August 2026 healthcare data breach news centers on three large HHS hacking reports and several still-developing incidents at medical companies. The largest reported case involves DentaQuest and 15 million people, but HHS investigations remain open. A healthcare breach report records a suspected compromise involving protected health information or related personal data. It does not, by itself, prove every reported detail, establish liability, or show that every listed person suffered identity theft.
Table of Contents
- Which reported healthcare breaches were largest?
- Did all three major reports involve new August attacks?
- Which August incidents disrupted healthcare operations?
- What remains unknown about other medical-company incidents?
- What should potentially affected people do?
Which reported healthcare breaches were largest?
As of august 31, the HHS Office for Civil Rights listed DentaQuest, Unlimited Technology Systems, and CareCloud among hacking incidents affecting at least 500 people. Their reported totals were 15 million, 3,803,750, and 3,756,469, respectively. The HHS breach portal identifies all three as under investigation, so the entries are reports rather than final enforcement findings.
DentaQuest said an intruder accessed its network from May 17 through May 20. The affected information involved identification details and dental or vision health data belonging to some members, providers, and others. DentaQuest began sending notices July 17 and offered 24 months of Kroll identity monitoring. Its breach notice explains the incident and available assistance.
Did all three major reports involve new August attacks?
No. A report or public disclosure date may come months after the underlying intrusion. Unlimited Technology Systems reported a network-server hacking incident affecting 3,803,750 people.
Although its HHS filing appeared in July 2026, the California Department of Justice records the breach date as October 5, 2025. That makes it a 2025 intrusion disclosed in 2026. CareCloud's July filing describes a network-server hacking incident affecting 3,756,469 people. HHS identifies the new Jersey company as a business associate, an organization that handles protected health information for healthcare entities.
Which August incidents disrupted healthcare operations?
Boston Scientific reported the clearest operational disruption. Its August cyber incident affected operating systems, manufacturing, and order processing. The company's August 30 incident update said the activity remained confined to certain on-premise systems.
It reported no cloud-system impact and no new unauthorized activity after August 25. Boston Scientific found no known effect on implanted cardiac-rhythm devices or existing remote monitoring. However, new remote-monitoring activations could not proceed until affected systems were restored. Patients facing a delayed activation should contact their healthcare provider rather than change device use independently.
What remains unknown about other medical-company incidents?
Abbott said a voice-phishing, or "vishing," attack accessed limited systems in its Cancer Diagnostics business. Some files may contain personal information or protected health information, but investigators had not established the exact data or affected population. Abbott reported no disruption to products, manufacturing, laboratories, patient services, or other operations in its updated statement. Globus Medical reported unauthorized access to a limited number of employee email accounts, files, and data.
Preliminary findings showed no exfiltration of sensitive customer, consumer, or patient information, no ransomware, and no effect on product care. Nutex Health said an unauthorized party accessed and removed some server data that could include patient and employee information. The company was still assessing the scope and notification requirements. It reported no material effect on operations or financial reporting.
What should potentially affected people do?
A large reported population does not confirm that every person had the same information exposed. The organization's individual notice should identify the data categories involved and any protection being offered.
People who receive a notice can take these practical steps: Regulatory consequences may also arrive years after an intrusion. In July 2026, HHS announced that OSF Healthcare paid $552,250 and accepted two years of monitored corrective action after a ransomware incident exfiltrated protected health information belonging to 53,907 people.
- Confirm the notice through the organization's official website or a known phone number.
- Enroll in offered monitoring before the stated deadline.
- Watch medical insurance statements and account activity for unfamiliar services or changes.
- Treat unexpected calls requesting passwords, codes, payment, or sensitive details as suspicious.
- Keep the notice and related records in case misuse appears later.
You Might Also Like
- What Is New With Healthcare Data Breach News in August 2026? Latest breach notices and security advisories and Key Takeaways
- Healthcare Data Breach News August 2026 Update: What Changed, Why It Matters, and What to Watch Next
- Healthcare Data Breach News 2026 Guide: exposure, response, and recovery; Key Facts and Questions to Ask