
Healthcare In Action 2026 Data Breach (1.1 Thousand People Affected)
The 2026 Healthcare In Action data breach involved compromised user credentials and unauthorized access to an organizational email account and a limited number of files. According to the official notice, the access occurred from January 28 through January 30, 2026.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/information-technology incident involving email and other systems and reported 1,143 affected individuals.
Verified Incident TimelineHealthcare In Action identified suspicious activity on January 30, 2026, disabled the account's access, and began an investigation with an independent forensic firm. The review of information in the affected email and files was completed on March 20, 2026.
What Information May Have Been Affected?The data varied by person. For patients and clients, it may have included names, dates of birth, driver's-license or state-ID numbers, email addresses, phone numbers, ethnicity, housing-application or HMIS numbers, health-plan names and member IDs, addresses, medical-record numbers, diagnoses, dates and locations of service, treatment information, disability-verification information, medications, and Social Security numbers. For one community member, the notice lists name, address, and Social Security number.
How the Organization RespondedThe organization says it ended the unauthorized access, secured the affected systems, reinforced security policies, and provided targeted security training to its workforce. One year of Experian IdentityWorks is available to affected individuals.
What Should Affected People Do?Notice recipients should monitor credit reports and financial accounts while also reviewing health-plan explanations and medical records for an unfamiliar service or change. If an unexpected message refers to the incident, use Healthcare In Action's official channels before providing identity, health, or account information.