All Breaches
January 8, 2026 Verified Healthcare

CardioFit 2026 Data Breach (7.2 Thousand People Affected)

The 2026 CardioFit data breach involved CardioFit Medical Group sending some patient information in unencrypted emails during January and February 2026. The organization says it discovered the issue on February 17, 2026.

The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as an unauthorized access/disclosure incident involving email and reported 7,243 affected individuals.

Verified Incident Timeline

The California Attorney General entry identifies relevant email dates of January 8, 9, 18, and 22 and February 5, 2026. CardioFit discovered the issue on February 17, and its patient notification letter is dated April 10, 2026.

What Information May Have Been Affected?

The emails may have included names, demographic details, in limited cases clinical information including diagnoses, and health-insurance information. CardioFit says Social Security numbers, bank-account details, and credit-card information were not included.

How CardioFit Responded

The organization says it conducted a thorough review, strengthened its email-encryption procedures, and provided additional staff training. As of the notice date, it said there was no indication that the information had been viewed by unauthorized people or misused.

What Should Affected People Do?

Notice recipients should review health-insurance explanations of benefits and medical records for services or changes they do not recognize. People who want to confirm which information applied to them should verify the contact details in the official notice hosted by the California Attorney General and contact CardioFit directly.

7.2 Thousand
Affected People
4
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

4
Names
Medical information
Diagnoses
Health insurance information

Additional Information

Added DateJuly 29, 2026
Breach DateJanuary 8, 2026
Domaincardiofitla.com