Brown Health Medical Group-MA historic file-server incident

Unauthorized access to a historic file server at the Practice's Hawthorn location. Personal, personnel, financial, and health information that may have been impacted; categories varied by individual.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to a historic file server at the Practice’s Hawthorn location. [1]

Impact

Personal, personnel, financial, and health information that may have been impacted; categories varied by individual. [1][2][3]

Documented data types include:

  • Dates of birth [1]
  • Names [1]
  • Clinical information — Medical or disability-related records may have been involved. [1]
  • Contact information [1]
  • Social Security numbers [1]
  • Driver’s license numbers — Driver’s-license or other government-issued identification numbers may have been involved. [1]
  • Financial account information — Credit or debit card numbers and financial-account information may have been involved. [1]

A cited record reports 311,760 individuals (Individuals listed for the Practice in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [1][2][3]

A cited record reports 290,357 individuals (Massachusetts residents affected according to incident report 2026-1151; not a national total; as of 2026-07-16). [1][2][3]

The incident affected a historic file server and did not affect the Practice’s electronic health record system. [1]

Timeline

  1. Activity began

    Start of the unauthorized-access interval identified by the Practice.

    [1]
  2. Documented activity ended

    End of the unauthorized-access interval identified by the Practice.

    [1]
  3. Discovery

    Date the Practice says it first became aware of the incident.

    [1]
  4. Documented event

    Date printed on the Massachusetts sample notice.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Personnel and human-resources records may have included compensation or payroll, licensure or credentialing, and medical or disability-related records. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The Practice isolated the server, investigated, retrained employees, added technical safeguards, and notified law enforcement. The Practice offered two years of Experian IdentityWorks identity restoration and fraud-detection services. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]