INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Ransomware Against Healthcare Provider in Data Breach

| 2026-09-30 16:44 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH STATE-SPONSORED & ESPIONAGE CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
In the first half of 2026, large healthcare data breaches were reported in 44 U.S. states and Puerto Rico by HIPAA-regulated entities, affecting approximately 33.77 million individuals, a decline of 22.6% compared to H1 2025. The majority of these breaches, nine out of twenty, were due to hacking incidents or ransomware attacks, with the largest breach affecting over 5.8 million individuals. These data breaches occurred at various healthcare providers and business associates, including Lumexa Imaging, TriZetto Provider Solutions, and OpenLoop Health, Inc., among others. The U.S. Department of Health and Human Services Office for Civil Rights reported a total of 397 data breaches in the first six months of the year, with more than 140 million individuals affected in 2025, suggesting that this year could see a major reduction in affected individuals if similar rates continue to be reported in the second half of the year.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
GE MO MD PR VA NC MX JE
healthhealth
Incident Timeline
‎late 2019
The HIPAA Right of Access enforcement initiative began its active period in late 2019.
organisation The HIPAA Right of Access
general_metric 55 financial penalties
‎December 2020
OCR proposed an update to the HIPAA Privacy Rule in December 2020.
industry Healthcare
‎January 2021
The proposed rule was formally introduced in the Federal Register in January 2021.
organisation the Federal Register
organisation the Biden Administration
‎October 2024
The risk analysis enforcement initiative was formally launched in October 2024.
‎late December 2024
OCR announced a notice of proposed rulemaking in late December 2024.
‎January 6, 2025
OCR announced a notice of proposed rulemaking in the Federal Register on January 6, 2025.
‎H1 2025
A single improper disposal incident was reported in H1 2025, resulting in a significant decrease of 97% in the number of affected individuals compared to the previous year.
general_metric 97 %
‎February 16, 2026
Threat actors did not specifically target the entities mentioned in this report, but rather reported healthcare data breaches affecting 500 or more individuals to the HHS' Office for Civil Rights.
industry Healthcare
organisation HIPAA
organisation the HHS’ Office for Civil Rights
organisation The Notice of Privacy Practices
organisation CFR
‎May 2026
The target release date for the final rule was initially set for May 2026 but has been pushed back to July 2027.
‎June 30, 2026
OCR reported 397 data breaches in the first half of 2026, affecting approximately 33.77 million individuals and resulting in $1.4 million in fines and settlements.
organisation OCR
data_breach 804 data breaches
data_breach 37 data breaches
organisation Change Healthcare
organisation HIPAA Regulated Entities
data_breach 290 data breaches
data_breach 59 data breaches
data_breach 48 data breaches
financial $320,000 $ analysis failure
organisation Assured Imaging Affiliated Covered Entities
financial $375,000 $ analysis failure
financial $103,000 $ analysis failure
organisation the Illinois Department of Human Services
organisation MCBS
organisation GA Business Associate
organisation OpenLoop Health, Inc.
organisation Illinois Department of Human Services
organisation IL Health Plan
organisation Civil Monetary
organisation Privacy, Security
organisation Breach Notification Rule
financial $450,000 $ analysis failure
data_breach 397 data breaches
organisation Regional Women’s Health Group
organisation Consociate, Inc.
organisation Consociate Health
organisation Star Group
organisation L.P. Health Benefits Plan Health Plan
financial $245,000 $ Plan analysis failure
organisation the Identity Theft Resource Center
organisation Financial
organisation the HIPAA Security Rule
organisation the HIPAA Breach Notification Rule
organisation MMG Fusion Business Associate
organisation PHI
financial $10,000 $ Associate analysis failure
organisation the Massachusetts Data Security Regulations
financial $225,000 $ Associate analysis failure
financial $515,000 $ financial penalty
‎August 2026
The OCR set a target date of August 2026 for the release of its final rule, but it has yet to be issued.
