Multiple Healthcare and Service Providers Hit by Data Breaches Affecting Nearly 87,000 Individuals
Four organizations across the U.S. have reported significant data breaches, exposing sensitive personal and health information of nearly 87,000 individuals. The incidents, detected between 2025 and 2026, involved unauthorized access to networks and email systems, with some cases linked to cybercriminal activity.
NFI North (New Hampshire/Maine)
NFI North, a nonprofit providing mental health and behavioral support services, disclosed a breach affecting 49,540 individuals. Suspicious activity was detected on September 6, 2025, with an investigation concluding on July 6, 2026. Compromised data included names, addresses, birth dates, Social Security numbers, driver’s license details, financial account information, medical records, and health insurance data. The organization implemented additional safeguards following the incident.
Nephrology Associates (Kansas/Missouri)
A network of kidney care clinics reported a breach impacting 24,088 patients. Unauthorized access occurred between January 17 and April 9, 2026, with the intrusion detected on April 9. Exposed data included names, birth dates, Social Security numbers, driver’s license numbers, treatment details, and health insurance information. While no misuse has been confirmed, affected individuals were offered credit monitoring services. The breach appears linked to the cybercriminal group The Gentlemen, which allegedly offered the data for sale.
PAMCAH-UA Local 675 Health and Welfare Fund (Hawaii)
A Honolulu-based benefits provider for union plumbers and fitters disclosed unauthorized access to employee email accounts between September 23 and October 9, 2025. The breach exposed 8,319 individuals’ personal and health data, including names, birth dates, medical records, insurance details, driver’s license numbers, and Social Security numbers. Notification letters were sent to affected parties.
Indico Data Solutions (Massachusetts)
An AI-powered software company reported a breach affecting 4,840 individuals, confirmed on May 7, 2026. Compromised data included names, addresses, and Social Security numbers. The company responded by rotating credentials, tightening access controls, and offering credit monitoring to impacted individuals.
The breaches highlight ongoing vulnerabilities in healthcare and service provider systems, with sensitive data remaining a prime target for cybercriminals.
Source: https://www.hipaajournal.com/nfi-north-nephrology-associates-data-breaches/
NFI cybersecurity rating report: https://www.rankiteo.com/company/nfi
"id": "NFI1788864149",
"linkid": "nfi",
"type": "Breach",
"date": "9/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '49,540',
'industry': 'Healthcare (Mental Health and Behavioral '
'Support)',
'location': 'New Hampshire/Maine, USA',
'name': 'NFI North',
'type': 'Nonprofit'},
{'customers_affected': '24,088',
'industry': 'Healthcare (Kidney Care)',
'location': 'Kansas/Missouri, USA',
'name': 'Nephrology Associates',
'type': 'Healthcare Provider'},
{'customers_affected': '8,319',
'industry': 'Healthcare/Insurance',
'location': 'Honolulu, Hawaii, USA',
'name': 'PAMCAH-UA Local 675 Health and Welfare Fund',
'type': 'Benefits Provider'},
{'customers_affected': '4,840',
'industry': 'Technology (AI-Powered Software)',
'location': 'Massachusetts, USA',
'name': 'Indico Data Solutions',
'type': 'Software Company'}],
'attack_vector': ['Unauthorized network access', 'Unauthorized email access'],
'customer_advisories': 'Credit monitoring services offered to affected '
'individuals',
'data_breach': {'data_exfiltration': 'Allegedly sold on dark web (Nephrology '
'Associates)',
'number_of_records_exposed': '86,787',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (PII, PHI, financial data)',
'type_of_data_compromised': ['Names',
'Addresses',
'Birth dates',
'Social Security numbers',
'Driver’s license details',
'Financial account information',
'Medical records',
'Health insurance data',
'Treatment details']},
'date_detected': ['2025-09-06', '2026-04-09', '2025-09-23', '2026-05-07'],
'date_resolved': ['2026-07-06'],
'description': 'Four organizations across the U.S. have reported significant '
'data breaches, exposing sensitive personal and health '
'information of nearly 87,000 individuals. The incidents, '
'detected between 2025 and 2026, involved unauthorized access '
'to networks and email systems, with some cases linked to '
'cybercriminal activity.',
'impact': {'data_compromised': 'Sensitive personal and health information',
'identity_theft_risk': 'High',
'payment_information_risk': 'High (for NFI North)',
'systems_affected': ['Networks', 'Email systems']},
'initial_access_broker': {'data_sold_on_dark_web': 'Alleged (Nephrology '
'Associates)'},
'investigation_status': 'Completed (NFI North), Ongoing (others)',
'motivation': 'Cybercriminal activity (data theft/sale)',
'post_incident_analysis': {'corrective_actions': ['Additional safeguards',
'Credential rotation',
'Access control tightening'],
'root_causes': 'Unauthorized access to '
'networks/email systems'},
'references': [{'source': 'Cyber Incident Report'}],
'response': {'communication_strategy': ['Notification letters sent to '
'affected parties'],
'containment_measures': ['Rotated credentials',
'Tightened access controls'],
'remediation_measures': ['Additional safeguards',
'Credit monitoring services']},
'threat_actor': 'The Gentlemen (linked to Nephrology Associates breach)',
'title': 'Multiple Healthcare and Service Providers Hit by Data Breaches '
'Affecting Nearly 87,000 Individuals',
'type': 'Data Breach'}