Two healthcare breach threads landed on 17 September. Modernizing Medicine, the Boca Raton EHR and AI-software provider, has agreed to pay nearly US$3 million to settle class-action litigation over a July 2025 incident in which a criminal hacker accessed two servers used to convert data from retiring EHR platforms, exposing names, addresses, limited Social Security numbers, health insurance and medical information of 198,795 individuals. The settlement, which received preliminary court approval, establishes a US$2,999,750 fund offering class members a two-year CyEx medical-data monitoring membership plus either up to US$5,000 in documented-loss reimbursement or a pro rata cash payment expected around US$75. Separately, a relatively new extortion group called Wallstreet has claimed responsibility for the August cyberattack on Cedar County Memorial Hospital in Missouri, adding the facility to its dark-web leak site; the claim has yet to be verified, and the hospital's data-review is ongoing. The same HIPAA roundup notes Next Level Medical (Texas) disclosing a PEAR-group theft-and-extortion incident and Vandalia Health's Grafton Hospital notifying 1,215 individuals after a phishing compromise.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-18 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |