← Blog

May 2026 HIPAA Breach Roundup: Nine Disclosures You Should Know

Share on X

May 2026 brought another dense cluster of U.S. healthcare data-breach disclosures—spanning research software flaws, ransomware on legacy servers, vendor-hosted 9/11 responder records, cloud misconfigurations, and third-party portal incidents. This guide summarizes the nine HIPAA-regulated entities highlighted in HIPAA Journal’s May 2026 data breach roundup and links each incident to its canonical record on BreachHistory so patients, compliance teams, and journalists can track primary sources as investigations mature.

Why May’s healthcare notices matter

Healthcare breaches rarely arrive as single headlines. They surface through HHS OCR filings, state attorney general mirrors, substitute notices, and specialty reporting—often weeks after the underlying intrusion. May 2026’s batch is useful because it mixes confirmed victim counts (for example UNMC’s 26,937 individuals) with cases still awaiting OCR denominators (Singing River Health System). If you received a letter from any organization below, treat it as authoritative over forum rumors and cross-check timelines on our breach blog.

University of Nebraska Medical Center (26,937 individuals)

UNMC disclosed that a vulnerability in the third-party REDCap research application was exploited from September 20, 2023 through February 3, 2026. UNMC took REDCap offline after learning of the flaw in February 2026 and confirmed 26,937 people had data exposed. Categories varied by individual and could include names, dates of birth, addresses, medical information, and some Social Security numbers—typical of research and public-health datasets rather than a single clinic EHR export.

What to do: Research participants should watch for targeted phishing referencing study names; enable fraud alerts if SSN exposure was cited in your letter.

Singing River Health System (count pending on OCR)

Singing River Health System, a Mississippi Gulf Coast nonprofit operating three hospitals and 50+ clinics, notified patients about a hacking incident discovered around December 21, 2025. Forensics confirmed unauthorized network access December 19–21, 2025, and by February 10, 2026 the organization confirmed patient files were viewed and potentially copied. A nationwide HHS total had not been posted in early summaries—monitor the company timeline for updates.

Tampa Bay Dental Implants & Prosthetics (6,400 individuals)

Tampa Bay Dental Implants & Prosthetics reported ransomware on January 19, 2026 that encrypted a legacy server holding EMR backups, affecting 6,400 people. Exposed data included treatment notes, clinical histories, and limited Social Security numbers. The practice described enhanced logging and encryption afterward; credit monitoring was not clearly offered in early HIPAA Journal summaries.

World Trade Center Health Program (1,071 individuals)

The WTC Health Program—which provides no-cost care to 9/11 responders and survivors—reported 1,071 individuals affected after a vendor incident at Managed Care Advisors / Sedgwick Government Solutions. TridentLocker ransomware was detected December 4, 2025 with initial access November 16, 2025; stolen data was later published when ransom was not paid. Highly sensitive categories included SSNs, DOB, addresses, and PHI; victims were offered 12 months of credit monitoring.

Aligned Orthopedic Partners (7,213 individuals)

Aligned Orthopedic Partners (Maryland) disclosed unauthorized email access November 16–December 16, 2025 affecting 7,213 people. February 2026 file review confirmed extensive PHI exposure—SSNs, driver’s licenses, Medicaid/Medicare numbers, diagnoses, prescriptions, and financial identifiers. Notifications went out April 17, 2026 with identity protection services.

Pivot Health (1,172+ Texas residents; nationwide TBD)

Pivot Health, a short-term and supplemental insurer, blocked unauthorized AWS access on March 13, 2026 after activity between February 26 and March 13. Member files with billing and coverage identifiers were viewed or copied. Texas regulators were notified about 1,172 residents while a full HHS count was still pending—use state filings as early signal, not final scope.

LHC Group and Mays Housecall (vendor Doctor Alliance)

Two home-health providers reported impermissible portal access at vendor Doctor Alliance between October and November 2025:

  • LHC Group (Louisiana): 8,644 individuals—demographics, clinical summaries, diagnoses, insurance data.
  • Mays Housecall Home Health (OK/KS/TX): 5,208 individuals—clinical and insurance documentation.

Vendor-chain breaches are a recurring 2026 theme: covered entities remain accountable for downstream notices even when their own data centers were not the intrusion point.

South Alabama Regional Planning Commission (3,043 individuals)

South Alabama Regional Planning Commission reported 3,043 individuals affected after files were copied; client data included Medicaid information, SSNs, and medical service details tied to regional programs.

How to use BreachHistory for ongoing monitoring

Each incident above has a dedicated breach page with technical write-ups, root-cause labels, and reference links. Use company monitoring to receive alerts when victim counts or regulatory filings change, and explore platform capabilities if you run security research across multiple sectors.

Advanced Psychiatry Associates — May 29 extortion claim

Separately from the HIPAA Journal roundup, BreachHistory cataloged an Everest ransomware claim on May 29, 2026 against Advanced Psychiatry Associates in California. No HHS denominator was available at catalog time—treat it as an actor-claimed event until the provider publishes a substitute notice. Mental-health data carries heightened stigma and fraud risk; patients should be wary of extortion emails threatening to publish therapy-related files.

Compliance and workforce training angles

Several May notices explicitly mention refreshed workforce privacy training—UNMC after REDCap exploitation, Singing River after network intrusion, and Aligned Orthopedic after email compromise. For compliance officers, the cluster is a useful board-level reminder that Business Associate Agreements and vendor SOC reports do not replace runtime monitoring: research tools, legacy backups, and SaaS portals need the same hunt-team attention as hospital VLANs.

Bottom line

May 2026’s HIPAA cluster underscores three defensive priorities for healthcare organizations: patch third-party research tools promptly, retire legacy backup servers from production networks, and contractually require MFA and logging on vendor portals that touch PHI. Patients should read notification letters carefully—data elements often vary person by person—and enroll offered credit monitoring when Social Security numbers or government IDs were involved.

Primary source: HIPAA Journal — May 2026 Data Breach Round Up