
Good morning everyone,
This week’s developments reinforce a familiar but important message: healthcare organizations remain exposed through both their own systems and the technology companies, billing partners, clinical groups and other vendors connected to them.
Several newly reported incidents involved compromised credentials, unauthorized network access or information being sent to the wrong business associate. The latest breach statistics also show that hacking continues to dominate healthcare incident reports, even though 2026 has so far avoided some of the exceptionally large breaches seen in recent years.
For compliance teams, the practical priorities remain clear: understand where protected health information resides, control remote access, continuously oversee vendors, and maintain an incident-response process that can quickly determine what happened, whose information was involved and which notification obligations apply.
Vendor & Supply Chain Risk
Craneware reports cyberattack affecting customer and employee data (July 20, 2026)
What happened: Craneware, a healthcare financial-performance software company serving approximately 2,000 U.S. hospitals and health systems and thousands of clinics and pharmacies, disclosed unauthorized access to part of its data environment. The company said a significant volume of file names was viewed and exfiltrated, along with some employee information and a subset of customer and partner records. Craneware reported that the incident had been contained, customer services and operations were not disrupted, and an investigation with external forensic specialists remained underway. The company notified the FBI, the UK Information Commissioner’s Office and other appropriate authorities.
Why it matters: A compromise at a widely used healthcare technology vendor can create downstream exposure for many organizations even when clinical operations are not interrupted. The event also illustrates why an incident should not be considered low risk merely because systems remain available. Confidentiality, notification and contractual obligations may still be triggered by data exfiltration.
Recommended actions:
- Confirm whether Craneware or related platforms are included in the organization’s vendor inventory and data-flow diagrams.
- Require potentially affected vendors to identify the systems accessed, data elements involved and affected customers as the investigation develops.
- Review contracts and business associate agreements for incident-notification deadlines, investigation cooperation and evidence-preservation requirements.
- Ensure vendor-risk monitoring continues after procurement rather than relying solely on an initial security assessment.
Breach & Incident Notices
Compromised VPN credentials expose women’s health information (July 17, 2026)
What happened: All About Women’s Care, an obstetrics and gynecology practice in Colorado, reported that an unauthorized actor obtained an employee’s VPN credentials and used them to enter the organization’s network. Files were copied, and the attacker reportedly attempted to extort the practice. The incident affected up to 12,000 patients and potentially exposed names, Social Security numbers, driver’s license and other identification numbers, clinical and treatment information, laboratory results, prescription information, ultrasound images, insurance information and copies of identification documents.
Why it matters: Women’s health information can be particularly sensitive and may also be subject to state privacy, reproductive-health or consumer-protection requirements in addition to HIPAA. The incident demonstrates how a single compromised remote-access account can provide an attacker with broad access to highly detailed clinical records.
Recommended actions:
- Require phishing-resistant multifactor authentication for VPN and other remote-access accounts.
- Review VPN logs for impossible travel, unusual login times, unfamiliar devices and excessive data transfers.
- Restrict remote users to the systems and data required for their assigned duties.
- Include medical images, scanned identification documents and unstructured file repositories in risk analyses and data inventories.
Erlanger discloses information to the wrong billing partner (July 16, 2026)
What happened: Erlanger Health System reported that information concerning 4,237 patients who received anesthesia services at Erlanger Western Carolina Hospital was inadvertently transmitted to a billing partner serving Erlanger’s Tennessee facilities. The information was reportedly sent between July 1, 2025, and May 27, 2026. Data involved included names, dates of birth, medical record numbers, contact information, insurance information, dates of service and limited clinical information, including operative notes.
Why it matters: Not every breach begins with ransomware or an external attacker. Data-routing, interface and workflow errors can create impermissible disclosures that persist for months before detection. The fact that the recipient was already a business associate did not make the disclosure permissible because the information fell outside the services the partner was authorized to perform.
Recommended actions:
- Validate recipient, facility and patient-population rules used in automated billing interfaces.
- Reconcile outbound data transfers against the vendor’s approved scope of services.
- Test interface changes before deployment and document approval through formal change-management procedures.
- Periodically sample vendor data feeds to verify that the minimum necessary standard is being applied.
Heart of America Eye Care investigates network intrusion (July 16, 2026)
What happened: Heart of America Eye Care, which operates ophthalmology and optometry practices in Kansas and Missouri, notified regulators and patients of a hacking incident. Its investigation determined that information may have been viewed or copied between April 1 and April 6, 2026. The organization was still reviewing the affected information and initially reported the incident to HHS OCR as involving at least 500 individuals.
