GuardDog Telehealth admitted in a proposed consent judgment that it obtained patient medical records through a health information exchange by falsely claiming the access was for treatment, then provided those records to law firms. The filing emerged in litigation brought by Epic and other plaintiffs, who allege GuardDog and other sham entities improperly accessed records through Health Gorilla, an interoperability platform and Qualified Health Information Network participating in nationwide data exchange frameworks including TEFCA and Carequality.
The case could result in GuardDog being barred from further participation in health data exchanges, underscoring the risk of abuse within trusted interoperability channels when organizations misrepresent their purpose for accessing protected health information. A separate report about a $5 million settlement involving Geisinger Health and Nuance Communications concerns a different incident: the alleged theft of roughly 1.3 million patient records by a former Nuance employee, and is not part of the Epic-Health Gorilla-GuardDog dispute.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Health Gorilla said GuardDog did not disclose any non-treatment use to it and argued that the proposed consent judgment has no legal impact on Health Gorilla, while maintaining Epic's lawsuit is an attack on interoperability.
Under the proposed consent judgment, GuardDog would be permanently barred from requesting patient records through TEFCA and Carequality and would have to delete patient data obtained through those frameworks.
A proposed consent judgment disclosed by March 17, 2026 states that GuardDog Telehealth admitted it requested patient records by falsely claiming the requests were for treatment and then provided those records to law firms.
After Epic's lawsuit, three new putative class action lawsuits were filed against Epic and other defendants. The plaintiffs allege Epic negligently failed to prevent misuse of its Care Everywhere platform, resulting in alleged data breaches.
In January 2026, Epic filed a lawsuit alleging that GuardDog Telehealth and other companies improperly obtained patient medical records through Health Gorilla's interoperability connections to Carequality, TEFCA, and related exchanges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.