The 2026 data breach at Amicus Solutions, also known as Fedora Solutions, in its health revenue cycle and managed service provider, is related to unauthorized access to the company's environment between February 2, 2026, and February 18, 2026. The organization reported that around April 2, 2026, it detected suspicious activity on its network, initiated an incident response process, and during the investigation found that some personal and health data had been copied by an unauthorized third party. Publicly available health breach records indicate that the incident appears to have affected 1,137 individuals. Notifications stated that the incident involved patients of certain medical practices managed by OneOncology, including specific patient groups at New York Cancer and Blood Specialists.The important distinction is as follows: according to the disclosed information, the incident occurred in the Amicus Solutions environment, and there has been no finding shared regarding unauthorized access to the client institutions' own networks. Nevertheless, due to the copying of patient data and its publication on an attacker site, this record should be considered a high-sensitivity health and identity data breach.
Leaking Data Types and Risks
The types of data confirmed in this breach are first and last name, email address, phone number, date of birth, gender information, Social Security number, medical data, and health insurance information. These fields can be risky on their own; when evaluated together, they provide a strong basis for identity theft, health insurance fraud, fake patient communication, targeted social engineering, and account takeover attempts. Specifically, the presence of name, date of birth, and Social Security number in the same incident increases the risk of opening new credit accounts, answering identity verification questions, or making fraudulent applications in tax or financial transactions. Email and phone information, on the other hand, can make personalized messages appear more convincing.
Medical data and health insurance information are sensitive not only in terms of financial loss but also privacy. Health service history, treatment relationships, or insurance plan information may appear in messages crafted by fraudsters using the real institution's name and patient relationship. Such messages can come with promises of invoice correction, appointment renewal, insurance approval, missing documents, identity verification, or reimbursement. Gender, date of birth, and contact information also increase the risk of profiling. The risk is not limited to internal access because the data may have been copied and published by an attacker; the information can be reused in other fraud attempts.
Verified Scope and Boundaries
The verified time frame for the Amicus Solutions incident is between February 2, 2026, and February 18, 2026. Suspicious activity was noticed around April 2, 2026, after which the review and notification process began. Public records indicate that the number of affected individuals is 1,137. Independent healthcare sector news and government notification records show that this number matches the breach report containing health data. The fields identified in the data review are first and last name, email, phone number, date of birth, gender, Social Security number, medical data, and health insurance information. Verification is left open in this record because the existence of the breach, the incident timeframe, the number of affected individuals, and the types of data are consistent with multiple public records.
Nevertheless, the scope needs to be properly understood. This incident concerns patient data associated with services provided by Amicus Solutions or Fedora Solutions; it should not be confused with different technology companies that share the same name. Furthermore, the notifications did not indicate any unauthorized access to the networks of client healthcare institutions. This distinction is important for the user to understand which system the incident occurred in; however, it does not mitigate the outcome in terms of personal data risk. This is because the types of data confirmed to be copied include identity, contact, health, and insurance information together. If a user match is observed, the incident requires broader identity and health account control than merely changing a single password.
User Groups at Risk
The primary group at risk consists of patients and their relatives whose data is processed by Amicus Solutions or Fedora Solutions in the context of revenue cycle management, patient financing, billing, or administrative services. Individuals associated with medical practices managed by OneOncology and relevant healthcare organizations such as New York Cancer and Blood Specialists should be particularly cautious regarding this incident. If a person's data appears in this record, it may have been processed through a related healthcare service or billing process, even if they did not directly interact with the Fedora brand. Therefore, users should check not only their own doctor's office but also insurance, payment, and patient portal notifications.
Cancer treatment, specialist physician services, or individuals with long-term health monitoring are at higher risk; fake messages prepared through health relationships can appear realistic. The combination of social security number, date of birth, and health insurance information increases the likelihood of misuse in identity verification and insurance transactions. People with email and phone information can be targeted through calls, text messages, and emails. Fields such as gender and medical data can also be used for privacy pressure or personalized manipulation, not just fraud. Therefore, users with matched information need to be cautious for a long time in both financial and health account aspects.
Urgent Measures to Be Taken
Users who believe they are affected by this breach should first review health insurance explanation documents, patient portal notifications, billing transactions, and unexpected payment requests. If any unknown appointment, treatment, test, prescription, or insurance claim is seen, they should contact the healthcare provider and insurance organization directly. Since Social Security numbers and birth dates may have been affected, credit reports should be checked, and alerts for new account openings, credit applications, or address changes should be closely monitored. If deemed necessary, options such as credit freezes or fraud alerts should be considered.
Since email and phone information are also affected, users should pay special attention to message security. Messages involving invoice correction, insurance renewal, medical record verification, free identity protection, patient portal updates, or urgent payment requests should be verified directly through the known phone number or official website address. If the same password is used for the patient portal, email account, or insurance account, passwords should be made unique and multi-factor authentication should be enabled. Messages using the institution's name and actual health relation can be particularly misleading; it is safer to type the address manually instead of clicking on the link.
Long-Term Security Strategies
This incident shows that third-party service providers who do not work directly with healthcare providers but process patient data also pose a serious risk. In the long term, users should keep track of which healthcare institutions work with which administrative service providers, keep their contact information up to date in patient portals, and not leave old accounts unnecessarily open. In breaches involving health insurance and medical data, the risk can emerge months later; therefore, checks should be made not only in the week when the notification letter arrives but also during subsequent insurance periods, tax seasons, and credit application periods.
Strong data segmentation, the principle of least privilege, reducing the retention periods of patient data, alerts for abnormal data output, and regular incident drills become critical on the part of the institution. The user cannot directly manage these technical measures; however, they can regularly check which accounts have multi-factor authentication, which email address is used for health accounts, and which insurance notifications they have received. In verified incidents of data copying, the most effective individual defenses are rapid password renewal, long-term credit and insurance monitoring, early detection of unexpected health transactions, and careful verification of communications outside the institution.
Record Control and User Action
A match with the record Amicus Solutions / Fedora Solutions 2026 indicates that the user may be included in a risky data set in this incident. In this case, the user should act on the assumption that the types of data listed could be present in their record; however, they should not panic unnecessarily assuming that every type of data would be equally affected for everyone. The best step is to check health service providers, insurance accounts, billing statements, credit reports, and identity protection alerts together. Especially in incidents involving Social Security numbers, birth dates, and health insurance information, a single channel appearing clean does not mean the risk has completely passed.
If there is a match, users should use unique passwords for patient portals and email accounts, verify authentication requests received via phone or email directly with the institution, and report any unknown health or insurance transactions without delay. Misuse of records containing health data is sometimes not immediately visible like financial card activity; it can appear later as a fraudulent insurance claim, an incorrect bill, an unexpected service explanation, or a new credit application. Therefore, this record should be treated not as a short-term notification, but as a high-sensitivity breach requiring long-term monitoring for identity and health account security.