Skip to content
>_ITDITDWeb Security Platform

Security Guides

The breach wasn't at the company you gave your data to: six 2026 US healthcare breaches, and how to check a notice from a company you don't know

Six 2026 healthcare breaches reported to HHS (NYC Health + Hospitals, Xsolis, CareCloud, Unlimited Technology Systems, Baylor Genetics, Navia), compared from their own notices. How to verify a letter from an unfamiliar company, and what organizations should require of vendors.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 19 min read

For: anyone in the US who has received care and got a "notice of data breach" from a company they don't recognize, their families, and staff at providers and businesses that entrust patient data to outside companies. This article compares six cases using each organization's own notices and letters, the US Department of Health and Human Services (HHS) Office for Civil Rights breach portal, state attorney general filings and federal regulations. It does not cover attack techniques.

First: if you got a letter from a company you don't know

1

Before you bin it, look for a name you do know

A vendor's letter usually names the provider you actually used, or says it's being sent on that provider's behalf. Xsolis's sample letter, for example, opens by explaining that your healthcare provider uses a vendor, Xsolis, for case and utilization management services. Baylor Genetics says it received patients' information from its third-party clients, such as the providers who ordered tests. Look first for a hospital, insurer or employer name you recognize.

2

Search the HHS breach portal yourself

Type ocrportal.hhs.gov into your browser yourself (not through a link or QR code in the letter), choose "View HIPAA Breach Reports", and look for the company. The list shows the entity name, state, type (provider or business associate), number of people affected and submission date. It only includes breaches affecting 500 or more people, and a vendor's breach is sometimes reported under the provider's name, so absence alone doesn't prove a letter is fake.

3

Compare with the sample letter on a state attorney general's listing

The California Attorney General's breach list (oag.ca.gov/privacy/databreach/list) posts the sample notification letter each company submits. Five of our six cases were listed there (we could not find NYC Health + Hospitals when we checked). Hold your letter next to the sample and compare the help line number, the domain of the credit monitoring enrollment site and the enrollment deadline. Samples are templates with names and codes left blank, so what you're checking is that the format and contact details match.

4

Only type your SSN into an enrollment site you've verified

Genuine credit monitoring enrollment asks for your SSN, which is exactly why you should never enter it on a site you haven't verified. QR codes appear on genuine letters too (the Baylor Genetics and CareCloud samples both have enrollment QR codes), so don't judge by whether there's a QR code. Judge by whether the destination domain matches the sample filed with the state. Don't "confirm" your SSN, card number or password on a call or text you didn't initiate (see what is phishing?).

5

Once it checks out, lock each number

Enroll in the monitoring before the deadline. If your SSN was involved, place a credit freeze with Equifax, Experian and TransUnion, get an IRS IP PIN, and read your Explanation of Benefits statements for care you didn't receive. The full US checklist, including children, is on one page in our DentaQuest article. If online account credentials were involved, as NYC Health + Hospitals lists, change those passwords too.

Signs of a genuine notice

  • Names your provider, insurer or employer and explains the company's relationship to it
  • The company appears on the HHS portal or a state AG listing
  • Phone number and enrollment site match the sample letter filed with the state
  • Offers free credit monitoring with an enrollment deadline (you enroll yourself)

Signs of a scam

  • A call, text or email asks you to "confirm" your SSN, card number or password
  • Asks for payment or a fee
  • Contact details or domains don't match public listings or the sample
  • Pushes you to act today (real enrollment deadlines are usually months away)

The six cases at a glance

Based on the HHS Office for Civil Rights breach portal (checked September 30, 2026) and each organization's notice. Counts are the HHS portal figures.

OrganizationWhat it doesHHS entity typeAffected (HHS)Submitted to HHSAccess period (per the organization)
NYC Health + HospitalsNew York City's public hospital systemHealthcare provider1,800,000Mar 24, 2026~Nov 25, 2025 to Feb 11, 2026
Navia Benefit SolutionsBenefits administration (HRA, FSA, COBRA)Business associate2,151,330Mar 18, 2026Dec 22, 2025 to Jan 15, 2026
XsolisCase and utilization management for providersBusiness associate1,396,519Jun 5, 2026Resulting from a Jan 20, 2026 phishing attack (aware Jan 22)
Unlimited Technology SystemsPractice management software for providersBusiness associate3,803,750Jul 21, 2026Oct 5 to 10, 2025
CareCloudElectronic health records and other health ITBusiness associate3,756,469Jul 24, 2026Mar 10 to 16, 2026
Baylor GeneticsGenetic and clinical lab testingHealthcare provider2,810,878Aug 14, 2026Jun 11 to 17, 2026
4 / 6
Registered on the HHS portal as business associates
15,718,946
Simple sum of the six HHS counts (the same person may be counted in more than one)
5 / 6
Had a sample letter posted on the California AG breach list
5 / 6
Organization's own notice lists SSNs as possibly involved (CareCloud per press reports)

