News
CareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachOhio Healthcare Software Vendor Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients — Largest HHS Report of 2026 · Data BreachAmgen Patient PHI Stolen via Third-Party Cloud Vendors; Pharmaceutical Giant Discloses Breach in SEC 8-K Filing · Data BreachFour Surgical Centers and Hospitals Disclose Patient Data Breaches: Wildwood, Michigan Surgical, Penobscot Valley, and Whitfield Regional · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachOhio Healthcare Software Vendor Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients — Largest HHS Report of 2026 · Data BreachAmgen Patient PHI Stolen via Third-Party Cloud Vendors; Pharmaceutical Giant Discloses Breach in SEC 8-K Filing · Data BreachFour Surgical Centers and Hospitals Disclose Patient Data Breaches: Wildwood, Michigan Surgical, Penobscot Valley, and Whitfield Regional · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data Breach

Data Breach

Five Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others

TL;DR

Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and a fifth named provider have each disclosed separate patient data breaches. These are breach disclosures, not enforcement actions. No fines have been announced. Each organization is now subject to HIPAA Breach Notification Rule requirements including patient notification and HHS OCR reporting.

Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and a fifth named provider have each disclosed separate patient data breaches. These are breach disclosures, not enforcement actions. No fines have been announced. Each organization is now subject to HIPAA Breach Notification Rule requirements including patient notification and HHS OCR reporting.

Five small healthcare organizations spanning primary care, oral surgery, vision care, and insurance benefits have newly disclosed patient data breaches under the HIPAA Breach Notification Rule. Here is what compliance officers need to know.

medcomply.ai editorial teamPublished August 12, 2026Updated August 12, 20266 min read

Five separate healthcare organizations, spanning primary care, oral surgery, eye care, and insurance benefits administration, disclosed patient data breaches in a single reporting cycle, a reminder that no corner of healthcare is insulated from security incidents.

This article covers what is known about each disclosure, what the HIPAA Breach Notification Rule requires, and what compliance officers at small-to-mid-size covered entities should take from this roundup. To be clear: these are breach disclosures, not enforcement actions. HHS OCR has not announced fines or penalties in connection with any of these incidents.

Warning

Five simultaneous disclosures across five different practice types signals a systemic pattern, not isolated bad luck. If your organization has not conducted a formal risk analysis recently, these disclosures are a prompt to do so.

The Five Organizations

The HIPAA Journal reported on August 12, 2026 that the following organizations have each disclosed a separate security incident involving patient data:

  • Family Medical Associates of Raleigh (primary care)
  • Arkansas Oral & Maxillofacial Surgeons (oral surgery and dental)
  • Alpine Agency of the Midlands (insurance or benefits administration)
  • Princeton Family Eye Care (vision care)
  • A fifth named provider disclosed in the same roundup

The number of patients affected at each organization has not been independently verified by medcomply.ai. Refer to the HIPAA Journal source and the HHS OCR breach portal for the most current figures as they become available.

What the HIPAA Breach Notification Rule Requires

Each of these organizations is now subject to the requirements of the HIPAA Breach Notification Rule. The core obligations are straightforward but operationally demanding, particularly for small organizations without dedicated compliance staff.

45 CFR §164.400 establishes the general requirement that covered entities notify individuals following the discovery of a breach of unsecured protected health information.

45 CFR §164.404 requires that affected individuals be notified without unreasonable delay and in no case later than 60 calendar days after the breach is discovered.

45 CFR §164.408 requires notification to HHS OCR. For breaches affecting 500 or more individuals, that notification must be submitted immediately. For smaller breaches, organizations may report annually, but the clock still starts at discovery.

45 CFR §164.406 addresses media notification. Organizations that experience a breach affecting 500 or more residents of a state or jurisdiction must also notify prominent media outlets in that area.

Meeting these deadlines while simultaneously conducting an investigation, securing affected systems, and communicating with patients is a significant operational burden. Organizations that lack a written incident response plan often find themselves scrambling to do all of this at once.

Why This Roundup Matters for Compliance Teams

The breadth of practice types in this single roundup is notable. An oral surgery practice, a primary care clinic, a vision care provider, and an insurance or benefits agency operate with very different workflows, software systems, and patient populations. They share one thing: each handles protected health information and each is required to meet the same HIPAA standards.

