Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to a historic file server at the Practice’s Hawthorn location. [1]
Impact
Personal, personnel, financial, and health information that may have been impacted; categories varied by individual. [1][2][3]
Documented data types include:
- Dates of birth [1]
- Names [1]
- Clinical information — Medical or disability-related records may have been involved. [1]
- Contact information [1]
- Social Security numbers [1]
- Driver’s license numbers — Driver’s-license or other government-issued identification numbers may have been involved. [1]
- Financial account information — Credit or debit card numbers and financial-account information may have been involved. [1]
A cited record reports 311,760 individuals (Individuals listed for the Practice in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [1][2][3]
A cited record reports 290,357 individuals (Massachusetts residents affected according to incident report 2026-1151; not a national total; as of 2026-07-16). [1][2][3]
The incident affected a historic file server and did not affect the Practice’s electronic health record system. [1]
Timeline
Activity began
Start of the unauthorized-access interval identified by the Practice.
[1]Documented activity ended
End of the unauthorized-access interval identified by the Practice.
[1]Discovery
Date the Practice says it first became aware of the incident.
[1]Documented event
Date printed on the Massachusetts sample notice.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Personnel and human-resources records may have included compensation or payroll, licensure or credentialing, and medical or disability-related records. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The Practice isolated the server, investigated, retrained employees, added technical safeguards, and notified law enforcement. The Practice offered two years of Experian IdentityWorks identity restoration and fraud-detection services. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
