[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ff7Ig4djFsaKi4adIKIEc0vUsB7XRwy9cT4ZmlgXq1v0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":36,"source":37,"isVerified":4,"isSpamList":38,"isSensitive":4,"severity":39,"processingStatus":40,"logoUrl":41,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66f6aaae49986e10e20330","CommunityHealthCenterOfBuffalo2026","Community Health Center of Buffalo 2026 Data Breach","community-health-center-buffalo-2026","chcb.net",{"name":12,"sector":13,"country":14,"website":10},"Community Health Center of Buffalo, Inc.","Healthcare","United States","2026-04-20T00:00:00.000Z","2026-07-27T06:11:54.340Z",501,[19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35],"Personal information","Protected health information","Names","Addresses","Dates of birth","Social Security numbers","Driver's license numbers","Prescription information","Treatment information","Medical diagnoses or conditions","Laboratory results","Medications","Medical record numbers","Medical provider names","Medical histories","Health insurance policy information","Health insurance identification numbers","\u003Cp>\u003Cstrong>The Community Health Center of Buffalo 2026 data breach\u003C\u002Fstrong> was discovered when the New York community-health organization identified suspicious activity in its computer network on April 21, 2026. CHCB's official incident page says an unknown actor accessed the network on April 20 and April 21, with certain files accessed or acquired without authorization during that short period.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights lists the Community Health Center of Buffalo event as a Hacking\u002FIT Incident affecting 501 people. LeakData imported no patient or person rows, and importedRecordCount is zero. This entry presents only verified event metadata from the organization's official notice and the federal regulatory record.\u003C\u002Fp>\n\u003Ch2>How Was the CHCB Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the Information About Recent Security Incident page published on Community Health Center of Buffalo's own domain. The organization directly explains the discovery date, verified two-day access window, file access or acquisition, ongoing data review, possible personal and health information, and available support resources.\u003C\u002Fp>\n\u003Cp>The second source is HHS OCR's current breach report, which identifies CHCB as a healthcare provider, classifies the event as a hacking\u002FIT incident involving a network server, reports 501 affected individuals, and gives a June 19, 2026 submission date. A 2020 date appearing on some secondary pages conflicts with the official notice and is not used here.\u003C\u002Fp>\n\u003Ch2>What Happened on April 20 and 21, 2026?\u003C\u002Fh2>\n\u003Cp>CHCB detected suspicious network activity on April 21 and took immediate steps to further secure the network while avoiding substantial interruption to patient care. An investigation with digital-forensics and cybersecurity specialists determined that the unknown actor accessed the network on both April 20 and April 21.\u003C\u002Fp>\n\u003Cp>During this unauthorized-access period, certain files were opened and\u002For acquired without CHCB's authorization. The breachDate field uses April 20, 2026, the first verified day of access. The sources do not disclose the entry technique, file volume, attacker identity, or a ransomware group, so LeakData does not speculate about them.\u003C\u002Fp>\n\u003Ch2>How Did the Data Review and Notification Process Work?\u003C\u002Fh2>\n\u003Cp>CHCB said it was conducting a detailed data review to identify which information was affected and to whom it related. When the website notice was published, the review remained underway; the organization said potentially affected people would receive written letters plus complimentary credit monitoring and identity-theft protection services.\u003C\u002Fp>\n\u003Cp>HHS's 501-person entry is the verifiable regulatory total as of July 27, 2026. Because the official page described an ongoing review, the scope may later change; if a new total is disclosed, this same incident record should be updated. CHCB said it avoided substantial interruption to care, but that does not eliminate the data risk.\u003C\u002Fp>\n\u003Ch2>What Personal Information May Have Been Affected?\u003C\u002Fh2>\n\u003Cp>Possible personal fields include a name, address, date of birth, Social Security number, and driver's-license number. This combination creates substantial exposure to identity theft, fraudulent account opening, credit fraud, and targeted social engineering. The organization did not say every field was present for every person.\u003C\u002Fp>\n\u003Cp>The official notice provides no field-level counts and does not say all 501 people had an SSN or license number involved. LeakData therefore does not assign the same data scope to everyone. Passwords, payment cards, bank accounts, and biometric information are not added because the sources do not confirm those categories.\u003C\u002Fp>\n\u003Ch2>What Health Information Was Involved?\u003C\u002Fh2>\n\u003Cp>Possible health data includes prescription information, treatment location and information, medical diagnosis or condition, laboratory results, medications, medical-record numbers, provider names, and patient medical histories. Health-insurance policy information and identification numbers also appear in the official list.\u003C\u002Fp>\n\u003Cp>These categories are sensitive for medical-identity theft, fraudulent insurance claims, and scams targeted around a person's health condition. Still, the official page does not say every data type was present for all 501 people. LeakData reports only the possible fields disclosed and does not infer complete medical-file exposure for everyone.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>People should review bank and credit accounts, credit reports, health-insurance explanation-of-benefits statements, prescription histories, and medical-service records for unfamiliar activity. If an unknown account, provider, medication, laboratory result, or insurance claim appears, the relevant organization should be contacted through a verified channel.\u003C\u002Fp>\n\u003Cp>CHCB announced a dedicated weekday assistance line at 844-507-8852. A fraud alert or free credit freeze may be appropriate, and personal or health information should not be shared through unexpected links claiming to represent the organization. LeakData does not host, distribute, or make searchable breach files, patient lists, SSNs, or medical records.\u003C\u002Fp>","Official CHCB notice confirming two days of unauthorized network access and file acquisition",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fchcb_net.png"]