Multiple healthcare organizations have reported significant data breaches involving unauthorized access to patient information. CareOregon and Health Share of Oregon notified patients of a breach where protected health information, including names, dates of birth, health plan details, and Medicaid/Medicare numbers, was accessed without authorization, raising concerns about potential insurance fraud. Canopy Health, a major New Zealand oncology provider, disclosed a cyberattack that resulted in unauthorized access to administrative systems and possible data exfiltration, with the incident being contained and legal action taken to prevent misuse of the compromised data. Additionally, a Manhattan plastic surgery practice suffered a cyberattack in which sensitive patient images and personal information were stolen and published online, with extortion attempts made directly to patients; this attack is linked to a series of similar incidents targeting plastic surgery practices.
In parallel to these incidents, California authorities have taken regulatory action against Datamasters, a marketing firm found to be illegally selling health and personal data of millions of individuals without proper registration as a data broker. The company was fined and banned from selling Californians' personal information after it was discovered to have traded in sensitive data, including health conditions and demographic details, for targeted advertising. These events highlight ongoing risks to health data privacy from both cyberattacks and improper commercial data practices, as well as the increasing regulatory scrutiny and enforcement in this sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
CareOregon and Health Share of Oregon notified affected patients about the breach and warned of potential insurance fraud. They also reported the incident to law enforcement, remediated the issue, and retrained staff.
The California Privacy Protection Agency took enforcement action against Rickenbacher Data LLC, doing business as Datamasters, for operating as an unregistered data broker and reselling sensitive health and personal data. The agency fined the company $45,000, barred further sales of Californians' personal information, and ordered deletion of previously purchased Californians' data.
The California Privacy Protection Agency fined S&P Global Inc. $62,600 for failing to register as a data broker for 2024 by the required deadline. The agency said the company remained unregistered for 313 days before the enforcement action was announced.
CareOregon and Health Share of Oregon discovered unauthorized access to protected health information on 2025-10-27. Exposed data included names, dates of birth, health plan information, Medicaid/Medicare numbers, and primary care provider details, but not Social Security or financial data.
Andover Eye Associates discovered in June 2025 that two employee email accounts had been accessed without authorization. The incident exposed names and Social Security numbers of 1,638 patients.
California required data brokers to register annually, and S&P Global Inc. missed the January 31, 2025 deadline for 2024 registration. CalPrivacy later said the lapse continued for 313 days and was attributed to an administrative error.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.