Overview
Severity: CRITICAL | Affected: SynapseHealth AI | Category: breach
SynapseHealth AI, a provider of AI-powered diagnostic imaging analysis, has confirmed a major data breach affecting approximately 1.5 million patients. The incident was discovered on July 5, 2026, after attackers exploited a critical zero-day vulnerability in a widely used MLOps platform integrated into the company's data processing pipeline. The threat actors gained unauthorized access to cloud storage buckets containing sensitive patient data, including medical images (X-rays, MRIs), AI-generated diagnostic reports, and personally identifiable information (PII) such as names, dates of birth, and medical record numbers. The company stated it has patched the vulnerability and is working with forensic investigators to determine the full scope. This breach underscores the significant security risks associated with third-party dependencies in AI supply chains, particularly in highly regulated sectors like healthcare, and has triggered investigations by regulatory bodies.