The PIH Health 2024 data breach concerns a ransomware-linked cyber incident affecting the California healthcare network that was detected on December 1, 2024. A forensic investigation determined that the threat actor had network access from November 14 through December 23, 2024. PIH Health later confirmed that patient information was present in files on compromised network areas and that the attacker may have accessed or acquired those files.
The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows 2,947,264 affected individuals. pwnCount and totalRecords use the current figure in that single federal row. The incident involved names, addresses, Social Security and taxpayer identifiers, medical and insurance information, and financial-account and card details; LeakData imports no personal records.
How Was the Breach Confirmed?
PIH Health detected the operational attack on December 1, 2024 and began a review with cyber-forensics specialists. Around December 16, 2025, the organization determined that files in the compromised portions of its network contained patient information and may have been accessed or acquired by the threat actor. That finding and the HHS report establish the event as a personal-data breach.
HHS OCR lists the event as a Hacking/IT Incident, the information location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal reviewed PIH Health's updated statement, the regulatory record, and the attack timeline, corroborating the scope of nearly 2.95 million patients. The sources agree that the event affected personal and protected health information beyond the system outage.
What Was the Access and Notification Timeline?
Forensic findings place the threat actor in PIH Health's network from November 14 through December 23, 2024. breachDate is November 14, the beginning of that window. The attack detected on December 1 disrupted some computer systems and phone lines; healthcare staff used downtime procedures and manual records to continue care.
Detailed review of the affected files and preparation of the person list took about a year. After obtaining the full affected population in December 2025, PIH Health gathered contact details and began notifications. The HHS row retains an original submission date of January 31, 2025, while the 2,947,264 now displayed reflects the later scope review.
What Identity and Health Information Was Affected?
PIH Health said the information types varied by person. Along with names and mailing addresses, files could include Social security numbers and taxpayer identification numbers. Driver's-license numbers were also among the disclosed identity fields. This combination raises the risks of identity theft, fraudulent tax activity, and new-account abuse.
Medical and health-insurance information was involved. Financial-account details and credit or debit card numbers were also present in some files. Sources do not say every field appeared for all 2,947,264 people; passwords, email contents, and every detailed treatment field asserted by the attacker are not added as organization-confirmed general scope.
How Was the Total of 2,947,264 Determined?
The HHS OCR open-investigation list shows one PIH Health Inc. row with 2,947,264 individuals. This figure represents the affected population established after the organization's data review. pwnCount and totalRecords use only this regulatory value; earlier estimates, hospital visits, and the attacker's claimed record volume are not added.
The HHS number represents affected people rather than stolen files or database rows. One patient can have multiple medical records, so a record count need not equal a person count. LeakData preserves that distinction and does not invent hospital-, clinic-, or data-field-level subtotals that were not published.
Why Is the Attacker's 17 Million Record Claim Excluded?
The publicly unidentified attacker claimed to have taken roughly 2 TB of data and 17 million patient records, issued a ransom demand, and posted some samples online. The assertion described medical episodes, cancer-treatment records, private emails, and organization documents. PIH Health initially said it could not verify the authenticity of the ransom note or data-theft claims.
The later HHS population of 2,947,264 indicates that the 17 million-record assertion did not represent unique patients or was exaggerated. LeakData does not use the attacker figure for pwnCount, attribute the event to a named group, or treat 2 TB as a company-confirmed amount. The entry relies on the regulatory total and information classes confirmed by the organization.
What Should Affected Patients Do?
PIH Health said it had found no evidence of misuse or attempted misuse of the affected information when notices were issued and offered complimentary credit monitoring and identity-theft protection. Recipients should review credit reports, tax accounts, and financial activity and consider a security freeze if a Social Security number was involved.
Unfamiliar services, providers, or claims in medical and insurance statements should be reported through PIH Health and the health plan's official privacy channels. People with affected card or account information may discuss replacement and enhanced monitoring with the financial institution. importedRecordCount is zero; LeakData does not store or publish identity, medical, insurance, financial-account, or card data.