Billing vendor tells patients their data may have been taken

A Pennsylvania medical billing and records provider has begun notifying individuals after a July network disruption.

MedRisk Staff
By
2 Min Read

A Pennsylvania medical billing and health record company is warning patients that their clinical and personal information may have been compromised. Secure Healthcare Information Management, which serves healthcare practices, disclosed the incident after discovering trouble on its network.

An online notice the company posted on October 6, 2026 says the disruption surfaced on July 17. Between July 6 and July 16, an unauthorized party accessed or took personal information, the company concluded after working with cybersecurity specialists. On September 18 the company finished its review of the affected files and confirmed how far the exposure reached, and it mailed letters to people who may be affected the same day the web notice appeared.

Records that may have been exposed reach across both clinical and financial territory, from medical information and health insurance information to names, birth dates, Social Security numbers, and driver’s license or state identification numbers.

Attorneys working with ClassAction.org are weighing whether a class action can be filed and want to hear from people whose information was exposed.

Why it matters for healthcare security teams — billing intermediaries hold the same sensitive records as the practices they serve, often on smaller security budgets. A ten-day gap between first access and detection points to monitoring gaps a covered entity inherits. Before renewing a business associate agreement, security leaders should demand proof of logging, alerting, and incident-response timelines, not just a signature.

Share This Article