Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
State reporting associated identity, financial, medical, and health-insurance information with the incident. [3]
Documented data types include:
- Social Security numbers — Social Security numbers; reported by the Texas Attorney General and varying by individual. [3]
- Driver’s license numbers — Driver’s-license numbers; reported by the Texas Attorney General and varying by individual. [3]
- Payment card information — Credit- or debit-card information; the Texas field combines account and payment-card examples, and data varied by individual. [3]
- Names — Names; reported by the Texas Attorney General and varying by individual. [3]
- Financial account information — Financial-account information; the Texas field combines account and payment-card examples, and data varied by individual. [3]
- Clinical information — Medical information; reported by the Texas Attorney General and varying by individual. [3]
- Health insurance information — Health-insurance information; reported by the Texas Attorney General and varying by individual. [3]
A cited record reports 550,164 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005185; regulator-reported and not independently verified; as of 2026-07-21). [3][4]
A cited record reports 1,270 individuals (Texas residents in report BR-0005185; a subset of the overall count and not additive; as of 2026-07-21). [3][4]
A cited record reports 500 individuals (Individuals in the HHS OCR incident report submitted May 4, 2026; retained as a separately scoped regulator figure rather than treated as a correction to the later overall state figure; as of 2026-05-04). [3][4]
Timeline
Activity began
Beginning of the incident range in Texas Attorney General report BR-0005185.
[3]Documented activity ended
End of the Texas incident range and the single incident date shown on the California Attorney General page.
[1]Public disclosure
California Attorney General reported date for the BAYADA sample notice; not asserted as the mailing date for every person.
[2]Public disclosure
Publication date of Texas Attorney General report BR-0005185.
[3]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