How to read the numbers

HHS portal counts are what the entity reported at the time and can be updated later. For Navia, the HHS portal shows 2,151,330, while press reports say its filing with the Maine Attorney General listed 2,697,540 (we could not open the Maine listing directly). NYC Health + Hospitals' notice gives no count; 1,800,000 is the HHS portal figure. This article does not rank the six by how "bad" they were.

You (patient or member)

You only know the hospital, plan or employer

↓ care / enrollment

Provider, plan or employer

Hands part of the work to outside companies

↓ vendor

Vendor or lab

EHR / practice management / utilization management / benefits admin / lab testing

The notice coming back

Vendor → reports to provider → notice to you (may arrive under a name you don't know)

How to verify (open these yourself)

HHS breach portal (ocrportal.hhs.gov) / state AG breach listings and sample letters

Your information flows past the provider you saw. The breach happens further down the line, and the notice comes back under a name you don't know. The way to verify it lies outside the letter, in public listings.
  1. Mar 13 and 18, 2026

    Navia begins substitute notice (notice by means other than individual letters), then mails written notices from on or about March 18. HHS submission date: March 18.
  2. Mar 24

    NYC Health + Hospitals publishes its breach notice (same date as its HHS submission).
  3. Mar 27

    CareCloud files a Form 8-K with the SEC disclosing the March 16 disruption.
  4. Jun 5

    Xsolis announces the incident in a press release (same date as its HHS submission).
  5. Jul 21

    Unlimited Technology Systems' HHS submission date.
  6. Jul 24

    CareCloud's HHS submission date (3,756,469 affected).
  7. Aug 14

    Baylor Genetics' letters are dated (same date as its HHS submission).

What each organization has disclosed

Based on each organization's notice, letters and state filings. Client providers, and the investigators and service firms the organizations engaged, are not named.

NYC Health + Hospitals (New York City's public hospital system)
What happened
Discovered suspicious activity on February 2, 2026. Says an unauthorized actor accessed systems and copied files between approximately November 25, 2025 and February 11, 2026
Entry (its account)
Says the unauthorized actor may have gained access due to a security breach at a third-party vendor
Information
Health insurance information, medical information (diagnoses, medications, test results, images and more), biometric information (fingerprints and palm prints), billing and payment information, SSNs, driver's license and other government ID numbers, taxpayer ID numbers or IRS-issued identity protection numbers, precise geolocation, card numbers, financial account information or credentials, and online account credentials. Varies by individual
Response
Enhanced detection rules and updated remote access management policies. 24 months of free credit monitoring. Help line (844) 403-4518
Navia Benefit Solutions (benefits administration)
What happened
Discovered suspicious activity on January 23, 2026. Says an unauthorized actor accessed and potentially acquired information between December 22, 2025 and January 15, 2026
Information
Name, date of birth, SSN, phone number, email address and health plan information. Health plan refers only to participation in HRAs, FSAs or COBRA, limited to items such as termination and election dates; the company says no claims or financial data were disclosed
Notice
Substitute notice from March 13 and written notice from on or about March 18 (per its Nebraska AG filing). 12 months of free credit monitoring. Help line (844) 443-1645
Xsolis (case and utilization management for providers)
What happened
Became aware on January 22 of unauthorized activity resulting from a targeted phishing attack on January 20, 2026, terminated the access, and isolated affected hosts and user accounts. The actor acquired a limited number of files
Information
Name, address, date of birth, health insurance information, SSN and medical treatment information. Varies by individual
Response
Per its sample letter, reset passwords for all users and key accounts, increased monitoring and strengthened credential management, among other steps. 12 months of free credit monitoring. Help line (844) 403-4585
Unlimited Technology Systems (practice management software)
What happened
Discovered unauthorized activity in its commercial datacenter on October 19, 2025. Says an unauthorized actor obtained a copy of some personal information between October 5 and 10, 2025
Information
Health insurance and patient balance information, medical information (record numbers, dates of service, diagnoses), scanned documents (driver's licenses or other government ID, insurance cards, intake forms), SSN, and date of birth and contact details. The company says it does not include full medical records, medical imaging, or card or bank account information
Response
Two years of free credit monitoring. Help line (844) 576-3063
CareCloud (electronic health records and health IT)
What happened (8-K)
On March 16, 2026, a temporary network disruption in its CareCloud Health division partially affected functionality and data access in one of its six EHR environments for approximately 8 hours, restored that evening
Findings (letter)
Between March 10 and 16, 2026, an unauthorized third party accessed one of its cloud environments and claimed to have exfiltrated data from databases in it. The company identified the affected information on June 24
Information
The letter lists full name plus elements that vary by person. Press reports say its state filings list SSNs, driver's license and other government ID numbers, financial account numbers, card numbers, and medical and health insurance information
Response
12 or 24 months of free credit monitoring (sample enrollment deadline: December 17, 2026)
Baylor Genetics (genetic and clinical lab testing)
What happened
Identified suspicious activity on or around June 15, 2026. Says an unauthorized third party accessed portions of its network and data between June 11 and 17, 2026. Its review of who was affected was completed on or about July 30
Information (patients)
Name plus date of birth, medical testing information, lab test results, and potentially health insurance information. SSNs for a very limited subset of patients. For some employees: SSNs, government ID numbers and financial account information
Response
12 or 24 months of free credit monitoring (enrollment deadline November 14, 2026). Help line 1-866-200-0985

