All Breaches
February 18, 2026 Verified Sensitive Record Healthcare

BAYADA Home Health Care Şubat 2026 Data Breach

The BAYADA Home Health Care February 2026 data breach was a cybersecurity event in which an unauthorized actor accessed certain systems and data at the healthcare provider between February 18 and March 2, 2026. BAYADA's official notice confirms that the organization became aware of the event on March 2, initiated its incident-response process, and engaged third-party specialists for a forensic investigation.

A subsequent Texas Attorney General record, BR-0005185, reports that 550,164 people across the United States were affected, including 1,270 Texas residents. Names, Social security numbers, driver's-license numbers, financial information, medical information, and health-insurance information appear in the official state record; BAYADA's notice also identifies birth dates and several care-related fields as potentially involved.

How Was the BAYADA Breach Confirmed?

The primary incident source is BAYADA's three-page “recent data privacy event” notice linked from its own website. The notice directly describes the unauthorized actor's access period, affected systems and data, nature of the investigation, initial information categories, reports made to government agencies, and protective steps recommended by the organization.

The second official source is Texas Attorney General record BR-0005185. It uses the BAYADA Home Health Care, Inc. legal name and Pennsauken address and publishes the February 18 through March 2 incident dates, 550,164-person nationwide total, 1,270-person Texas subset, final information categories, and consumer notice by mail and website. The exact organization, address, and incident-period match shows that both sources describe the same event.

What Happened Between February 18 and March 2, 2026?

BAYADA says it first became aware of a cybersecurity event on March 2, 2026. The resulting forensic investigation determined that an unauthorized actor gained access to certain BAYADA systems and data from February 18 through March 2. The public notice does not identify the account, application, vulnerability, or initial-access method used to enter the environment.

The incident therefore should not be assumed to involve ransomware, phishing, credential theft, or exploitation of a particular software flaw. BAYADA confirms unauthorized access to systems and data but does not identify the actor, say whether data was transferred out, describe a ransom demand, or confirm online publication. It says there was no indication of identity theft or fraud related to the event as of the notice; that time-bound observation does not eliminate later risk.

What Information Was Affected?

BAYADA's initial public notice says the affected data could include names, dates of birth, diagnosis and medical or physical-treatment information, provider information, health-insurance plan information, prescription information, hospital admissions and discharges, disability information, and Social security numbers. At that point, the organization said the data review remained underway and the fields could vary by person.

The later Texas entry lists names, SSNs, driver's-license numbers, financial information, medical information, and health-insurance information as confirmed categories. Read together, the sources indicate that the later review clarified scope for at least some people, but no field should be assumed for every individual. A recipient's own notification letter is the most direct source for that person's particular data.

How Many People Were Affected?

Texas Attorney General record BR-0005185 gives an exact nationwide total of 550,164 people and a Texas subset of 1,270. The Texas figure is included in the nationwide population and is not added again. The portal entry appears as published on July 21, 2026 and provides the broader population result after the data review that BAYADA's first notice described as ongoing.

The company's initial public notice did not state a total because third-party data review was still underway. The later exact figure in the Texas record therefore controls. This event is separate from an earlier BAYADA disclosure tied to a different vendor, Doctor Alliance, with an October 31 through November 17, 2025 incident period; the two affected populations should not be combined.

How Did BAYADA Respond?

BAYADA says it activated incident-response protocols, opened a forensic investigation with third-party specialists, and worked to confirm scope and secure its systems. The organization reported the event to relevant government agencies, including federal law enforcement and the U.S. Department of Health and Human Services, and said it was reviewing existing safeguards, policies, and procedures to strengthen protections.

The initial notice says individual notifications would follow completion of the data review; the later Texas record confirms that consumer notice was provided through a website and U.S. mail. The public notice does not identify a specific credit-monitoring or identity-protection offer. It gives an assistance line at 1-800-305-3000, available daily from 8 a.m. to 7 p.m. Eastern, and a mailing address for BAYADA's Privacy Officer in Pennsauken.

What Should Affected People Do?

Recipients should rely on their own letter for the fields applicable to them and review health-insurance explanations of benefits, patient portals, bank and card activity, and free credit reports for an unfamiliar transaction or claim. If an SSN or driver's license was involved, consider a free credit freeze or fraud alert; if financial-account information was involved, contact the relevant institution through a known official channel.

Independently verify unexpected messages invoking BAYADA, an insurer, bank, or government agency. A message containing real healthcare details is not automatically legitimate; do not disclose a password, SSN, insurance member number, or one-time code. Report a suspicious healthcare claim to the insurer, financial activity to the relevant institution, and suspected identity misuse through IdentityTheft.gov and law enforcement when appropriate.

550.2 Thousand
Affected Accounts
14
Data Types
High
Severity
Yes
Verification

Exposed Data Types

14
Personal information
Protected health information
Names
Dates of birth
Social security numbers
Driver's license numbers
Financial information
Diagnosis information
Medical treatment information
Provider information
Health insurance information
Prescription information
Hospital admission and discharge information
Disability information

Additional Information

Added DateJuly 27, 2026
Breach DateFebruary 18, 2026
Domainbayada.com
SourceBAYADA official incident notice and Texas Attorney General record confirming unauthorized access, event dates, affected data, notice method, and nationwide count
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information