An intruder reached 280,000 patient files at a New York medical group

Premier Medical Group says the June intrusion reached more than 280,000 patients across its Hudson Valley practices.

MedRisk Staff
By
2 Min Read

An unauthorized party reached files inside a New York multi-specialty practice in June, and the group now says the exposure covers more than 280,000 patients.

Premier Medical Group of the Hudson Valley, P.C. said the intruder touched files on its systems on June 14, 2026, after the practice noticed disruption across parts of its IT environment. The group runs offices across the Hudson Valley and offers cardiology, dermatology, gastroenterology, neurology, plastic surgery, gynecology, and internal medicine. It brought in outside forensic investigators and called law enforcement.

By July 14, the review had tied the intrusion to a set of patient records. Depending on the individual, those files could hold names, contact details, dates of birth, health insurance information, provider names, internal patient identifiers, dates of service, medication information, and treatment or diagnostic details. PMG said it has tightened its privacy and security controls and is mailing notice letters to affected patients.

It is urging recipients to review statements from their providers and insurers and to flag any service they do not recognize, a standard warning because stolen treatment and billing data often resurfaces in medical-identity fraud.

The case echoes a pattern healthcare risk teams have tracked all year. Attackers frequently sit inside a practice for weeks before the scope of a file review is known, which stretches the gap between the intrusion and notification. Even when core clinical systems stay online, records pulled during that window can feed downstream fraud long after the incident is contained.

Share This Article