The Clinical Registry Solutions 2026 data breach was a confirmed ransomware incident in the network of a Brooklyn company that provides clinical data abstraction and registry support to healthcare organizations. Official regulatory documents say CRS discovered suspicious activity on April 9, 2026 and that an unauthorized party took certain files containing patient and human-resources information.
The U.S. Department of Health and Human Services Office for Civil Rights lists the Clinical Registry Solutions event as a Hacking/IT Incident affecting 8,545 people. LeakData imported no patient, employee, or person rows, and importedRecordCount is zero. This entry is verified through official California, Nebraska, and HHS documents.
How Was the Clinical Registry Solutions Breach Confirmed?
The California Attorney General publishes a sample patient notice submitted for Clinical Registry Solutions and identifies April 9 as the breach date. It directly explains that CRS provides registry support to Dignity Health's St. Mary's Medical Center, maintains certain St. Mary's patient information, experienced network access, and had particular patient files acquired.
The official Nebraska Attorney General filing confirms that the event was ransomware and records discovery on April 9, learning on April 17 that files had been taken, and completion of the data review on May 22. HHS OCR classifies CRS as a New York business associate and supplies the federal total of 8,545 people.
What Happened on April 9, 2026?
Employees experienced problems accessing the computer network on April 9, and CRS identified suspicious activity that day. The organization took systems offline to secure the network, retained cybersecurity specialists, and reported the event to law enforcement. The investigation confirmed that an unauthorized actor accessed the network and took files.
CRS learned on April 17 that certain files had been removed from its network and began a detailed review to identify the information and people involved. Its internal review concluded on May 22, and notices were mailed around June 17. The official filings do not name the attacking group, so LeakData does not make a definitive group attribution.
How Are Patient and Employee Data Distinguished?
The California sample letter for St. Mary's patients lists first and last names, medical-record numbers, and procedure dates. The same notice specifically says the information for that patient group did not include Social security numbers, diagnoses, or treatment plans. This boundary prevents broader fields from being incorrectly assigned to the patient subset.
The official Nebraska filing confirms that separate human-resources files contained one employee's name, Social Security number, and driver's-license number. These notices represent different groups and combinations of information. LeakData does not apply the employee fields to every patient or the patient fields to every employee.
What Does the Total of 8,545 People Mean?
The current HHS row reports 8,545 people, a network-server location, and a hacking/IT incident type; this is the nationwide regulatory count of people. It is not the number of files taken, medical procedures, or data fields. LeakData records 8,545 in pwnCount and totalRecords while keeping the number of imported person rows at zero.
The official samples demonstrate that each person did not have the same information involved. Some patients may have had only a name, medical-record number, and procedure date, while some employees may have had a name with an SSN and driver's-license number. The sources do not disclose the patient-to-employee split, so LeakData does not estimate subgroup counts.
How Did CRS Respond?
Clinical Registry Solutions secured the network, took systems offline, investigated with outside forensic specialists, reset passwords, and implemented additional security measures. It reviewed the affected data to identify owners, notified relevant people, and reassessed security policies and protections to reduce the risk of a similar event.
The official notices reported no evidence that personal or health information had been misused for fraud or identity theft. The employee notice involving an SSN and driver's license offered 12 months of CyberScout credit monitoring, dark-web monitoring, identity-recovery support, and insurance; the patient notice recommends monitoring accounts and explanation-of-benefits forms.
What Should Affected People Do?
St. Mary's patients should review health-insurance explanation-of-benefits statements and patient portals for unknown procedures or services and contact the provider through a verified channel if an unusual entry connected to their medical-record number appears. Employees with SSN or driver's-license exposure should check credit reports and consider a free fraud alert or credit freeze.
Identity or health information should not be shared in unexpected email or calls claiming to represent CRS, St. Mary's, or CyberScout; source-verified channels such as the 1-800-405-6108 assistance line should be used. LeakData does not host, distribute, or make searchable the acquired files, patient records, SSNs, driver's-license numbers, or medical-record numbers.