Gastro Health experienced two separate phishing incidents on February 25, 2026, and March 2, 2026. These incidents led to unauthorized access to patient data, which was reported to the HHS Office for Civil Rights on May 22, 2026. Official notification letters were mailed to affected individuals on or after May 22, 2026.
The breach affected 35,632 individuals, with 1,813 individuals in Washington and 291 in Massachusetts. Exposed data types include Personal Identifiable Information (PII) such as names, Social Security numbers (SSNs), dates of birth, addresses, and government IDs. Protected Health Information (PHI) like medical record numbers, patient account numbers, Medicare/Medicaid numbers, diagnosis, treatment, prescription, provider, and clinic information was also exposed. Some financial data, such as credit card or financial account information, was involved in one account, though payment card information was not part of the main incident.
More details may emerge as investigations continue. Affected individuals can find additional information and contact resources on the Gastro Health website.