Ransom Cartel Mastermind Sentenced to 16 Years in Prison

The Belarusian cybercriminal behind the Ransom Cartel ransomware group has been sentenced to 16 years in prison for his role in ransomware attacks on at least 18 companies worldwide.

Maksim Silnikau, 40, was the creator and administrator of the Ransom Cartel ransomware-as-a-service operation and recruited other cybercriminals to conduct ransomware attacks globally. According to court documents, Silnikau began developing the ransomware operation in May 2021, initially under a different name, before rebranding it as Ransom Cartel in 2022. Between 2021 and 2023, along with his co-conspirators, at least 18 companies fell victim to attacks, including companies in California, New York, and Nebraska. The attacks caused more than $6.7 million in losses, and the group attempted to extort at least $5.2 million from victims.

Silnikau did not conduct many of the intrusions himself. He was the administrator of the operation and purchased stolen credentials from initial access brokers, recruited affiliates to conduct attacks, negotiated with victims, used cryptocurrency mixers to hide the proceeds from the attacks, and split the money with the group’s affiliates.

Silnikau has a long history of cybercrime, having reportedly been a core member of the REvil ransomware operation, a member of Russian-speaking cybercrime forums since at least 2005, and a member of the cybercrime website Direct Connection from 2011 until the site was shut down in 2016. Silnikau was involved in the distribution of the Angler exploit kit and various malvertising and malware distribution schemes between October 2013 and March 2022. Along with a Ukrainian national and a Russian national, Silnikau was charged with participation in the distribution of the Angler exploit kit in a separate indictment in New Jersey.

Following an international law enforcement investigation, Silnikau was arrested in Spain on July 18, 2023; however, fled while awaiting extradition to the United States to face the charges. He was recaptured attempting to return to Belarus from Poland and was extradited to the U.S. from Poland in 2024 to face the charges in the Eastern District of Virginia. Prosecutors charged Silnikau with seven counts, although he was only convicted on three: conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft, and was sentenced to 16 years in jail.

The post Ransom Cartel Mastermind Sentenced to 16 Years in Prison appeared first on The HIPAA Journal.

Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance

Settlements have been agreed to resolve class action data breach lawsuits against McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts.

McKenzie Health System Data Breach Settlement

McKenzie Health System, the operator of the McKenzie Memorial Hospital, a critical access hospital in Sanilac County, Michigan, has settled a class action lawsuit that was filed in response to an April 2025 cyberattack and data breach. McKenzie Health identified unauthorized access to its computer network on April 15, 2025. The forensic investigation determined that an unauthorized third party accessed its network between April 14, 2025, and April 15, 2025, and potentially obtained files containing patient information.

Data potentially compromised in the incident included names, addresses, birth dates, Social Security numbers, patient account numbers, medical record numbers, diagnosis and treatment information. The data breach was reported to the HHS’ Office for Civil Rights as affecting 58,839 individuals, who started to be notified on or around July 24, 2025.

Several class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In Re: McKenzie Memorial Hospital d/b/a McKenzie Health System 2025 Data Breach Litigation – in the Circuit Court for Sanilac County, Michigan. The consolidated lawsuit alleges that the cyberattack and data breach should have been prevented and occurred due to the defendant’s negligence.

McKenzie Health denies wrongdoing and liability; however, it agreed to a settlement to avoid the litigation costs and expenses, distractions, burden, expense, and disruption to its business operations associated with further litigation. McKenzie Health has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the eight class representatives.

Under the terms of the settlement, all class members are eligible to enroll in two years of credit monitoring and identity theft protection services. In addition, they may either submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,000 per class member or claim a one-time $50.00 cash payment. The deadline for opting out, objecting, and submitting a claim is August 24, 2026. The final fairness hearing has been scheduled for October 6, 2026.

Aspire Health Alliance Data Breach Settlement

South Shore Mental Health Center, Inc., doing business as Aspire Health Alliance, a state-designated community behavioral health center with facilities in Quincy, Braintree, and Marshfield in Massachusetts, has agreed to settle class action litigation stemming from a September 2023 cybersecurity incident that affected 17,490 individuals.

Aspire Health Alliance detected unauthorized network access on September 13, 2023, and confirmed that an unauthorized third party accessed and acquired files containing patient information, including names, dates of birth, dates of service, health insurance information, condition or treatment information, Medicare/Medicaid numbers, and patient account numbers. The affected individuals started to be notified about the data breach on April 26, 2024.

