According to The HIPAA Journal, the Dublin, Ohio healthcare-navigation company traced the compromise to a caller who persuaded a Quantum Health user to provide access. The intruder remained in the environment from May 29 through June 1, and Quantum Health determined by June 8 that files taken in the incident held both personal information and protected health information, including Social Security numbers, insurance and claims data, diagnoses, treatments, prescriptions, provider information, and dates of service.
The report also covers newly disclosed incidents at North Dakota’s Heart of America Medical Center and Florida’s Precision Imaging Centers. The three cases are separate, but together they show why healthcare IT teams cannot use a published breach total—or the absence of one—as a measure of exposure: all three disclosures still leave major scope questions unanswered.
Quantum Health’s compromise began with a voice call
Vishing is voice phishing: a social-engineering attack in which a caller poses as a trusted employee, customer, vendor, or IT support contact to obtain credentials, reset passwords, persuade someone to approve a sign-in, or direct them to install remote-access tooling. CISA classifies voice spearphishing as an initial-access technique and has warned that attackers combine phone calls with credential theft and MFA-prompt manipulation.
Quantum Health’s disclosure, as reported by The HIPAA Journal, identifies the vishing call as the start of the incident but does not say what the employee supplied. That missing detail is operationally important. There is a material difference between a user revealing a password, approving an MFA request, enrolling an attacker-controlled device, surrendering a session token, or giving a caller access through remote-support software. Each route produces different log trails and demands different containment steps.
The company also has not publicly named the threat group responsible. The HIPAA Journal noted that the method resembles tactics associated with ShinyHunters, following a Health-ISAC alert, but a familiar technique is not attribution. CISA and partner agencies have documented similar multilayered vishing activity by Scattered Spider and other financially motivated operators, including calls designed to learn password-reset procedures before targeting an employee or help desk. On the evidence available, Quantum Health’s breach should be treated as an identity compromise with no confirmed public attribution.
For Windows and enterprise administrators, this is the key practical point: a password policy and conventional MFA prompt are not sufficient controls against an attacker who can persuade a user or service desk to act. A user who believes they are talking to internal support may voluntarily complete the very verification step designed to stop a stolen-password login.
Quantum Health says it is offering affected people credit monitoring and identity-theft protection. It has not publicly disclosed the number of affected individuals or identified affected employer clients. Because the company works with self-insured employers to coordinate benefits, the eventual population may extend beyond patients who directly recognize Quantum Health’s name. Benefits and claims information can be especially useful to criminals crafting realistic follow-up scams: callers can cite insurers, providers, recent services, or benefits terminology to create credibility.
The first response should be an identity investigation
A vishing-driven breach should trigger a broader review than a routine password reset. Security teams should establish precisely which identity system the attacker reached, which user account was involved, whether the account held delegated or administrative roles, and what additional accounts, applications, or file repositories were accessed during the exposure window.
For organizations using Microsoft Entra ID, Active Directory, Microsoft 365, VPN gateways, Citrix, remote-desktop infrastructure, or third-party SSO, the review should cover successful and failed sign-ins, new device registrations, MFA method changes, password resets, authentication-policy changes, consent grants, unusual OAuth application activity, mailbox forwarding rules, privileged-role assignments, and impossible-travel or unfamiliar-device events. An attacker who gains a valid user session may not need malware or an exploit to reach sensitive files.
CISA recommends phishing-resistant MFA, with FIDO/WebAuthn security keys and other cryptographic methods providing meaningfully stronger protection against fake login pages and social-engineering scenarios than SMS codes or ordinary push notifications. Number matching can reduce accidental approval of MFA prompts, but it does not solve a determined phone-based social-engineering attack where the victim is coached through the prompt.
The help desk deserves equal attention. Password resets, MFA re-enrollment, recovery-factor changes, and device registration are high-risk identity events, particularly for staff with access to medical records, claims platforms, shared drives, virtual desktops, or administrative tools. Organizations should require a verified callback to a known number, manager confirmation for sensitive resets, and separate approval for privileged accounts rather than trusting caller ID, an employee ID number, or knowledge-based questions that may already be exposed in prior breaches.
CISA’s healthcare-sector guidance also stresses least privilege and phishing-resistant authentication. Quantum Health’s disclosure does not establish which safeguards were in place or whether an MFA method was bypassed, so it would be wrong to infer a particular control failure. But the three-day interval between initial access and service disruption shows why identity telemetry, rapid session revocation, and limits on broadly accessible file stores matter after a user account is compromised.
Heart of America’s notice documents a year-long disclosure trail
Heart of America Medical Center in Rugby, North Dakota, presents a different but equally important problem: a breach can remain unresolved long after the intrusion is contained.
The hospital’s public notice from September 2025 said it detected suspicious activity on or around June 12, 2025 and engaged an outside cybersecurity firm. The notice initially said the investigation was ongoing and that the organization was still identifying affected people and exposed data. The HIPAA Journal now reports that Heart of America determined an unauthorized third party accessed its network and exfiltrated files, some containing names, Social Security numbers, medical records, and other medical information.
The reported timeline is sobering. The investigation reportedly determined unauthorized access on September 15, 2025; third-party data review did not conclude until May 12, 2026; internal review finished June 9; and the final notification list was obtained July 9. Notification letters were subsequently sent, with single-bureau credit monitoring and related services offered.
That sequence is not evidence that Heart of America delayed improperly; data review and contact validation can be labor-intensive, especially for a smaller provider. It does show why incident-response planning needs a defensible data-discovery process before a breach occurs. If clinical records, scanned documents, and identity data are spread across file shares, old applications, backups, and departmental systems, determining whose data left the environment becomes a second major incident.
The Embargo ransomware group claimed responsibility and claimed to have taken about 800 GB of data, according to The HIPAA Journal. That figure remains a criminal group’s assertion, not independently verified breach scope. Heart of America’s public notice confirms a security incident and its response, but it does not verify the claimed volume or establish that every purportedly stolen file contained patient data.
As of the report, the incident was not listed on the HHS Office for Civil Rights breach portal. That does not prove the breach falls below a reporting threshold or was omitted; public listings can lag notifications and reporting. It does mean administrators and patients should not treat a missing OCR entry as proof that an incident is minor or fully resolved.
Precision Imaging’s “501” is a placeholder, not a final count
The Medical Imaging Partnership, doing business as Precision Imaging Centers, reported suspicious network activity on May 7, 2026. The HIPAA Journal says its investigation found that an unauthorized party entered the network and copied files, while the organization continues to determine both the affected data types and the people involved.
Precision reported the event to HHS OCR using an estimate of 501 people, the common placeholder used when a provider has confirmed a reportable incident but has not completed record-by-record analysis. The number should not be read as a settled victim count. It is an administrative floor that allows a healthcare entity to report a potentially significant breach while its file review continues.
Precision has told current and former patients to monitor credit reports, accounts, and explanation-of-benefits statements, with notification letters to follow after the review. Patients should take that advice seriously, particularly with healthcare data. Medical and benefits information can support account takeover, insurance fraud, fraudulent care, and tailored scam attempts even when a criminal does not immediately open a conventional credit account.
There is also relevant history. Precision previously disclosed a separate cybersecurity event that occurred around November 2022, resulting in litigation and a settlement process that continued into 2026. The prior case does not establish a connection to the May 2026 intrusion, and it should not be conflated with it. Still, the recurrence makes clear why the current notice needs more than generic vigilance language: patients and regulators will reasonably seek a fuller account of what data was copied, which systems were involved, and whether safeguards changed after the earlier incident.
What healthcare IT teams should change now
The Quantum Health event is the most concrete of the three disclosures because it identifies the initial-access method. The immediate defensive response is to make it harder for a caller to convert trust into a valid session.
- Require phishing-resistant MFA first for administrators, help-desk staff, remote-access users, executives, and personnel who can reach shared patient-data repositories.
- Remove or tightly restrict self-service and help-desk workflows that permit MFA reset, password reset, or new-device enrollment based solely on information a caller may know or obtain.
- Configure alerting for MFA method changes, new authenticator enrollment, new Entra device registration, OAuth consent grants, mailbox-rule creation, remote-support-tool installation, and unusual access to high-volume file stores.
- Rehearse a vishing incident in which the attacker has already authenticated successfully, including how teams will revoke sessions, disable accounts, rotate credentials, preserve logs, and assess cloud as well as on-premises access.
- Treat employees whose benefits or medical information may have been exposed as likely targets for follow-up fraud, and make the reporting channel for suspicious calls easy to find.
Quantum Health has established that a phone call preceded network access; Heart of America’s lengthy review illustrates the cost of discovering data exposure after the fact; and Precision Imaging’s placeholder report shows that the public count may be the least useful number in the early stages of an incident. The practical consequence is simple: healthcare organizations need to test whether their identity systems can withstand a persuasive caller before the next notification letter makes the answer public.