Data Breaches

Former Nuance Employee Arrested After Geisinger Data Breach Exposed 1.2 Million Records

A class action lawsuit was filed against Geisinger for failing to properly secure patients’ personal and health information.

A class action lawsuit was filed against Geisinger for failing to properly secure patients’ personal and health information.

Pennsylvania healthcare provider Geisinger is facing a class action lawsuit after a former Nuance employee accessed the personal information of more than 1.2 million individuals in November 2023.

Geisinger discovered the data breach in late November and immediately notified Nuance – a Microsoft-owned company – that “a former Nuance employee had accessed certain Geisinger patient information two days after the employee had been terminated,” the company said in an incident notice. The employee’s access to the data was immediately terminated.

The information that was potentially accessed and stolen, the healthcare provider said, included names, addresses, dates of birth, phone numbers, race, gender, admit and discharge or transfer codes, and medical record numbers.

“No claims or insurance information, credit card or bank account numbers, other financial information, or Social Security numbers were inappropriately accessed by the company’s former employee,” Geisinger said.

According to the company, Nuance is notifying individuals potentially impacted by the incident, and the former employee – Max Vance, aka Andre J. Burke – has been arrested and indicted.

Geisinger said notifications to impacted individuals were delayed at the request of law enforcement agencies investigating the incident.

Advertisement. Scroll to continue reading.

Last month, Geisinger informed the U.S. Department of Health and Human Services that 1,276,026 individuals were affected by the data breach.

Last week, a federal class action lawsuit was filed against Geisinger in the U.S. Middle District Court of Pennsylvania for failing to properly secure patients’ personal and health information. The plaintiff, James Wierbowski, seeks damages of more than $5 million.

Recently acquired by Kaiser Permanente’s non-profit charitable organization Risant Health, Geisinger operates 134 care sites across Pennsylvania, including 10 hospital campuses, and has over 26,000 employees.

Related: 300k Affected by Year-Old Data Breach at Florida Community Health Centers

Related: Prudential Financial Data Breach Impacts 2.5 Million

Related: Neiman Marcus Data Breach Disclosed as Hacker Offers to Sell Stolen Information

Related: Data Breach Victims Sue Rhode Island Transit Agency, Insurer

Related Content

Data Breaches

Hackers stole personal, medical, and health insurance information from a company’s data center.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version