Abbott Laboratories

Update, July 27, 2026: The first class-action lawsuit against Abbott Laboratories and its cancer diagnostics business, Exact Sciences, was filed in the Illinois District Court. The lawsuit alleges that Abbott failed to implement “necessary data security safeguards” to protect the plaintiff’s and class members’ sensitive personal and health information from unauthorized access and theft by cybercriminals. More lawsuits are expected to follow.

  • Two hacker groups — ShinyHunters and ShadowByt3$ — have separately claimed breaches at Abbott Laboratories involving its Cancer Diagnostics business and the LabCentral customer portal.
    • Abbott serves as both a covered entity and a business associate, so breach notification obligations may run in multiple directions.
    • A vendor breach doesn’t stay contained — covered entity clients face compliance exposure too, making BAAs and vendor oversight legal obligations, not optional.
    • Also this week: UK-based Craneware, a billing software provider to more than 2,000 U.S. hospitals, confirmed that hackers stole customer and employee data.
    • Attackers often target vendors rather than individual covered entities because a single breach yields far more data.

Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two separate cybersecurity incidents — claimed by two different hacker groups — that together illustrate why the healthcare vendor ecosystem remains one of the most vulnerable parts of the HIPAA compliance framework.

The story is still unfolding. What has already emerged is a textbook example of the business associate risk problem we have written about before: when a major healthcare technology company is breached, the consequences extend far beyond its own walls.

Two Incidents, Two Threat Actors

The first incident, confirmed by Abbott in a July 16, 2026, statement, involved unauthorized access to internal legacy systems within its Cancer Diagnostics business — specifically, systems inherited from Exact Sciences, the cancer screening and precision oncology company Abbott acquired in late 2025. The ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with the group, and later extended the deadline to July 21.

ShinyHunters claimed it gained access through a vishing attack in mid-June that targeted several Abbott employees, allowing it to compromise a Microsoft Entra single sign-on account and access internal systems. This aligns with the group’s established playbook: since last year, ShinyHunters has been conducting social engineering campaigns targeting employees’ Microsoft Entra, Okta, and Google SSO accounts.

ShinyHunters has also been targeting the healthcare sector, including Amazon One Medical, Medtronic, and AdaptHealth.

The second incident involves a separate threat actor, ShadowByt3$, who claims to have breached Abbott’s LabCentral portal — a platform used by laboratory customers and clinicians to access diagnostic data and order management tools. ShadowByt3$ told BleepingComputer that it gained access on July 4 using compromised customer credentials and a “weak point” in the environment, and that it exfiltrated technical documentation, manufacturing certificates, operating manuals, technical specifications, and regulatory documents.

Abbott’s public statement characterizes the first incident as limited in scope — confined to legacy Exact Sciences systems and having no impact on other business units, manufacturing, lab operations, or patient services — and asserts that the LabCentral portal contains only public, non-sensitive documents. As of July 17, neither group had publicly released any data they claim to have stolen. Investigations by Abbott and third-party cybersecurity experts are ongoing.

Abbott’s Dual Role: Provider and Vendor

Abbott’s position in the healthcare ecosystem is worth understanding clearly because it affects how HIPAA obligations flow.

Abbott is not simply a technology vendor operating at arm’s length from patient care. Through its Cancer Diagnostics business — now including Exact Sciences’ cancer screening operations, Abbott handles patient test results and clinical data, making it a healthcare provider and, in that capacity, a covered entity under HIPAA. At the same time, its LabCentral portal serves hospitals, clinicians, and laboratory customers, positioning Abbott as a vendor to covered entities and thereby also functioning as a business associate.

This dual status matters. When a breach occurs at an organization like Abbott, the HIPAA obligations that flow from it can run in multiple directions simultaneously: as a covered entity, Abbott has its own breach notification obligations to patients; as a business associate, it has notification obligations to the covered entity clients it serves.

