All Breaches
January 20, 2026 Verified Sensitive Record Healthcare

FMRS Health Systems 2026 Data Breach

The FMRS Health Systems 2026 data breach was a confirmed cyber incident in which the nonprofit West Virginia behavioral-health organization identified unauthorized access and file copying on certain network systems. FMRS's official notice says access lasted from January 20 through February 27, 2026 and that irregular activity was identified on February 27.

The U.S. Department of Health and Human Services Office for Civil Rights lists the FMRS Health Systems event as a Hacking/IT Incident affecting 500 people. LeakData imported no patient or person rows, and importedRecordCount is zero. This record is verified through FMRS's official PDF notice, the HHS report, and an independent incident summary linking the sources.

How Was the FMRS Health Systems Breach Confirmed?

The primary source is the Notice of Data Security Incident linked from FMRS's own domain. The organization directly states the incident dates, unauthorized access, copying of files, initial investigation status, possible personal and health-information categories, systems that were not affected, and protective steps available to individuals.

The second confirmation is the HHS OCR record, which identifies FMRS as a West Virginia healthcare provider, classifies the event as a hacking/IT incident involving a network server, reports 500 individuals, and gives an April 28, 2026 submission date. Claim Depot joins the same official notice with the HHS record and supports the chronology and data fields.

What Happened Between January 20 and February 27?

FMRS identified irregular activity on certain computer systems in its network on February 27, took steps to secure the network, and opened an investigation. Initial findings showed that an unauthorized party accessed certain systems from January 20 to February 27 and copied files during that period. The breachDate field uses the confirmed January 20 start date.

The official notice specifically says the organization's electronic health record and email systems were not affected. That boundary matters: sensitive information may have been present in copied files, but the sources do not say the entire clinical platform, all email, or every patient's complete file was obtained. LeakData limits the scope to the systems and files described.

What Personal Information May Have Been Affected?

Possible personal information includes names, addresses, dates of birth, Social security numbers, driver's-license numbers, and financial-account information. This combination creates elevated identity-theft, fraudulent-credit, account-takeover, and persuasive social-engineering risks. The official text explains that the information involved can vary from one individual to another.

The federal count is 500 people, not the number of copied files or data fields. The official notice says not all patients were affected and that its review was still underway when the initial notice was issued. LeakData therefore does not claim that every category applied to all 500 people and does not confuse the person total with file volume.

What Health Information Was Involved?

FMRS's official list includes medical-history, diagnosis, treatment, prescription, physician, medical-record-number, and health-insurance information. In a behavioral-health setting these categories are especially sensitive and may create risks involving medical privacy, discrimination, targeted fraud, and medical-identity impersonation.

The source can state that the EHR was unaffected while also confirming that separate files may have contained or exposed these health fields; the statements are not contradictory. LeakData does not interpret documents stored outside the EHR as a complete clinical chart. Payment-card numbers, passwords, and biometric data are omitted because the official list does not name them.

What Is Known About Attribution and the Response?

Claim Depot reports that a ransomware group known as Qilin posted a dark-web responsibility claim on March 13, 2026. FMRS's official notice does not name a particular group. LeakData treats that claim as a secondary element of the chronology and does not make a definitive technical or legal attribution to an attacker.

FMRS says it secured the network, launched an investigation to confirm the nature and scope of the event, and notified law enforcement and applicable regulators. Its initial notice reported no indication of identity theft or fraud related to the event. That finding does not eliminate the possibility that copied sensitive files could be misused later.

What Should Affected People Do?

People should regularly review bank and payment-card activity, credit reports, health-insurance explanation-of-benefits statements, and prescription histories for unusual transactions. If an unknown account, medical service, prescription, or insurance claim appears, the institution should be contacted through a verified channel; a free fraud alert or credit freeze may also be appropriate.

Phishing messages that refer to the FMRS incident should be treated cautiously, and SSNs, driver's-license details, account information, or health data should not be shared through unexpected links or calls. FMRS published 304-256-7100 for weekday questions. LeakData does not host, distribute, or make searchable the copied files, patient records, or personal identifiers.

500
Affected Accounts
15
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

15
Personal information
Protected health information
Names
Physical addresses
Dates of birth
Social security numbers
Driver's license numbers
Financial account information
Medical histories
Diagnosis information
Treatment information
Prescription information
Physician information
Medical record numbers
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateJanuary 20, 2026
Domainfmrs.org
SourceOfficial FMRS notice confirming unauthorized access and copied files containing possible PII and PHI
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information