‎September 10, 2026
The data breach report was obtained from the OCR on September 10, 2026.
tactic Data Breach
organisation the HIPAA Journal
‎Sep 30, 2026
There was a 5.9% decline in healthcare breaches from the first half of 2025 to the same period in 2026, according to the H1 2026 Healthcare Data Breach Report posted on September 30, 2026.
industry Healthcare
tactic Data Breach
general_metric 5.9 %
general_metric 2025 H1
‎Between January 1 and June 30, 2026
Between January 1 and June 30, 2026, OCR announced seven settlements to resolve alleged violations of the HIPAA Rules.
industry Health
organisation the U.S. Department of Health and Human Services
organisation HHS) Office for Civil Rights
data_breach 397 data breaches
general_metric 500 individuals
organisation the HIPAA Rules
‎2026/09/30
Over 1,000,000 individuals were affected by at least 999,999 healthcare data breaches involving regulated entities in the United States.
infrastructure 5 Mississippi
infrastructure 60,133 Mississippi
infrastructure 26,937 Mississippi
infrastructure 36 Mississippi
organisation Healthcare Data Breach Report
organisation Lumexa Imaging
organisation Healthcare Provider
organisation Hacking Incident
organisation TriZetto Provider Solutions
organisation Business Associate
organisation LLC
organisation TN
organisation Nacogdoches Memorial Hospital
organisation TX
organisation Navia Benefit Solutions, Inc.
organisation Insightin Health, Inc.
organisation Xsolis
organisation Scale of Breach
data_breach 999,999 Data Breaches
data_breach 10,000 Data Breaches
data_breach 1000 Data Breaches
‎H1 2026
In H1 2026, unauthorized access and disclosure incidents were the second leading cause of healthcare data breaches.
target_region Puerto Rico
industry Healthcare
general_metric 44 U.S. states
organisation The Biggest Healthcare Data Breaches
general_metric 20 Texas
general_metric 16 Washington
general_metric 15 New York
general_metric 14 Georgia
general_metric 13 Maryland
general_metric 17 Indiana
general_metric 18 Kentucky
general_metric 19 Maryland
industry Health
target_region New Caledonia
industry Technology
organisation Ransomware
organisation Business Services
organisation Hacking Incident (
organisation Erie Family Health Centers IL
organisation Centers Lab NJ
organisation NJ
organisation Networking Technology, Inc.
organisation Minnesota Department of Human Services
organisation MN Health Plan
organisation Unauthorized Access Incident
organisation North Texas Behavioral Health Authority
organisation Radiology Associates
target_region Holy See (Vatican City State)
organisation Anatomic and Clinical Laboratory Associates
general_metric 626,540 LLC GA Business Associate
general_metric 570,000 Hacking Incident
general_metric 542,377 Hacking Incident
general_metric 353,844 Hacking Incident
general_metric 303,965 Unauthorized Access Incident
general_metric 285,086 Hacking Incident
general_metric 276,498 Hacking Incident
general_metric 266,183 Hacking Incident
general_metric 169,626 TN Healthcare Provider
general_metric 10,000 individuals
organisation HIPAA
‎the first half of 2026
There were no new updates to the HIPAA Rules in the first half of 2026, but two pending final rules remained.
organisation HIPAA Regulatory Updates
‎July 2027
The target release date for the final rule was pushed back from May 2026 to July 2027.
Tactical Metrics
Metrics
infrastructure
5
Mississippi
Metrics
infrastructure
60,133
Mississippi
Metrics
infrastructure
26,937
Mississippi
Metrics
infrastructure
36
Mississippi
Metrics
data_breach
397
Data Breaches
Metrics
data_breach
804
Data Breaches
Metrics
data_breach
37
Data Breaches
Metrics
data_breach
999,999
Data Breaches
Metrics
data_breach
10,000
Data Breaches
Metrics
data_breach
1,000
Data Breaches
Metrics
data_breach
290
Data Breaches
Metrics
data_breach
59
Data Breaches
Metrics
data_breach
48
Data Breaches
Metrics
financial
450,000
$ Analysis Failure
Metrics
financial
320,000
$ Analysis Failure
Metrics
financial
375,000
$ Analysis Failure
Metrics
financial
245,000
$ Plan Analysis Failure
Metrics
financial
103,000
$ Analysis Failure
Metrics
financial
10,000
$ Associate Analysis Failure
Metrics
financial
225,000
$ Associate Analysis Failure
Metrics
financial
515,000
$ Financial Penalty
Intelligence Sources
HIPAA Journal 2026-09-30