This site's view: think "how far did it flow," not "who did I give it to"

Patients handed their information to a hospital, a plan or an employer. Yet five of these six cases happened further down the line, at billing, records, utilization management, benefits and lab companies. The sixth, NYC Health + Hospitals, says its entry point may have been a vendor's breach. Your information's safety depends on the defenses of companies you never chose.

For patients that means two things. First, the shortcut "unknown company = scam" no longer works in 2026. Second, the flip side: scammers can pose as "a company you've never heard of" too. Either call can only be made outside the letter, in the public listings. The HHS portal and the sample letters on state AG sites are among the few answer keys patients can check for themselves.

This site's articles on other cases from the same year

Cases with the same "letter from an unfamiliar company" shape have their own articles:

  • DentaQuest (dental and vision benefits): the company says one employee was tricked into providing credentials and an MFA code. This is also where the one-page US checklist (freezes, IP PIN, children) lives → The DentaQuest breach and what members should do
  • Aesto Health (medical record migration and archiving): the problem with record archives → The Aesto Health breach
  • Medtronic (medical device maker): device safety and what patients should do → The Medtronic breach

For providers and businesses that send patient data outside

1

Put everyone you've handed patient data to on one sheet

EHR, billing and practice management, utilization management, benefits administration, lab work, record archiving. List every company that holds patient or member data, whichever department signed the contract, with the fields you hand over (including SSNs, ID scans or biometrics), the number of records and how many years. Most of these notices travel from vendor to provider to patient. Without that sheet, when a vendor calls you can't quickly say how many of your patients are affected and which fields. The approach is the same as a security inventory.

2

Check three clauses in your business associate agreements

Federal regulations require business associate contracts to provide that the business associate will: (1) report to the covered entity any use or disclosure not provided for by the contract, including breaches (45 CFR 164.504(e)(2)(ii)(C)); (2) ensure its subcontractors agree to the same restrictions (paragraph (D)); and (3) at termination, if feasible, return or destroy all protected health information and retain no copies (paragraph (J)). Clause (3) only works if you have a step that confirms the return or destruction actually happened when the contract ended. Use the "ended contracts" column on your sheet to check whether former vendors still hold patient data.

3

Require phishing-resistant MFA, for yourself and your vendors

Xsolis says its incident resulted from a targeted phishing attack. The US Cybersecurity and Infrastructure Security Agency (CISA) points to FIDO/WebAuthn (passkeys and FIDO2 security keys) as the widely available phishing-resistant option. Start with admin accounts that touch patient data, and remote access. Add one line to your vendor questionnaire at selection and renewal: "Do you use phishing-resistant MFA for admin accounts and remote access?" How code-based MFA gets handed over is covered in the DentaQuest article.

4

Hand over fewer fields

Unlimited Technology Systems' breach included scans of government IDs and insurance cards; NYC Health + Hospitals' included fingerprints and palm prints. SSNs and biometrics can't be changed. Going field by field through what you send each vendor and asking whether that job really needs it is the most reliable way to shrink the damage when a breach does happen.

5

Be able to say quickly who needs to be notified

As the letters show, every incident is followed by a review of whose records and which fields were affected. In general, if you know in normal times which files hold whose records and which fields, identifying affected people after an incident goes faster. For the overall baseline, see the minimum security baseline for organizations.

