Highlands Oncology Group PA Data Breach
Highlands Oncology Group Confirms Network Breach Affecting 55K Patients
What happened in the Highlands Oncology Group PA data breach?
The Highlands Oncology Group PA data breach was reported on December 22, 2023 and affected 55,297 individuals. The breach type was Hacking/IT Incident involving Desktop Computer, Network Server. This breach occurred in Arkansas. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Highlands Oncology Group PA Breach Details
Highlands Oncology Group PA Data Breach Report
Breach Overview
Highlands Oncology Group PA, an Arkansas-based oncology practice, experienced a significant data breach involving unauthorized access to patient information stored on desktop computers and network servers. The breach was discovered and reported to the U.S. Department of Health and Human Services on December 22, 2023, affecting 55,297 individuals. This hacking incident represents a substantial compromise of the organization's information security infrastructure and exposed sensitive protected health information (PHI) belonging to cancer patients and other individuals who sought care at the facility.
Discovery and Response Timeline
The specific date of breach discovery was not disclosed in the submission, though the HHS notification occurred on December 22, 2023. Upon discovering unauthorized access to their systems, Highlands Oncology Group PA initiated an investigation to determine the scope and nature of the compromise. The organization was required under HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) to notify affected individuals without unreasonable delay and no later than 60 calendar days following discovery of the breach. The organization also notified the HHS Office for Civil Rights and, given the scale of the breach (affecting more than 500 Arkansas residents), likely issued a press release or media notification as required by HIPAA regulations.
Technical Details of the Incident
The breach involved unauthorized access to both desktop computers and network servers within the organization's IT infrastructure. This dual-location compromise suggests either a sophisticated attack that penetrated multiple system layers or an extended period of unauthorized access that allowed threat actors to move laterally through the network. Desktop computer compromises typically indicate either physical theft, remote access trojans, or compromised credentials that allowed attackers to establish persistent access. Network server breaches are particularly concerning as servers typically store centralized databases containing large volumes of patient records. The combination of both locations being compromised suggests the attackers may have exploited vulnerabilities in the organization's network security, potentially through methods such as phishing attacks targeting employee credentials, unpatched software vulnerabilities, weak password policies, or inadequate network segmentation. No business associate was involved in this breach, indicating the compromise occurred directly within Highlands Oncology Group PA's own systems rather than through a third-party vendor or service provider.
Organizational Context
Highlands Oncology Group PA is an oncology-focused medical practice operating in Arkansas. As a cancer care provider, the organization serves patients with one of the most serious health conditions, making the confidentiality and security of their medical information particularly critical. Oncology practices maintain extensive clinical records including detailed treatment histories, genetic testing results, medication regimens, and prognosis information—all highly sensitive data that patients entrust to their healthcare providers. The organization's operations span the state of Arkansas, serving a regional patient population. The fact that the breach affected over 55,000 individuals suggests either a large, multi-location practice or a centralized records system that consolidated patient data from multiple service delivery points.
Patient Impact and Affected Population
The breach directly impacted 55,297 individuals whose personal health information was stored on the compromised systems. This substantial number of affected patients represents a significant portion of the organization's patient base and indicates that the breach was not limited to a single location or department but rather affected the organization's broader patient database. Affected individuals likely included current and former patients who had received oncology services, diagnostic imaging, laboratory testing, or related healthcare services from Highlands Oncology Group PA. The notification process required the organization to contact each affected individual by mail, email, or telephone to inform them of the breach, the types of information compromised, and recommended protective measures. Given the December 22, 2023 submission date, notifications would have been distributed during the final weeks of 2023 or early 2024, requiring patients to take action during the holiday season—a particularly challenging time for individuals to monitor their accounts and implement protective measures.
HIPAA Compliance and Regulatory Context
Under the HIPAA Breach Notification Rule, any unauthorized access to unsecured PHI must be reported to affected individuals, the HHS Office for Civil Rights, and potentially the media. The fact that this breach exceeded 500 Arkansas residents triggered mandatory media notification requirements. Hacking and IT incidents represent one of the most common breach categories in healthcare, accounting for a significant percentage of all reported breaches in recent years. The 2023 healthcare breach landscape has been characterized by increasing sophistication in cyber attacks targeting healthcare organizations, including ransomware attacks, credential compromise, and exploitation of unpatched vulnerabilities. Organizations like Highlands Oncology Group PA are particularly attractive targets for threat actors because they maintain valuable patient data including Social Security numbers, financial information, and detailed medical histories that can be sold on dark web marketplaces or used for identity theft and medical fraud. The breach notification requirement serves to inform patients so they can take protective action, such as monitoring credit reports, placing fraud alerts, and implementing identity theft protection measures.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Highlands Oncology Group PA Breach
Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review them carefully for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Monitor financial accounts, credit card statements, and bank accounts closely for unauthorized transactions. Set up account alerts with your financial institutions to be notified of unusual activity. Consider enrolling in credit monitoring or identity theft protection services, which Highlands Oncology Group PA may be offering at no cost.
Review your medical records and explanation of benefits (EOB) statements from your insurance company for unauthorized claims or services you did not receive. Contact your healthcare providers and insurance company immediately if you identify suspicious activity.
Change passwords for any online accounts associated with Highlands Oncology Group PA or your insurance provider, using strong, unique passwords. Enable multi-factor authentication where available to add an additional layer of security to your accounts.
Consider placing a security freeze with the three major credit bureaus to prevent criminals from opening new accounts in your name. While this may inconvenience you when applying for legitimate credit, it provides strong protection against identity theft.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused. This creates an official record that can help you dispute fraudulent charges and accounts.
Be cautious of unsolicited communications claiming to be from Highlands Oncology Group PA, your insurance company, or financial institutions. Verify any requests for personal information by contacting the organization directly using a phone number from an official source.
Document all communications related to the breach, including notification letters, credit monitoring enrollment information, and any suspicious activity you discover. Keep these records for at least several years for reference and potential dispute resolution.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Arkansas Breaches
Search all breaches reported in Arkansas
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsTechnical Notes
Highlands Oncology Group PA Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Highlands Oncology Group PA