News
CareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachOhio Healthcare Software Vendor Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients — Largest HHS Report of 2026 · Data BreachAmgen Patient PHI Stolen via Third-Party Cloud Vendors; Pharmaceutical Giant Discloses Breach in SEC 8-K Filing · Data BreachFour Surgical Centers and Hospitals Disclose Patient Data Breaches: Wildwood, Michigan Surgical, Penobscot Valley, and Whitfield Regional · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachOhio Healthcare Software Vendor Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients — Largest HHS Report of 2026 · Data BreachAmgen Patient PHI Stolen via Third-Party Cloud Vendors; Pharmaceutical Giant Discloses Breach in SEC 8-K Filing · Data BreachFour Surgical Centers and Hospitals Disclose Patient Data Breaches: Wildwood, Michigan Surgical, Penobscot Valley, and Whitfield Regional · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data Breach

Data Breach

Optalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands

TL;DR

Optalis Management Solutions disclosed a network breach affecting 13,723 patients, with at least one additional entity reporting an email breach exposing names, Social Security numbers, financial account numbers, and clinical data. These are voluntary breach notifications, not OCR enforcement actions. Compliance teams overseeing post-acute and long-term care vendors should review their business associate agreements and incident response timelines.

Optalis Management Solutions disclosed a network breach affecting 13,723 patients, with at least one additional entity reporting an email breach exposing names, Social Security numbers, financial account numbers, and clinical data. These are voluntary breach notifications, not OCR enforcement actions. Compliance teams overseeing post-acute and long-term care vendors should review their business associate agreements and incident response timelines.

Optalis Management Solutions, a Michigan-based skilled nursing and rehabilitation management company, notified 13,723 individuals of unauthorized network access occurring April 14–19, 2025. At least one additional entity disclosed an email breach exposing sensitive patient data. Neither incident is an OCR enforcement action, and no fines have been announced.

medcomply.ai editorial teamPublished August 14, 2026Updated August 14, 20265 min read

A Michigan-based skilled nursing and rehabilitation management company took more than 13 months from the start of a network intrusion to complete its document review, a timeline that raises immediate questions for compliance officers overseeing post-acute and long-term care vendors.

This is a breach disclosure, not an OCR enforcement action. No fine has been announced.

What Happened at Optalis Management Solutions

Optalis Management Solutions, based in Michigan, reported that unauthorized individuals accessed its network between April 14 and April 19, 2025. The company's review of the affected documents concluded on June 10, 2026, more than a year after the intrusion began. Optalis notified a reported 13,723 individuals of the incident, according to coverage by HIPAA Journal published August 13, 2026.

The breach notification process is governed by the HIPAA Breach Notification Rule, which requires covered entities and business associates to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach. 45 CFR §164.404 When a business associate is involved, notification obligations flow through the business associate agreement, and the covered entity bears ultimate accountability for ensuring patients are informed. 45 CFR §164.410

The specific categories of protected health information exposed have not been detailed in available reporting. Compliance teams should monitor the HHS breach portal and any direct notifications from Optalis for updates.

Warning

Optalis Management Solutions operates as a management company for skilled nursing and rehabilitation facilities, a classic business associate context. If your organization contracts with similar post-acute or long-term care management vendors, your business associate agreements and incident response coordination procedures are directly relevant to this type of event.

A Second Entity: Email Breach With Broad Data Exposure

HIPAA Journal's August 13, 2026 report also covers at least one additional HIPAA-regulated entity that disclosed an email breach. That entity's document review concluded July 14, 2026. The exposed data reportedly included names, dates of birth, Social Security numbers, financial account numbers, and clinical information, a combination that creates elevated risk of identity theft and financial fraud for affected individuals.

This second entity is distinct from Optalis and from entities previously covered in medcomply.ai's August 12 roundup. No further identifying details about the entity are available in the source reporting at this time.

