[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1riesbog3z9hh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":13,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":35,"seoTitle":36,"seoDescription":37,"logoUrl":38,"isVerified":4,"isSensitive":4,"isSpamList":39,"isMalware":39,"company":40},"6a4cfaa4a85f57e170ce5f47","Gastro Health 2026","Gastro Health 2026 Data Breach","gastro-health-2026","gastrohealth.com","2026-02-25T00:00:00.000Z","2026-07-07T13:09:56.622Z",null,"2026-07-19T00:10:30.024Z","Manual reviewed breach record","",[],35632,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":9},{"slug":9},"Medium",[29,30,31,32,33,34],"Names","Dates of birth","Social security numbers","Government issued IDs","Personal health data","Health insurance information","\u003Cp>The Gastro Health 2026 data breach involves two separate phishing incidents affecting patient and identity information at a healthcare organization serving numerous gastroenterology clinics in the United States. In a notice issued by the institution, it was stated that the first incident was detected on February 25, 2026, after some staff responded to phishing messages. This incident led to unauthorized access to certain files and systems that the affected staff could access. The second separate incident was identified on March 2, 2026, involving a similar phishing process that included an employee. The investigation revealed that the affected files contained personal and health information of some individuals. The total number of affected individuals was recorded as 35,632; this record represents the combined user risk of the two incidents disclosed under the same notice by the same institution.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The official notification clearly states that the types of data affected vary from person to person. Possible data fields include name, date of birth, Social Security number, government or state-issued identification number, medical record number, patient account number, Medicare or Medicaid number, health insurance or group account number, diagnosis or treatment information, prescription information, and provider or clinic information. It is also stated that payment card information was not affected by this incident. Therefore, the data classes in the record are kept narrow and verifiable: Names, Dates of birth, Social security numbers, Government issued IDs, Personal health data, and Health insurance information. Not all fields should be assumed to be present for each individual; the record represents the secure upper limit of the possible types of data disclosed.\u003C\u002Fp>\n\u003Cp>The presence of these fields together creates a more serious scenario than the risk posed by ordinary contact information. Date of birth and government ID information can be abused in identity verification processes. Social Security numbers pose risks such as credit account openings, fraudulent account applications, and identity theft. Medical record numbers, patient account numbers, diagnosis, treatment, and prescription information should be considered sensitive in terms of health privacy. Insurance and Medicare or Medicaid-related information can be used in fraudulent health claims, misdirected billing, or personalized scam scenarios. Therefore, the incident is not a simple account security warning that can be resolved merely by changing the password.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The first verified date of the incident is February 25, 2026. This date has been used as the day when the first phishing incident was noticed. The second incident was identified on March 2, 2026, and it was described as a separate incident within the same institution announcement. The total number of individuals has been entered as 35,632; this number is consistent with the total number of affected individuals seen in regulatory notifications. The record has been marked as verified because the type of incident, dates, institution name, data fields, and total number of individuals are supported by multiple open sources.\u003C\u002Fp>\n\u003Cp>The scope limitation is equally important. This record does not claim that payment card information, user passwords, bank account, or phone numbers have been leaked. The official announcement clearly states that payment card information was not affected. Since addresses, email addresses, or phone numbers were not listed as separate data fields in the notification, these fields were not added to the record. It is understood that unauthorized access occurred through personnel access areas and that personal information was present in the relevant files; therefore, the record has been classified as a health data risk originating from file and system access. Broader claims have not been used in this record unless there is definitive evidence.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of current or former patients who have been directly informed by Gastro Health. Since gastroenterology services work with sensitive health data such as diagnosis, treatment, prescriptions, clinical information, and insurance records, the privacy risk for affected individuals is high. When a person's name, date of birth, and health information are used together, attackers can create realistic-looking appointment, prescription, invoice, insurance, or patient portal messages. For individuals with a Social Security number or government ID number, the risk of financial identity theft additionally increases.\u003C\u002Fp>\n\u003Cp>Family members acting on behalf of the patient, legal representatives, or individuals involved in payment processes may also be indirectly at risk. Records that include Medicare, Medicaid, or group health insurance numbers can be used in fraud attempts involving false claims, incorrect service reporting, or people acting as institutional representatives. Areas such as diagnosis and prescription information allow for the creation of more convincing scenarios targeting the person's health history. Therefore, affected users should regularly check not only their credit activity but also health insurance statements, treatment records, and unusual activity in the patient portal.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Individuals who are notified should first review health insurance statements, patient account activities, and treatment or prescription records they do not recognize. If a service they did not receive, an unexplained bill, incorrect clinical information, or an unexpected insurance claim appears, they should contact the relevant provider and insurance plan directly. Those whose Social Security number or government ID information may have been affected should check their credit reports and, if deemed necessary, consider fraud alerts or credit freezes. Authentication should not be done through unknown links, and communication with institutions should be conducted through known official channels.\u003C\u002Fp>\n\u003Cp>Since password information is not among the official data fields, this incident has not been directly classified as a password leak. Nevertheless, it is important to use unique passwords for patient portals, insurance accounts, and email accounts, and to enable multi-factor authentication wherever possible. Because phishing was at the center of the incident, users should be more cautious about unexpected emails, attachments, fake appointment messages, and calls requesting personal information. Any person or form requesting a date of birth, Social Security number, insurance number, or patient account number should first be verified through a separate and reliable channel.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident highlights how critical staff accounts and file access are in healthcare institutions. Long-term protection should not be limited to securing only central patient systems. The principle of least privilege should be applied to folders accessible by staff, shared files, patient account lists, prescription information, and insurance documents. Phishing training, multi-factor authentication, unusual session alerts, and regular review of access logs to sensitive files reduce the impact of such incidents. Cleaning up old or unnecessary files also decreases the amount of data that can be leaked if a single account is compromised.\u003C\u002Fp>\n\u003Cp>A permanent strategy on the user side is not to leave health and identity information with a one-time check. The affected person should monitor insurance statements, credit reports, and patient portal activities for several months. Requests for payment, prescription, document renewal, or account verification from unknown individuals should be handled carefully. Even a message using the institution's name correctly should not be considered trustworthy; attackers can prepare personalized and convincing texts using leaked health information. Every request containing health data should be re-verified through the institution's known phone number or patient portal.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Users who see this record on LeakData should consider the result as a top-priority warning in terms of health privacy and identity protection. The incident date used in the record is February 25, 2026; this date represents the day the first incident was noticed. The second incident was identified on March 2, 2026. The total number of people is kept as 35,632, and the data fields are limited only to the elements mentioned in verified reports. Payment card, bank account, password, address, phone, or email fields are not included in this record because in the current verification, these fields are not explicitly part of the incident.\u003C\u002Fp>\n\u003Cp>The person receiving the result should keep any notification sent to them, if available, and use the official instructions contained therein. If they see unfamiliar medical services, prescriptions, insurance claims, or account transactions, they should quickly contact the relevant provider and insurance plan. Individuals at risk of Social Security or government ID information exposure should also monitor financial account openings and credit activity. This record alone does not prove which specific personal areas of the user have been definitively compromised; however, based on the verified scope of the incident, it indicates which types of data may be at risk and which steps should be prioritized.\u003C\u002Fp>","Gastro Health 2026 Data Breach (35.6 Thousand Reported Records)","Gastro Health 2026 Data Breach. 35.6 Thousand reported records are reported. Reported data: Names, Dates of birth, Social security numbers. Review the scope…","\u002Fuploads\u002Flogo\u002Fgastro-health-2026.svg",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":13},"Gastro Health","Healthcare \u002F Gastroenterology","United States"]