Patient notifications are going out from five US health organizations over intrusions that exposed personal and medical records, with the largest disclosure involving a Dallas community health center serving the LGBTQIA+ community.
Resource Center of Dallas is notifying 12,490 individuals after an unauthorized party reached its network for eight days in February 2026 and removed files. Names, birth dates, medical details, insurance data, and Social Security numbers for certain individuals were among the records, according to the notice. The center said it has reviewed and strengthened its privacy and security practices.
A California behavioral health provider is also affected through its management company. Kern Psychiatric Health and Wellness Center in Bakersfield told state regulators that Genesis Healthcare Management spotted suspicious activity on June 22, 2026, with patient records including diagnoses, lab results, Medicare and Medicaid numbers, and government identification numbers among the exposed data.
Two more disclosures trace to smaller windows of access. Philadelphia allergy practice Allergic Disease Associates, known as The Asthma Center, found network access spanning roughly three weeks from late October 2025 that may have exposed diagnosis, prescription, and treatment information. Dallas emergency medicine group Integrative Emergency Services is notifying 2,009 patients after an intruder held an employee email account for four hours on June 16, 2026, viewing a message with names and medical record identifiers.
Houston psychiatric practice Psychiatry of Texas, operating as PsychPlus, is notifying 4,565 patients about a March 31, 2026 network intrusion. Records in the accessed files included names, Social Security numbers, diagnoses, insurance details, and account credentials. No ransomware involvement was indicated in any of the five incidents.