NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Nationwide Home Health Care Provider Announces Major Data Breach

Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir Medical Corporation in California, and Central Arkansas Pediatrics.

LHC Group

LHC Group, a Lafayette, Louisiana-based provider of home health, hospice, and home- and community-based services in 28 U.S. states and the District of Columbia, has been affected by a data security incident involving a third-party technology vendor. The unnamed vendor assisted LHC Group with referral management, care coordination, and clinical workflows, and the provision of those services required access to patients’ personal and protected health information.

LHC Group said it became aware on April 7, 2026, that an employee may have fallen victim to a voice phishing attack. LHC’s vendor subsequently reported suspicious activity within the vendor’s platform associated with an LHC user account. LHC worked closely with its vendor to secure systems and investigate the activity, and third-party cybersecurity experts were engaged to assist with those processes. LHC Group determined that the threat actor stole credentials in the vishing attack and accessed a large volume of files on the vendor’s platform, including files containing patients’ protected health information.  The threat actor had access from April 7, 2026, through April 15, 2026.

The impacted data was reviewed, and LHC started confirming the identities of the impacted individuals on July 9, 2026. The data types involved varied from individual to individual and included full names, addresses, dates of birth, demographic information, clinical summaries, treatment plans, diagnosis codes, dates of service, physician/provider information, Medicare/Medicaid numbers, health insurance information, and, in limited cases, Social Security numbers and/or financial information.

LHC Group said it disabled the compromised account, reviewed security measures to identify potential areas for improvement, enhanced authentication and monitoring, and strengthened other security controls. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for two years.

It is currently unclear how many individuals have been affected in total, but based on the breach notifications sent to state attorneys general, more than 28,000 individuals have been affected. The total is likely to be considerably higher, as not all state attorneys general publicly disclose how many state residents have been affected. This is the second data breach to be announced by LHC Group this year. LHC Group was also impacted by a breach at vendor Doctor Alliance.

Provident Behavioral Health

Provident Behavioral Health, a nonprofit provider of mental health care services in St. Louis, Missouri, has notified certain patients about a potential breach of their protected health information. Suspicious activity was identified within its computer network on April 3, 2026. The affected systems were isolated, and a third-party cybersecurity firm was engaged to investigate the activity and determine the nature and scope of the activity.

The investigation confirmed that an unauthorized third party had accessed its network and acquired data stored on the impacted systems. The data review concluded on September 4, 2026, when it was confirmed that patient data was present in the copied files, including names, contact information, demographic information, dates of birth, Social Security numbers, driver’s license numbers/state ID numbers, medical information, and health insurance information.

Provident Behavioral Health has confirmed there has been no further unauthorized access, and additional security measures have been implemented to prevent similar incidents in the future. As a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The incident has been reported to state attorneys general and the HHS’ Office for Civil Rights; however, it is currently unclear how many individuals have been affected.

Central Arkansas Pediatrics

Central Arkansas Pediatrics, P.A., a Conway, Arkansas-based medical practice that provides healthcare services for infants, children, and adolescents, has notified 1,500 current and former patients about a recent hacking incident that involved some of their personal and protected health information.

The data breach has been reported to the Department of Health and Human Services’ Office for Civil Rights; however, there is currently no substitute breach notice on the practice website, and no press release appears to have been released, so the exact types of data impacted are unknown, and the exact nature of the hacking incident has yet to be confirmed. This appears to have been a ransomware attack by a prolific ransomware-as-a-service group known as The Gentlemen. The group has conducted many attacks on healthcare providers and added Central Arkansas Pediatrics to its dark web data leak site on June 8, 2026, claiming data was exfiltrated in the attack

Elixir Medical Corporation

Elixir Medical Corporation, a Milpitas, California-based medical device company specializing in products for treating heart and vascular disease, has notified the California Attorney General about a recent security incident that exposed the data of current and former employees, consultants, and certain beneficiaries and dependents.

According to the notice, an unauthorized third party gained access to parts of its computer network between July 20, 2026, and July 21, 2026. The investigation confirmed that human resources files were exposed in the incident, which contained names and Social Security numbers, along with some or all of the following: driver’s license number, credit/debit card number, medical information, and/or direct deposit bank account information.

The affected individuals have been notified, and complimentary credit monitoring and identity theft protection services have been offered. Additional safeguards have been implemented, along with further security awareness training for the workforce. The number of affected individuals has not yet been publicly disclosed.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist