Gastro Health disclosed a phishing-related data security incident following its discovery on February 25 and March 2, 2026. This incident involved unauthorized access to employee email accounts. Notification letters were mailed to affected individuals starting on or around May 28, 2026, and credit monitoring and identity theft protection were offered.
The reported data types that may have been involved include Social Security numbers, dates of birth, names, medical record numbers, health records, and health insurance information. The exact number of affected individuals and the specific states impacted by this breach have not been publicly confirmed. Details regarding State Attorney General filings and the official breach notification letter are not available at this time.
Additional information about this incident may emerge as investigations continue. Notices to affected individuals may also be delayed.