Inc., and Change Healthcare Inc. Plaintiffs argue the breach could have been prevented if the defendants had implemented proper security protocols.
The data breach, first disclosed in February 2024, revealed that hackers accessed sensitive information for up to 100 million individuals, including names, Social Security numbers, dates of birth, addresses, medical records, insurance details, and other confidential data.
Although Change Healthcare is not a household name, it plays a vital role behind the scenes in the healthcare system. It provides software, analytics, and services for medical providers. It is estimated that one in three Americans has had their private health information pass through the company’s systems, underscoring the scope of the breach.
This lawsuit is the latest in a wave of class action complaints filed in federal courts across the country, all making similar claims that cybersecurity failures at Change Healthcare allowed hackers to access highly sensitive personal and medical information. The allegations highlight widespread concerns about the security vulnerabilities in systems that handle critical healthcare data.
The Center for Vein Restoration
The Maryland-based Center for Vein Restoration (CFVR) announced a data breach that compromised the sensitive personal and protected health information of 446,094 individuals. This incident has raised concerns about the security of sensitive data entrusted to CFVR.
On October 6, 2024, CFVR identified a security breach within its IT network. In response, the organization promptly initiated an investigation with the assistance of third-party cybersecurity experts to assess the nature and scope of the attack. The investigation revealed that sensitive personal and protected health data, along with certain employment information, may have been exposed during the incident.
This is a big one—there could be up to 446,094 victims.
Iowa Radiologic Medical Services Data Breach
The Iowa Radiologic Medical Services (IRMS) data breach has left thousands of patients vulnerable, with sensitive information such as medical records, Social Security numbers, and billing data exposed.
On November 11, 2024, Radiologic Medical Services, P.C., the parent company of Corridor Radiology and Muscatine Radiology, reported a data breach to the U.S. Department of Health and Human Services Office for Civil Rights. The breach occurred after unauthorized access to two employee email accounts between February 22 and March 19, 2024, potentially exposing sensitive patient information contained in emails and attachments. After securing the accounts, Radiologic Medical Services worked with cybersecurity experts to investigate the incident, identify affected individuals, and assess the compromised data. On September 13, 2024, the company completed its review and began sending personalized data breach notification letters to impacted individuals in November.
The breach underscores the risks of unauthorized access to sensitive healthcare data, including potential identity theft or fraud. Radiologic Medical Services, which oversees Corridor Radiology in Coralville, IA, and Muscatine Radiology in Muscatine, IA, employs over 35 people and provides radiological services such as CT scans, MRIs, and X-rays. Those affected by the breach are encouraged to review their notification letters for details on the compromised data and consider seeking legal advice to protect against potential risks and explore legal options.
Lawyers (not our law firm, by the way) are investigating whether IRMS failed to meet the stringent cybersecurity standards required by laws like the Health Insurance Portability and Accountability Act (HIPAA). Patients impacted by this healthcare data breach may face risks such as identity theft and medical fraud. If you were affected, it’s critical to monitor your financial and medical accounts closely and stay informed about any legal settlements or class actions resulting from this incident.
Atlantic Orthopaedic Specialists Data Breach
Atlantic Orthopaedic Specialists (AOS), headquartered in Virginia Beach, Virginia, with additional locations in Chesapeake and Norfolk, is under scrutiny following a significant data breach that compromised sensitive patient information, including protected health information (PHI). This incident highlights the growing cybersecurity challenges faced by healthcare organizations and the serious consequences for patients when data protection measures fail.
Investigators are now examining whether AOS implemented adequate safeguards to protect patient data and whether it complied with state and federal notification requirements for data breaches. These breaches are more than just administrative headaches—they expose patients to risks of identity theft, fraud, and the unauthorized use of their medical information. The legal and regulatory fallout from this breach will likely set important precedents for how healthcare providers handle similar incidents in the future.
Between June 20 and August 6, 2024, an unauthorized party accessed a corporate email account at AOS. This breach compromised the personal information of more than 15,000 individuals. The exposed data included names, Social Security numbers, medical records, health insurance details, and in some cases, financial information. While AOS reports that it has no evidence of data misuse so far, the implications of this breach are troubling. Can you imagine the anxiety of discovering that your most sensitive personal information might now be in the hands of bad actors?
In response to the breach, AOS engaged third-party cybersecurity experts to investigate the incident, secured the affected account, and reviewed the compromised files to assess the extent of the exposure. Notification letters were sent to affected individuals in late November, and those whose Social Security numbers were exposed were offered complimentary credit monitoring services.
The breach appears to have been triggered by unauthorized access to a single email account—often the result of a phishing attack or inadequate security protocols. It only takes one small vulnerability, like a single successful phishing email, to open the door for a breach. These incidents underscore the need for healthcare organizations to invest in comprehensive cybersecurity training for employees and robust technical safeguards, such as two-factor authentication and real-time intrusion monitoring.
Rocky Mountain Gastroenterology Data Breach
Rocky Mountain Gastroenterology (RMG), based in Littleton, Colorado, with multiple locations throughout the state, has become the latest healthcare provider facing scrutiny after a significant data breach exposed sensitive patient records. This breach highlights the growing threat of cyberattacks targeting healthcare organizations, which store vast amounts of personal and medical information. Cybersecurity experts and legal investigators are raising concerns about whether RMG had implemented adequate protections, such as encryption and intrusion detection systems, to prevent such an incident.
Reports indicate that unauthorized parties accessed the sensitive information of over 150,000 patients, with records spanning from 2015 to 2019. The compromised data includes a wide range of personal identifiers and medical information, such as names, Social Security numbers, dates of birth, addresses, phone numbers, email addresses, medical records, and health insurance details. The breadth and sensitivity of this information make the breach particularly concerning, as it opens the door to risks like identity theft, medical fraud, and financial scams.
