A breach at a north-central Massachusetts health system exposed sensitive patient information, according to a filing with Vermont’s attorney general.
The September 10 disclosure from Heywood Healthcare lists Social Security numbers, government identification numbers and health records among the data involved. The organization has not yet published how many people were affected or a detailed timeline.
Heywood operates Henry Heywood Memorial Hospital in Gardner, Athol Hospital and Heywood Medical Group, giving it a patient base that spans north-central Massachusetts and reaches into neighbouring states.
Attorneys have begun soliciting affected patients about a possible class action.
The mix of data types is the alarming part. When Social Security numbers and government IDs sit alongside clinical records, victims face both identity-theft and medical-fraud risk, and the second is harder to unwind.
The breach reinforces a familiar gap for smaller and mid-sized health systems: identity data and clinical data often live in the same environment. Segregating those stores, tightening identity controls and watching for anomalous record access can limit how much a single intrusion yields.
Affected patients should watch explanation-of-benefits statements and credit reports for unfamiliar activity and consider a fraud alert or credit freeze.