Skip to content

Four US healthcare providers report patient data breaches

WindRose Health Network, Advantage Home Health Care, Camden Family Health and Lakes Region VNA report cybersecurity incidents involving patient data

Four US healthcare providers – WindRose Health Network, Advantage Home Health Care, Camden Family Health and Lakes Region VNA – have disclosed cybersecurity incidents involving patient information, with tens of thousands of individuals affected across Indiana, West Virginia and New Hampshire. The incidents involved unauthorized network access, compromised files and an employee email account.

WindRose Health Network, Indiana

WindRose Health Network has started notifying 33,158 individuals after an unauthorized third party accessed part of its network through a vulnerability in a vendor’s remote access tool. The organization operates Federally Qualified Health Centers providing primary care and behavioral health services at several locations in central Indiana.

The vendor notified WindRose about the previously undisclosed vulnerability on August 4, 2026. WindRose secured its environment and engaged cybersecurity specialists, whose investigation found unauthorized access between August 3 and August 4.

The remote access tool did not provide access to patients’ medical records, though patient information was stored in files located on affected parts of the network. The review found that names, patient ID numbers, health insurance information, dates of service and provider names were potentially viewed or copied.

WindRose advised affected patients to watch for signs of identity theft and fraud.

Advantage Home Health Care

Advantage Home Health Care has notified 19,851 individuals after discovering unauthorized access to one of its computer servers. The home healthcare provider learned of the intrusion on June 16, 2026, and a forensic investigation determined that access began on June 9.

On June 26, AHHC determined that files containing patient information had been acquired. The exposed data included first and last names, dates of birth, addresses, phone numbers, Social Security numbers and medical information related to care received.

Information associated with employees enrolled in the AHHC health plan was also compromised. The affected records included health insurance and plan enrollment information, claims data, healthcare provider information and health benefits information.

Adults and minors affected by the incident have been offered 12 months of complimentary single-bureau credit monitoring, credit report and credit score services. The notification did not identify the attacker, though The Gentlemen ransomware group has claimed responsibility for the incident.

Camden-on-Gauley Medical Center, West Virginia

Camden Family Health identified unauthorized access to parts of its computer network after detecting suspicious activity on July 18, 2026. The organization operates community health centers serving the Mountain Lake Region in West Virginia.

Camden Family Health secured its systems and launched an investigation, which confirmed that an unauthorized third party accessed its network on July 18. Files involving patients of Camden-on-Gauley Medical Center were potentially viewed or obtained during the incident.

A review found that medical and health insurance information was potentially exposed. Camden Family Health has not publicly disclosed the final number of affected patients.

The incident was reported to the US Department of Health and Human Services’ Office for Civil Rights using an estimate of at least 501 affected individuals.

Lakes Region Visiting Nursing Association, New Hampshire

Lakes Region Visiting Nursing Association has notified 1,274 individuals following unauthorized access to an employee email account. The Meredith, New Hampshire-based nonprofit provides Medicare-certified home health and hospice services.

Suspicious activity was detected in its email environment on June 2, 2026. The organization activated its incident response procedures and brought in third-party cybersecurity specialists, who confirmed that an unauthorized party had accessed a single employee account.

A review completed on August 13 found that patient information had been exposed. The substitute breach notice posted on the organization’s website did not specify the exact categories of information involved.

Affected individuals have been offered complimentary credit monitoring and identity theft protection services. Lakes Region Visiting Nursing Association also reset passwords and implemented multifactor authentication across its email tenant following the incident.