Health Payment Systems, a Wisconsin-based healthcare billing technology company, reported a breach to the HHS Office for Civil Rights on July 10 that exposed the personal information of 9,380 individuals.
The company identified suspicious activity in its email environment on or around June 27, 2025, and secured the affected accounts. An investigation confirmed that an unauthorized party accessed certain employee email accounts between June 24 and June 27, 2025, and copied emails.
Exposed data included names, addresses, birth dates, identification numbers, and subscription IDs. The review of what was in the compromised mailboxes took more than a year to complete, and notification letters are now being mailed to affected individuals.
Health Payment Systems builds billing and payment software used by healthcare providers, which makes the incident a business associate matter for its clients. Billing vendors concentrate financial and demographic data across many provider organizations, so a compromise of their email systems can reach patients who have no direct relationship with the firm.
Providers that work with the company should confirm whether their own data was in scope, review their business associate agreements and breach notification obligations, and treat any emails purporting to come from the vendor with extra scrutiny.
