Summary
- Environment: Date the three organizations say they detected unauthorized network access.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to a shared network and possible access or removal of files maintained by Operation PAR, Boley Centers, and Eleos. [1]
Impact
Potential exposure of patient or employee personal information in files accessed or removed from the affected network. [2][3][4]
Documented data types include:
- Names [2]
- Health insurance information — Operation PAR’s June 24 update says categories varied by individual; none of these fields is asserted for every person or for the other two organizations. [2]
- Clinical information [2]
- Dates of birth [2]
- Social Security numbers [2]
- Driver’s license numbers [2]
- Financial account information [2]
A cited record reports 145,714 individuals (Individuals listed for Operation PAR in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [2][3][4]
A cited record reports 375 individuals (Massachusetts residents affected according to incident report 2026-1031; not a national total; as of 2026-06-25). [2][3][4]
The joint notice says some files may have been accessed or removed by one or more unauthorized individuals; it does not identify them or the access method. [1]
At the time of the joint notice, the organizations said they had no evidence the recipient’s information had been used for financial fraud or identity theft. [1]
Timeline
Activity began
Start of the possible file-access or removal interval identified in the joint notice.
[1]Discovery
Date the three organizations say they detected unauthorized network access.
[1]Documented activity ended
End of the possible file-access or removal interval identified in the joint notice.
[1]Documented event
Date the organizations say their review determined that impacted files may have contained personal information.
[1]Public disclosure
Date Operation PAR says it began notifying affected individuals and date reported to Massachusetts OCA and HHS OCR.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The organizations say they secured the network, investigated with external cybersecurity professionals, strengthened the network, and implemented additional third-party recommendations; Operation PAR also says it reported the incident to law enforcement. The joint notice offered complimentary Epiq one-bureau credit monitoring and identity-protection features; the coverage length was redacted in the sample reviewed. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
