Autoaps, a California-based medical data retrieval company, detected unusual activity in its network on December 25, 2025. After containing the incident, an investigation determined that an unauthorized actor may have accessed files containing personal information. The company reported the data breach to the U.S. Department of Health and Human Services on May 22, 2026. The compromised data types include names, addresses, dates of birth, driver's license numbers, email addresses, phone numbers, Social Security numbers, financial information, medical records, and medical information. The breach affected 1,591 individuals in the United States. Autoaps notified Knights of Columbus customers on May 4, 2026. Details surrounding the specific states affected and any official company notification letters have not been publicly disclosed. Further information may emerge as the investigation continues.