Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir Medical Corporation in California, and Central Arkansas Pediatrics.
LHC Group
LHC Group, a Lafayette, Louisiana-based provider of home health, hospice, and home- and community-based services in 28 U.S. states and the District of Columbia, has been affected by a data security incident involving a third-party technology vendor. The unnamed vendor assisted LHC Group with referral management, care coordination, and clinical workflows, and the provision of those services required access to patients’ personal and protected health information.
LHC Group said it became aware on April 7, 2026, that an employee may have fallen victim to a voice phishing attack. LHC’s vendor subsequently reported suspicious activity within the vendor’s platform associated with an LHC user account. LHC worked closely with its vendor to secure systems and investigate the activity, and third-party cybersecurity experts were engaged to assist with those processes. LHC Group determined that the threat actor stole credentials in the vishing attack and accessed a large volume of files on the vendor’s platform, including files containing patients’ protected health information. The threat actor had access from April 7, 2026, through April 15, 2026.
The impacted data was reviewed, and LHC started confirming the identities of the impacted individuals on July 9, 2026. The data types involved varied from individual to individual and included full names, addresses, dates of birth, demographic information, clinical summaries, treatment plans, diagnosis codes, dates of service, physician/provider information, Medicare/Medicaid numbers, health insurance information, and, in limited cases, Social Security numbers and/or financial information.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
LHC Group said it disabled the compromised account, reviewed security measures to identify potential areas for improvement, enhanced authentication and monitoring, and strengthened other security controls. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for two years.
It is currently unclear how many individuals have been affected in total, but based on the breach notifications sent to state attorneys general, more than 28,000 individuals have been affected. The total is likely to be considerably higher, as not all state attorneys general publicly disclose how many state residents have been affected. This is the second data breach to be announced by LHC Group this year. LHC Group was also impacted by a breach at vendor Doctor Alliance.
Provident Behavioral Health
Provident Behavioral Health, a nonprofit provider of mental health care services in St. Louis, Missouri, has notified certain patients about a potential breach of their protected health information. Suspicious activity was identified within its computer network on April 3, 2026. The affected systems were isolated, and a third-party cybersecurity firm was engaged to investigate the activity and determine the nature and scope of the activity.
The investigation confirmed that an unauthorized third party had accessed its network and acquired data stored on the impacted systems. The data review concluded on September 4, 2026, when it was confirmed that patient data was present in the copied files, including names, contact information, demographic information, dates of birth, Social Security numbers, driver’s license numbers/state ID numbers, medical information, and health insurance information.
Provident Behavioral Health has confirmed there has been no further unauthorized access, and additional security measures have been implemented to prevent similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident has been reported to state attorneys general and the HHS’ Office for Civil Rights; however, it is currently unclear how many individuals have been affected.
Central Arkansas Pediatrics
Central Arkansas Pediatrics, P.A., a Conway, Arkansas-based medical practice that provides healthcare services for infants, children, and adolescents, has notified 1,500 current and former patients about a recent hacking incident that involved some of their personal and protected health information.
The data breach has been reported to the Department of Health and Human Services’ Office for Civil Rights; however, there is currently no substitute breach notice on the practice website, and no press release appears to have been released, so the exact types of data impacted are unknown, and the exact nature of the hacking incident has yet to be confirmed. This appears to have been a ransomware attack by a prolific ransomware-as-a-service group known as The Gentlemen. The group has conducted many attacks on healthcare providers and added Central Arkansas Pediatrics to its dark web data leak site on June 8, 2026, claiming data was exfiltrated in the attack
Elixir Medical Corporation
Elixir Medical Corporation, a Milpitas, California-based medical device company specializing in products for treating heart and vascular disease, has notified the California Attorney General about a recent security incident that exposed the data of current and former employees, consultants, and certain beneficiaries and dependents.
According to the notice, an unauthorized third party gained access to parts of its computer network between July 20, 2026, and July 21, 2026. The investigation confirmed that human resources files were exposed in the incident, which contained names and Social Security numbers, along with some or all of the following: driver’s license number, credit/debit card number, medical information, and/or direct deposit bank account information.
The affected individuals have been notified, and complimentary credit monitoring and identity theft protection services have been offered. Additional safeguards have been implemented, along with further security awareness training for the workforce. The number of affected individuals has not yet been publicly disclosed.
The post Nationwide Home Health Care Provider Announces Major Data Breach appeared first on The HIPAA Journal.
