All Breaches
February 26, 2026 Verified Sensitive Record Insurance

Pivot Health 2026 Data Breach

The Pivot Health 2026 data breach involved the health-insurance product provider detecting suspicious activity in its Amazon Web Services environment March 13, 2026 and confirming that an unknown person accessed the cloud environment at various times between February 26 and March 13 and viewed or copied certain information.

The Indiana Attorney General's official breach table gives an updated nationwide affected population of 8,391. The 5,864-person HHS/OCR row with the same notification date reflects an earlier healthcare scope and is not combined with the new total. pwnCount and totalRecords are 8,391, while importedRecordCount is zero because no person-level data was loaded.

How Was the Pivot Health Breach Confirmed?

The primary source is Pivot Health's own Notice of Data Privacy Incident PDF. It confirms the March 13 discovery, February 26–March 13 AWS access window, viewing or copying of information, investigation with outside forensic specialists, disclosed data categories, and dedicated assistance line at 844-593-8519.

The second source is the Indiana Attorney General's official June 2026 breach table. The Pivot Health row shows a May 13, 2026 notice date, February 26 event start, and 8,391 people nationwide. The 5,864-person HHS Office for Civil Rights entry independently confirms the earlier scope through another regulatory channel.

What Happened Between February 26 and March 13, 2026?

Pivot Health identified suspicious activity in its AWS cloud environment around March 13, secured its systems, and engaged third-party forensic specialists to examine the nature and scope of access. The investigation determined that the unauthorized person entered the AWS environment at multiple times during the roughly two-week period.

The provider explicitly said certain information was viewed or copied by the unknown person. It then conducted a comprehensive review to identify the at-risk data, data types, and associated people and sent written letters to affected individuals. The public document does not disclose the initial-entry method, credential used, or technical vulnerability.

What Identity and Insurance Information Was Involved?

Fields that varied by person were names, dates of birth, and health-insurance information. Insurance data included billing and payment information; identification-number examples were member, person, certificate, and coverage identifiers. Dates of insurance coverage were also present in the affected files.

These fields can make fake policy, premium, claim, invoice, or membership messages more convincing. A communication is not trustworthy merely because it includes a real member number or coverage date. Use a known insurer website or the number on an insurance card to verify claims, payments, and contact changes separately.

What Financial Information Was Involved?

Pivot Health says financial account information was present for some people. The public notice does not state whether this meant a bank account number, routing number, payment card, or another financial subtype. This entry therefore records only the broad “financial account information” category and does not infer unreported details.

A recipient whose letter lists a financial-account field can check unfamiliar transactions, new payees, automatic payments, and contact-information changes through a known institutional channel. Pivot Health said it was unaware of identity theft or fraud resulting from the event; that is a status as of the notice and does not eliminate the value of monitoring.

Why Do the 8,391 and 5,864 Figures Differ?

The HHS/OCR entry carries a healthcare notification for 5,864 people dated May 13, 2026. The Indiana Attorney General's later June table shows 8,391 nationwide for the same entity and event start. These are sequential notification scopes, not two separate events or two populations that should be added together.

Because the latest official total controls, pwnCount and totalRecords are 8,391. importedRecordCount remains zero to show that LeakData does not hold these people's insurance or financial records. Resident counts reported in Texas, Indiana, or other states are subsets of the nationwide total and are not added a second time.

How Did Pivot Health Respond and What Should Recipients Do?

Pivot Health said it secured its systems after detecting the activity, opened a forensic investigation to confirm the event's nature and scope, reviewed existing security policies, and implemented additional cybersecurity measures. It listed 844-593-8519 for questions, available weekdays from 8:00 a.m. to 8:00 p.m. Eastern.

A recipient should rely on the fields in their own letter and monitor benefits, claims, and bills for insurance or coverage data and transactions for financial-account data. Do not share a password, financial-account information, payment, or one-time code in an unexpected message using the Pivot Health or insurer name.

8.4 Thousand
Affected Accounts
10
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

10
Names
Dates of birth
Health insurance information
Health insurance billing and payment information
Member identification numbers
Person identification numbers
Certificate identification numbers
Coverage identification numbers
Dates of coverage
Financial account information

Additional Information

Added DateJuly 27, 2026
Breach DateFebruary 26, 2026
Domainpivothealth.com
SourceOfficial Pivot Health notice, Indiana Attorney General breach table, and HHS/OCR report
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information