For patients and families: the most immediate risk is the convincing message that follows the letter

These notices say names, addresses, phone numbers, dates of birth and insurance details may be involved. That's enough to build a convincing call, email or letter. If someone asks for your SSN or account number to "process your breach compensation" or "re-register your insurance", hang up and call back a number you've verified against the HHS portal and the state AG sample letter.

Sources (public record)

The facts in this article come from the official notices and public records below. Counts are only those stated by the organizations, HHS or state authorities; press estimates and speculation about undisclosed causes are not used. Client providers and the organizations' vendors and investigators are described by role only.

  • NYC Health + Hospitals, "Notice of Data Breach" (March 24, 2026) — nychealthandhospitals.org
  • Xsolis, Inc., "Xsolis, Inc. Provides Notice of Data Security Incident" (PR Newswire, June 5, 2026) — prnewswire.com
  • CareCloud, Inc., Form 8-K (filed March 27, 2026; date of report March 24) — sec.gov
  • California Attorney General, "Data Security Breach" list and sample letters (CareCloud, Unlimited Technology Systems, Xsolis, Baylor Genetics, Navia) — oag.ca.gov / CareCloud / Unlimited Technology Systems / Xsolis / Baylor Genetics (PDF) / Navia (PDF)
  • Baylor Genetics, "Security Update" — baylorgenetics.com
  • Navia's filing with the Nebraska Attorney General (notice dates and data involved) — nebraska.gov (PDF)
  • HHS Office for Civil Rights, "Breach Portal" (counts, entity types and submission dates for all six; checked September 30, 2026) — ocrportal.hhs.gov
  • Code of Federal Regulations, 45 CFR 164.504(e) (business associate contracts) — ecfr.gov
  • CISA, "Implementing Phishing-Resistant MFA" (fact sheet) — cisa.gov (PDF)
  • Press reports (Navia's Maine filing count; data elements in CareCloud's state filings): SecurityWeek — Navia / CareCloud

Update history

2026-09-30: First version, based on the organizations' notices and letters, CareCloud's Form 8-K, the California and Nebraska attorney general postings, the HHS Office for Civil Rights breach portal (as of September 30, 2026), federal regulations and CISA guidance. We will update it if the organizations or regulators publish more.

FAQ

QWhat were the major US healthcare data breaches in 2026?
A

The HHS Office for Civil Rights breach portal lists, among others, Unlimited Technology Systems (3,803,750 individuals), CareCloud (3,756,469), Baylor Genetics (2,810,878), Navia Benefit Solutions (2,151,330), NYC Health + Hospitals (listed as New York City Health and Hospitals Corporation, 1,800,000) and Xsolis (1,396,519). Four of these are registered as business associates, companies that do work on behalf of providers and plans. DentaQuest, Aesto Health and Medtronic from the same period are covered in this site's individual articles.

QI got a breach letter from a company I've never heard of. Is it a scam?
A

Not necessarily. Providers hand electronic health records, billing, utilization management, benefits administration and lab work to outside companies, and when one of them has a breach the letter may come under that company's name. Before using any number or link in the letter, open the HHS breach portal (ocrportal.hhs.gov) and a state attorney general's breach listing, such as California's, yourself. Check that the company is listed and that the phone number and enrollment site match the sample letter posted there.

QIf the company isn't on the HHS list, is the letter fake?
A

Not necessarily. The HHS portal only lists breaches affecting 500 or more people, and a breach at a vendor may be reported under the provider's name instead. State attorney general listings only include breaches that affected residents of that state. If you can't find it, check with the provider named in the letter (a hospital or clinic you actually used) through its official website or a phone number you look up yourself.

QOnce I know the letter is real, what should I do?
A

Enroll in the free credit monitoring offered in the letter before the deadline. If your Social Security number was involved, place a credit freeze with all three bureaus and get an IRS IP PIN, and read your Explanation of Benefits statements for care you didn't receive. The full one-page US checklist is in this site's DentaQuest article. If online account credentials were involved, as in the NYC Health + Hospitals notice, change those passwords too.

QWhat should providers and businesses check about their vendors?
A

This site recommends starting with three things: (1) list every vendor that holds patient data, with which fields and how many years; (2) confirm your business associate agreements require the vendor, at termination, to return or destroy all protected health information and keep no copies, and check that it actually happened (45 CFR 164.504(e)(2)(ii)(J)); (3) require MFA that can't be phished (passkeys or FIDO2 security keys) for your own staff and your vendors.