Beverly Hills plastic surgeon Terry Dubrow has confirmed that an intruder copied patient files from his practice’s network after claiming to have breached its systems. The practice notified California’s attorney general that unauthorized access began January 16, 2026, and that files were copied. A review completed July 27 confirmed the stolen data included names, patient chart information, and referring physician details, with some records containing Social Security numbers, driver’s license numbers, birth dates, prescriptions, treatment information, procedure images, and X-rays. The affected count has not been disclosed.
The disclosure landed alongside four other incidents reported to regulators this week. SunCloud Health, a Northbrook, Illinois behavioral health network, found unauthorized access to employee email accounts between April 22 and May 4, exposing names and medical information including diagnoses and medications for 2,594 people. Integer Precision Technologies, a Hudson, Massachusetts maker of medical device coatings, said an unauthorized party accessed a cloud-based SaaS file sharing application and copied files containing names, Social Security numbers, passport numbers, and some health-related information. Minnesota ENT, an Oakdale ear, nose, and throat practice, confirmed that six employee email accounts were accessed, with a July 15 review finding HIPAA-protected data including Social Security numbers, financial account information, and medical records. Nipro Medical Corp., the New Jersey-based hospital supplier of renal care and vascular products, said an unauthorized party may have viewed credit and debit card information, Social Security numbers, and other government identifiers.
All five organizations are offering credit monitoring or identity theft protection. The incidents underscore how varied the healthcare attack surface remains, from celebrity practices to medical device suppliers and hospital vendors.