A Syracuse GI practice and a Dallas hospice group report breaches

An upstate New York digestive health practice and a Texas hospice group have begun notifying patients about intrusions that took months to uncover.

MedRisk Staff
By
2 Min Read

A New York digestive health practice and a Texas hospice group have each begun notifying patients about intrusions that took months to untangle.

A Syracuse-area digestive health practice spent months untangling an incident it first noticed on March 6, 2026. Gastroenterology & Hepatology of Central New York treats liver disease and digestive disorders from offices in Liverpool and Syracuse, and it brought in outside forensics to contain the threat and establish what was taken. The intruder walked off with patient identifiers, including names, addresses, phone numbers, birth dates, Social Security numbers, and medical record numbers. Notices went out on September 17, 2026, alongside credit monitoring and identity theft protection. No misuse has surfaced yet.

A second disclosure came out of Texas, where an intruder sat in limited email accounts at a hospice provider from August 8, 2025. Three Oaks Hospice of Dallas runs hospice and palliative care with sister providers Agape Hospice Care, Elevation Hospice of Colorado, and Sage Hospice of Arizona across nine states. Its affiliated hospices were not told until August 17, 2026, more than a year on. The affected records hold identity and insurance details together with medical information. Texas regulators were told 3,034 residents were caught up; no national tally has been released.

Both cases follow the same lag pattern: an intrusion dated to 2025 or early 2026, and disclosure landing only now, after forensic review.

Share This Article