Three more healthcare organizations have tallied who was caught in recent intrusions, adding detail to a week already crowded with breach notices.
An employee mailbox at a Baltimore benefits administrator became the entry point for a breach that reached the protected health information of 9,268 people. Bridgeway Benefit Technologies runs health, welfare and retirement plans for multiemployer groups, and it told federal regulators that the compromise stayed inside its own mail system rather than touching client systems. Social Security numbers were among the exposed data, and the company offered affected individuals credit monitoring.
A Nashville firm that sells software and training to providers alerted Massachusetts regulators to an incident it had already disclosed to the SEC on July 29, 2026. That filing described unauthorized access to corporate file servers, with employee data, customer and vendor billing records, and legal information involved, and roughly 75 credentialing customers affected. HealthStream said protected health information did not appear to be involved.
In West Virginia, a phishing attack that staff detected on May 6, 2026 compromised several email accounts at a critical access hospital. The review wrapped in late June and found that 1,215 people had names, birth dates, addresses, phone numbers, Social Security numbers, health information, and health insurance details exposed. The hospital, Grafton City Hospital, is now part of Vandalia Health.