New York disability agency breach exposes 1,918 clients’ health files

The New York disability agency ANIBIC told 1,918 members their health files were accessed in a March network intrusion.

MedRisk Staff
By
2 Min Read

A New York nonprofit serving people with developmental and neurological disabilities has told federal regulators that files on 1,918 program members were accessed without authorization in early March.

The Association for Neurologically Impaired Brain Injured Children, or ANIBIC, reported the incident to the HHS Office for Civil Rights after spotting suspicious activity in its network on or around March 8, 2026. Its investigation determined that an unauthorized party opened files containing member information on March 7 and March 8, and notification letters went out on July 17. The substitute breach notice lists names, contact details, Social Security numbers, dates of birth, health insurance information, and service records covering diagnoses, treatment, and prescriptions among the exposed categories.

Members whose Social Security numbers were involved are being offered identity monitoring. The notice does not name a threat actor or say whether any data appeared on a leak site.

The case reflects a trend security researchers have flagged all year: smaller care organizations with lean security teams are absorbing intrusions that expose deeply sensitive PHI, including disability diagnoses and prescription records.

Disability service agencies rarely make headlines, but they sit squarely inside the HIPAA ecosystem and hold some of the most sensitive health information a person carries, which makes them a meaningful target for credential theft and extortion.

Share This Article