On May 10, 2024, a class action lawsuit was filed in the Superior Court of the Commonwealth of Massachusetts, Norfolk County, which was subsequently moved to the Superior Court of the Commonwealth of Massachusetts, Suffolk County. The lawsuit – Joan Tozzi v. South Shore Mental Health Center, Inc. d/b/a Aspire Health Alliance – alleged that the data breach could have been prevented as it occurred as a result of the failure to implement reasonable and appropriate cybersecurity measures. The lawsuit asserted claims for negligence, breach of implied contract, breach of fiduciary duty, and unjust enrichment. Aspire Health Alliance denies wrongdoing or liability.

All parties agreed to a settlement to avoid further legal costs and the uncertainty of a trial and related appeals. Under the terms of the settlement, Aspire Health Alliance has agreed to establish a $400,000 settlement fund to cover class member benefits, attorneys’ fees and expenses, settlement administration costs, and a service award for the class representative.

Class members are entitled to a one-year membership to the CyEx Medical Shield medical data monitoring service and may also submit a claim for one of two cash payments: reimbursement of documented, unreimbursed losses up to a maximum of $2,500 per class member, or a pro rata cash payment, the value of which will depend on the number of valid claims received. The deadline for objection, opting out, and submitting a claim is September 16, 2026. The final fairness hearing has been scheduled for October 1, 2026.

The post Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance appeared first on The HIPAA Journal.

Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced that two settlements have been agreed to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA).

EMTALA was enacted by Congress in 1986 to ensure public access to emergency medical services. EMTALA requires Medicare-participating hospitals that offer emergency services to provide a medical screening examination (MSE) to patients who present to their emergency department requesting an examination or treatment for an emergency medical condition, regardless of the patient’s ability to pay.

A patient must be provided with stabilizing treatment if the MSE determines that they have an emergency medical condition. If the hospital lacks the capability to provide stabilizing treatment, or if requested by the patient, they must initiate an appropriate transfer.  The receiving hospital must have the available space and qualified personnel and must agree to accept the transfer. The transferring hospital must send all medical records related to the emergency condition that are available at the time of the transfer, and send all other records as soon as is practicable. Hospitals that violate EMTALA can face heavy civil monetary penalties, and individuals harmed may pursue legal action for EMTALA violations.

Merit Health Central Hospital

Merit Health Central Hospital in Jackson, Mississippi, formerly known as Central Mississippi Medical Center, has agreed to settle alleged EMTALA violations with HHS-OIG and will pay a $350,000 financial penalty. Unusually, the case relates to patients who presented at the hospital emergency room more than a decade ago. The delay in issuing the penalty was due to a False Claims Act lawsuit related to the alleged EMTALA violations that was working its way through the legal system. HHS-OIG’s investigation determined that the hospital failed to provide an adequate MSE and stabilizing treatment to fourteen patients who presented to its emergency room between January 2013 and April 2015 requesting an examination or treatment for a medical condition.

Out of the fourteen individuals, nine had emergency medical conditions and were transferred to another hospital between January 2013 and May 2013 without providing an appropriate MSE and treatment to stabilize the patients to minimize the risk of transfer, despite having staff within its facilities or available as on-call physicians who could have provided the necessary stabilizing treatment. In six cases, the transfers were based on its application of Central MS Trauma Region Trauma Activation Criteria and Destination Guidelines for the transfer of individuals with penetrating trauma to another hospital. Several of the patients had presented with gunshot wounds.

Four patients presented to the emergency room between March 2015 and April 2015 with a psychiatric emergency medical condition and were not provided with an appropriate MSE within the capabilities of the hospital or stabilizing treatment. The four individuals were transferred by taxi in an unstable condition to a homeless day shelter. One patient presented to the emergency room in March 2015 for treatment related to end-stage renal disease and had an emergency medical condition requiring dialysis, yet stabilizing treatment was not provided even though it was within the hospital’s capabilities.

NorthShore University Health System

NorthShore University Health System in Evanston, Illinois, agreed to settle alleged an EMTALA violation concerning a patient who presented to its emergency room in February 2025 complaining of leg pain and nausea.

The 64-year-old man presented to the emergency department at 10:53 a.m. and was triaged at 11:15 a.m. During triage, the patient’s vitals were taken. He had a heart rate of 126 bpm and was assigned an emergency severity index (ESI) level of 2 – high risk. The patient was placed in a wheelchair in a waiting room but was not reassessed, and his vitals were not rechecked. The patient was found slumped over and unresponsive in the wheelchair at 8:55 p.m – more than 9 hours after he was triaged. The patient was determined to be in cardiac arrest, and CPR was quickly initiated. HHS-OIG’s investigation determined that Northshore failed to provide an appropriate MSE. The case was settled with a $105,000 financial penalty.

