MoneyMessage gang leaks Florida family services agency patient data

A Florida child welfare contractor says the MoneyMessage gang leaked 8,151 people's records online while a New Jersey PT clinic reported an email breach.

MedRisk Staff
By
2 Min Read

Patient records from a Florida agency that manages foster care and child welfare services have been published online by the MoneyMessage extortion group, according to a breach notice reviewed by HIPAA Journal.

Community Based Care of Brevard, which runs the region’s family services programs under a contract with the Florida Department of Children and Families, told 8,151 people their records were exposed after an intruder held network access from December 4, 2025, through January 2, 2026. Files pulled from the environment included names, birth dates, Social Security numbers, driver’s license numbers, state IDs, financial account information, and personal health data, and MoneyMessage has claimed responsibility, the agency’s substitute breach notice states.

Because the material is already public, the agency is urging affected individuals to watch for identity theft and fraud. No credit monitoring is on offer, and the organization said it is reviewing how sensitive records are stored and accessed.

A smaller disclosure came out of New Jersey, where a physical therapy clinic found an intruder inside a single employee email account. SportsMed Physical Therapy in Glen Rock spotted suspicious activity in the mailbox on May 8, 2026, and a review tied the exposure to patient names together with service dates, clinical details, and insurance information. The clinic said no misuse has been found, advised patients to stay vigilant, and has reported the breach to the HHS Office for Civil Rights.

The notices add to a steady stream of small-practice disclosures this year. For healthcare CISOs, they underline two realistic exposure paths: contractor-run agencies that hold child welfare records, and single-mailbox compromises that can quietly leak PHI.

Share This Article