The Nacogdoches Memorial Hospital 2026 data breach involved a threat actor entering the Texas hospital's computer network and information systems on January 15, 2026 and maintaining unauthorized access for roughly two weeks. The hospital identified the security incident on January 31. Its forensic review determined that files containing sensitive personal and protected health information may have been accessed or acquired.
The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows 2,507,073 affected individuals. pwnCount and totalRecords use the figure in that single federal report. The scope includes identity, contact, Social Security, medical-record, patient-account, and health-plan information plus face photographs for some people; LeakData imports no records.
How Was the Breach Confirmed?
Nacogdoches Memorial Hospital said a hacker accessed its computer network and information systems. The organization's investigation determined that the attacker may have viewed or acquired files containing patient information during approximately two weeks of access. The large report submitted to HHS confirms that the event entered the regulatory record as a breach of personal health data.
HHS OCR lists the event as a Hacking/IT Incident, the information location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal reviewed the hospital notice and federal entry, corroborating the access start, discovery date, affected population, and data fields. Sources provide no confirmed detail about the attacker's identity or initial entry method.
What Was the Access and Notification Timeline?
According to the forensic review, the threat actor first accessed the hospital network on January 15, 2026. Nacogdoches Memorial Hospital identified the event on January 31 and began its response. breachDate is January 15, the start of the verified access window; the discovery or regulatory submission date is not substituted for it.
After identifying affected files and people, the hospital began mailing notification letters on March 31, 2026. The HHS row carries a March 30 submission date and now shows 2,507,073 people. An early figure of roughly 257,000 appearing in news reports later expanded, so that older total is not added to the current value.
What Identity and Contact Information Was Affected?
Affected fields include names, mailing addresses, telephone numbers, and email addresses. Social security numbers and dates of birth were also among the disclosed sensitive identifiers. This combination creates high risks of targeted phishing, account-recovery fraud, fraudulent credit applications, and tax-identity abuse.
Full-face photograph images were also present for certain people. The hospital did not say every field appeared for all 2,507,073 individuals; the combination varies by person. Driver's-license data, payment cards, bank accounts, and passwords are not in the published confirmed list and therefore are not added to this original record.
What Health and Account Data Was Involved?
Medical record numbers and patient account numbers were among the affected data types. Health-plan beneficiary numbers were also in the disclosed scope. When combined with identity details, these fields can support fraudulent healthcare claims, medical identity theft, and targeted scams built around a hospital account.
Sources do not confirm diagnoses, detailed treatment notes, prescriptions, laboratory results, or payment-card information for the incident as a whole. The phrase “protected health information” is not used to invent categories beyond the notice. LeakData limits its classes to the expressly named medical-record, patient-account, and health-plan beneficiary numbers.
How Should the Total of 2,507,073 Be Read?
The HHS OCR open-investigation list shows one Nacogdoches Memorial Hospital row with 2,507,073 people. This is newer than the interim figure of roughly 250,000 or 257,073 seen in early coverage. pwnCount and totalRecords use only the latest federal value; the older number is not added because it represented an earlier scope of the same event.
Nacogdoches Memorial is a 226-bed hospital, but bed count, annual patient volume, and affected population are different measures. LeakData does not convert operating size into victims or invent unpublished patient-group subtotals. The entry presents only the number of affected individuals reported to the regulator.
What Should Affected People Do?
The hospital offered affected people complimentary credit monitoring and identity-theft protection. Notice recipients should check the enrollment deadline, review credit reports, and consider a security freeze if their Social Security number was involved. Messages claiming to represent the hospital or health plan and requesting more identity information should be verified through an independent official channel.
Unfamiliar services, providers, patient accounts, or beneficiary-number use in medical and insurance statements should be reported to the hospital privacy office and health plan. People whose face photograph was involved should be especially cautious about biometric-verification requests. importedRecordCount is zero; LeakData does not store or publish identity, contact, health, account, or photograph data.