Forgotten Dairies
American Healthcare Is Hoarding Data It Cannot Defend -By Fransiscus Nanga Roka
Treating patients is one thing, but hoarding life-long biological secrets without the lifelong security of healthcare institutions. They are manufacturing hostages.
Two Health Care Breaches, More Than 6.9 Million Victims And One Ultimate Finding: America’s Medical-Data Economy Gathers Each Piece Of Data With Clinical Precision But Secures It With Institutional Negligence
AdaptHealth and Baylor Genetics announced separate June hacks targeting 4,115,802 and 2,810,878 people on August 14. Both were reported to the US2 Department of Health and Human Services putting them on the 2026 largest healthcare breaches list. Under HIPAA, significant violations are investigated by HHS’s Office for Civil Rights.
The why, who, what and when are all crystal clear. The how unveils two very different types of security failure.
In the case of AdaptHealth, a home medical equipment and related services company an attacker was reportedly able to take over an active session from a third-party contractor via social engineering. Unauthorized use started on approximately June 5. The firm was issued an extortion note by the perpetrator on June 15th which claimed that it stole files from its systems. AdaptHealth went on to confirm that information could have retrieved behind the attack may also include names, contact and demographic details, health information and insurance data. A disclosure with the SEC confirms the breach claimed by actor on June 15.
AdaptHealth said Social Security numbers and financial information were not included. That is comforting only by the appropriately low bar for American breach response. Data can include diagnoses, treatment information, insurance records and contact details — any of which could be used to commit medical-identity theft, fraudulent billing, blackmail or even tailored phishing. This is even truer if you think about how health data can expose weaknesses that no amount of password resetting will ever cover up.
The more immediate danger comes from Baylor Genetics. The cybercriminal had access to portions of its network between June 11 and June 17. The compromised data may have contained names, birth dates, medical-testing information, laboratory results and insurance details as well as Social Security numbers for a small number of patients. Some present and past employees were also exposed to government identifiers and financial-account data. (globenewswire. com)
The genetic and lab data are not ordinary assets of a corporation. They could reveal risks of inherited diseases, biological relationships and private medical information—not just about patients but perhaps also about their relatives. It is too late to put the genie back in the bottle: credit monitoring cannot restore genetic privacy. You cannot delete a genome and issue a different one.
The why is structural. Healthcare organizations have created huge ecosystems incorporating cloud platforms, laboratories, insurers, contractor sand billing intermediaries. Each additional integration increases the potential area for attack, but blame is diffused between contracts. Describing the AdaptHealth hack as social engineering is on the verge of obfuscating an architectural failure: a single compromised contractor session should not get access to millions of PII records.
Both companies report that the systems were secured, monitoring and access controls enhanced, forensic experts engaged and protective services offered. These steps are required but post-breach remediation is as poor proof of pre-breach diligence.
HHS should perform its own HIPAA Security Rule investigations, and publicly state whether access controls, audit logs, risk analyses and vendor oversight were sufficient; if not, fines should be calibrated based on the number and sensitivity of exposed records. Every contractor accessing protected health information should use phishing-resistant authentication, sessions bound to devices, continuous behavioral analysis, least-privilege access and near-instantaneous revocation of compromised credentials.
There is no doubt Congress needs to do the same for genetic data: strict limits on retention, prohibitions on secondary commercialization, encryption with segregated keys plus a private right of action without proof of completed identity theft.
Lastly, healthcare boards should personally certify the effectiveness of cyber-risk controls, similar to how executives certify financial reporting. Accountability has to climb the chain of command—for those who approved insecure systems—not just end with a duped employee or contractor.
Treating patients is one thing, but hoarding life-long biological secrets without the lifelong security of healthcare institutions. They are manufacturing hostages.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and managing Partner Law Firm Victorious Indonesia