Laurel Health Centers, operating as North Penn Comprehensive Health Services, Inc., experienced a data breach stemming from unauthorized access to email accounts between July 11-25, 2025. The incident was discovered on July 14, 2025, and public notification began after a data review concluded on December 30, 2025. The company directly notified affected individuals by mail and posted an official notice on its website.
The breach exposed sensitive personal identifiable information (PII) and protected health information (PHI) for an undetermined number of individuals. The types of data exposed include names, dates of birth, Social Security numbers, addresses, phone numbers, emails, medical record numbers, dates of service, medical providers, Medicare/insurance information, diagnostic/treatment/diagnosis details, procedure codes, disability status, dental/denture/immunization/behavioral health information, PA Account IDs, account numbers, credit card information, checking account details, and claim information. The exact number of affected individuals has not been publicly disclosed, but notifications were sent to current and former patients. It remains unclear whether all email accounts were accessed or what the full scope of the compromise entails.
Additional details about this data breach may emerge as investigations continue. Notices to regulatory agencies likely occurred after December 30, 2025, as is standard practice for healthcare data breaches.