PrivacySignal
Breach

Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits

HIPAA Journal · · US Federal · Data Breaches

Palomar Health Medical Group in California and Summit Medical Group have each agreed to settlements resolving class action lawsuits stemming from data breaches. The cases were reported by The HIPAA Journal, indicating the breaches involved protected health information.

Why this matters: Medical data breaches hit differently than most. Patients do not choose to share their information with a hospital or medical group — they hand it over because they need care. When that data gets exposed, people can face insurance complications, embarrassment, or worse. A settlement closes the legal case, but it rarely means the harm is undone. If you were a patient at either organization, this is worth watching to see whether you are included in the class and what, if anything, you are owed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach Critical
BleepingComputer · · International

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

AdaptHealth confirms 4.1 million people exposed in July cyberattack

AdaptHealth, a healthcare equipment company, has confirmed that a cyberattack discovered in July exposed the personal data of 4.1 million people. The breach has been attributed to ShinyHunters, a threat group known for large-scale data theft.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
CyberScoop · · US Federal

FTC rescinds policy requiring health apps to notify customers after a breach

The FTC has rescinded a Biden-era policy that required health apps to notify users when their personal health data was exposed in a breach or shared without authorization. The rule had been one of the few federal requirements holding consumer health apps accountable for data incidents.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
WIRED — AI · · International

I Let an AI Agent Hack All My Gadgets—and I’d Do It Again

A writer disabled safety restrictions on an open-source AI model and used it as an autonomous agent to probe household devices for security vulnerabilities. The model successfully found weaknesses and broke into a PC, then provided guidance on how to fix the exposed flaws.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
Microsoft Threat Intelligence · · International

Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation#security Read original →