Cybersecurity Incidents Impact Healthcare and Medical Device Sectors in Mid-2026
A series of data breaches and extortion incidents have recently affected healthcare providers and medical device manufacturers across the U.S., exposing sensitive patient and corporate information.
Terry J. Dubrow, MD (Beverly Hills, CA)
A Beverly Hills-based plastic surgery practice confirmed unauthorized access to its systems beginning January 16, 2026, after an individual claimed to have breached its network and copied patient data. An investigation revealed that compromised files included names, Social Security numbers, driver’s license details, medical records, procedure images, and X-rays. The practice has implemented additional security measures and offered affected patients complimentary identity theft protection, though the total number of impacted individuals remains undisclosed.
SunCloud Health (Northbrook, IL)
A behavioral health treatment network detected unusual activity in employee email accounts between April 22 and May 4, 2026. An investigation confirmed unauthorized access, exposing the personal and medical data of 2,594 patients, including names, diagnoses, medications, and treatment details. Notifications were sent on July 23, 2026, and security protocols have since been strengthened.
Integer Precision Technologies (Hudson, MA)
A medical device coatings manufacturer disclosed a breach involving a cloud-based file-sharing application, though the exact timeline of the incident remains unclear. Compromised data included names, addresses, Social Security numbers, financial account details, and some health-related information. Affected individuals were offered 24 months of credit monitoring and identity theft protection, with security enhancements now in place.
Minnesota ENT (Oakdale, MN)
An unauthorized third party accessed six employee email accounts, exposing HIPAA-protected data such as names, birth dates, Social Security numbers, medical records, and insurance information. The breach was confirmed on July 15, 2026, with notifications mailed to affected individuals on August 12. The total number of impacted patients has not been disclosed.
Nipro Medical Corp. (New Jersey)
The U.S. subsidiary of Japanese medical supplier Nipro Corp. identified suspicious activity within its IT systems, potentially exposing credit card information, Social Security numbers, and other sensitive data. Affected individuals were offered 24 months of complimentary credit monitoring, though the scope of the breach remains unconfirmed.
These incidents highlight ongoing cybersecurity risks in the healthcare and medical device sectors, with multiple organizations reinforcing security measures in response.
Source: https://www.hipaajournal.com/data-theft-extortion-incident-beverly-hills-plastic-surgeon/
Terry Reilly Health Services cybersecurity rating report: https://www.rankiteo.com/company/terry-reilly-health-services
SunCloud Health cybersecurity rating report: https://www.rankiteo.com/company/suncloud-health
Sun Control of Minnesota cybersecurity rating report: https://www.rankiteo.com/company/sun-control-of-minnesota
"id": "TERSUNSUN1786998811",
"linkid": "terry-reilly-health-services, suncloud-health, sun-control-of-minnesota",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'healthcare',
'location': 'Beverly Hills, CA',
'name': 'Terry J. Dubrow, MD',
'type': 'healthcare provider'},
{'customers_affected': '2594',
'industry': 'healthcare',
'location': 'Northbrook, IL',
'name': 'SunCloud Health',
'type': 'behavioral health treatment network'},
{'industry': 'medical devices',
'location': 'Hudson, MA',
'name': 'Integer Precision Technologies',
'type': 'medical device manufacturer'},
{'industry': 'healthcare',
'location': 'Oakdale, MN',
'name': 'Minnesota ENT',
'type': 'healthcare provider'},
{'industry': 'medical devices',
'location': 'New Jersey, US',
'name': 'Nipro Medical Corp.',
'type': 'medical supplier'}],
'data_breach': {'file_types_exposed': ['images', 'documents'],
'number_of_records_exposed': [None, '2594', None, None, None],
'personally_identifiable_information': 'yes',
'sensitivity_of_data': 'high',
'type_of_data_compromised': ['names',
'Social Security numbers',
'driver’s license details',
'medical records',
'procedure images',
'X-rays',
'diagnoses',
'medications',
'treatment details',
'addresses',
'financial account details',
'health-related information',
'birth dates',
'insurance information',
'credit card information']},
'description': 'A series of data breaches and extortion incidents have '
'recently affected healthcare providers and medical device '
'manufacturers across the U.S., exposing sensitive patient and '
'corporate information.',
'impact': {'data_compromised': 'sensitive patient and corporate information',
'identity_theft_risk': 'high',
'payment_information_risk': 'high'},
'motivation': ['data theft', 'extortion'],
'regulatory_compliance': {'regulations_violated': ['HIPAA']},
'response': {'communication_strategy': ['notifications sent to affected '
'individuals',
'public disclosure'],
'remediation_measures': ['additional security measures',
'complimentary identity theft '
'protection',
'strengthened security protocols',
'24 months of credit monitoring',
'security enhancements']},
'title': 'Cybersecurity Incidents Impact Healthcare and Medical Device '
'Sectors in Mid-2026',
'type': ['data breach', 'extortion']}