Georgia health system joins four fresh breach filings to regulators

A rural Georgia nonprofit, a Connecticut orthopedic group, an Iowa services provider, and a Massachusetts plan all reported intrusions this week.

MedRisk Staff
By
2 Min Read

A cluster of new filings landed with federal regulators, spanning a rural hospital network, an orthopedic practice, a disability services nonprofit, and a health plan.

In Georgia, Bacon County Health Services found suspicious activity on July 27 and later confirmed an intruder had network access between July 10 and July 27, with files exfiltrated. The Alma-based nonprofit runs Bacon County Hospital, Twin Oaks Convalescent Center, and a rural clinic. The review is unfinished, so affected numbers are unknown and the Office for Civil Rights holds a placeholder estimate of at least 501 people.

Connecticut’s Comprehensive Orthopaedics & Musculoskeletal Care told OCR that 21,897 people were caught in a breach tied to suspicious activity seen February 12. The review wrapped June 17, exposing names, birth dates, Social Security numbers, financial and payment card data, government IDs, and medical and insurance information. A group called Crypto24 claimed the data and posted it to a dark web leak site, though the practice did not describe the incident as ransomware.

Iowa’s Imagine the Possibilities, which supports people with intellectual difficulties, and Massachusetts-based Health Plans Inc. also reported breaches to regulators.

Why it matters for healthcare security teams — small and mid-size providers remain prime targets. Fast containment from detection to lockdown took weeks in the Georgia case, a reminder that detection speed, not just defenses, shapes the damage. Organizations should rehearse threat-hunting on the assumption an intruder is already inside.

Share This Article