Five small healthcare organizations disclosed patient data incidents this week, two of them drawing ransomware group credit claims and one involving a 22-month notification delay.
Family Medical Associates of Raleigh, a multi-provider practice in North Carolina, confirmed an unauthorized party intermittently accessed its systems between April 18 and April 20. The Genesis ransomware group claimed responsibility, though the practice has not confirmed the number of affected patients.
Arkansas Oral & Maxillofacial Surgeons in Hot Springs confirmed on June 2 that files were exfiltrated from its network, including Social Security numbers, diagnoses, and treatment records. The PEAR group, which steals data rather than encrypting it, claimed the attack. The incident has not yet appeared on the HHS Office for Civil Rights breach portal.
Alpine Agency of the Midlands, a health and benefits insurance agency in Columbia, South Carolina, reported that a single employee email account was accessed by an outside party in late October, with emails and attachments possibly copied. It reported the breach to OCR as affecting at least 500 individuals.
Princeton Family Eye Care in Texas reported an email account compromise discovered May 4, telling the Texas attorney general that 933 residents were affected. James C. Standring, DDS, a dental practice in Crescent City, California, notified 6,658 patients about a breach first identified on September 2, 2024, roughly 22 months before letters went out. OCR was notified July 17.
