type: incident ยท created: 2026-09-05 ยท updated: 2026-09-05 ยท tags: [incident, breach, healthcare, ransomware, third-party] ยท confidence: medium ยท affected_sectors: [healthcare] ยท au_impact: false
Two US Providers Report Cyber Incidents; Midwest Spine Hit by Third-Party Ransomware
HIPAA-breach notifications published this week cover two US providers. The Resource Center of Dallas, a Texas nonprofit, is notifying 12,500 patients about a cyber incident, and the Midwest Spine and Brain Institute, a Minnesota surgical practice, reported its operations were impacted by a ransomware attack that targeted third-party vendor 3C Care Systems, which handles its data.
| Attribute | Detail |
|---|---|
| Resource Center of Dallas | 12,500 patients (cyber incident) |
| Midwest Spine & Brain Institute | Operations impacted; ransomware at 3C Care Systems (third-party vendor) |
| Source | HIPAA Journal โ Tier 2/4 |
The Midwest Spine case is another third-party-vendor ransomware incident: the surgical practice was affected via its data-handling vendor, underscoring the supply-chain exposure in healthcare.
Related Pages
- Resource Center Of Dallas Notifies 12 500 Patients About Cyber Incident โ the Resource Center of Dallas notification