The investigation is ongoing, and it remains to be seen what data was accessed and which notification obligations will ultimately be triggered. But the architecture of the exposure — a major healthcare technology company at the center of a web of clinical and institutional relationships — is precisely what makes incidents like this so consequential.

The Business Associate Risk Problem, Illustrated Again

We have written about this dynamic in two recent posts — one explaining what a business associate is under HIPAA and another documenting the lopsided risk that breaches involving business associates pose to covered entities. The Abbott situation reinforces both points.

The healthcare industry depends on a dense network of technology vendors, diagnostic companies, billing platforms, and device manufacturers to function. Each relationship involves the flow of protected health information (PHI) and represents a potential entry point for a threat actor. When a vendor of Abbott’s scale is targeted, the potential downstream exposure to covered entity clients — hospitals, physician practices, health systems — is enormous, even if the vendor’s public statement characterizes the incident as contained.

This is not a hypothetical concern. Last year, Conduent, a business process services firm serving multiple state Medicaid programs, reported a breach that spread to its covered entity clients before the scope was fully understood. The number of individuals affected skyrocketed over the months of investigation. When the breach was first reported last fall, the number was estimated at 10.5 million. By June, 2026, Conduent reported that 62.2 million individuals were affected.

The February 2024 Change Healthcare breach, which ultimately affected 192.7 million people, began with a single business associate. The pattern is the same: highly skilled threat actors have learned that attacking a well-connected vendor is far more efficient than targeting individual covered entities one at a time.

Craneware: Another Vendor Breach, This Week

The Abbott incidents are not the only business associate breach in the news this week. Craneware, a UK-based healthcare billing software maker whose flagship accounting and billing software is used by thousands of clinics, hospitals, and pharmacies across the United States, confirmed that hackers stole a significant volume of customer data from its systems. Craneware says it works with more than 2,000 hospitals and nearly 10,000 clinics and retail pharmacies.

The company said that although a significant volume of file names was viewed and exfiltrated, the incident has been contained and has not disrupted customer services or the company’s operations. Craneware did not say whether patient information was among the stolen data — a question that would determine whether U.S. health privacy rules apply. As a company whose software helps healthcare providers bill patients for services and handles large amounts of medical records and patient data on behalf of its customers, Craneware is a business associate of its U.S. hospital and clinic clients.

Two major healthcare vendor breaches were disclosed within days of each other in the same week. This is not a coincidence — it is a pattern.

What Covered Entities Should Take Away

For covered entities whose vendors include diagnostic companies, billing software providers, device manufacturers, or any other organization that handles PHI on their behalf, the Abbott and Craneware situations are a timely reminder of several key points.

First, your business associate relationships need to be inventoried and up to date. If you do not have a clear picture of which vendors handle PHI on your behalf — and a signed, enforceable Business Associate Agreement with each — a breach at one of those vendors becomes your compliance problem as well as theirs.

Second, BAAs need to include meaningful breach-notification requirements. When a vendor is breached, covered entities need to know quickly. A BAA that doesn’t specify clear notification timelines leaves the covered entity in the position Abbott’s hospital and laboratory customers may now be in: waiting for a vendor’s investigation to determine what, if anything, was exposed.

Third, a vendor’s size and reputation are not proxies for security. Abbott is one of the world’s largest healthcare companies. Craneware serves more than 2,000 hospitals. Neither size nor market position prevented these incidents. OCR has consistently held that covered entities cannot simply execute a BAA and walk away — ongoing monitoring of business associate compliance is a legal obligation, not a best practice.

The HIPAA E-Tool® Can Help

Identifying your business associate relationships, evaluating your BAAs, and building the oversight program HIPAA requires is exactly the kind of structured work The HIPAA E-Tool® is designed to support — done internally by your own staff, without the cost of outside consultants. If the Abbott and Craneware breaches have prompted questions about your vendor risk exposure, now is the time to answer them.

We will continue to monitor the Abbott situation and update our coverage as the investigations progress.

Free HIPAA Checklist
What best describes you?