TWO unrelated organizations named 'Nephrology Associates' suffered cyberattacks in 2026, with only one disclosing the breach.
1. **Kansas Incident**: On March 7, a Kansas-based entity, Nephrology Associates, M.D., P.A., was added to a leak site after reporting a breach affecting 24,088 patients. This breach involved unauthorized network access between January 17 and April 9. The exposed information included personal identifiers and health data. However, no data was leaked or verified by the group claiming the attack.
2. **Arkansas Incident**: On April 28, another entity, Nephrology Associates, PA, was listed by the Insomnia group, which claimed to have exfiltrated data and provided proof via screenshots. Despite the claims, no official report has been filed with HHS and the entity has remained silent. The leaked data reportedly included health insurance details and sensitive medical information, impacting potentially thousands of patients.
Both incidents highlight issues of data security in healthcare organizations, raising concerns over patient privacy and breach notifications.