Email-based breaches frequently involve unauthorized access to employee email accounts or misdirected messages containing protected health information. Both scenarios fall under HIPAA's Security Rule requirements for access controls and information system activity review. 45 CFR §164.312

Why Post-Acute and Long-Term Care Vendors Deserve Closer Scrutiny

Skilled nursing facilities, rehabilitation centers, and their management companies handle some of the most sensitive patient data in healthcare. Residents in these settings often have complex, chronic conditions, and their records contain extensive clinical histories, financial information tied to Medicare and Medicaid billing, and Social Security numbers used for benefits coordination.

Management companies like Optalis frequently operate across multiple facilities simultaneously, meaning a single network compromise can propagate risk across an entire portfolio of care sites and potentially affect thousands of individuals, as this incident illustrates.

The HIPAA Security Rule requires covered entities and business associates to implement policies and procedures to prevent, detect, contain, and correct security violations. 45 CFR §164.306 Risk analysis and risk management are foundational requirements under that framework. 45 CFR §164.308

What Compliance Teams Should Do Now

Several concrete steps are worth prioritizing in light of these disclosures.

Review your business associate agreements. Confirm that every agreement with a post-acute or long-term care management vendor includes clear breach notification timelines, incident response obligations, and provisions requiring the vendor to cooperate with any investigation. 45 CFR §164.504

Check your vendor's network security posture. Unauthorized network access incidents like the Optalis breach often stem from gaps in access controls, multi-factor authentication, or network segmentation. Your due diligence process for business associates should include asking vendors to document their security controls.

Verify your own incident response timelines. The 60-day notification clock under HIPAA runs from the date a breach is discovered, not from the date a document review concludes. 45 CFR §164.404 If your vendors are treating document review completion as the discovery date, that interpretation may not align with OCR's position on when discovery occurs.

Document your oversight activity. If one of your business associates discloses a breach, your organization's response and any communications with the vendor should be documented thoroughly. OCR expects covered entities to demonstrate active oversight of their business associates.

Source and Scope

This article is based on reporting by HIPAA Journal, published August 13, 2026, covering multiple HIPAA-regulated entities that disclosed new patient data breaches. The entities discussed here are separate from those covered in medcomply.ai's August 12, 2026 roundup. Reported figures such as the 13,723 individual count come from HIPAA Journal's coverage and should be treated as reported pending any official corrections or updates.

The Optalis Management Solutions network breach, affecting a reported 13,723 individuals, is a disclosure event, not an enforcement action, and no fine has been announced. Compliance teams should treat this as a signal to audit business associate agreements with post-acute and long-term care vendors, verify incident response timelines, and confirm that HIPAA's 60-day notification requirement is being applied correctly from the date of discovery, not the date a document review ends.

Sources & citations

  • HIPAA Journal: Data Breaches – Five HIPAA-Regulated EntitiesOpen

All content verified against official HHS guidance and the Code of Federal Regulations.

Frequently asked questions

Is the Optalis Management Solutions breach an OCR enforcement action or a fine?
No. This is a voluntary breach notification under the HIPAA Breach Notification Rule. As of the publication date, no fine or corrective action plan has been announced by the HHS Office for Civil Rights.
How many individuals were affected by the Optalis breach?
Optalis Management Solutions reported that approximately 13,723 individuals were notified. This figure comes from reporting by HIPAA Journal and should be treated as reported, pending any official updates from the company or HHS.
What types of data were exposed in the additional email breach disclosed alongside the Optalis incident?
According to HIPAA Journal, the additional email breach exposed names, dates of birth, Social Security numbers, financial account numbers, and clinical information. The specific entity involved differs from Optalis and from entities covered in medcomply.ai's August 12 roundup.
What is a business associate under HIPAA, and why does it matter here?
A business associate is a vendor or partner that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Optalis Management Solutions operates as a management company for skilled nursing and rehabilitation facilities, placing it in a business associate context. Covered entities are required to have signed business associate agreements in place and must coordinate breach response with their business associates.
What should compliance teams do in response to these disclosures?
Compliance teams should audit their business associate agreements with post-acute and long-term care vendors, verify that incident response and notification timelines meet HIPAA's 60-day requirement, and confirm that access controls and network monitoring are in place for vendors handling protected health information.

Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.