All Breaches
April 23, 2024 Verified Sensitive Record Healthcare

Palomar Health Medical Group 2024 Data Breach

The Palomar Health Medical Group 2024 data breach was a network security incident announced by Arch Health Partners, Inc. on behalf of Palomar Health Medical Group (PHMG), Graybill Medical Group, Inc., and Pacific Accountable Care, LLC. PHMG said it identified suspicious activity on certain computer systems on May 5, 2024. Its investigation found that an unauthorized actor accessed certain files from April 23 through May 5, 2024 and may have copied them.

The U.S. Department of Health and Human Services Office for Civil Rights HHS/OCR portal lists a Network Server Hacking/IT Incident for Palomar Health Medical Group affecting 501 people. The federal row was submitted on May 8, 2026. LeakData uses that figure as the affected-person count; importedRecordCount is zero because no raw person-level data was obtained or imported.

How Was the Palomar Health Medical Group Incident Verified?

The primary evidence is PHMG's July 3, 2024 “Notice of Data Event” PDF hosted on its own domain. Published while the investigation was continuing, it identifies the unauthorized-access window, says files may have been copied, and notes that some files may have become unrecoverable. The organization also clearly stated that it could not yet identify the specific people and information affected at that stage.

The second source is the reissued notification filed with the California Attorney General on October 15, 2025. It confirms that the data review concluded on September 4, 2025 and found that information related to current and former patients could be affected. The third source is the HHS/OCR row providing the federal count of 501 people, incident type, and network-server location. The production duplicate search covered PHMG, Arch Health Partners, Graybill, Pacific Accountable Care, the domain, and likely year slugs and found no matching record.

Incident and Notification Timeline

April 23, 2024 is the earliest known unauthorized-access date, so breachDate and dateOccurred use that date. PHMG detected suspicious activity on May 5, which is used as dateDiscovered. When the first online notice was published on July 3, the file and individual review was still underway, which is why that announcement did not provide a final affected-person total.

PHMG completed its comprehensive file review on September 4, 2025. It reissued notice on October 15 to reach people who might not previously have received it and to reinforce awareness of the 2024 event. The HHS/OCR row's May 8, 2026 submission date does not indicate a new cyberattack; the federal entry and organizational documents point to the same April-May 2024 access window.

What Personal and Health Information May Have Been Involved?

The updated organizational notice says the data combination varies by person. Listed identity and financial categories include name, address, date of birth, Social Security number, driver's license, state identification, military identification, passport, and U.S. alien registration number. Financial account, payment card, and health savings account information are also within the possible scope.

Health and account categories include medical history, diagnostic and treatment information, biometric data, medical record number, Medicare or Medicaid identification, patient account number, and health insurance information. Email address and password as well as username and password combinations are listed too. This catalog does not show that every field applied to all 501 people; an individual's notification letter is the best source for the categories relevant to that recipient.

501 Affected People Versus Zero Imports

501 is the number of affected people shown for Palomar Health Medical Group in the public HHS/OCR federal breach table. pwnCount and totalRecords equal that official figure. PHMG's July 2024 general warning to all patients was issued before the individual review was complete, however, so 501 should not be interpreted as the number of everyone who saw the general notice or the size of the organization's entire patient population.

An importedRecordCount value of zero does not mean no one was affected. LeakData did not obtain or import person-level files containing names, Social security numbers, medical records, or passwords. The event volume displayed to users is 501 people, while the number of raw person-level records searchable through LeakData is zero. These metrics answer different questions and should not be substituted for each other.

Identity, Account, and Medical-Fraud Risks

Email and password combinations can support credential-stuffing attacks when the same password was reused elsewhere. Passwords used for PHMG or related health portals should be made unique, and reused credentials for email and financial accounts should be changed first. Multi-factor authentication should be enabled. Users should reach accounts through known addresses rather than links in unexpected password-reset, payment-card, or health-account messages.

Combining Social Security, government-ID, and financial-account information can facilitate new-account fraud, while insurance, patient-account, diagnosis, and treatment data can enable medical identity theft. Credit reports, bank and card activity, and insurance explanations of benefits should be reviewed. An unfamiliar provider, service, claim, or bill should be reported through official channels to the insurer and healthcare organization.

Organization Response and Interpreting the LeakData Result

PHMG said it investigated the event, took steps to secure the network environment, notified law enforcement and relevant regulators, and enhanced existing security protocols. Its initial and updated public statements say it had seen no evidence of actual or attempted misuse connected with the event. That statement does not guarantee that misuse could never occur later.

Recipients of an individual PHMG letter should rely on that letter for their affected data categories and any protection options offered by the organization. People without a letter who still have questions should use PHMG's current official contact channel. A LeakData event page does not by itself mean the visitor appears in the affected population; it documents the verified incident and practical precautions. Evidence of identity or medical-data misuse should be preserved and reported promptly to the relevant institutions.

501
Affected Accounts
21
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

21
Full names
Physical addresses
Dates of birth
Social security numbers
Driver's license or state id numbers
Military id numbers
Passport numbers
Alien registration numbers
Financial account information
Payment card information
Health savings account information
Medical history
Diagnosis or treatment information
Biometric data
Medical record numbers
Medicaid or medicare numbers
Patient account numbers
Health insurance information
Email addresses
Passwords
Usernames

Additional Information

Added DateJuly 27, 2026
Breach DateApril 23, 2024
Domainpalomarhealthmedicalgroup.org
SourceOfficial PHMG notice, California Attorney General filing, and HHS/OCR breach report
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information