Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: healthcare (14 articles)Clear

Exact Sciences breach exposes data of nearly 11 million in extortion campaign

Data from a breach at cancer-screening company Exact Sciences, now part of Abbott, was indexed by Have I Been Pwned with about 10.9 million unique email addresses. The extortion group ShinyHunters claimed the intrusion, saying it reached internal legacy systems and then pivoted from a corporate single-sign-on account into connected cloud services such as Microsoft 365, Salesforce, and others to steal data. It is part of a wider ShinyHunters wave hitting medical-technology companies. Abbott is investigating and disputed the attacker's characterization of some data. The pattern, one stolen sign-on unlocking many linked services, is now a recurring route to large healthcare breaches.

Check
People who used Exact Sciences services should watch for breach notices and health-themed phishing, and organizations should map which cloud services a single corporate sign-on can unlock.
Affected
Roughly 11 million people whose data sat in Exact Sciences systems and connected cloud services; attackers used one corporate sign-on to reach linked platforms, a pattern behind repeated large medical breaches.
Fix
Enforce phishing-resistant MFA on single-sign-on, scope what each connected cloud app can access, monitor for bulk exports across integrated services, and prepare for extortion-driven leaks of healthcare data.

Amgen says patient health and research data stolen from third-party cloud systems

Biotechnology company Amgen disclosed that attackers stole patient and corporate data from multiple cloud systems run by third-party providers, rather than from its own servers. In a securities filing, Amgen said it detected the intrusion in July, confirmed data was exfiltrated, and determined the incident material based on the volume and sensitivity of affected files. Confirmed stolen data includes proprietary company information and patient protected health information, and the company is still assessing whether intellectual property, research and development data, and further patient records were taken. Operations, product supply, and financial systems were not disrupted. Amgen has not named a provider, entry point, or responsible party.

Check
Organizations relying on third-party cloud providers should confirm what sensitive data those providers hold, how it is protected, and whether breach notification and monitoring obligations are covered in contracts.
Affected
Amgen patients and partners whose protected health information and proprietary data sat in third-party cloud environments; intellectual property and research data may also be affected, deepening the impact beyond ordinary personal information.
Fix
Minimize and segment sensitive data held by vendors, require strong access controls and logging on third-party cloud environments, monitor for bulk exfiltration, and prepare for extortion and phishing after healthcare breaches.

DentaQuest notifies more than 23 million people after a data theft attack

Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.

Check
People with DentaQuest or associated Medicaid or Medicare dental coverage should watch for a notification, enroll in the offered monitoring, consider a credit freeze, and be alert to health-themed phishing.
Affected
More than 23 million DentaQuest members whose names, Social Security numbers, government program identifiers, and dental and vision health records were exposed and leaked, supporting identity theft and targeted fraud.
Fix
Affected people should freeze credit and monitor benefits statements. Organizations holding health data should segment it, enforce phishing-resistant MFA, monitor for bulk data access, and prepare for extortion-driven leaks.

Medtronic breach notifications reach 3.8 million people with SSNs and health data exposed

Medtronic has begun notifying about 3.8 million people that their data was exposed in the breach of its corporate IT systems earlier this year, giving a concrete scale to the ShinyHunters attack it first disclosed in April. The exposed information includes names, contact details, dates of birth, Social Security numbers, and health-related data, a more sensitive set than the company initially detailed. The intrusion, which the extortion group claimed involved around nine million records, was limited to corporate systems, with Medtronic saying its products, patient safety, and device networks were not affected. Affected individuals are being offered credit monitoring, and several class-action lawsuits have followed.

Check
People who have been customers, patients, or partners of Medtronic should watch for a notification letter, take up any offered credit monitoring, and stay alert to phishing that references Medtronic.
Affected
About 3.8 million individuals whose names, contact details, dates of birth, Social Security numbers, and health information were exposed in Medtronic's corporate IT breach; device networks and patient safety were not affected.
Fix
Affected people should enroll in the offered monitoring, consider a credit freeze given the exposed Social Security numbers, and treat medical-themed phishing with caution. Organizations should segment corporate IT from clinical systems.

Medtronic notifies customers after ShinyHunters breach of corporate systems

Medical device maker Medtronic has begun notifying customers that their personal data was exposed in a breach of its corporate IT systems earlier this year, an attack claimed by the extortion group ShinyHunters. Medtronic noticed unusual activity in mid-April and its investigation found that an unauthorized actor had access between April 13 and 19. ShinyHunters claimed to hold roughly nine million records containing personal and internal corporate data, and Medtronic did not pay, with its listing later removed from the group's leak site. The company says its products, patient safety, and the networks running its medical devices were not affected, crediting separation between corporate and clinical systems.

Check
People who have dealt with Medtronic as customers, patients, providers, or partners should watch for their notification and stay alert to phishing or fraud that references Medtronic or medical accounts.
Affected
Individuals whose personal data sat in Medtronic's corporate IT systems, accessed between April 13 and 19; ShinyHunters claimed about nine million records, though device networks and patient safety were not affected.
Fix
Affected people should monitor for targeted phishing and identity fraud. Organizations should segment corporate IT from operational and clinical systems, harden SaaS and identity against social engineering, and enforce phishing-resistant MFA.

Healthcare AI vendor Xsolis breach exposes data on 1.4 million people

Xsolis, a US healthcare technology company whose AI software is used by more than 600 hospitals and insurers for utilization management and reimbursement decisions, has disclosed a breach affecting 1,396,519 people. Attackers got in through a targeted phishing attack on an employee in January, accessing files containing patient data Xsolis handles for its clients. The exposed information includes names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information. Because Xsolis is a vendor, affected individuals may never have dealt with it directly; downstream health systems including Mayo Clinic are among those whose patients are impacted.

