Multiple healthcare organizations in the United States have experienced significant data breaches involving the exposure of protected health information (PHI) and other sensitive personal data. In Albemarle County, Virginia, a ransomware attack compromised the PHI of members of its self-insured health plan, as well as data belonging to current and former government and public school employees, their dependents, and individuals who interacted with the county. The compromised information included names, Social Security numbers, health insurance details, and other identifiers. The county has concluded its investigation, notified affected individuals, and is offering complimentary credit monitoring and identity theft protection services.
Separately, class action settlements have been reached with three healthcare providers—Hypertension Nephrology Associates, Asheville Arthritis and Osteoporosis Center, and Intermountain Planned Parenthood—following data breaches that exposed patient health and financial information. In one case, Hypertension Nephrology Associates agreed to a $625,000 settlement after a ransomware attack led to the theft of data from nearly 40,000 patients. The lawsuits alleged failures in security practices and delayed breach notifications, with affected individuals being offered credit monitoring services. These incidents highlight ongoing legal and regulatory consequences for healthcare organizations following data breaches involving PHI.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On December 19, 2025, Albemarle County confirmed that protected health information and other personal data were stolen in the June ransomware attack. The county began notifying affected individuals and offered 12 months of complimentary credit monitoring and identity theft protection.
By December 18, 2025, Hypertension Nephrology Associates, Asheville Arthritis and Osteoporosis Center, and Intermountain Planned Parenthood had agreed to settle class action lawsuits over their 2024 data breaches. The settlements created funds of roughly $500,000 to $625,000 for losses, monitoring services, and legal and administrative costs, while the defendants denied wrongdoing.
Following the June 2025 intrusion, the INC Ransom group claimed responsibility for the Albemarle County attack, stating it had exfiltrated 229 GB of data. The group subsequently published the stolen information on its dark web leak site.
On June 11, 2025, county staff discovered they had lost access to certain files, confirming the operational impact of the ransomware attack. The county engaged law enforcement, cybersecurity experts, and HIPAA compliance specialists to investigate and respond.
On June 10, 2025, Albemarle County, Virginia, was targeted in a ransomware attack that compromised county systems and led to data theft. The incident affected information tied to the county's self-insured health plan and other individuals connected to the county.
Intermountain Planned Parenthood suffered a significant data breach in 2024 involving protected health and other sensitive information. The breach later resulted in a class action lawsuit and proposed settlement.
Asheville Arthritis and Osteoporosis Center experienced a 2024 breach involving unauthorized access to sensitive patient information. The incident prompted litigation alleging inadequate safeguards and delayed notification.
Hypertension Nephrology Associates discovered suspicious activity in 2024 that led to a data breach affecting patients' sensitive information. The incident later became the basis for a class action lawsuit and settlement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.