More than 560,000 people were affected by four data breaches disclosed last week to authorities, from healthcare organizations Hillcrest Convalescent Center, Gastroenterology Associates of Central Florida, Community Care Alliance and Sunflower Medical Group.
See also: Ascension: Data breach affects 5.6 million people

The largest of the breaches in terms of the number of people affected was disclosed by Kansas-based healthcare provider Sunflower Medical Group.
Sunflower learned of the data breach on January 7, 2025 , and an investigation showed that hackers had accessed its systems since December 15, 2024, obtaining information such as name, address, date of birth, social security number, driver's license number, medical information, and health insurance.
The Rhysida ransomware group claimed credit for the attack on Sunflower Medical in January 2025, claiming to have stolen more than 3TB of files , which they had offered to sell. The hackers claimed to have stolen the information of 400,000 people , but Sunflower told the Maine Attorney General's Office that 220,000 people were affected .
Hillcrest Convalescent Center , a North Carolina-based nursing home and rehabilitation center, detected suspicious activity on its network in late June 2024. An investigation showed that hackers had accessed its systems and stolen data, including names, Social Security numbers, dates of birth, financial account information, driver's license and other government- issued identification numbers , medical information, and health insurance information.
Hillcrest told the Maine Attorney General that the incident affected just over 106,000 people.
See also: Anna Jaques Hospital: Ransomware attack exposed patient data
Gastroenterology Associates of Central Florida (dba Center for Digestive Health) discovered a breach in its IT network in April 2024, and its investigation showed that threat actors may have obtained the name, social security number, date of birth, and health information of more than 122,000 individuals.

The data was breached by the BianLian, which took credit for the attack on the Digestive Health Center in mid-May 2024.
Rhode Island-based Community Care Alliance was breached in early July 2024. An investigation completed in January 2025 showed that cybercriminals may have obtained information such as name, address, date of birth, driver's license numbers, social security numbers, diagnostic information, lab results, insurance information, and treatment information.
The Community Care Alliance told the Maine Attorney General's Office and the Department of Health and Human Services that the incident affected about 115,000 people.
The Rhysida ransomware group took credit for the attack on Community Care Alliance in late July 2024.
In 2024, organizations notified the US government of 720 healthcare data breaches affecting a total of 186 million user records .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: PIH Health was attacked by Ransomware
Healthcare data breaches are incidents in which unauthorized individuals gain access to sensitive patient information, such as medical records, personal information, or financial information, stored by healthcare organizations. These breaches can occur at hospitals, clinics, insurance companies, and other healthcare-related entities that store and manage health data. The consequences of healthcare data breaches are significant, as they compromise privacy , can lead to identity theft, and can cause financial or reputational damage to the organizations involved.
Source: securityweek
