Homeless health network breach hits 185,000 Massachusetts residents

A network intrusion at Boston Healthcare for the Homeless Program exposed records of at least 184,914 state residents, while a Chicago clinic faces an Inc Ransom extortion claim.

MedRisk Staff
By
2 Min Read

At least 184,914 Massachusetts residents have been pulled into a breach at Boston Healthcare for the Homeless Program, a nonprofit that provides medical care to people experiencing homelessness. The organization said it first spotted a network disruption on November 11, 2025, and brought in third-party cybersecurity experts who confirmed an unauthorized party had accessed its systems.

The data review wrapped up on June 8, 2026, revealing exposed files with names, Social Security numbers, credit and debit card details, government identification numbers, financial account codes, medical records, and health insurance information. Affected individuals are being offered 12 months of credit monitoring, and the nonprofit has notified state attorneys general.

In a separate incident, Open Door Health Center of Illinois, a primary care and sexual health clinic in Chicago, appears to have had patient data stolen in a cyberattack. The clinic reported the breach to the HHS Office for Civil Rights with a placeholder estimate of at least 501 affected individuals, and no detailed notice has been posted yet. The Inc Ransom group added the clinic to its dark web leak site on May 21, 2026, claiming to have exfiltrated data.

Both cases show how providers serving vulnerable populations remain prime targets. The long gap between detection and final data review at the Boston nonprofit is a reminder that forensic timelines can stretch well past initial containment. Clinics facing Inc Ransom claims should treat any communication referencing stolen files as extortion-related, reset credentials, and prepare patient notification templates before OCR deadlines force a scramble.

Share This Article