Notification delays stretch past a year in four new healthcare breaches

Four hospitals and surgery centers across four states disclosed breaches with notification delays stretching more than a year.

MedRisk Staff
By
1 Min Read

More than a year passed between detection and patient notification in the latest round of healthcare breach disclosures, with four separate facilities across Ohio, Michigan, Maine, and Alabama now confirming that cyber intruders accessed sensitive patient records including Social Security numbers, medical diagnoses, and insurance data.

A breach at Wildwood Surgical Center in Ohio went undetected for a full year before notification letters dated July 13, 2026 finally went out, covering an incident that began in June 2025. The Gentlemen ransomware group is believed responsible for the Michigan Surgical Center breach in East Lansing, where the facility was added to the group’s dark web leak site in early June.

Penobscot Valley Hospital in Maine discovered suspicious network activity on January 28, confirming four months later that Social Security numbers, financial details, and medical records were among the exposed data. Whitfield Regional Hospital in Alabama faced the longest gap, with unauthorized access occurring between May and June 2025 and notifications finally mailed July 17, 2026. None of the four sites have disclosed the total number of affected patients, a transparency gap that regulators have repeatedly flagged as a compliance concern for the healthcare sector.

Share This Article