A Massachusetts medical group is notifying nearly 312,000 patients that a December intrusion into a legacy file server exposed Social Security numbers, financial account details, and personnel records.
Lifespan Physicians Group of Massachusetts, which operates as Brown Health Medical Group-MA, reported the incident to the Massachusetts and Vermont attorneys general after discovering unauthorized activity on the server on December 16, 2025. The forensic review found an unauthorized third party accessed the server between December 15 and 16, and confirmed the electronic medical record system was not involved.
File analysis completed June 22, 2026 determined the exposed data included names, dates of birth, contact information, Social Security numbers, driver’s license and other government ID numbers, credit and debit card numbers, financial account information, and human resources records with compensation and medical or disability-related data. The incident affected 290,357 Massachusetts residents and 86 Vermont residents, and the HHS Office for Civil Rights portal lists 311,760 individuals with potentially stolen protected health information.
The group said it implemented enhanced technical safeguards and is offering affected individuals 24 months of complimentary credit monitoring and identity theft protection. The roughly six-month gap between the intrusion and the completion of the data review underscores how long legacy systems can remain unexamined after a compromise.
