In early 2026, Kaiser Permanente, a major U.S. healthcare provider, experienced a data breach stemming from a cyberattack on its systems. The incident was publicly reported on February 25, 2026, with an estimated 13.4 million individuals affected. Kaiser Permanente issued official breach notifications, including sample patient letters and a statement on their website, detailing the discovery of unusual activity on January 15, 2026.
The breach involved the exposure of Protected Health Information (PHI) such as medical diagnoses, treatment records, and prescription details. Additionally, personal identifiers including names, dates of birth, addresses, phone numbers, and email addresses were compromised. Social Security numbers were exposed for a subset of approximately 2.5 million individuals. Limited billing and insurance details were also involved, but no full payment card data was confirmed. The affected individuals reside primarily in California, Colorado, Georgia, Hawaii, Maryland, Oregon, Virginia, Washington, and Washington D.C.
Details about data breaches can emerge over time, and official notices to affected individuals may be delayed. The full extent of this incident and any ongoing developments may become clearer with further investigation and public disclosures.