311,000 People's Medical and Financial Records Stolen from Brown Health Medical Group in Massachusetts

A hack at the group's Hawthorn location last December exposed Social Security numbers, credit card details, and medical records for more than 311,000 patients and staff. The breach sat undiscovered for six months.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial shot of a modern medical diagnostics laboratory at night, rows of automated testing machines lit by cool blue LEDs, a single unattended moni
Share

Key points

  • Brown Health Medical Group-MA notified 311,760 people of a data breach first discovered on June 22, 2026.
  • The attack occurred in December 2025 at the group's Hawthorn location in Massachusetts.
  • Stolen data includes Social Security numbers, credit and debit card numbers, medical records, and payroll information.
  • 290,357 of those affected are Massachusetts residents.
  • Affected individuals will receive two years of free fraud detection and identity protection services.

A Massachusetts medical group has told more than 311,000 people that criminals broke into a file server at one of its offices last December and walked off with some of the most sensitive information a person can have: Social Security numbers, medical histories, bank account details, and credit card numbers.

The organisation is Brown Health Medical Group-MA, the name under which Lifespan Physician Group operates in the state. The affected location was its Hawthorn site.

What exactly was taken?

The stolen files covered a wide range of personal details. Names, dates of birth, addresses, driver's licence numbers, and government ID numbers were all exposed, alongside medical and disability-related records and financial account information including credit and debit card numbers.

Payroll and compensation records were also taken, meaning some current or former employees had their income details exposed alongside their health information. Brown Health says not every category applied to every person affected, so the full picture varies by individual.

Data category Potentially exposed
Names and contact details Yes
Social Security numbers Yes
Medical and disability records Yes
Credit and debit card numbers Yes
Payroll and HR records Yes
Electronic health record system Not affected

Why did it take six months to find out?

The break-in happened in December 2025, but Brown Health only confirmed on June 22, 2026, that attackers had accessed files containing personal information. The server involved was described as a "historic" file server, meaning older, legacy storage that may not have been monitored as closely as the main patient records system.

The group's electronic health record system, the software clinicians use day-to-day to log appointments and treatments, was not touched. That is a meaningful distinction, though it offers cold comfort to anyone whose Social Security number was sitting on the older machine.

Brown Health says it isolated the affected server as soon as the incident was identified, has added security safeguards, and is retraining staff. The organisation notified the US Department of Health and Human Services, as required by law when a healthcare breach affects 500 or more people. As first reported by SecurityWeek, no ransomware or extortion group has publicly claimed responsibility.

Should affected patients and staff be worried?

Yes, practically speaking. The combination of Social Security numbers, medical records, and financial account details is exactly what fraudsters use to open new credit accounts or commit medical identity theft, where someone uses another person's details to obtain healthcare or insurance.

Brown Health is offering two years of free fraud detection and identity protection services to everyone affected. If you receive a notification letter, sign up for that service immediately. Also check your credit reports for any accounts or enquiries you do not recognise, and consider placing a free credit freeze with the major bureaus, which blocks anyone from opening new credit in your name without your explicit consent.

MFA, meaning multi-factor authentication (a second confirmation step beyond a password, like a code sent to your phone), would not necessarily have prevented access to an internal file server in this case. What might have helped is regular auditing of older storage systems to catch unusual access early.

© 2026 Threat Vectr