Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds

A business email compromise (BEC) attack on a vendor of Children’s Healthcare of Atlanta in 2023 resulted in $5.3 million in funds being stolen. While it is unclear if the hacker has been identified and will face justice, a former certified public accountant who conspired with the hacker has been sentenced for attempting to launder the stolen funds.

The hacker compromised the email account of a vendor of Children’s Healthcare of Atlanta that provided furniture and other supplies. On or around June 13, 2023, the hacker impersonated the vendor and requested a change to the vendor’s automatic clearinghouse electronic payment instructions. When the vendor was paid, the funds were directed to a bank account belonging to former CPA and Atlanta business owner Ronald Deabler, 66.

According to court documents, Deabler conspired with the hacker to distribute the stolen funds in exchange for a commission. Deabler opened a second account and tried to transfer the funds; however, the bank would not transfer the entire amount, and only around $1 million of the funds were transferred. Around $3.5 million of the funds obtained from Children’s Healthcare of Atlanta were converted to cashiers’ checks, which were mailed out to a range of different entities and individuals at the direction of the hacker.

Fraudulent transfers are usually identified quickly when the intended recipient of the funds contacts their client to find out why the transfer has not been made. In this case, the vendor contacted Children’s Healthcare of Atlanta within a few days when the expected payment was not received. The fraudulent transfer was quickly identified and traced to Deabler.

Deabler was convicted by a federal jury in February, and this month, a judge sentenced Deabler to four years in prison, followed by two years of supervised release, and ordered him to pay more than $682,000 in restitution. Around $4 million was recovered from Deabler’s accounts and the accounts that received the cashier’s checks.

“Deabler used his knowledge of the banking system to launder millions of dollars stolen from a not-for-profit pediatric healthcare system that is dedicated to the welfare of Georgia’s infants, children, and teens,” said U.S. Attorney Theodore S. Hertzberg. “Scammers, swindlers, and thieves who target our vital healthcare institutions, and their associates who launder stolen money, will face the full consequences of their actions.”

BEC scams are among the costliest types of cybercrime, second only to investment fraud. The FBI’s Internet Crime Complaint Center (IC3) received 24,768 BEC complaints about BEC attacks in 2025, with losses to the scams totaling more than $3.046 billion. In the past three years alone, more than $8.5 billion has been lost to BEC scams.

The post Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds appeared first on The HIPAA Journal.

Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits

Two healthcare providers have agreed to settle lawsuits over their use of pixels and other website tracking technologies. The tools allegedly resulted in the disclosure of patient data to the third-party providers of those tools, without the knowledge or consent of website users.

Banner Health Pixel Settlement

Banner Health is a Phoenix, Arizona-based health system that operates 33 hospitals in six U.S. states. Banner Health faced multiple class action lawsuits over its use of pixels and other tracking and analytics tools on its website between June 1, 2020, and November 22, 2023, which were alleged to have disclosed sensitive information to Meta Platforms (Facebook) and Google LLC. The lawsuits were consolidated into a single action – McCulley, et al. v. Banner Health – as they had overlapping claims. The consolidated lawsuit, which names 8 individuals as class representatives, was filed in the District Court for Weld County in the State of Colorado.

The lawsuit asserted claims for breach of confidence, violation of the Electronic Communications Privacy Act (unauthorized interception, use, and disclosure), invasion of privacy-intrusion upon seclusion, unjust enrichment, violations of the Arizona Consumer Fraud Act, California Invasion of Privacy Act, California Confidentiality of Medical Information Act, California Unfair Competition Law, and Colorado Consumer Protection Act. Banner Health denies any wrongdoing and liability.

All parties agreed to a settlement to bring the litigation to an end, and avoid further legal costs and expenses and the uncertainty of a trial. There are approximately 1,028,000 individuals in the settlement class, which consists of individuals who logged into a Banner Health patient account (MyBanner patient portal) between June 1, 2020, and November 22, 2023.

Banner Health has agreed to pay attorneys’ fees and expenses (up to $3,750,000), settlement administration costs, and service awards of $2,500 to each of the 8 class representatives. All class members are entitled to claim a one-time cash payment of $20 and are eligible to receive a one-year membership for the CyEx Privacy Shield Pro service. The deadline for objection, opting out, and submitting a claim is September 5, 2026. The final fairness hearing has been scheduled for September 10, 2026.

LifeStance Health Group Pixel Settlement

LifeStance Health Group is a Scottsdale, Arizona provider of outpatient behavioral health services. Two class action lawsuits were filed alleging that the defendant disclosed information about individuals’ physical and mental health and other sensitive patient information to third parties via tracking tools on its website. The plaintiffs alleged that the tools were used without their knowledge or consent. The lawsuits were consolidated into a single action – Montana Strong, et al. v. LifeStance Health Group Incorporated – in the United States District Court for the District of Arizona.