Check
Healthcare organizations should check whether they share data with Xsolis and confirm their breach-notification obligations; affected individuals should watch for medical, insurance, and identity fraud and any Xsolis-related notice.
Affected
Patients and health-plan members whose data Xsolis processed for hospitals and insurers (1,396,519 affected); exposed Social Security numbers and medical information carry lasting identity-theft and medical-fraud risk.
Fix
Affected people should enroll in the offered monitoring, freeze credit, and watch insurance statements. Healthcare organizations should strengthen phishing-resistant MFA, map which vendors hold patient data, and tighten access to health-data repositories.

Cardiac monitoring firm iRhythm says patient health data stolen in attack

iRhythm, the US digital-health company behind the Zio wearable heart monitor, has told regulators that attackers stole patient data in a breach it considers material. In an SEC filing, the company said it detected unauthorized activity on June 8 in third-party-hosted business applications, accessed through a social-engineering attack, and received an extortion demand the next day from a threat actor claiming to hold proprietary data, protected health information, and other personal data. iRhythm says its clinical systems, medical devices, patient safety, and operations were not affected, with no payment-card or financial data involved. No ransomware group has publicly claimed the attack, and the number of affected people is not yet known.

Check
Healthcare and other organizations should review how third-party-hosted business applications are secured and monitored, and confirm that help desks and staff can resist social-engineering attempts to grant access.
Affected
iRhythm patients and others whose protected health information and personal data sat in the affected third-party business applications; clinical systems, devices, and financial data were reportedly not involved.
Fix
Enforce phishing-resistant MFA and strong identity verification on third-party SaaS, limit and log access to systems holding health data, and rehearse social-engineering scenarios with staff and help-desk teams.

Novo Nordisk says clinical trial patient data stolen in breach

Novo Nordisk, the pharmaceutical giant behind Wegovy and Ozempic, has disclosed that attackers copied data from its internal IT systems, including information on patients in some of its clinical trials. The company stressed the patient data was de-identified, containing fields like patient ID, year of birth, sex, biomarkers, and lifestyle factors rather than names or direct identifiers. Novo has not said how many people are affected or named the attacker, and is not offering credit monitoring, instead advising patients and healthcare professionals to stay alert for unexpected messages or calls. Pharma firms are increasingly targeted for their valuable research and patient data.

Check
Patients in Novo Nordisk trials and contacted healthcare professionals should watch for unexpected calls or messages referencing the company or a trial, and verify any such contact through official channels.
Affected
Patients in some Novo Nordisk clinical trials whose de-identified data (patient ID, year of birth, sex, biomarkers, lifestyle factors) was copied, plus healthcare professionals the company has contacted.
Fix
There is no direct user fix; stay alert for targeted phishing referencing the breach. Pharma and research organizations should tighten access controls, monitoring, and segmentation around trial and research data stores.

Dental-benefits provider DentaQuest added to Have I Been Pwned with 2,553,599 breached accounts; healthcare-themed phishing risk

Have I Been Pwned has added US dental-benefits provider DentaQuest to its breach corpus with 2,553,599 unique email addresses. DentaQuest is one of the largest dental and vision benefits administrators in the United States, serving Medicaid, Medicare, and commercial members. As is typical for HIBP additions, the underlying breach source and disclosure details are not published alongside the entry, but the listing lets individuals and organizations check whether their accounts appear in the leaked dataset. Healthcare and insurance data carries elevated risk: affected members should anticipate benefits-themed phishing, claim-status lures, and identity-theft attempts, and should rotate any reused passwords. It is among the larger US healthcare-adjacent breaches surfacing recently.

Check
Check whether your @company emails appear in HIBP's DentaQuest corpus. Warn affected staff about dental/medical-benefits-themed phishing - claim status, coverage updates, refund lures - over the next 60-90 days.
Affected
2,553,599 unique email addresses tied to DentaQuest dental and vision benefits members (Medicaid, Medicare, commercial). Healthcare data elevates identity-theft and benefits-phishing risk.
Fix
Affected individuals: rotate DentaQuest passwords and any reused elsewhere, enable MFA, monitor benefits statements. Organizations: add DentaQuest to breach-monitoring watchlists and brief staff on healthcare-themed social engineering.

Oncology Institute confirms patient data exposure via third-party breach; reports point to Cognizant-owned TriZetto (3.4M+ patients in original incident)

The Oncology Institute, a US outpatient cancer-care network, has filed an SEC 8-K confirming that patient information was exposed in a third-party vendor breach. Kroll, acting as the vendor's third-party administrator, notified the company on May 20 that unauthorized access had been detected. The vendor is not officially named, but multiple reports point to Cognizant-owned TriZetto Provider Solutions, which previously disclosed a breach in March 2026 affecting more than 3.4 million patients via its provider-portal infrastructure. The Oncology Institute first flagged the incident in a November 2025 8-K. The vendor has set up a patient portal for inquiries.

Check
If your organization uses TriZetto Provider Solutions or other Cognizant healthcare-data services, request a fresh breach assessment from your account team. Audit shared-data agreements for blast-radius.
Affected
Patients of The Oncology Institute and the wider TriZetto Provider Solutions ecosystem (3.4M+ patients in the original March 2026 disclosure). Healthcare providers using TriZetto for eligibility verification are exposed.
Fix
Notify affected patients per HIPAA. Tighten third-party risk reviews for healthcare-data processors. Implement strict data-handling SLAs in vendor contracts with breach notification deadlines.