Multiple healthcare organizations disclosed data security incidents involving potential exposure of patient and personal information. Jackson Hospital and Clinic (Montgomery, Alabama) notified 14,485 individuals about a breach at its former debt-collection vendor Nationwide Recovery Services, where suspicious activity was identified in July 2024 and an unauthorized party accessed the vendor’s network between July 5–15, 2024. Jackson Hospital stated its own IT systems were not affected, but data shared for collections work may have been compromised, including names, contact details, dates of birth, Social Security numbers, account/insurance information, and dates of service; affected individuals were offered credit monitoring and identity theft protection.
Separately, Community Health Action of Staten Island reported a data security incident that may have involved unauthorized access to sensitive personal and medical information, and Insight Hospital and Medical Center (Chicago) reported a cyber incident involving unauthorized access to its network between Aug. 22 and Sept. 11, 2025, with potential exposure of patient and financial data. The disclosures underscore ongoing third-party and direct-network intrusion risks in the healthcare sector, with notification timing and scope varying by organization and investigation status.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Insight Hospital and Medical Center reported on 2026-03-09 that it was investigating a cybersecurity incident involving unauthorized network access. The notice said patient, medical, and financial data may have been exposed.
Community Health Action of Staten Island disclosed a data security incident that may have involved unauthorized access to sensitive personal and medical information. No additional technical details, scope, or incident timeline were provided in the available report.
On 2026-02-27, Jackson Hospital and Clinic began mailing breach notifications to 14,485 individuals affected by the 2024 vendor incident. The hospital also offered complimentary credit monitoring and identity theft protection.
Jackson Hospital and Clinic said it was not informed that it was impacted by the Nationwide Recovery Services breach until 2026-01-27. The hospital stated its own IT systems were not affected and that it no longer uses the vendor.
Insight Hospital and Medical Center later disclosed that unauthorized access to its network occurred between 2025-08-22 and 2025-09-11. The incident may have exposed sensitive personal, medical, and financial information.
Nationwide Recovery Services notified affected HIPAA-regulated clients about the 2024 breach between February and March 2025. Public reporting indicated the incident may have affected more than 560,000 individuals across its client base.
A forensic investigation found an unauthorized party accessed Nationwide Recovery Services' network between 2024-07-05 and 2024-07-15 after suspicious activity was detected in July 2024. The breach potentially exposed sensitive personal and health-related data belonging to clients' patients.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourceteiss.co.uk
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.