AcademyHealth Hit by SAFEPAY Ransomware Attack, Exposing Sensitive Data
AcademyHealth, a non-partisan professional organization focused on health policy and research, suffered a ransomware attack in April 2026, resulting in the exposure of sensitive personal and financial data. The breach was carried out by the cybercriminal group SAFEPAY, which claimed on the dark web on April 6, 2026, that it had stolen the organization’s data and threatened to publish it within a day.
The incident was formally disclosed to the Vermont Attorney General on July 27, 2026, though the full scope of affected individuals remains unreported. Compromised data includes credit and debit account details, financial account codes, government ID numbers, and Social Security numbers.
Class action law firm Shamis & Gentile P.A. is investigating the breach on behalf of potentially impacted individuals, who may be eligible for compensation. AcademyHealth, formed in 2000 through the merger of the Alpha Center and the Association for Health Services Research, serves as a key resource for health policy professionals through conferences, training, and research translation. The attack highlights ongoing risks to organizations handling sensitive data.
Source: https://www.claimdepot.com/investigations/academyhealth-data-breach-2026
AcademyHealth cybersecurity rating report: https://www.rankiteo.com/company/academyhealth
"id": "ACA1785278349",
"linkid": "academyhealth",
"type": "Ransomware",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Health policy and research',
'name': 'AcademyHealth',
'type': 'Non-profit professional organization'}],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credit and debit account '
'details',
'Financial account codes',
'Government ID numbers',
'Social Security numbers']},
'date_detected': '2026-04',
'date_publicly_disclosed': '2026-07-27',
'description': 'AcademyHealth, a non-partisan professional organization '
'focused on health policy and research, suffered a ransomware '
'attack in April 2026, resulting in the exposure of sensitive '
'personal and financial data. The breach was carried out by '
'the cybercriminal group SAFEPAY, which claimed on the dark '
'web on April 6, 2026, that it had stolen the organization’s '
'data and threatened to publish it within a day. Compromised '
'data includes credit and debit account details, financial '
'account codes, government ID numbers, and Social Security '
'numbers.',
'impact': {'data_compromised': 'Sensitive personal and financial data',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential class action investigation',
'payment_information_risk': 'High'},
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'SAFEPAY'},
'references': [{'source': 'Dark web claim by SAFEPAY'},
{'date_accessed': '2026-07-27',
'source': 'Vermont Attorney General disclosure'},
{'source': 'Shamis & Gentile P.A. class action investigation'}],
'regulatory_compliance': {'legal_actions': 'Class action investigation by '
'Shamis & Gentile P.A.',
'regulatory_notifications': 'Vermont Attorney '
'General'},
'threat_actor': 'SAFEPAY',
'title': 'AcademyHealth Hit by SAFEPAY Ransomware Attack, Exposing Sensitive '
'Data',
'type': 'Ransomware'}