On December 25, 2025, AutoAPS, a medical record retrieval services company, detected unusual activity on its network. An investigation confirmed unauthorized access to files containing personal information. AutoAPS notified Knights of Columbus about the data breach on May 4, 2026. The breach was subsequently disclosed to the Massachusetts Attorney General on August 3, 2026.
The exposed data includes names, addresses, dates of birth, email addresses, phone numbers, Social Security numbers, driver’s license numbers, financial information, and medical records/other protected health information. The specific number of individuals affected has not been publicly reported, and a complete list of affected states is not available beyond the notification to Massachusetts regulators.
Details surrounding the breach, including the exact number of individuals impacted and any further notifications, may emerge as the situation develops. Official company statements regarding the breach have not been made public.