PrivacySignal
Breach

Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals

HIPAA Journal · · US Federal · Data Breaches

Brown Health Medical Group-MA, operating under Lifespan Physicians Group of Massachusetts, has confirmed a data breach involving the protected health information of approximately 312,000 individuals. The incident falls under HIPAA reporting requirements, indicating that sensitive patient data was exposed or compromised.

Why this matters: Medical data is not just sensitive — it is permanent. You cannot change your diagnosis, your treatment history, or what you told a doctor in confidence. When a physicians group exposes 312,000 patients, those people have no real recourse. They cannot opt out retroactively. Healthcare providers collect this information because they have to, which makes the duty to protect it even clearer. The size of this breach suggests a systemic failure, not a one-off mistake, and patients deserve a straight answer about exactly what was taken and how.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
Schneier on Security · · International

Iran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”...

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Microsoft Threat Intelligence · · International

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach Critical
CyberScoop · · US Federal

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →