13 cybersecurity updates for ASC leaders to know

Advertisement

Several ASCs and physician groups have suffered data breaches in recent months, with some resulting in class-action lawsuits.

Thirteen updates to know since January:

Lawsuits

1. St. Louis-based Esse Health, an independent physician group with 45 locations, agreed to pay $2.53 million to settle a class-action lawsuit stemming from a 2025 data breach.

2. Mount Kisco (N.Y.) Surgery Center agreed to pay $527,500 to settle a class-action lawsuit involving a data breach from November 2023.

3. Jacksonville-based Florida Physician Specialists is facing a potential class-action lawsuit following a November 2025 data breach.

4. Phoenix-based Cardiovascular Consultants agreed to pay $3.85 million to settle a class-action lawsuit related to a 2023 data breach.

5. Amherst, N.Y.-based Excelsior Orthopaedics and Buffalo (N.Y.) Surgery Center agreed to pay $2.4 million to settle a class-action lawsuit stemming from a 2024 data breach.

6. Stockton (Calif.) Cardiology Medical Group experienced a data incident potentially exposing patient information and company records.

7. Seattle-based Proliance Surgeons agreed to a $4.45 million settlement to resolve class-action litigation stemming from a February 2023 data breach that affected more than 437,000 patients.

8. St. Louis-based EyeCare Partners, which supports a network of more than 700 affiliated practices across 18 states, suffered a data breach after a third-party accessed certain ECP-managed email accounts.

9. Birmingham-based Alabama Cardiovascular Group agreed to a $2.23 million settlement in a data privacy class-action lawsuit.

Data breaches

1. Glendora (Calif.) Surgery Center experienced a data breach affecting patient information after an unauthorized party accessed part of its computer network.

2. Northwoods Surgery Center in Virginia, Minn., disclosed a data breach affecting more than 5,000 individuals.

3. Tri-Cities Gastroenterology, a GI practice with five locations in Tennessee, suffered a data breach when an unauthorized third-party removed files from the practice’s network.

4. Torrance, Calif.-based CardioFit Medical Group experienced a data breach when it sent protected health information via email without encryption.

At the Becker’s 32nd Annual Meeting: The Business and Operations of ASCs, taking place October 29-31 in Chicago, ASC leaders, surgeons and healthcare executives will explore strategies to drive growth, enhance operational performance, navigate reimbursement challenges and prepare for the future of ambulatory surgery. Apply for complimentary registration now.

Advertisement

Next Up in ASC News

Advertisement