PrivacySignal
Healthcare

Medtronic Starts Notifying Individuals Affected by April 2026 Cyberattack

HIPAA Journal · · US Federal · Healthcare Privacy

Medtronic has begun notifying people whose data was exposed in a cyberattack that occurred in April 2026, with the ShinyHunters threat group claiming responsibility for the breach. The medical device company's notification process follows reporting by The HIPAA Journal.

Why this matters: Medtronic makes devices like pacemakers, insulin pumps, and spinal implants. The people in its systems are not just customers — they are patients with serious medical conditions. That data is among the most sensitive anyone holds. ShinyHunters has a long track record of selling stolen data, so this is not an abstract risk. If your information was in Medtronic's systems, the concern is not just spam. It is your diagnosis, your device, your treatment history. Medical data does not expire, and neither does the harm from losing it.

Who should care: Healthcare professionals · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Five HIPAA-Regulated Entities

Five healthcare organizations covered under HIPAA have disclosed data breaches, including the Women's Center for Radiology in Florida and Optalis Management Solutions in Michigan, along with three other named entities. The announcements follow standard breach notification requirements under federal health privacy law.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
Nextgov/FCW · · US Federal

VA seeks to extend its Oracle health record contract through 2031

The Department of Veterans Affairs is seeking to extend its electronic health records contract with Oracle through 2031, citing the need to continue deployment across VA medical centers until all facilities have fully transitioned to the new system.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
DataBreaches.net · · International

CA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related Breaches

Newfoundland and Labrador's Privacy Commissioner is recommending that public bodies disclose the names of employees responsible for snooping-related privacy breaches to the people whose records were accessed. The recommendation follows an incident in which an NL Health Services employee viewed a patient's health record without authorization.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

Critical Vulnerabilities Identified in Popular Consumer Fertility Device

Security researchers have identified critical vulnerabilities in the Mira Hormone Monitor, a consumer fertility tracking device. The findings were reported by The HIPAA Journal, suggesting the flaws carry potential health data privacy implications.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

#healthcare#surveillance#security Read original →
Healthcare
DataBreaches.net · · International

A serious incident occurred at MyDr, a Polish healthcare system provider

MyDr, one of Poland's largest healthcare system providers, is investigating a security breach after attackers claimed to have accessed patient data from multiple Polish clinics. The alleged hackers say they obtained nearly 18.8 million unique PESEL numbers, Poland's national identification numbers used across government and financial services.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Five Small Healthcare Organizations

Five small healthcare organizations have disclosed security incidents that exposed patient data, according to reporting by The HIPAA Journal. The organizations were not named in the excerpt beyond one partial reference, but all involve breaches of protected health information.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →