Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers.
Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers.
The healthcare group identified a data security breach involving a legacy file server on December 16, 2025 and launched an investigation into the incident that found unauthorized access occurred between December 15–16, 2025. The organization immediately isolated the affected server. According to the notification letter, the security breach did not impact the electronic health record system.
The organization determined the potential scope of exposed data on June 22, 2026, and notified affected individuals as a precaution.
“We first became aware of a data security incident impacting a historic file server at the Practice on December 16, 2025. We immediately initiated an investigation and isolated the server. Through our investigation, we determined that the unauthorized access to the server occurred between December 15–16, 2025. This incident did not impact the Practice’s electronic health record system.” reads the data breach notification letter.
The compromised information may include personal details, employment and HR records, medical or disability-related information, government identification numbers, payment card data, and financial account information. Not all data categories were affected for every individual.
“Due to the nature of the incident, we have been unable to conclusively determine exactly what information was impacted. However, on June 22, 2026, we determined the scope of personal information that may have been impacted by this incident, and we are providing this notice out of an abundance of caution.” continues the letter.”The following are the categories of information that may have been impacted: demographic information (such as name, date of birth, and contact information); personnel and human resources records (such as compensation or payroll information, licensure or credentialing information, and medical or disability-related records); and other personal information (such as Social Security numbers, driver’s license numbers or other government-issued identification numbers, credit or debit card numbers, and financial account information). Not all categories of information were impacted for all individuals.”
The Practice stated that it is taking steps to address the incident, including employee retraining, additional security measures, and cooperation with law enforcement. It also offered affected individuals two years of free identity protection and fraud monitoring services through Experian IdentityWorks, while advising them to monitor financial accounts for suspicious activity.
Brown Health Medical Group-MA reported the breach to the U.S. HHS revealing that 311,760 individuals were impacted.

At this time, no ransomware group has claimed responsibility for the attack.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Brown Health Medical Group-MA)

