Four US healthcare data breaches disclosed this week

Western Orthopaedics, Community Health Systems California, Tri-Cities Gastroenterology, and Integrated Pain Associates have all disclosed breaches. The PEAR ransomware group leaked the Western Orthopaedics dataset after a refused ransom.

Rows of server racks in a data centre
Photo: Victor Grigas (Wikimedia Commons, CC BY-SA 3.0)

A cluster of US healthcare data breaches has been disclosed in the past week.

Integrated Pain Associates (Texas) reported unauthorised network access on or around 24 February 2026. The leaked dataset includes names, addresses, dates of birth, driver's licence numbers, Social Security numbers, diagnoses, medications, insurance details, and provider names. The threat actor behind the Integrated Pain incident has not been publicly identified.

Tri-Cities Gastroenterology (Tennessee) had files exfiltrated in mid-December 2025; an external review concluded on 22 April 2026 that they contained names, Social Security numbers, dates of birth, addresses, contact details, gender, and medical record numbers. Patient notification letters began on 29 April.

Western Orthopaedics (Colorado) disclosed a ransomware incident affecting 113,330 patients, with network access between 17–25 September 2025 detected on 2 October 2025 and notification letters issued on or about 5 May 2026. The PEAR cyber-extortion group claimed responsibility and, after the ransom was refused, published the stolen data, reported to total around 1.7 TB of patient PII/PHI, financial records, and email correspondence. Community Health Systems (California) also disclosed an incident in the same window.

Share
Sources

Sources: Data Breaches Announced by Four Healthcare Providers (HIPAA Journal); Western Orthopaedics says criminals stole the data of over 113,000 patients (teiss); Multiple US Healthcare Data Breaches Expose Millions of Patient Records (Security Boulevard).

Related chapter:

← All news