A Minneapolis translation and interpretation vendor has become the latest third party to expose health plan members, telling federal regulators that an intruder spent two days inside parts of its network.
United Language Group notified the HHS Office for Civil Rights that the protected health information of 4,649 people was caught up in the intrusion, spotted on July 9, 2025, and traced to unauthorized access across July 8 and 9. The data belonged to clients UnitedHealthcare and UnitedHealthcare Global and covered claims, billing and member or provider correspondence.
Exposed fields varied by person but included names, contact details, insurance identifiers, diagnoses, prescriptions, provider information, Social Security numbers, financial accounts, driver’s licenses, passports, military IDs and residence permits. Affected members were offered 24 months of credit monitoring.
The disclosure lands on a sector still working through the lesson that vendor connections are systemic risk, from the Change Healthcare clearinghouse outage to this year’s run of third-party intrusions.
Two other providers reported incidents in the same batch of filings. Desert Pulmonary & Sleep Consultants in Gilbert, Arizona, said a former physician partner copied more than 3,000 names, addresses and health records over three days beginning June 29, 2026, then handed the file to another person to mail letters advertising his new practice. The practice’s lawyers told him to stop and never heard back.
In Texas, Azle Cube Smiles told the state attorney general that a May 26 attack on remote desktop session hosts exposed 2,940 residents’ names, birth dates, license numbers and medical information. The dental practice reset passwords office-wide and restored its records platform.