Five small healthcare organizations across the United States have reported data breaches exposing patient protected health information, with incidents ranging from ransomware attacks to email account compromises. The breaches affected Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and James C. Standring, DDS. The incidents occurred between 2024 and 2026, with some organizations still determining the full scope of affected individuals.
Family Medical Associates of Raleigh detected a cybersecurity incident on May 7, 2026, after unauthorized access occurred between April 18 and April 20, 2026. The Genesis ransomware group claimed responsibility for the attack, which potentially exposed names, demographic information, medical records, health insurance details, financial information, and government-issued ID numbers. Arkansas Oral & Maxillofacial Surgeons discovered unauthorized network access on April 7, 2026, with the PEAR threat group claiming responsibility for what appears to be a data theft and extortion attempt rather than traditional ransomware encryption.
Email account compromises affected Alpine Agency of the Midlands and Princeton Family Eye Care. Alpine identified unusual activity in an employee email account in November 2025, with unauthorized access confirmed starting October 28, 2026, affecting at least 500 individuals. Princeton Family Eye Care detected suspicious email activity on May 4, 2026, ultimately affecting 933 Texas residents. Both incidents exposed combinations of names, birth dates, Social Security numbers, and limited medical information contained in emails and attachments.
The most significant delay in breach notification came from James C. Standring, DDS, which discovered unauthorized system access on September 2, 2024, but only reported the breach to federal authorities on July 17, 2026. This 22-month gap between discovery and notification affected 6,658 patients whose Social Security numbers, driver's license numbers, medical information, health insurance details, and financial account information were exposed. The dental practice provided no explanation for the extended delay in patient notification.
All affected organizations have engaged third-party cybersecurity firms to investigate the incidents and are conducting ongoing data reviews. None of the providers have identified confirmed misuse of patient data, but affected individuals are advised to monitor credit reports, explanation of benefits statements, and financial accounts for signs of identity theft or fraud. The incidents highlight ongoing security challenges facing small healthcare providers, which often lack the resources of larger health systems to implement robust cybersecurity defenses against increasingly sophisticated threat actors..
Source: https://www.hipaajournal.com/data-breaches-five-small-healthcare-organizations/


