Hacks & Exploits
Cybersecurity Breach Exposes Personal Data of Over 311,000 Americans
A serious cybersecurity incident has jeopardized the personal, medical, and financial information of more than 311,000 individuals in the United States. The Lifespan Physician Group, operating as the Brown Health Medical Group in Massachusetts, reported unauthorized access to its systems, leading to the potential theft of sensitive data.
According to the U.S. Department of Health and Human Services Office for Civil Rights, the breach may have exposed names, dates of birth, contact information, payroll and credentialing records, medical data, Social Security numbers, driver’s license numbers, and credit or debit card details.
The organization first detected the security incident on December 16, 2025, and promptly initiated an investigation. It was determined that the unauthorized access occurred between December 15 and 16, 2025. Importantly, the breach did not affect the electronic health record system.
While the full extent of the compromised information remains unclear, the Brown Medical Group has proactively notified affected individuals and is providing two years of complimentary identity restoration and fraud detection services through Experian IdentityWorks.
FAQ
What personal information was exposed in the cybersecurity breach?
The breach may have exposed names, dates of birth, contact information, payroll and credentialing records, medical data, Social Security numbers, driver’s license numbers, and credit or debit card details.
When did the Lifespan Physician Group detect the security incident?
The security incident was first detected on December 16, 2025.
Did the breach affect the electronic health record system?
No, the breach did not affect the electronic health record system.
What services are being offered to affected individuals?
The Brown Medical Group is providing two years of complimentary identity restoration and fraud detection services through Experian IdentityWorks.
How many individuals were impacted by the breach?
The breach has jeopardized the personal data of more than 311,000 individuals in the United States.