Modern Health Data Breach Exposes Sensitive Health Information of Limited Users
In November 2025, Modern Health, a San Francisco-based mental health care provider, detected unauthorized access to a small number of member profiles on its behavioral health platform. The breach involved an individual within its provider network who accessed sensitive data without authorization. The company promptly disabled the affected profiles and initiated an internal investigation, finalizing the list of impacted individuals by January 5, 2026.
The incident was officially disclosed to the Massachusetts Attorney General’s office on January 16, 2026, with only two affected individuals reported in the state. While Social Security numbers and financial data were not compromised, exposed information may have included protected health records, varying by individual.
Modern Health serves over 200 global companies through its digital platform, which offers therapy, coaching, and wellness tools to employees. Founded in 2017, the company employs more than 750 people.
Affected individuals were advised to monitor accounts and credit reports, though no further details on the scope of the breach or the number of impacted users beyond Massachusetts have been publicly confirmed. Shamis & Gentile P.A., a class action law firm, is investigating potential compensation for those affected.
Source: https://www.claimdepot.com/investigations/modern-health-data-breach-2026
Modern Health cybersecurity rating report: https://www.rankiteo.com/company/modern-health
"id": "MOD1768956524",
"linkid": "modern-health",
"type": "Breach",
"date": "6/2017",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Limited number (2 in '
'Massachusetts)',
'industry': 'Healthcare (Mental Health)',
'location': 'San Francisco, California, USA',
'name': 'Modern Health',
'size': '750+ employees',
'type': 'Company'}],
'attack_vector': 'Insider Threat',
'customer_advisories': 'Monitor accounts and credit reports',
'data_breach': {'personally_identifiable_information': 'Yes (varies by '
'individual)',
'sensitivity_of_data': 'High (health information)',
'type_of_data_compromised': 'Protected health records'},
'date_detected': '2025-11',
'date_publicly_disclosed': '2026-01-16',
'description': 'In November 2025, Modern Health detected unauthorized access '
'to a small number of member profiles on its behavioral health '
'platform. The breach involved an individual within its '
'provider network who accessed sensitive data without '
'authorization. The company disabled the affected profiles and '
'initiated an internal investigation, finalizing the list of '
'impacted individuals by January 5, 2026. The incident was '
'disclosed to the Massachusetts Attorney General’s office on '
'January 16, 2026, with only two affected individuals reported '
'in the state. Exposed information may have included protected '
'health records, though Social Security numbers and financial '
'data were not compromised.',
'impact': {'data_compromised': 'Protected health records',
'legal_liabilities': 'Potential class action investigation',
'systems_affected': 'Behavioral health platform'},
'investigation_status': 'Completed (list of impacted individuals finalized by '
'January 5, 2026)',
'post_incident_analysis': {'root_causes': 'Unauthorized access by an '
'individual within the provider '
'network'},
'recommendations': 'Affected individuals advised to monitor accounts and '
'credit reports',
'references': [{'source': 'Massachusetts Attorney General’s office '
'disclosure'}],
'regulatory_compliance': {'legal_actions': 'Class action investigation by '
'Shamis & Gentile P.A.',
'regulatory_notifications': 'Massachusetts Attorney '
'General’s office'},
'response': {'communication_strategy': 'Disclosure to Massachusetts Attorney '
'General’s office; advisories to '
'affected individuals',
'containment_measures': 'Disabled affected profiles',
'incident_response_plan_activated': 'Yes'},
'threat_actor': 'Individual within provider network',
'title': 'Modern Health Data Breach Exposes Sensitive Health Information of '
'Limited Users',
'type': 'Data Breach'}