A cluster of US healthcare data breaches has been disclosed in the past week.
Integrated Pain Associates (Texas) reported unauthorised network access on or around 24 February 2026. The leaked dataset includes names, addresses, dates of birth, driver's licence numbers, Social Security numbers, diagnoses, medications, insurance details, and provider names. The threat actor behind the Integrated Pain incident has not been publicly identified.
Tri-Cities Gastroenterology (Tennessee) had files exfiltrated in mid-December 2025; an external review concluded on 22 April 2026 that they contained names, Social Security numbers, dates of birth, addresses, contact details, gender, and medical record numbers. Patient notification letters began on 29 April.
Western Orthopaedics (Colorado) disclosed a ransomware incident affecting 113,330 patients, with network access between 17–25 September 2025 detected on 2 October 2025 and notification letters issued on or about 5 May 2026. The PEAR cyber-extortion group claimed responsibility and, after the ransom was refused, published the stolen data, reported to total around 1.7 TB of patient PII/PHI, financial records, and email correspondence. Community Health Systems (California) also disclosed an incident in the same window.
Sources
Sources: Data Breaches Announced by Four Healthcare Providers (HIPAA Journal); Western Orthopaedics says criminals stole the data of over 113,000 patients (teiss); Multiple US Healthcare Data Breaches Expose Millions of Patient Records (Security Boulevard).
