Cardiovascular Institute Data Breach Exposes Personal and Health Info

Published
August 3, 2026
Updated
August 3, 2026
Cardiovascular Institute Data Breach Exposes Personal and Health Info
Cardiovascular Institute of New England
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Cardiovascular Institute of New England (CINE), a cardiology group practice that operates eight office locations across Rhode Island, disclosed a data breach that may have resulted in unauthorized access to personal and protected health information belonging to its employees and patients.

A public notice about the data security incident was posted through BusinessWire on July 30, 2026.

On or around Feb. 12, 2026, the practice observed unusual activity in its email environment. The incident involved unauthorized access to an email account that contained personal and health information belonging to employees and patients.

In response, Cardiovascular Institute of New England launched an investigation with the assistance of third-party cybersecurity specialists to determine the nature and scope of the activity.

In addition to a thorough forensic investigation, the practice undertook a comprehensive review of the data in the impacted email account to determine exactly what information may have been affected. The review process was completed on or around July 14, 2026.

The types of personally identifiable information (PII) that may have been exposed included names, phone numbers, dates of birth and financial account numbers.

Protected health information (PHI) that may also have been subject to unauthorized access included medical information, medical diagnosis and treatment information, treatment locations, clinical information, prescription information and medical insurance provider information.

The practice began notifying potentially affected individuals on July 28, 2026. The total number of individuals affected by the breach was not publicly disclosed.

Cardiovascular Institute of New England's response to the breach

The practice is offering complimentary credit monitoring and identity restoration services through Epiq. The deadline to enroll in these complimentary services is Oct. 31, 2026.

Individuals who have questions about the incident or who need help enrolling in the complimentary services can contact the dedicated assistance line at 888-289-7132. The call center is available Monday through Friday from 9:00 a.m. to 9:00 p.m. ET.

The practice encouraged potentially affected individuals to remain vigilant against identity theft and fraud by continuing to review their financial account statements and credit reports for any unusual activity.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
February 12, 2026
Total People Affected
Information Types Exposed
  • name
  • phone number
  • date of birth
  • financial account number
  • medical information
  • medical diagnosis and/or treatment information
  • treatment location
  • clinical information
  • prescription information
  • medical insurance provider information
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image