[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpAXO_9tr-_ocQxbp2DCL5fBGIeYhkcCTeOGvt8MGhOY":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":41,"source":42,"isVerified":4,"isSpamList":43,"isSensitive":4,"processingStatus":44,"logoUrl":45,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":46},"6a67794ac6460c11f3e7f27c","PalomarHealthMedicalGroup2024","Palomar Health Medical Group 2024 Data Breach","palomar-health-medical-group-2024","palomarhealthmedicalgroup.org",{"name":12,"sector":13,"country":14,"website":10},"Palomar Health Medical Group","Healthcare","United States","2024-04-23T00:00:00.000Z","2026-07-27T15:29:14.121Z","2026-07-27T16:16:34.836Z",501,[20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40],"Full names","Physical addresses","Dates of birth","Social Security numbers","Driver's license or state ID numbers","Military ID numbers","Passport numbers","Alien registration numbers","Financial account information","Payment card information","Health savings account information","Medical history","Diagnosis or treatment information","Biometric data","Medical record numbers","Medicaid or Medicare numbers","Patient account numbers","Health insurance information","Email addresses","Passwords","Usernames","\u003Cp>\u003Cstrong>The Palomar Health Medical Group 2024 data breach\u003C\u002Fstrong> was a network security incident announced by Arch Health Partners, Inc. on behalf of Palomar Health Medical Group (PHMG), Graybill Medical Group, Inc., and Pacific Accountable Care, LLC. PHMG said it identified suspicious activity on certain computer systems on May 5, 2024. Its investigation found that an unauthorized actor accessed certain files from April 23 through May 5, 2024 and may have copied them.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights HHS\u002FOCR portal lists a Network Server Hacking\u002FIT Incident for Palomar Health Medical Group affecting 501 people. The federal row was submitted on May 8, 2026.\u003C\u002Fp>\n\u003Ch2>How Was the Palomar Health Medical Group Incident Verified?\u003C\u002Fh2>\n\u003Cp>The primary evidence is PHMG's July 3, 2024 “Notice of Data Event” PDF hosted on its own domain. Published while the investigation was continuing, it identifies the unauthorized-access window, says files may have been copied, and notes that some files may have become unrecoverable. The organization also clearly stated that it could not yet identify the specific people and information affected at that stage.\u003C\u002Fp>\n\u003Cp>The second source is the reissued notification filed with the California Attorney General on October 15, 2025. It confirms that the data review concluded on September 4, 2025 and found that information related to current and former patients could be affected. The third source is the HHS\u002FOCR row providing the federal count of 501 people, incident type, and network-server location.\u003C\u002Fp>\n\u003Ch2>Incident and Notification Timeline\u003C\u002Fh2>\n\u003Cp>The incident date is based on the earliest technical activity that can be verified from public sources. When the first online notice was published on July 3, the file and individual review was still underway, which is why that announcement did not provide a final affected-person total.\u003C\u002Fp>\n\u003Cp>PHMG completed its comprehensive file review on September 4, 2025. It reissued notice on October 15 to reach people who might not previously have received it and to reinforce awareness of the 2024 event. The HHS\u002FOCR row's May 8, 2026 submission date does not indicate a new cyberattack; the federal entry and organizational documents point to the same April-May 2024 access window.\u003C\u002Fp>\n\u003Ch2>What Personal and Health Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>The updated organizational notice says the data combination varies by person. Listed identity and financial categories include name, address, date of birth, Social Security number, driver's license, state identification, military identification, passport, and U.S. alien registration number. Financial account, payment card, and health savings account information are also within the possible scope.\u003C\u002Fp>\n\u003Cp>Health and account categories include medical history, diagnostic and treatment information, biometric data, medical record number, Medicare or Medicaid identification, patient account number, and health insurance information. Email address and password as well as username and password combinations are listed too. This catalog does not show that every field applied to all 501 people; an individual's notification letter is the best source for the categories relevant to that recipient.\u003C\u002Fp>\n\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\n\u003Cp>501 is the number of affected people shown for Palomar Health Medical Group in the public HHS\u002FOCR federal breach table. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person. PHMG's July 2024 general warning to all patients was issued before the individual review was complete, however, so 501 should not be interpreted as the number of everyone who saw the general notice or the size of the organization's entire patient population.\u003C\u002Fp>\n\u003Cp>These metrics answer different questions and should not be substituted for each other.\u003C\u002Fp>\n\u003Ch2>Identity, Account, and Medical-Fraud Risks\u003C\u002Fh2>\n\u003Cp>Email and password combinations can support credential-stuffing attacks when the same password was reused elsewhere. Passwords used for PHMG or related health portals should be made unique, and reused credentials for email and financial accounts should be changed first. Multi-factor authentication should be enabled. Users should reach accounts through known addresses rather than links in unexpected password-reset, payment-card, or health-account messages.\u003C\u002Fp>\n\u003Cp>Combining Social Security, government-ID, and financial-account information can facilitate new-account fraud, while insurance, patient-account, diagnosis, and treatment data can enable medical identity theft. Credit reports, bank and card activity, and insurance explanations of benefits should be reviewed. An unfamiliar provider, service, claim, or bill should be reported through official channels to the insurer and healthcare organization.\u003C\u002Fp>\n\u003Ch2>How Should This Incident Be Interpreted?\u003C\u002Fh2>\n\u003Cp>PHMG said it investigated the event, took steps to secure the network environment, notified law enforcement and relevant regulators, and enhanced existing security protocols. Its initial and updated public statements say it had seen no evidence of actual or attempted misuse connected with the event. That statement does not guarantee that misuse could never occur later.\u003C\u002Fp>\n\u003Cp>Recipients of an individual PHMG letter should rely on that letter for their affected data categories and any protection options offered by the organization. People without a letter who still have questions should use PHMG's current official contact channel. A LeakData event page does not by itself mean the visitor appears in the affected population; it documents the verified incident and practical precautions. Evidence of identity or medical-data misuse should be preserved and reported promptly to the relevant institutions.\u003C\u002Fp>","Official PHMG notice, California Attorney General filing, and HHS\u002FOCR breach report",false,"completed","\u002Fuploads\u002Flogo\u002Fpalomarhealthmedicalgroup_org.png","Low"]