The Phia Group, a healthcare cost containment provider, experienced a data security incident where unauthorized access to its network occurred between July 8 and July 9, 2024. The company detected the incident on July 9, 2024. The Phia Group posted an official company statement on its website on December 4, 2025, and notified clients on the same date. Individual notifications began on January 30, 2026.
The breach exposed personal and health information for at least 125,354 individuals nationwide. This included names, Social Security numbers, dates of birth, addresses, driver’s license numbers, medical information, health insurance details, prescription data, treatment records, Medicare/Medicaid information, financial account information, and government IDs. The Phia Group has stated it has no evidence of fraudulent misuse of the exposed data. The company is offering complimentary credit monitoring and identity theft recovery services through Kroll to affected individuals.
Data breach details can continue to emerge over time, and notification processes may be delayed due to various factors.