[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fy3iY5C-ZUsFTTaY2RiIRJl7XNV642ITYJtPCdVjGndQ":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":31,"source":32,"isVerified":4,"isSpamList":33,"isSensitive":4,"severity":34,"processingStatus":35,"logoUrl":36,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66f5b0265150d1779e9f27","CherryHealth2026","Cherry Health 2026 Data Breach","cherry-health-2026","cherryhealth.org",{"name":12,"sector":13,"country":14,"website":10},"Cherry Street Services, Inc. (Cherry Health)","Healthcare","United States","2026-04-19T00:00:00.000Z","2026-07-27T06:07:44.482Z",501,[19,20,21,22,23,24,25,26,27,28,29,30],"Personal information","Protected health information","Names","Addresses","Telephone numbers","Dates of birth","Health insurance information","Health insurance identification numbers","Patient identification numbers","Medical provider names","Medical dates of service","Social Security numbers","\u003Cp>\u003Cstrong>The Cherry Health 2026 data breach\u003C\u002Fstrong> was discovered when the Michigan healthcare organization legally named Cherry Street Services, Inc. identified suspicious activity on its network on or about April 19, 2026. Its official preliminary notice says an unauthorized individual accessed and copied certain network information, potentially affecting current or former patients and current or former staff members.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights currently lists the Cherry Street Services event as a Hacking\u002FIT Incident affecting 501 people. LeakData imported no person, patient, or employee rows, and importedRecordCount is zero. Because the official data review remains in progress, 501 is presented as the current regulatory figure, not assumed to be a final total.\u003C\u002Fp>\n\u003Ch2>How Was the Cherry Health Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is Cherry Health's June 18, 2026 Notice of Data Privacy Event PDF on its own domain. The official bilingual English and Spanish document directly explains the discovery date, network containment, unauthorized access and copying, ongoing data review, possible information categories, and protective resources.\u003C\u002Fp>\n\u003Cp>The second confirmation is HHS OCR's breach report, which identifies Cherry Street Services as a healthcare provider, classifies the incident as a hacking\u002FIT event involving a network server, reports 501 individuals, and gives a June 18, 2026 submission date. Claim Depot independently connects the official PDF and HHS record while reporting the same event type and disclosed categories.\u003C\u002Fp>\n\u003Ch2>What Happened on April 19, 2026?\u003C\u002Fh2>\n\u003Cp>After detecting suspicious network activity, Cherry Health promptly took steps to secure its environment and opened an investigation with third-party specialists to determine the nature and scope. The investigation found that an unauthorized individual accessed and copied certain information stored on the organization's network.\u003C\u002Fp>\n\u003Cp>The sources do not disclose the first or last day of unauthorized access, intrusion method, amount of copied data, or attacker identity. The breachDate field therefore uses the approximate April 19, 2026 official discovery date without inventing an access start or duration. No verified ransomware or public-data-release claim is added.\u003C\u002Fp>\n\u003Ch2>Why Is the Data Review Still Ongoing?\u003C\u002Fh2>\n\u003Cp>The organization said it was conducting a comprehensive file review with third-party specialists to determine exactly which fields were involved and to whom they belonged. That work was incomplete when the preliminary notice was issued; Cherry Health said potentially affected people would receive written letters after the review was finalized.\u003C\u002Fp>\n\u003Cp>HHS's 501-person entry is the public verifiable regulatory figure as of July 27, 2026. Still, the official notice's ongoing-review language means the scope may change. If a new total is disclosed, this same incident entry should be updated rather than creating another duplicate. The company said it then had no evidence of identity theft or fraud.\u003C\u002Fp>\n\u003Ch2>What Personal Information May Have Been Affected?\u003C\u002Fh2>\n\u003Cp>Possible personal fields include a name, address, telephone number, and date of birth. Social Security numbers may also be involved in a limited number of cases. When combined with other sources, these fields can support impersonation, fraudulent account opening, targeted telephone fraud, and convincing phishing attempts.\u003C\u002Fp>\n\u003Cp>The official notice does not say every field was present for all 501 people or disclose the size of the limited SSN subgroup. This entry therefore does not assume that everyone's SSN was involved. Passwords, payment cards, driver's licenses, and bank accounts are not added because the sources do not confirm those categories.\u003C\u002Fp>\n\u003Ch2>What Health Information Was Involved?\u003C\u002Fh2>\n\u003Cp>Possible healthcare-related information includes health-insurance information, health-insurance identification numbers, patient-identification numbers, provider names, and dates of service. These fields are sensitive for insurance fraud, medical impersonation, and social engineering targeted around a person's healthcare relationship.\u003C\u002Fp>\n\u003Cp>The preliminary notice does not list diagnoses, treatment, prescriptions, test results, clinical notes, or payment-card information. LeakData therefore does not infer complete medical-record exposure from a general patient or staff relationship. Each person's scope may contain several fields or only one, with exact fields expected in individual notices.\u003C\u002Fp>\n\u003Ch2>What Should Potentially Affected People Do?\u003C\u002Fh2>\n\u003Cp>People should review financial accounts, credit reports, health-insurance explanation-of-benefits statements, and service histories for unfamiliar activity. If an unknown account, provider, service, or insurance claim appears, the relevant organization should be contacted through a verified channel; a fraud alert or free credit freeze may also be appropriate.\u003C\u002Fp>\n\u003Cp>Cherry Health published the 888-204-2407 number and its official Grand Rapids mailing address for incident questions. SSNs, insurance details, or patient identifiers should not be shared through unexpected links or calls claiming to represent the organization. LeakData does not host, distribute, or make searchable copied files, patient lists, employee records, or health information.\u003C\u002Fp>","Official Cherry Health preliminary notice confirming unauthorized network access and copying",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fcherryhealth_org.png"]