Why it matters: Initial breach reports frequently contain estimated or placeholder totals while forensic and document reviews continue. Compliance teams must therefore manage notification deadlines without waiting for every detail to be finalized and should maintain a process for supplementing regulatory reports when the scope changes.
Recommended actions:
- Define who is authorized to make preliminary breach determinations when the affected population is not yet known.
- Maintain a decision log documenting discovery dates, investigative findings and notification calculations.
- Develop a process for updating OCR, state regulators and affected organizations when estimated totals change.
- Preserve forensic evidence before systems are rebuilt, reimaged or returned to service.
Partnered Health reports stolen data from 21 Australian clinics (July 15, 2026)
What happened: Partnered Health announced that personal and sensitive information had been stolen from at least 21 clinics in Australia. Potentially affected records included personal details, consultation notes, referral letters, pathology information and diagnostic results. The organization reported the incident to Australian cybersecurity, privacy and law-enforcement authorities and sought a court injunction intended to prevent the information from being published or used. Its investigation remained ongoing.
Why it matters: Although the incident occurred outside the United States, it illustrates the cross-border responsibilities facing healthcare groups, cloud providers and technology vendors. Organizations operating internationally may need to manage several privacy regimes, notification standards and regulator relationships following the same incident.
Recommended actions:
- Document the countries and jurisdictions in which patient and workforce information is stored or accessed.
- Include international notification and regulator-coordination requirements in incident-response playbooks.
- Review cross-border vendor agreements for data-location, subcontractor and breach-cooperation provisions.
- Prepare communications that can be adapted for different legal requirements without creating inconsistent factual statements.
Cybersecurity & Threat Intelligence
Abbott and Clover Health investigate separate cyber incidents (July 17, 2026)
What happened: Abbott Laboratories disclosed that it was investigating two cybersecurity incidents involving unauthorized access to certain internal systems. Clover Health Investments separately reported unusual login activity involving employee accounts. Both developments were reported amid broader concerns about increasing AI-assisted cyberattacks and ransomware activity.
Why it matters: The simultaneous disclosures illustrate how attackers continue to focus on identity systems, employee accounts and internal networks across the healthcare and medical-technology ecosystem. AI may make phishing, credential attacks and reconnaissance faster, but the initial weaknesses being exploited often remain familiar: compromised accounts, excessive privileges and insufficient monitoring.
Recommended actions:
- Review employee-account alerts to ensure suspicious logins are investigated promptly.
- Enforce conditional-access controls based on device health, geography, authentication risk and user behavior.
- Disable inactive accounts and regularly recertify access for employees, contractors and vendors.
- Test whether incident-response teams can quickly revoke sessions, reset credentials and identify downstream system access.
Industry Breach Trends
May breach reports rise as hacking continues to dominate (July 14, 2026)
What happened: An analysis of the HHS OCR breach portal identified 61 healthcare breaches affecting 500 or more individuals reported during May 2026, a 27.1% increase from April. The incidents affected at least 879,447 people. Hacking and IT incidents accounted for 54 of the 61 breaches and approximately 88.5% of the individuals affected. The analysis also found that 22 incidents occurred at business associates, even though some were reported to OCR under the affected covered entity’s name. From January through May, 319 large breaches affecting more than 21 million individuals had been reported.
Why it matters: The number of individuals affected is lower than during the same period in 2025, but the underlying frequency of incidents remains high. The business-associate figures are especially important because breach-portal reporting can obscure how often the original compromise occurred within the vendor ecosystem.
Recommended actions:
- Track vendor incidents by the location of the compromise, not merely by the entity listed as the OCR reporter.
- Use breach trends to update risk-analysis threat assumptions and security investment priorities.
- Prioritize network-server security, email protection, remote-access controls and vulnerability management.
- Review whether vendors can meet contractual investigation and notification timelines when multiple customers are affected.
Closing Thoughts
This week’s incidents demonstrate that healthcare data can be exposed through several very different paths: stolen credentials, network intrusions, vendor compromises and ordinary data-routing errors. A defensible compliance program must address all of these scenarios rather than treating cybersecurity and privacy as separate disciplines.
Healthcare organizations should continue strengthening risk analyses, remote-access protections, access controls, vendor oversight and breach-notification readiness. Just as importantly, teams should test whether documented safeguards actually work in daily operations. Regular monitoring, interface validation, workforce training and clear evidence of follow-up actions can reduce both the likelihood of an incident and the organization’s regulatory exposure when one occurs.
Stay vigilant, and have a secure week!
