Hawaii union fund and AI intake vendor report breaches

Two very different healthcare organizations, a Honolulu benefits trust and a Massachusetts AI vendor, disclosed intrusions exposing about 13,000 people combined.

MedRisk Staff
By
2 Min Read

Two healthcare-connected organizations have reported separate breaches, according to filings with the HHS Office for Civil Rights.

In Honolulu, PAMCAH-UA Local 675 Health and Welfare Fund disclosed that intruders reached employee email accounts between September 23 and October 9, 2025. The multiemployer trust provides medical, dental, vision and welfare benefits to union plumbers and fitters and their families. A review found the accounts held personal and protected health information for 8,319 people, including names, birth dates, medical and insurance details, driver’s license numbers and Social Security numbers. Notifications have been mailed.

Indico Data Solutions, a Massachusetts company whose AI-powered intake and orchestration platform serves healthcare customers, confirmed a cybersecurity incident on May 7, 2026, affecting 4,840 people. The notice does not say when the intrusion was detected or how long attackers had access. Exposed data included names, addresses and Social Security numbers. The vendor rotated credentials, tightened access controls and added monitoring, then notified corporate customers and affected individuals, offering credit monitoring.

The two cases show a persistent pattern: short exposure windows in email accounts at benefits administrators, and third-party AI platforms that quietly hold patient data. Both remain frequent blind spots. Security teams should inventory vendors that touch protected health information, confirm notification duties in business associate agreements, and treat unmanaged mailboxes at benefits trusts as part of their own attack surface.

Share This Article