Operation PAR, Boley Centers, and Eleos network incident

Unauthorized access to a shared network and possible access or removal of files maintained by Operation PAR, Boley Centers, and Eleos. Potential exposure of patient or employee personal information in files accessed or removed from the affected network.

Last modified

Summary

  • Environment: Date the three organizations say they detected unauthorized network access.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to a shared network and possible access or removal of files maintained by Operation PAR, Boley Centers, and Eleos. [1]

Impact

Potential exposure of patient or employee personal information in files accessed or removed from the affected network. [2][3][4]

Documented data types include:

  • Names [2]
  • Health insurance information — Operation PAR’s June 24 update says categories varied by individual; none of these fields is asserted for every person or for the other two organizations. [2]
  • Clinical information [2]
  • Dates of birth [2]
  • Social Security numbers [2]
  • Driver’s license numbers [2]
  • Financial account information [2]

A cited record reports 145,714 individuals (Individuals listed for Operation PAR in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [2][3][4]

A cited record reports 375 individuals (Massachusetts residents affected according to incident report 2026-1031; not a national total; as of 2026-06-25). [2][3][4]

The joint notice says some files may have been accessed or removed by one or more unauthorized individuals; it does not identify them or the access method. [1]

At the time of the joint notice, the organizations said they had no evidence the recipient’s information had been used for financial fraud or identity theft. [1]

Timeline

  1. Activity began

    Start of the possible file-access or removal interval identified in the joint notice.

    [1]
  2. Discovery

    Date the three organizations say they detected unauthorized network access.

    [1]
  3. Documented activity ended

    End of the possible file-access or removal interval identified in the joint notice.

    [1]
  4. Documented event

    Date the organizations say their review determined that impacted files may have contained personal information.

    [1]
  5. Public disclosure

    Date Operation PAR says it began notifying affected individuals and date reported to Massachusetts OCA and HHS OCR.

    [2]
  6. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The organizations say they secured the network, investigated with external cybersecurity professionals, strengthened the network, and implemented additional third-party recommendations; Operation PAR also says it reported the incident to law enforcement. The joint notice offered complimentary Epiq one-bureau credit monitoring and identity-protection features; the coverage length was redacted in the sample reviewed. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]