Heart to Heart Hospice Partners with CyberMaxx to Bolster Cybersecurity and Protect Patient Data

Heart to Heart Hospice, one of the largest private hospice providers in the U.S., has partnered with cybersecurity firm CyberMaxx to guard sensitive data for more than 4,500 patients and 2,800 employees, according to PRNewswire. The deal brings 24/7 security monitoring and incident response to an organization that suffered a major data breach just 15 months ago.
The announcement comes after a March 2025 breach exposed the personal and medical records of 19,034 people — including Social Security numbers and treatment details — and triggered multiple class-action lawsuit investigations, according to Yahoo Finance.
On March 18, 2025, Heart to Heart Hospice discovered an unauthorized third party had broken into its IT systems and stolen files. The breach hit 10,835 Texas residents alone, according to Yahoo Finance. Law firms Federman & Sherwood and Arnold Law Firm quickly launched investigations, alleging the hospice failed to put proper safeguards in place.
The average cost of a healthcare data breach reached $7.42 million in 2025, according to PRNewswire. For a hospice growing at roughly 25% over 18 months — now spanning 80-plus locations — the financial and legal risk of another breach was simply too large to ignore.
CyberMaxx will monitor more than 4,500 Android devices used by H2H clinicians working in patients' homes. Those devices connect through Microsoft Intune, a device management platform. CyberMaxx pulls logs from that system in real time, giving its security team visibility into every tablet and phone in the field, according to PRNewswire.
David Ewers, H2H's Senior Director of Information Technology, said the goal is clear protection without disruption. "Our IT and security teams recognize the importance of protecting patient, employee, and company information without interrupting patient care," Ewers said, as reported by PRNewswire. CyberMaxx operates three global Security Operations Centers staffed by roughly 216 employees.
Hospice organizations are especially vulnerable to cyberattacks. Their staff is highly mobile, working in private homes rather than a single building. That creates a wide and hard-to-watch attack surface. By 2026, the dominant threat in home health care is "double-extortion" ransomware — where criminals both lock your data and threaten to publish it, according to ADVFN.
The managed detection and response market — the category CyberMaxx operates in — is projected to reach $17.64 billion by 2031, according to Yahoo Finance. Industry analysts say basic endpoint security tools are no longer enough against AI-enhanced attacks. Human-led, around-the-clock monitoring is now the standard for organizations of H2H's size.
H2H and CyberMaxx describe the deal as part of a broader push toward "responsible growth" and operational resilience, according to PRNewswire. The partnership adds specialized threat-hunting and defined escalation paths on top of H2H's existing internal IT team — rather than replacing it. CyberMaxx CEO Brian Ahern has built the firm around what he calls a "Zero-Latency Response" model for healthcare clients.
Legal analysts view the move differently. They say partnering with a dedicated security firm is a key step in reducing "negligence" claims tied to the 2025 breach. Either way, the outcome is the same: end-of-life patient records for more than 4,500 people now have a stronger line of defense, according to Yahoo Finance.
Publishers
5
Articles
4
Reach
5