---
title: "Brown Health Medical Group-MA historic file-server incident"
description: "Evidence-backed account of Brown Health Medical Group-MA historic file-server incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/brown-health-medical-group-historic-file-server-incident-2025"
markdown_url: "https://www.ally.security/incidents/brown-health-medical-group-historic-file-server-incident-2025.md"
stix_url: "https://www.ally.security/incidents/brown-health-medical-group-historic-file-server-incident-2025/stix.json"
---

# Brown Health Medical Group-MA historic file-server incident

Unauthorized access to a historic file server at the Practice's Hawthorn location. Personal, personnel, financial, and health information that may have been impacted; categories varied by individual.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to a historic file server at [the Practice](https://www.brownhealth.org/)'s Hawthorn location. [1](#source-1)

## Impact

Personal, personnel, financial, and health information that may have been impacted; categories varied by individual. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Dates of birth [1](#source-1)
- Names [1](#source-1)
- Clinical information — Medical or disability-related records may have been involved. [1](#source-1)
- Contact information [1](#source-1)
- Social Security numbers [1](#source-1)
- Driver's license numbers — Driver's-license or other government-issued identification numbers may have been involved. [1](#source-1)
- Financial account information — Credit or debit card numbers and financial-account information may have been involved. [1](#source-1)

A cited record reports 311,760 individuals (Individuals listed for the Practice in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 290,357 individuals (Massachusetts residents affected according to incident report 2026-1151; not a national total; as of 2026-07-16). [1](#source-1) [2](#source-2) [3](#source-3)

The incident affected a historic file server and did not affect the Practice's electronic health record system. [1](#source-1)

## Timeline

### December 15, 2025 — Activity began

Start of the unauthorized-access interval identified by the Practice. [1](#source-1)

### December 16, 2025 — Documented activity ended

End of the unauthorized-access interval identified by the Practice. [1](#source-1)

### December 16, 2025 — Discovery

Date the Practice says it first became aware of the incident. [1](#source-1)

### July 16, 2026 — Documented event

Date printed on the Massachusetts sample notice. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Personnel and human-resources records may have included compensation or payroll, licensure or credentialing, and medical or disability-related records. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The Practice isolated the server, investigated, retrained employees, added technical safeguards, and notified law enforcement. The Practice offered two years of Experian IdentityWorks identity restoration and fraud-detection services. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/brown-health-medical-group-historic-file-server-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Notice of Data Breach — Massachusetts filing

official · Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA

<https://www.mass.gov/doc/2026-1151-lifespan-physician-group-of-massachusetts-inc-dba-brown-health-medical-group-ma/download>

<a id="source-2"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-3"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: The Practice isolated the server, investigated, retrained employees, added technical safeguards, and notified law enforcement.
2. **Resulted In · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: The incident affected a historic file server and did not affect the Practice's electronic health record system.
3. **Affected Organization · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: Lifespan Physician Group of Massachusetts, Inc.
4. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Dates of birth
5. **Resulted In · 100% confidence · current**  
   Brown Health Medical Group-MA affected-individual notification: The Practice offered two years of Experian IdentityWorks identity restoration and fraud-detection services.
6. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Names
7. **Ended At · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: 2025-12-16
8. **Resulted In · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: Brown Health Medical Group-MA affected-individual notification
9. **Began At · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: 2025-12-15
10. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Clinical information
11. **Affected Individual Count · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: 311,760 individual
12. **Affected Individual Count · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: 290,357 individual
13. **Discovered At · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: 2025-12-16
14. **Resulted In · 100% confidence · current**  
   December 2025 Brown Health Medical Group-MA file-server incident: Brown Health Medical Group-MA historic-server data exposure
15. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Contact information
16. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Social Security numbers
17. **Resulted In · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Personnel and human-resources records may have included compensation or payroll, licensure or credentialing, and medical or disability-related records.
18. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Driver's license numbers
19. **Occurred At · 100% confidence · current**  
   Brown Health Medical Group-MA affected-individual notification: 2026-07-16
20. **Exposed Data Category · 100% confidence · current**  
   Brown Health Medical Group-MA historic-server data exposure: Financial account information

</details>