The lawsuit asserted claims for violation of the California Invasion of Privacy Act, California Confidentiality of Medical Information Act, Electronic Communications Privacy Act (unauthorized interception, use, and disclosure), California Unfair Competition Law, Arizona Consumer Fraud Act, New York General Business Law, and common law invasion of privacy-intrusion upon seclusion. LifeStance Health Group denies all claims and contentions in the lawsuit, including claims of liability and wrongdoing. All parties agreed to a settlement to avoid the cost and distraction of continuing with the litigation and the uncertainty of a trial.

There are two settlement subclasses. Subclass 1 includes all individuals who booked at least one session through the LifeStance online booking tool, accessed through the lifestance.com website, between March 1, 2020, and April 30, 2023. Settlement subclass 2 consists of other members of the LifeStance patient population between the same dates, who are not members of subclass 1.

LifeStance has agreed to establish a $3,027,874.44 settlement fund, which will be split into a subclass 1 fund of $1,203,405.00 and a subclass 2 fund of $1,824,469.44. Attorneys’ fees and expenses and other costs such as settlement administration expenses and service awards for the class representatives will be deducted from those settlement funds. The remainder will be paid to individuals who submit a valid claim.

LifeStance has agreed to discontinue the use of all third-party tracking tools, other than tools that are fully compliant with the HIPAA Rules, for a period of five years from the settlement date. The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 29, 2026, and the final approval hearing has been scheduled for October 16, 2026.

The post Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits appeared first on The HIPAA Journal.

Soniva Dental Care Data Breach Affects At Least 30,000 Patients

Data breaches have been announced by Soniva Dental Care in Texas, Optalis Management Solutions in Michigan, CareCloud in New Jersey, and Hudson Valley Medical Billing & Credentialing in New York.

Soniva Dental Care

Soniva Dental Care, a San Antonio, Texas-headquartered provider of dental services, orthodontics, and cosmetic dentistry across 14 locations, has recently disclosed a cybersecurity incident affecting patients of several of its practices. On May 26, 2026, Soniva Dental Care was informed by its IT support company about suspicious remote access sessions. It rapidly became apparent that its remote desktop web services infrastructure was under attack, and IT resources were shifted to containing the incident, terminating all external communications, disabling accounts with remote desktop access, and locking down its infrastructure. Soniva Dental Care said its patient record system was quickly restored and its archive data was unaffected.

While the incident was rapidly detected and contained, it was not possible to rule out unauthorized access to patient data. Files exposed in the incident were reviewed and found to contain names, addresses, dates of birth, driver’s license numbers, government-issued IDs, and medical information. Soniva Dental Care said its incident response was effective, and it has not identified any further suspicious activity. While Soniva Dental Care is unaware of any instances of data misuse, the affected individuals have been advised to place a fraud alert on their accounts with any of the three major credit bureaus. Security inspections are being conducted by its IT support company, which will continue to monitor for unauthorized activity.

Regulators have been notified about the data breach, but the incident is not yet shown on the HHS Office for Civil Rights breach portal. The Texas Attorney General was informed that up to 30,000 Texas residents were potentially affected. Affected practices include, but may not be limited to, Agave Dental Floresville, Allwyn Dental, Azle Smiles, Kashi Dental, Mysa Dental, and Wilson Dental.

A ransomware-as-a-service group called TheGentlemen claimed responsibility for the attack. The group is currently one of the most prolific ransomware groups, having attracted affiliates from other groups by offering a 90% split on ransom payments.

Optalis Management Solutions

Optalis Management Solutions, a Michigan-based operations management company specializing in the management of senior living and healthcare facilities, has reported a data breach to the HHS Office for Civil Rights involving the protected health information of 13,723 individuals.

Suspicious activity was identified within its computer network on or around April 19, 2025. The forensic investigation confirmed unauthorized access between April 14, 2025, and April 19, 2025, and on June 10, 2025, it was confirmed that files had been exfiltrated from its network. The review of the affected data has recently been completed, confirming that the following types of information were compromised in the incident: full names, Social Security numbers, driver’s license/state ID numbers, credit/debit card information, financial account information, diagnosis and treatment information, and health insurance information.

Notification letters started to be mailed to the affected individuals on June 29, 2026. While no evidence has been found to indicate any actual or attempted misuse of the stolen data, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services.

CareCloud

CareCloud Inc., a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined that data was exfiltrated from its systems in a recent security incident. CareCloud said it experienced a network disruption on March 16, 2026, that impacted one of its electronic health record environments. Third-party cybersecurity experts were engaged to assist with the investigation, who determined that the impacted AWS environment was accessed by an unauthorized third party between March 10 and March 16, 2026. The threat actor claimed to have exfiltrated databases from that environment.

