Gryphon Healthcare and Tri-City Medical Center disclosed separate data breaches last week in which personal information of more than 500,000 people.
See also: Comcast and Truist Bank victims of FBCS data breach

Houston, Texas-based Gryphon is notifying 393,358 people about an incident discovered on August 13, 2024, involving an anonymous associate “for whom Gryphon provides services medical billing.”
The third-party data breach led a hacker to gain access to records containing information about patients “for whom Gryphon Healthcare provides medical billing services,” the company noted in a notification letter to affected individuals, a copy of which was submitted to the Maine Attorney General.
According to Gryphon, names, addresses, dates of birth, social security numbers, dates of service, diagnosis and health insurance information, treatment and prescription information, provider information, and medical record numbers were breached in the incident.
The billing service provider is offering 12 months of free identity theft protection services, including credit monitoring, an insurance policy, and identity theft recovery services, to all affected individuals.
See also: Hawaii Health Center reveals data breach
Tri-City, a public full-service, acute care hospital based in Oceanside , California, notified the Maine AGO that 108,149 people were affected by a data breach over the past year.

According to the healthcare provider, a cyberattack in November 2023 that disrupted certain systems led to a data exposure, and the investigation into the matter found in late September 2024 that personal information, such as names and other identifiers, was compromised during the attack.
Although it contained detailed cyber response steps, similar to those taken during a ransomware incident , Tri-City did not say what type of cyberattack it had fallen victim to. In December 2023, however, ransomware group Inc Ransom claimed responsibility for the incident, adding Tri-City to the Tor-based leak site
The healthcare organization provides affected individuals with similar free identity protection services as Gryphon.
See also: USA 2024: Data breaches at healthcare organizations affected over 14 million patients
Healthcare data breaches, such as the one that affected Gryphon Healthcare, are a growing concern in the digital age, posing significant risks to privacy and security. These breaches often involve unauthorized access to sensitive health information, which can lead to identity theft, financial fraud, and a loss of trust in healthcare providers. The complexity of healthcare data, combined with its high value on the black market, makes it an attractive target for cybercriminals . To combat this, healthcare organizations must implement strong cybersecurity measures, educate staff about data privacy, and regularly update their systems to protect against emerging threats.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