Liberty First Credit Union Data Breach
The Liberty First Credit Union, based in Lincoln, Nebraska, has suffered a data breach that compromised the financial and personal information of an undisclosed number of customers. This breach exposes victims to serious risks, including identity theft and financial fraud, underscoring the vulnerabilities in the financial services industry. Legal experts are now investigating whether Liberty First Credit Union failed to comply with consumer protection laws, such as the Gramm-Leach-Bliley Act, which requires financial institutions to implement safeguards to protect customer data.
The breached data reportedly includes sensitive financial information, leaving affected customers at heightened risk of unauthorized transactions and fraudulent activities. If you believe you may have been impacted, you have to consider doing the annoying things you must to protect yourself. Consider placing a freeze on your credit to prevent unauthorized access, closely monitoring your account activity for suspicious transactions, and taking advantage of any credit monitoring services offered by the credit union.
Anna Jaques Hospital Data Breach
Anna Jaques Hospital, located in Newburyport, Massachusetts, has fallen victim to a cyberattack that exposed the medical and insurance records of numerous patients. This breach has raised significant privacy and cybersecurity concerns, with legal investigations now focusing on whether the hospital adhered to its obligations under HIPAA and other privacy laws designed to protect patient data.
The compromised data could leave victims vulnerable to medical identity theft, unauthorized access to their health information, and fraudulent use of their insurance details. As healthcare data breaches become more frequent, incidents like this highlight the critical need for hospitals to invest in advanced cybersecurity measures. Victims of this Anna Jaques Hospital data breach should closely monitor their medical and financial accounts for any unusual activity and consider taking steps such as placing fraud alerts or freezing their credit.
Channahon Lion Electric Layoff
The recent Channahon Lion Electric investigation has raised questions about potential violations of the Worker Adjustment and Retraining Notification (WARN) Act following a round of layoffs. This is a one-off—this was not a traditional data breach. This case focuses on employment law compliance, specifically whether the company provided the legally required notice to employees before terminating their positions. Under the WARN Act, employers must give at least 60 days’ advance notice of mass layoffs in certain circumstances, ensuring workers have time to prepare for the transition.
Legal experts are now scrutinizing Lion Electric’s actions to determine if the layoffs complied with federal and state labor laws. The investigation underscores the broader importance of corporate responsibility and adherence to legal requirements during workforce reductions. Mass layoffs can significantly impact employees and their families, making compliance with labor laws a critical aspect of ethical business practices. While this case doesn’t involve cybersecurity, it highlights how corporate decisions can trigger serious legal and reputational consequences.
Thompson Coburn LLP/ Presbyterian Healthcare Services
A proposed class action lawsuit was filed this month in a Missouri federal court, accusing U.S. law firm Thompson Coburn LLP and its client, Presbyterian Healthcare Services, of failing to adequately protect sensitive personal and medical information. The lawsuit stems from a May 2024 data breach in which an unknown hacker accessed Thompson Coburn’s network.
The plaintiff claims the firm held his personal data while providing legal services to Presbyterian and notified him of the breach in November. Exposed information reportedly includes names and medical details, such as prescription and clinical data. The lawsuit attributes the breach to inadequate cybersecurity measures by both parties.
Baptist Health System Data Breach
In 2022, Baptist Health System, which includes facilities in San Antonio, Texas, and Resolute Health Hospital in New Braunfels, Texas, experienced a massive cybersecurity breach that compromised the sensitive information of over 1.2 million individuals. Unauthorized parties gained access to the system between March 31 and April 24, 2022, during which critical personal data—including names, dates of birth, Social Security numbers, and insurance details—was exposed.
Change Healthcare Data Breach
In February 2024, Change Healthcare reported a massive data breach that exposed sensitive information for up to 100 million individuals. The breach began when the username and password of a customer support employee were posted on Telegram, in a chat known for stolen credentials. Hackers used these credentials to access the company’s systems through Citrix, a remote access service. Over nine days, the hackers navigated the systems undetected, creating privileged administrator accounts, installing malware, and exfiltrating terabytes of data.
The compromised information included Social Security numbers, driver’s license numbers, health insurance details, medical records, and billing information. The breach also involved ransomware that crippled Change Healthcare’s systems, forcing the company to take them offline. This caused widespread disruption in healthcare operations nationwide, particularly affecting rural hospitals in states like Nebraska, where providers struggled to process claims and faced delays in receiving payments. Patients also experienced disruptions, including delays in medications and treatments, as hospitals dealt with the fallout from the breach.
Richmond University Medical Center Data Breach Investigation
In May 2023, Richmond University Medical Center (RUMC), a Staten Island-based healthcare provider, fell victim to a ransomware attack, jeopardizing the personal and health information of over 674,000 patients. This cyberattack targeted RUMC’s network, potentially exposing names, dates of birth, medical records, insurance information, and Social Security numbers.
Ransomware attacks on healthcare providers are becoming increasingly common, and the consequences for patients can be devastating. When hospitals fail to implement sufficient cybersecurity protections, patients bear the brunt of the fallout. If you or a loved one have been affected by this breach, you may have the right to pursue a legal claim for damages, including costs related to identity theft monitoring, financial losses, and emotional distress. Contact our experienced attorneys today to discuss your case.
AuthoraCare Collective Data Breach Investigation
In August 2024, AuthoraCare Collective, a healthcare provider based in Greensboro, North Carolina, discovered unauthorized access to its systems, compromising the personal and health information of over 58,000 individuals. The exposed data may include names, medical records, and other sensitive details. The breach highlights a troubling pattern of healthcare organizations failing to protect patient information from cyberattacks.