All Breaches
February 7, 2024 Verified Sensitive Record Healthcare

ParkTree Community Health Center 2024 Data Breach

The ParkTree Community Health Center 2024 data breach involved the provider, legally named Pomona Community Health Center, reporting that patient health data may have been exposed to an unknown party on February 7, 2024. Its letter lists names, birth dates, health-plan, and clinical data and explicitly says Social Security and driver's license numbers were not involved.

The official HHS Office for Civil Rights breach portal lists ParkTree under the Pomona Community Health Center legal name with 40,964 affected people. It classifies the event as a network-server hacking/IT incident. pwnCount and totalRecords carry that reported population, while importedRecordCount is zero because no person-level data was transferred into LeakData.

How Was the ParkTree Breach Confirmed?

The primary source is the August 21, 2024 consumer letter in California Attorney General record SB24-590522. It confirms the February 7 exposure, affected fields, security improvements, assistance line, and exclusion of SSNs and driver's license data. The signature identifies the provider as Pomona Community Health Center dba ParkTree Community Health Center.

The second source is the official HHS/OCR row dated August 21, 2024, which gives 40,964 people, healthcare provider, hacking/IT incident, and network server. ClaimDepot links the California filing, but its secondary SSN headline and February 1 narrative conflict with the official letter; this record gives the primary regulatory document priority.

What Happened on February 7, 2024?

According to ParkTree's individual notification letter, personal health data may have been exposed to an unknown party February 7. The provider said it reported the event to the proper authorities, took steps to enhance network security and reduce repeat risk, and reviews and updates its security policies and procedures as needed.

The public letter does not explain how the unauthorized person first entered, which account or vulnerability was used, how long access lasted, or whether the data was definitively downloaded. The event is therefore recorded as a network-server breach without adding unverified claims about actor identity, tooling, ransomware, or exfiltration volume.

What Identity and Contact Fields Were Involved?

Core fields that varied by person were first and last names, dates of birth, contact information, and gender. “Contact information” appears as a broad category in the letter; the entry does not assume that every recipient had a specific address, telephone number, or email field involved. Each person's own notice defines the applicable scope.

The official letter expressly states that the event did not involve Social Security or driver's license numbers. A secondary webpage headline claiming an SSN exposure is therefore not used as a data class. This entry excludes SSNs and government identification; generic credit-protection material appended to the letter does not redefine the actual incident scope.

What Health and Clinical Information Was Involved?

Health fields were health-plan identification numbers, medical record numbers, and clinical details such as diagnoses, medications, and doctor's notes. These can expose treatment and insurance context and make messages using a patient or provider name more persuasive. The entry does not assume every individual had every clinical subtype involved.

Notice recipients can inspect explanations of benefits, patient-portal activity, unfamiliar services and medications, and health-plan communications. Even a message quoting a real diagnosis, medication, or doctor's note is not automatically legitimate. Verify it using a known ParkTree number or a patient portal opened directly rather than through the message.

How Should the 40,964 Figure Be Interpreted?

The 40,964 figure is the affected population reported to HHS/OCR and is a verified public total that can be used instead of a zero or unsupported estimate. It is not a number of users, accounts, or raw records loaded into LeakData. pwnCount and totalRecords are 40,964, while importedRecordCount is zero to reflect that no person-level data is held.

Any resident counts in state notices are subsets of the nationwide population and must not be added again. ParkTree and Pomona Community Health Center are represented as one record because the notice documents their legal-name and dba relationship. The event date is February 7 from the official letter, not February 1 from a secondary summary.

How Did ParkTree Respond and What Should Recipients Do?

ParkTree said it reported the security event to the appropriate authorities, strengthened network security, and updated policies and procedures. The August 21, 2024 letter lists 1-877-202-5507 for questions and weekday hours from 9:00 a.m. to 9:00 p.m. Eastern; recipients should confirm current availability through an official provider channel.

An affected person can monitor health-plan and patient-account activity based on the fields in their own letter, report unfamiliar services, and independently verify unexpected messages. Do not share a password, health-plan number, payment, or one-time code in a communication using the ParkTree, plan, or doctor name; use a known site or telephone number instead.

41 Thousand
Affected Accounts
9
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

9
First and last names
Dates of birth
Health plan identification numbers
Medical record numbers
Contact information
Gender
Diagnoses
Medications
Doctor’s notes

Additional Information

Added DateJuly 27, 2026
Breach DateFebruary 7, 2024
Domainparktreechc.org
SourceCalifornia Attorney General consumer notice and official HHS/OCR report
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information