---
title: "BAYADA direct systems data incident"
description: "Evidence-backed account of BAYADA direct systems data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/bayada-direct-systems-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/bayada-direct-systems-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/bayada-direct-systems-data-incident-2026/stix.json"
---

# BAYADA direct systems data incident

A hacking or IT incident affecting a BAYADA network server during a regulator-reported February 18-March 2 period. State reporting associated identity, financial, medical, and health-insurance information with the incident.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A hacking or IT incident affecting a [BAYADA](https://www.bayada.com/) network server during a regulator-reported February 18-March 2 period. [1](#source-1) [3](#source-3)

## Impact

State reporting associated identity, financial, medical, and health-insurance information with the incident. [3](#source-3)

Documented data types include:

- Social Security numbers — Social Security numbers; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Driver's license numbers — Driver's-license numbers; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Payment card information — Credit- or debit-card information; the Texas field combines account and payment-card examples, and data varied by individual. [3](#source-3)
- Names — Names; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Financial account information — Financial-account information; the Texas field combines account and payment-card examples, and data varied by individual. [3](#source-3)
- Clinical information — Medical information; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Health insurance information — Health-insurance information; reported by the Texas Attorney General and varying by individual. [3](#source-3)

A cited record reports 550,164 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005185; regulator-reported and not independently verified; as of 2026-07-21). [3](#source-3) [4](#source-4)

A cited record reports 1,270 individuals (Texas residents in report BR-0005185; a subset of the overall count and not additive; as of 2026-07-21). [3](#source-3) [4](#source-4)

A cited record reports 500 individuals (Individuals in the HHS OCR incident report submitted May 4, 2026; retained as a separately scoped regulator figure rather than treated as a correction to the later overall state figure; as of 2026-05-04). [3](#source-3) [4](#source-4)

## Timeline

### February 18, 2026 — Activity began

Beginning of the incident range in Texas Attorney General report BR-0005185. [3](#source-3)

### March 2, 2026 — Documented activity ended

End of the Texas incident range and the single incident date shown on the California Attorney General page. [1](#source-1)

### July 17, 2026 — Public disclosure

California Attorney General reported date for the BAYADA sample notice; not asserted as the mailing date for every person. [2](#source-2)

### July 21, 2026 — Public disclosure

Publication date of Texas Attorney General report BR-0005185. [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Texas reported that consumer notice was provided by U.S. mail and by a company or special website posting. HHS classified the report as a Hacking/IT Incident involving a Network Server. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3](#source-3) [4](#source-4)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/bayada-direct-systems-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Submitted Breach Notification Sample — BAYADA Home Health Care, Inc.

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-626658>

<a id="source-2"></a>

### Data Security Breach List — 2026 records

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list>

<a id="source-3"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-4"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Social Security numbers
2. **Resulted In · 100% confidence · current**  
   BAYADA July 2026 breach notifications: Texas reported that consumer notice was provided by U.S. mail and by a company or special website posting.
3. **Began At · 100% confidence · current**  
   February-March 2026 BAYADA direct systems incident: 2026-02-18
4. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Driver's license numbers
5. **Disclosed At · 100% confidence · current**  
   BAYADA July 2026 breach notifications: 2026-07-17
6. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Payment card information
7. **Resulted In · 100% confidence · current**  
   February-March 2026 BAYADA direct systems incident: BAYADA personal and health data exposure
8. **Affected Individual Count · 100% confidence · current**  
   BAYADA personal and health data exposure: 550,164 individual
9. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Names
10. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Financial account information
11. **Disclosed At · 100% confidence · current**  
   BAYADA July 2026 breach notifications: 2026-07-21
12. **Affected Individual Count · 100% confidence · current**  
   BAYADA personal and health data exposure: 1,270 individual
13. **Affected Organization · 100% confidence · current**  
   February-March 2026 BAYADA direct systems incident: BAYADA Home Health Care, Inc.
14. **Affected Individual Count · 100% confidence · current**  
   BAYADA personal and health data exposure: 500 individual
15. **Resulted In · 100% confidence · current**  
   February-March 2026 BAYADA direct systems incident: BAYADA July 2026 breach notifications
16. **Affected Organization · 100% confidence · current**  
   BAYADA personal and health data exposure: BAYADA Home Health Care, Inc.
17. **Resulted In · 100% confidence · current**  
   February-March 2026 BAYADA direct systems incident: HHS classified the report as a Hacking/IT Incident involving a Network Server.
18. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Clinical information
19. **Exposed Data Category · 100% confidence · current**  
   BAYADA personal and health data exposure: Health insurance information
20. **Ended At · 100% confidence · current**  
   February-March 2026 BAYADA direct systems incident: 2026-03-02

</details>
