Wilbarger General Hospital in Texas and Excellent Home Care Services in New York both reported data breaches involving unauthorized access to employee email accounts. In both cases, investigations revealed that sensitive patient information, including protected health information and, in some cases, Social Security numbers and medical details, may have been accessed or copied by unauthorized parties. Both organizations have notified affected individuals and are offering guidance or identity monitoring services, though the total number of impacted patients has not yet been disclosed.
Separately, the Louisiana Office of Student Financial Assistance (LOSFA) notified students of a data security incident involving unauthorized access to certain systems and the removal of files containing names and Social Security numbers. The incident did not affect the START Saving Program or 529 accounts. LOSFA is continuing its investigation and has issued public statements to inform those potentially affected.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Wilbarger General Hospital and Ochsner LSU Health – Regional Urology publicly disclosed their respective breaches. Ochsner said it was offering credit monitoring to affected individuals, while Wilbarger said no evidence of misuse had been identified at that time.
Following its investigation, Excellent Home Care Services notified affected individuals across several New York counties and offered identity monitoring services. The breach involved protected health information and required patient notification, but it was not yet listed on the HHS OCR breach portal at the time of reporting.
Excellent Home Care Services in New York discovered unauthorized access to an employee's email account on 2025-11-25. Potentially exposed data included patient names, contact details, Social Security numbers, and medical information, though the total number affected was not yet public.
Wilbarger General Hospital in Vernon, Texas detected suspicious activity in an employee email account on 2025-10-20. The hospital later confirmed protected health information was present in the compromised account, though the full scope and number of affected individuals remained under review.
Ochsner LSU Health System – Regional Urology identified unauthorized access to retired systems on 2025-10-10. The incident ultimately affected up to 4,519 patients, and accessed data included names, Social Security numbers, and medical histories.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.