Well Child, Inc., a private healthcare company based in Memphis, Tennessee, discovered a cybersecurity incident affecting its computer network on June 1, 2022. The company responded by taking affected servers offline and engaged an independent cybersecurity expert. By June 6, 2022, it was determined that certain files had been taken from a temporary file storage server, potentially exposing sensitive personal information.
The breach was officially disclosed to the U.S. Department of Health and Human Services on August 14, 2026. The exposed information may include Social Security numbers, assessment or testing results, billing or procedure codes, dates of birth, diagnoses, medical record numbers, names, protected health information, provider names, and treatment dates. The total number of affected individuals has not been publicly disclosed.
Further details about the incident and its full scope may emerge as investigations continue, and consumer notifications may be subject to various timelines.