The post Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations appeared first on The HIPAA Journal.

Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic

Settlements have been agreed to resolve class action data breach lawsuits against Omni Healthcare Financial Holdings and its subsidiaries, and Western Montana Clinic.

Omni Healthcare Financial Holdings Data Breach Settlement

Omni Healthcare Financial Holdings, along with defendants Omni Healthcare Financial, LLC, and Injury Finance, LLC (Omni Healthcare), have settled class action litigation over a January 2024 cybersecurity incident involving the protected health information of 16,852 individuals.

Omni Healthcare, a provider of financial solutions to healthcare organizations and patients, experienced a cybersecurity incident involving unauthorized network access between January 18 and January 19, 2024. Information exposed in the incident included names, contact information, dates of birth, Social Security numbers, diagnosis & treatment information, medical record numbers, treatment costs, provider names, and other information. The affected individuals were notified in April 2025, 15 months after the breach was first detected. In total, Omni Healthcare mailed around 42,000 notifications.

The first class action lawsuit was filed by plaintiff Latasha Hammond on April 16, 2025, followed by a second lawsuit by plaintiff Dawn Hairston. Both lawsuits were filed in the District Court for the Western District of North Carolina, and were consolidated, adding a further two plaintiffs – Hammond et al. v. Omni Healthcare Financial Holdings et al. The litigation was subsequently moved to the Superior Court of Mecklenburg County, North Carolina, where it is pending.

The consolidated lawsuit alleged that the data breach could have been prevented and occurred as a result of the defendants’ failure to implement appropriate industry-standard cybersecurity measures, and its failure to comply with the standards of the HIPAA Privacy and Security Rules. The lawsuit asserted claims for negligence/negligence per se, breach of implied contract, and unjust enrichment. The defendants deny all claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability.

The parties determined that a settlement was the best outcome, as it avoids further legal costs and the uncertainties of a trial and related appeals. The defendants will cover the cost of attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and benefits for the class members.

Class members are entitled to enroll in three years of medical data monitoring and medical identity theft services and may submit a claim for one of two cash payments:

  • Cash Payment A – Reimbursement of documented, unreimbursed losses due to the data breach up to $5,000 per class member, or
  • Cash Payment B – A one-time cash payment of $40 per class member

The final approval hearing has been scheduled for August 13, 2026, and the claims deadline is September 3, 2026.

Western Montana Clinic Data Breach Settlement

Western Montana Clinic, a medical group practice in Missoula, MT, has settled a class action lawsuit stemming from a breach of its email environment in Spring 2025. Suspicious email activity was detected on April 15, 2025, and the forensic investigation confirmed unauthorized access to certain employee email accounts between March 11, 2025, and April 15, 2025.

The data review determined that the protected health information of 8,255 individuals was compromised, and 9,506 individuals were affected in total. Data exposed in the incident included contact information, Social Security numbers, dates of birth, treating physician names, internal identification numbers, dates of service, medication information, diagnostic information, and treatment information. The affected individuals were notified on August 8, 2025.

Western Montana Clinic was sued over the data breach, and the lawsuit – Murphy v. Western Montana Clinic – is pending in the Fourth Judicial District of Montana. The lawsuit claimed the data breach occurred as a result of the failure of the clinic to implement reasonable and appropriate cybersecurity measures, and asserted claims for negligence, negligence per se, breach of implied contract, and unjust enrichment. Western Montana Clinic denies wrongdoing and liability; however, it agreed to settle the lawsuit to avoid the litigation costs and expenses, distractions, burden, and disruption to its business operations associated with further litigation.

Western Montana Clinic has agreed to pay attorneys’ fees and expenses, settlement administration costs, $2,500 service awards to the two named plaintiffs, and class member benefits. Class members may claim a one-year membership to a medical data monitoring service, up to three hours of lost time at $20 per hour, and reimbursement of documented, unreimbursed out-of-pocket losses up to a maximum of $5,000 per class member. The deadline for exclusion and objection is August 17, 2026. Claims must be submitted by September 15, 2026, and the final fairness hearing has been scheduled for September 9, 2026.

The post Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic appeared first on The HIPAA Journal.