Pinnacle Holdings Suffers Major Data Breach Exposing Patient and Healthcare Data
Healthcare consulting firm Pinnacle Holdings, LTD disclosed a data breach that compromised sensitive information belonging to patients of its healthcare organization clients. The incident was detected on November 25, 2024, after the company identified a network disruption affecting internal systems. An investigation revealed that an unauthorized actor accessed and potentially exfiltrated data from Pinnacle Holdings’ network between November 11 and November 25, 2024.
The breach exposed a wide range of personally identifiable information (PII) and protected health information (PHI), including:
- Personal details: Names, addresses, phone numbers, email addresses, Social Security numbers, driver’s license/state ID numbers, taxpayer ID numbers, passport numbers, dates of birth, and biometric data.
- Financial data: Payment card details and financial account information.
- Medical and insurance records: Treatment and diagnosis information, prescription details, patient and encounter ID numbers, provider names, medical record numbers, Medicare/Medicaid numbers, health insurance details, claim and policy numbers, and treatment cost information.
In response, Pinnacle Holdings has begun mailing notification letters to affected individuals and established a dedicated call center (1-866-686-2607) for inquiries, operating Monday through Friday from 9 a.m. to 6:30 p.m. ET. The company is also offering complimentary credit monitoring services to impacted parties. The breach underscores the heightened risks of identity theft and fraud due to the breadth of exposed data.
Source: https://www.claimdepot.com/data-breach/pinnacle-holdings-2026
Pinnacle Healthcare cybersecurity rating report: https://www.rankiteo.com/company/pinnacle-healthcare
"id": "PIN1772404120",
"linkid": "pinnacle-healthcare",
"type": "Breach",
"date": "11/2024",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'name': 'Pinnacle Holdings, LTD',
'type': 'Healthcare Consulting Firm'}],
'customer_advisories': 'Mailing notification letters to affected individuals; '
'established a dedicated call center (1-866-686-2607) '
'for inquiries',
'data_breach': {'data_exfiltration': 'Potentially exfiltrated',
'personally_identifiable_information': ['Names',
'Addresses',
'Phone numbers',
'Email addresses',
'Social Security '
'numbers',
'Driver’s '
'license/state ID '
'numbers',
'Taxpayer ID numbers',
'Passport numbers',
'Dates of birth',
'Biometric data',
'Payment card details',
'Financial account '
'information',
'Treatment and '
'diagnosis '
'information',
'Prescription details',
'Patient and '
'encounter ID numbers',
'Provider names',
'Medical record '
'numbers',
'Medicare/Medicaid '
'numbers',
'Health insurance '
'details',
'Claim and policy '
'numbers',
'Treatment cost '
'information'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Protected health information '
'(PHI)']},
'date_detected': '2024-11-25',
'description': 'Healthcare consulting firm Pinnacle Holdings, LTD disclosed a '
'data breach that compromised sensitive information belonging '
'to patients of its healthcare organization clients. The '
'incident was detected on November 25, 2024, after the company '
'identified a network disruption affecting internal systems. '
'An investigation revealed that an unauthorized actor accessed '
'and potentially exfiltrated data from Pinnacle Holdings’ '
'network between November 11 and November 25, 2024.',
'impact': {'data_compromised': 'Personally identifiable information (PII) and '
'protected health information (PHI)',
'identity_theft_risk': 'Heightened risks of identity theft and '
'fraud',
'operational_impact': 'Network disruption',
'payment_information_risk': 'Exposure of payment card details and '
'financial account information',
'systems_affected': 'Internal systems'},
'investigation_status': 'Ongoing',
'recommendations': 'Offering complimentary credit monitoring services to '
'impacted parties',
'response': {'communication_strategy': 'Mailing notification letters to '
'affected individuals; established a '
'dedicated call center '
'(1-866-686-2607) operating Monday '
'through Friday from 9 a.m. to 6:30 '
'p.m. ET'},
'title': 'Pinnacle Holdings Suffers Major Data Breach Exposing Patient and '
'Healthcare Data',
'type': 'Data Breach'}