All Breaches
February 21, 2026 Verified Sensitive Record Healthcare

South Florida Injury Centers 2026 Data Breach

The South Florida Injury Centers 2026 data breach was a confirmed cybersecurity incident identified through suspicious activity on certain network servers at a Florida chiropractic and injury-care provider. According to the official patient notice, an unauthorized third party accessed the SFIC network between February 21 and March 15, 2026; the event was detected on March 23.

The U.S. Department of Health and Human Services Office for Civil Rights lists the South Florida Injury Centers event as a Hacking/IT Incident affecting 1,525 people. LeakData imported no patient or person rows, and importedRecordCount is zero. This entry is verified through the official Massachusetts notice, HHS report, and a reliable incident summary linking the sources.

How Was the South Florida Injury Centers Breach Confirmed?

The primary source is the South Florida Injury Centers patient letter published by the Massachusetts Office of Consumer Affairs and Business Regulation. It directly describes the discovery date, access window, forensic review, law-enforcement report, possible personal and health information, complimentary identity protection, and steps available to patients.

The federal HHS OCR record classifies SFIC as a Florida healthcare provider and reports 1,525 people, a May 22, 2026 submission date, a network-server location, and a hacking/IT incident type. Claim Depot independently joins the same person total with Indiana and Massachusetts regulatory disclosures and the information categories in the official letter.

What Happened Between February 21 and March 15?

SFIC identified suspicious activity on certain servers in its network on March 23, 2026. It secured the environment, opened an investigation into the nature and scope of the event, engaged third-party cybersecurity experts to perform forensic analysis of affected systems, and notified law enforcement. The investigation placed network access between February 21 and March 15.

The official letter says some patient information may have been affected, but it does not state that the attacker definitively copied or exfiltrated files. The sources do not name an attacker, initial entry method, exploited vulnerability, or persistence technique. LeakData therefore does not add an unverified ransomware or data-exfiltration claim.

What Personal Information May Have Been Affected?

The official notice identifies names and Social security numbers as possible personal fields. A name combined with an SSN creates elevated risks of identity theft, fraudulent credit or tax applications, and targeted impersonation. The document indicates that information may vary by person, so this record does not assume that every patient had the same combination involved.

The source does not expressly list dates of birth, driver's licenses, bank accounts, payment cards, passwords, or biometric data, and LeakData does not add those fields. Offering identity monitoring also does not by itself prove that unlisted financial data was involved. Data classes remain limited to the scope verified in the official patient letter.

What Health Information Was Involved?

Possible health information includes diagnosis and treatment details, diagnostic test results such as Mri or x-ray reports, hospital records, and intake forms that may contain medical history supplied by the patient. These fields may reveal physical conditions, injuries, and care history and increase risks involving medical privacy and medical-identity impersonation.

The official source does not say that the entire electronic health-record platform or every patient's complete file was affected. “Hospital records” and “intake forms” describe particular documents in scope. LeakData does not infer prescriptions, insurance-policy details, a complete image archive, or other unspecified clinical fields from those phrases.

How Did SFIC Respond?

South Florida Injury Centers secured its environment, conducted a forensic investigation with outside cybersecurity specialists, reviewed potentially affected information, and notified relevant individuals out of caution. The organization reported no evidence of identity theft or fraud related to the event. That finding does not eliminate the possibility of future misuse.

Affected people were offered 24 months of Iris Identity Protection. The package includes Equifax single-bureau credit monitoring, identity monitoring, identity-fraud insurance, and identity-resolution services, with enrollment due within 90 days of the letter. LeakData does not store the recipient-specific promotional code because it is not published in the public source.

What Should Affected People Do?

Patients should review credit reports, financial-account activity, health-insurance explanation-of-benefits statements, and patient portals for unusual activity. If an unknown credit account, MRI, X-ray, hospital record, or treatment appears, the relevant organization should be contacted through a verified channel; a free fraud alert or credit freeze may be appropriate for SSN risk.

SSNs or health information should not be shared in unexpected email, messages, or calls claiming to represent SFIC or Iris; only assistance channels in the individual letter should be used. LeakData does not host, distribute, or make searchable any potentially affected files, patient records, diagnostic results, or Social security numbers.

1.5 Thousand
Affected Accounts
11
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

11
Personal information
Protected health information
Names
Social security numbers
Diagnosis information
Treatment information
Diagnostic test results
Mri or x-ray reports
Hospital records
Intake forms
Medical histories

Additional Information

Added DateJuly 27, 2026
Breach DateFebruary 21, 2026
Domainsflchiro.com
SourceOfficial patient notice confirming unauthorized server access involving possible PII and PHI
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information