This pattern is consistent with what the HHS OCR breach portal shows over time: small covered entities are not breached because they are targeted specifically, but because they often lack the layered defenses that larger organizations have built over years of investment. Smaller practices may use cloud-based practice management software from vendors that have not been thoroughly evaluated under a formal vendor management program. They may not have tested their backup and recovery processes. They may not have a written risk analysis as required under 45 CFR §164.308(a)(1).

None of that is an excuse, but it is an explanation, and it points directly to what compliance officers at similar organizations should do next.

Immediate Steps for Similarly Situated Organizations

If your organization resembles any of the five named entities in practice type, size, or technology stack, consider the following actions:

Review your risk analysis. 45 CFR §164.308(a)(1) requires a thorough and accurate assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI your organization creates, receives, maintains, or transmits. If your last risk analysis is more than 12 months old, or was never formally documented, that is your starting point.

Confirm your incident response plan is written and tested. A breach notification timeline of 60 days sounds generous until your organization is managing a live incident. Written procedures, assigned roles, and at least one tabletop exercise significantly reduce the likelihood of missing a regulatory deadline.

Audit your business associate agreements. 45 CFR §164.308(b)(1) and 45 CFR §164.502(e) require that covered entities enter into business associate agreements with vendors who handle PHI on their behalf. Many small organization breaches trace back to a vendor relationship that was never formally documented or reviewed.

Check your notification templates. Breach notification letters to patients must include specific content under 45 CFR §164.404(c), including a description of what happened, the types of information involved, steps individuals should take to protect themselves, and contact information for your organization. Having a reviewed template ready before you need it saves critical time.

The Broader Compliance Context

Each new batch of breach disclosures adds data points to a pattern HHS OCR has cited repeatedly: the volume of breaches affecting smaller covered entities remains high, and the most common contributing factors, inadequate risk analysis, missing or outdated business associate agreements, lack of workforce training, and insufficient access controls, are not new problems. They are recurring failures at organizations that have not treated HIPAA compliance as an ongoing operational function.

These five disclosures will eventually appear on the HHS OCR breach portal, which is publicly searchable. Patients, journalists, state attorneys general, and plaintiff attorneys all monitor that portal. A breach disclosure is not the end of an organization's exposure; it is the beginning of a period of heightened scrutiny.

Five healthcare organizations across primary care, oral surgery, vision care, and insurance benefits have disclosed patient data breaches in a single reporting cycle. These are breach disclosures, not enforcement actions, and no fines have been announced. Compliance officers at small-to-mid-size covered entities should treat this roundup as a prompt to review their risk analysis, incident response plan, and business associate agreements before a similar disclosure becomes necessary.

Sources & citations

  • HIPAA Journal: Data Breaches at Five Small Healthcare OrganizationsOpen

All content verified against official HHS guidance and the Code of Federal Regulations.

Frequently asked questions

Are these HIPAA enforcement actions or fines?
No. These are breach disclosures, not enforcement actions. HHS OCR has not announced any fines or penalties related to these incidents. The organizations are fulfilling their notification obligations under the HIPAA Breach Notification Rule.
What does the HIPAA Breach Notification Rule require when a breach occurs?
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach. Breaches affecting 500 or more individuals in a state must also be reported to prominent media outlets. All breaches must be reported to HHS OCR, with breaches affecting fewer than 500 individuals reportable annually.
Why do small healthcare organizations keep appearing in breach roundups?
Small organizations often have fewer dedicated security and compliance resources than large health systems. They may rely on smaller vendors, use legacy software, or lack formal incident response plans, all of which increase exposure. Breach risk is not proportional to organization size.
What types of organizations were affected in this roundup?
The five organizations span primary care, oral and maxillofacial surgery, vision care, and insurance or benefits administration, illustrating that breach risk cuts across virtually every care setting and business type in healthcare.
What should compliance officers do when a peer organization discloses a breach?
Use peer disclosures as a prompt to review your own risk analysis, incident response procedures, and vendor agreements. Identify whether your organization shares similar characteristics, such as practice type, software vendors, or data handling practices, with the disclosing entity, and address any gaps proactively.

Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.