Particle.news
Download on the App Store

Brown Health Data Breach Exposes Records for 311,760 People

The disclosure raises identity‑theft and financial risk for a large patient population and could trigger HHS and state regulatory review.

Overview

  • Brown Health Medical Group‑MA says an unauthorized party accessed a legacy file server between December 15 and 16, 2025 and the practice first identified the incident on December 16, 2025.
  • On June 22, 2026 the organization completed its scope review and has now reported that 311,760 individuals may have been affected, including 290,357 Massachusetts residents.
  • Potentially exposed records include names, contact details, dates of birth, Social Security and driver’s license numbers, medical and disability information, payroll and HR files, and payment or financial account data.
  • The practice says its electronic health record system was not affected, it isolated the compromised legacy server, began staff retraining, added security measures, and is cooperating with law enforcement.
  • Brown Health is offering two years of Experian IdentityWorks monitoring to those notified, no threat actor or ransom group has been publicly identified, and the breach could lead to further HIPAA oversight or civil inquiries.