xHealth Data Breach Affects 118,000 Individuals
A data breach at zHealth, a practice management and EHR software provider, has affected 118,000 individuals. Data breaches have also been announced by Bridgeway Benefit Technologies, Longview ER Operations, and HealthStream.
zHealth
zHealth, Inc., a San Francisco, California-based cloud-based practice management and electronic health records (EHR) software provider, has disclosed a cybersecurity incident that may have involved data being acquired by an unauthorized third party. According to the breach notice provided to the California Attorney General, zHealth became aware that certain information may have been copied on or around June 15, 2026. An investigation was launched, which confirmed that its network had been accessed by an unauthorized third party between January 20 and January 21, 2026. The review of the impacted data was completed on September 3, 2026.
The substitute breach notice on the zHealth website states that the impacted information varies from individual to individual and may include names, medical information, and health insurance information. The affected individuals have been offered single-bureau credit monitoring, credit report, and credit score services for 12 months. Data privacy and security policies and procedures have been reviewed and enhanced to prevent similar incidents in the future. The incident is not currently shown on the HHS’ Office for Civil Rights website; however, the Oregon Attorney General has been informed that the data breach affected 118,563 individuals.
Bridgeway Benefit Technologies
Bridgeway Benefit Technologies, a Baltimore, Maryland-headquartered third-party health plan administrator that provides software for managing multiemployer health, welfare, and retirement benefits, has notified the HHS Office for Civil Rights about a breach of the protected health information of 9,268 individuals. The company explained that it experienced a cybersecurity incident involving an employee email account that exposed data provided to the company in connection with the administration services it provides to its clients. The unauthorized activity was identified on May 18, 2026, and the forensic investigation determined that the account was accessed between March 5, 2026, and May 19, 2026.
Bridgeway Benefit Technologies confirmed that the breach was limited to its own email system. No client systems were compromised in the incident. The exact types of data involved are detailed in the individual notification letters. Attorneys General have been notified that the compromised data includes Social Security numbers. Steps have been taken to improve security to prevent similar incidents in the future, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.
Longview ER Operations
Longview ER Operations, LLC, doing business as Hospitality Health ER, a full-service emergency room operator with facilities in Longview, Tyler, and Galveston, Texas, has experienced a cybersecurity incident that involved patient data. Suspicious network activity was identified on July 22, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity professionals.
The investigation confirmed that an unauthorized third party had accessed its network and copied files. The file review is ongoing, and patients will be notified by mail as soon as the review is concluded. The notification letters will explain the types of information involved for each patient. The incident was limited to the Longview network. The facilities in Tyler and Galveston were unaffected. The number of affected individuals has not yet been determined. The incident has been reported to the HHS’ Office for Civil Rights using an estimate of at least 501 individuals. The total will be updated when the review is completed.
HealthStream
HealthStream Inc., a Nashville, Tennessee-based healthcare technology company that provides software and training solutions for the healthcare industry, has notified the Massachusetts Attorney General about a recent security incident. The letter provides no information about the nature of the data breach, other than stating that some “information” was involved and complimentary credit monitoring and identity theft protection services have been offered for 24 months. “Due to requirements imposed by Massachusetts law, we are unable to provide you with the details about the nature of this incident,” states the notification letter.
The notification letters appear to be about a cybersecurity incident reported to the U.S. Securities and Exchange Commission (SEC) on July 29, 2026. According to the Form 8-K filing, the incident involved unauthorized access to corporate file servers and does not appear to have involved protected health information. Data compromised in the incident included employee data, customer and vendor billing data, and legal information. Around 75 of its credentialing customers have been affected. HealthStream said no customer-facing systems were involved, there was no file encryption, operations were not disrupted, and the incident is unlikely to affect its financial position or results.



