A former Nuance Communications IT worker, Max Vance (also known as Andre Vance), pleaded guilty in Pennsylvania federal court to obtaining information from a protected computer without authorization after allegedly downloading and storing ~1.2 million Geisinger Health patient records on a personal hard drive shortly after being terminated in 2023. Nuance (now part of Microsoft) was providing IT services to Geisinger at the time of the incident, and the criminal case was initially filed in January 2024.
Geisinger previously stated the exposed data included patient names, birthdates, addresses, medical record numbers, race, gender, phone numbers, and facility name abbreviations. Under the plea agreement, prosecutors agreed to dismiss additional charges related to alleged false statements to the FBI that had been added in a superseding indictment, and Vance agreed to forfeit a Samsung PSSD T7 external drive cited in the case.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
A federal court approved a $5 million class-action settlement related to the Geisinger breach. A final approval hearing was scheduled for March 16, 2026.
On February 27, 2026, Vance pleaded guilty in Pennsylvania federal court to unlawfully obtaining information from a protected computer. Under the plea agreement, prosecutors agreed to dismiss two false-statement charges and Vance agreed to forfeit a Samsung external drive alleged to contain the stolen data.
In February 2024, investigators arrested Vance in connection with the Geisinger data theft. During a property search, authorities reported finding electronic devices containing the stolen data as well as unregistered firearms, fake or blank IDs, and equipment for producing fake IDs.
Prosecutors filed the criminal case in January 2024, alleging that Max Vance unlawfully obtained information from a protected computer and copied Geisinger patient data after his termination. The case also initially included false-statement charges tied to FBI interviews.
Geisinger said it discovered the unauthorized access on November 29, 2023 and notified Nuance, triggering investigation of the insider breach. The incident involved Nuance's role as Geisinger's IT services provider and business associate.
Two days after being fired in 2023, former Nuance employee Max Vance allegedly used still-active access to download and store more than 1 million Geisinger Health patient records on a personal external hard drive. The data reportedly covered about 1.2 million patients and included identifiers such as names, birthdates, addresses, medical record numbers, and demographic details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.