[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2xkw1sxtzceym":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":23,"affectedCount":23,"affectedCountStatus":24,"affectedCountLowerBound":13,"affectedCountUnit":25,"hasEnglishDescription":4,"contentLocale":26,"availableLocales":27,"translations":29,"severity":32,"dataClasses":33,"description":55,"seoTitle":56,"seoDescription":57,"logoUrl":58,"isVerified":4,"isSensitive":4,"isSpamList":59,"isMalware":59,"company":60},"6a4f90c3787822b3cace5f47","Community Health Center 2024","Community Health Center 2024 Data Breach","community-health-center-2024","chc1.com","2024-10-14T00:00:00.000Z","2026-07-09T12:14:59.296Z",null,"2026-07-19T00:11:09.969Z","Notice letter; Maine AG; HHS OCR; healthcare security reporting; official website logo","https:\u002F\u002Fwww.classaction.org\u002Fmedia\u002Fcommunity-health-center-inc-data-breach-notice.pdf",[16,18,19,20,21,22],"https:\u002F\u002Fwww.maine.gov\u002Fagviewer\u002Fcontent\u002Fag\u002F985235c7-cb95-4be2-8792-a1252b4f8318\u002Fef9efbea-06fa-4d12-814a-40c6e4456e72.html","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf","https:\u002F\u002Fwww.hipaajournal.com\u002Fcommunity-health-center-data-breach\u002F","https:\u002F\u002Fwww.classaction.org\u002Fdata-breach-lawsuits\u002Fcommunity-health-center-inc-january-2025","https:\u002F\u002Fwww.chc1.com\u002F",1060936,"known","unknown","en",[26,28],"tr",{"en":30,"tr":31},{"slug":9},{"slug":9},"Critical",[34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54],"Names","Dates of birth","Physical addresses","Phone numbers","Email addresses","Diagnoses","Treatment information","Test results","Social security numbers","Health insurance information","Guarantor information","Progress notes","Medications","Records from other providers","Demographic information","Gender","Race","Ethnicity","COVID-19 test information","Vaccine information","Protected health information","\u003Cp>Community Health Center 2024 data breach is an unauthorized access incident affecting patient data in the computer systems of Connecticut-based Community Health Center, Inc. The organization reported that on January 2, 2025, it noticed unusual activity in its systems, initiated a review with external experts the same day, and strengthened system security. The review revealed that a skilled criminal had accessed the system and obtained some data. It was assessed that the access initially occurred on October 14, 2024, but the incident was detected on January 2, 2025.\u003C\u002Fp>\n\u003Cp>The incident carries serious risk because it involves highly sensitive areas such as health records, identification information, contact information, and test and treatment data. The number of affected individuals has been reported as 1,060,936. This number is not the count of unique online accounts confirmed to have been leaked, but the impact figure used for individuals reported or determined to be affected within the scope of the incident. Community Health Center records may include current and former patients, parents or guardians of child patients, individuals who received COVID testing or vaccination services, guarantors, and those providing insurance on behalf of a patient, so the types of data may vary from person to person.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Within the scope of the Community Health Center incident, types of data that may be at risk include first and last name, date of birth, physical address, phone number, email address, diagnoses, treatment details, test results, Social Security number, and health insurance information. In pediatric patient notifications, guarantor information, progress notes, medication information, records obtained from other providers, and similar health record fields are also specified. In additional notifications, fields such as demographic information, gender, race, ethnicity, COVID test date and result, as well as vaccine type, dose, and administration date are also associated with the incident.\u003C\u002Fp>\n\u003Cp>When these types of data are evaluated together, the risk is not limited to contact information alone. Health data may contain personal information regarding a person's diagnosis, treatment, tests, medications, and vaccination history. Persistent identifiers such as Social Security number and date of birth increase the risk of identity theft and fraudulent applications. Health insurance information can be targeted for fraudulent service claims or insurance abuse. For child patients and guarantors, the risk may last longer, as identity information belonging to children can be misused for years without being noticed.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>In this record, the start of the violation is used as October 14, 2024, and the date the incident was detected as January 2, 2025. The organization reported that the attacker's access was stopped within hours, no data was deleted or locked, and daily operations were not affected. Therefore, the record does not contain any claim of operational disruption such as file encryption or prolonged system downtime. The risk arises from health and identity files that the attacker may have obtained.\u003C\u002Fp>\n\u003Cp>Since data classes can vary from person to person, the record does not claim that all fields are present for every individual. For example, the fields included in an adult patient notification may differ from those in a child patient or guarantor notification. For individuals receiving a COVID test or vaccination service, fields such as test date, result information, vaccine type, dose, and administration date may be prominent. The types of data listed on this page show verified categories associated with the event; person-specific exact fields should be evaluated according to the details in the notification letter.