The data was reviewed, and on June 24, 2026, CareCloud confirmed the data types involved. The affected individuals are now being notified, and the individual notification letters state the exact types of data involved. Complimentary identity theft protection services have been offered to the affected individuals. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

Hudson Valley Medical Billing & Credentialing

Hudson Valley Medical Billing & Credentialing, LLC, a New York-based provider of patient billing and accounts receivable services, has identified unauthorized access to computer systems containing the protected health information of 5,459 patients of its healthcare clients. The intrusion was first identified on March 6, 2026, and immediate action was taken to contain the incident and terminate the unauthorized access. The investigation was unable to determine whether patient data was accessed or copied, so notification letters have been mailed to individuals who have potentially been affected.

The company said it has enhanced its technical safeguards to strengthen system security, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The exact data types involved are detailed in the individual notification letters.

The post Soniva Dental Care Data Breach Affects At Least 30,000 Patients appeared first on The HIPAA Journal.

Global Data Breach Cost Rises 12% to Almost $5 Million

The IBM 2026 Cost of a Data Breach Study shows data breach costs have risen by 12% in a year to almost $5 million, with the United States facing the highest breach costs. In 2026, the average cost of a data breach in the United States was $11.5 million – more than double the average global data breach cost. Healthcare continues to face the highest breach costs, with an average cost of $6.64 million per incident, although healthcare data breach costs have fallen by 10.5% year-over-year from a global average of $7.42 million in 2025. Data breach costs increased in all sectors represented in the study, with the rise largely driven by increases in detection, escalation, and lost business costs.

In healthcare, 59% of breaches were malicious or criminal attacks, 26% were due to IT failures, and 13% were due to human error. Across all sectors, phishing (voice and SMS phishing) accounted for 17% of breaches and was the most common initial access vector and had an average breach cost of $5.9 million. The next most common vectors were supply chain compromise, abuse of valid accounts, drive-by compromise attacks, and social engineering.

For the first time in five years, the average time to identify and contain a breach increased, rising 2.5% from 2025. The attack vectors that proved most difficult to identify and contain were removable media and supply chain compromises, as they do not show up in malware scans or inbound traffic. Breaches involving either of these attack vectors took an average of 258 days to identify and resolve, compared to an average of 247 days across all attack types.

Attackers have embraced AI tools in all areas of their attacks, including scanning for vulnerabilities, crafting phishing and social engineering lures, and automating attacks at scale. There has been a 56% year-over-year increase in AI-driven attacks, with one in four organizations having experienced an AI-driven breach in the past year.

AI deepfake and impersonation accounted for 45% of AI-driven attacks, with AI-generated malware becoming more common, accounting for 19% of AI-generated attacks. AI-generated phishing or other communications accounted for 17% of attacks. AI-driven attacks have an increased financial impact, adding around $1 million to average data breach costs. Most AI-driven attacks targeted critical infrastructure, with the financial services and energy sectors the most targeted.

There has also been an increase in shadow AI incidents – AI applications used by employees that have not been approved for use. Incidents more than doubled to 43% of security incidents this year from 20% last year. IBM notes a lack of governance policies to mitigate or manage the risk to AI, with only around one third of organizations having a strict approval for deploying AI tools. The average breach cost was $5.39 million, and one in five of these breaches resulted in a regulatory fine.

There is growing concern about new threats from frontier AI models. Out of all breached organizations, 85% of organizations that were aware of frontier models said they were increasing their security spending to combat the threat. IBM notes that experts believe that AI will favor attackers over defenders by 31.7% within two years, highlighting the pressing need for speed in security.

While organizations are adopting AI for security, most are only using AI agents for detection and containment. Only a small fraction use AI agents for vulnerability management. That means exposures are available for exploitation for much longer, and given that attackers are using AI tools for vulnerability discovery, this is one of the key areas where organizations can make significant security gains. IBM recommends leveraging AI to analyze exposures, enforce policies, and coordinate detection and containment with minimal human intervention.

Ransomware attacks have continued to increase due to ransomware-as-a-service. Over the past 12 months, 39% of breached organizations said they experienced at least one ransomware attack, up from 24% in 2023 – a 62.5% increase over the past four years.  Attackers are increasingly threatening public shaming and data leaks to pressure victims into paying, rather than simply encrypting files. In 2026, 41% of ransomware attacks included brand reputation threats, such as data leaks and public shaming, with 35% of attacks targeting employee data and health records.

The post Global Data Breach Cost Rises 12% to Almost $5 Million appeared first on The HIPAA Journal.