CardioFit Medical Group, Inc., a cardiology practice based in Torrance, California, experienced a data breach that was discovered on February 17, 2026. The incident occurred in January and February 2026 and involved the unencrypted email transmission of patient information. The company disclosed the breach to the California Attorney General, notifying regulators on April 10, 2026.
The breach affected approximately 7,243 individuals. The exposed data types include names, Social Security numbers, demographic information, medical information (including diagnoses), and health insurance information. While the company stated it has no reason to believe the information was accessed or misused, it acknowledged an encryption failure and has implemented corrective measures such as enhanced email encryption and staff training.
More details may emerge over time as investigations proceed and consumer notifications are fully disseminated.