All Breaches
April 29, 2026 Verified Sensitive Record Healthcare

Community First Health Plans 2026 Data Breach

The Community First Health Plans 2026 data breach involved an employee uploading a file containing personal and protected health information about certain members to ChatGPT from a home computer network on the evening of April 29, 2026. The organization said the use circumvented firewall safeguards and violated company policy.

The HHS Office for Civil Rights public record classifies the event as Unauthorized Access/Disclosure involving a Laptop and reports 1,549 affected people. Community First's official notice identifies names, addresses, dates of birth, member identification numbers, and prescription drug information as possible fields. No person-level data was imported into LeakData.

How Was the Community First Health Plans Breach Confirmed?

The primary source is Community First Health Plans' own press release dated June 29, 2026. It directly states when and how the upload occurred, that company systems immediately detected the violation, the response that began the next morning, the disclosed data fields, the 12-month identity-monitoring offer, and the support channels provided to members.

The second official source is the HHS Office for Civil Rights breach portal. Its row identifies the company as a Texas Health Plan, classifies the event as Unauthorized Access/Disclosure involving a Laptop, reports 1,549 people, and gives a June 29, 2026 submission date. The organization notice and regulatory entry align on entity, event type, and timing.

What Happened on April 29, 2026?

According to Community First, an employee uploaded a file containing personal information about some members to ChatGPT from a home computer network on the evening of April 29. The company said it does not use ChatGPT, the action bypassed institutional firewall safeguards, and it violated policy. Company systems detected the violation that evening and alerted IT.

The next morning, leaders opened an investigation, revoked the employee's access to company systems, and directed and verified deletion of personal information from the ChatGPT account. Community First also contacted OpenAI, the operator of ChatGPT, to demand deletion of related data, retrieved all personal information from the employee, and ended the employment relationship.

What Member Information Was Involved?

The official statement's possible data list consists of names, physical addresses, dates of birth, member identification numbers, and prescription drug information. The public notice does not detail whether fields varied by member or whether all five fields appeared for everyone. The record therefore presents them as possible scope and preserves the priority of each person's notice.

SSNs, driver's licenses, payment cards, bank accounts, user passwords, and email accounts are not listed as affected fields in the notice. A member ID is a distinct health-plan identifier; it is not expanded into a policy number, financial account, or government ID. LeakData classifies only the elements that the organization publicly disclosed.

What Risks Follow From the AI Upload?

When combined, a name, address, birth date, health-plan relationship, and medication information can make targeted phishing more convincing. A malicious message could use a real drug, plan, or member context to request a prescription renewal, coverage update, payment, or portal verification. Recipients should independently verify a message even when it contains accurate details.

The organization said it was not aware of misuse of the affected information as of its public statement. That does not mean risk is zero or that the data was never processed; it means no confirmed misuse was known. The disclosed event was also not an external attacker breaking into company systems, but an internal user's unauthorized use of a third-party tool.

How Many People Were Affected and How Did the Company Respond?

The exact affected-person count in the HHS record is 1,549. pwnCount and totalRecords carry that public total; they do not represent 1,549 raw person records uploaded to LeakData. importedRecordCount is zero. The event occurred April 29, the company response began the morning of April 30, and the regulatory filing and public announcement are dated June 29, 2026.

In addition to access revocation and deletion requests, Community First said it was working to implement authorized employee log-on windows and mandatory VPN connectivity at all times. Policies were revised, the workforce was retrained, and the ban on unauthorized AI tools was reinforced. Affected members were offered 12 months of complimentary identity monitoring.

What Should Affected Members Do?

A member who receives a notice should identify which fields apply to them and, if desired, activate the offered identity-monitoring service within the stated period. Review the health-plan portal, prescription history, and explanation-of-benefits statements for an unfamiliar drug, provider, claim, or contact-detail change.

Do not disclose a member number, birth date, password, payment information, or one-time code in an unexpected message using the Community First or pharmacy name. Questions can be directed to privacy@cfhp.com or 800-434-2347 on weekdays from 8:00 a.m. to 5:00 p.m. Central; independently open the official notice to verify those contact details.

1.5 Thousand
Affected Accounts
5
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

5
First and last names
Physical addresses
Dates of birth
Health plan member identification numbers
Prescription drug information

Additional Information

Added DateJuly 27, 2026
Breach DateApril 29, 2026
Domaincommunityfirsthealthplans.com
SourceOfficial health-plan notice and HHS record confirming an unauthorized member-file upload to ChatGPT and 1,549 affected people
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information