A healthcare revenue cycle management company recently notified the Massachusetts Attorney General about a data breach. The breach, which occurred between March 18 and March 24, 2024, involved an unauthorized party accessing files stored on a third-party hosting service and impacted a handful of healthcare providers.
The Details: An investigation found that the compromised files contained sensitive information, including patients’ names, Social Security numbers, and financial account data. This breach at ALN Medical Management was traced back to suspicious activity detected in March 2024, which was linked to a third-party service provider’s systems. The company took immediate action by securing their network, isolating the affected environment, and beginning their investigation.
Who’s Affected: The data breach impacts a wide range of individuals whose information was stored on the company hosted systems. According to the breach reports, this may include Social Security numbers, driver’s licenses, medical information, and financial data. The breach affects individuals across several states, including Texas, California, and New Hampshire. While specific numbers are still pending, early reports suggest that the breach could involve tens of thousands of individuals.
The Company’s Response: The company began sending out data breach notification letters to all individuals whose information was affected by the breach.
The Legal Fallout: As of now, at least three federal class action lawsuits have been filed against ALN, accusing the company of negligence and failure to protect sensitive data. Legal experts are already weighing in, suggesting that healthcare providers need to be extra diligent when working with revenue cycle management (RCM) vendors to avoid incidents like this one.
What’s Next:
The breach may be part of a larger trend of increasing attacks targeting third-party vendors that manage sensitive data for healthcare and financial sectors. Experts point to the high value of personal, medical, and financial data as a key reason why these vendors are frequent targets. The company has not yet released a full update on the scope of the breach, but we expect more details to emerge in the coming weeks.