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The primary group at risk consists of current and former patients receiving health, dental, behavioral health, school-based health services, or similar clinical services through Community Health Center, Inc. Additionally, individuals who received COVID testing or vaccination services at a clinic operated by CHC, guarantors who provide payment or insurance information on behalf of a patient, parents, guardians, and certain staff groups may also fall within the scope of the incident. Even if a person does not directly recall the CHC name, they may have registered through a local clinic, school-based service, or testing center.\u003C\u002Fp>\n\u003Cp>The risk is more sensitive for child patients because children's identity data can be used without detection until adulthood. Individuals with health insurance information may face fake service requests or incorrect billing. Those with diagnosis, test result, treatment detail, medication, or vaccine information have a higher privacy risk. People with Social Security numbers should be cautious about credit and official application fraud. Individuals with email and phone information should be careful about messages that arrive under the pretext of health services, test results, vaccination records, or identity protection.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Individuals who may have been affected by this incident should first check which types of data are included in the notification sent to them. If a Social Security number is included, a credit report should be obtained, and options such as credit freezing or fraud alerts should be considered. For child patients, parents or guardians should check whether there is a credit file in the child's name and, if necessary, look into the steps for freezing child credit. Individuals with health insurance information should regularly check their explanation of benefits, insurance claims, and any unknown health services.\u003C\u002Fp>\n\u003Cp>Affected individuals should review medical records, diagnoses, treatment, test results, medication, or vaccination information in the patient portal and health service records. If an unrecognized service, incorrect record, unexpected bill, or unknown provider name is observed, written communication should be established with the relevant institution. Users should not click on unexpected links that come under the pretext of free identity protection, health record updating, test results, or insurance correction. Channels in the notification letter or independently verified channels should be used to communicate with the institution.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Protection should be long-term in events affecting both health and identity data, such as the Community Health Center 2024 data breach. Changing passwords may be helpful, but it is not sufficient on its own since the incident also involves permanent identity and health data. Users should regularly review their credit reports, be cautious of fraudulent applications before the tax season, monitor health insurance claims, and promptly correct any unfamiliar information in their medical records.\u003C\u002Fp>\n\u003Cp>Unique and strong passwords should be used on patient portals, and multi-factor login should be enabled wherever possible. For pediatric patients, parents or guardians should continue to monitor identity and credit checks not only during the initial reporting period but also in the following years. Since vaccination, test, diagnosis, or treatment information are private and sensitive areas, one should be cautious against personalized fraudulent messages using this information. When a suspicious transaction, faulty health record, or unknown insurance claim is observed, the date, institution name, transaction number, and correspondence records should be kept.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The record check on this page allows users to view personal and health data records that may be associated with the Community Health Center 2024 data breach. A match does not mean that all types of data listed have been exposed for the same individual. Users should rely on the fields in their own notification letters and assess different risks depending on whether they are an adult patient, child patient, guarantor, or recipient of COVID services.\u003C\u002Fp>\n\u003Cp>After users see the impact status, they should prioritize the steps according to the data type. Credit and official application checks should be prioritized for identity data, patient and insurance records for health data, and long-term identity protection checks for child data. The Community Health Center 2024 data breach is a large-scale health data security incident that demonstrates why rapid detection and data classification in healthcare institutions are critical for user safety.\u003C\u002Fp>","Community Health Center 2024 Data Breach (1.1 Million Reported Records)","Community Health Center 2024 Data Breach. 1.1 Million reported records are reported. Reported data: Names, Dates of birth, Physical addresses. Review the…","\u002Fuploads\u002Flogo\u002Fcommunity-health-center-2024.svg",false,{"name":61,"sector":62,"country":63,"website":10,"websiteArchiveUrl":64,"websiteStatus":64,"websiteCheckedAt":13},"Community Health Center, Inc.","Healthcare","United States",""]