
Brooklyn-based healthcare data management company, Clinical Registry Solutions, disclosed a data breach that involved patient information it maintained on behalf of St. Mary's Medical Center, a Dignity Health hospital. CRS is a vendor that provides clinical data abstraction and registry support services to hospitals and health systems.
On April 9, 2026, CRS identified suspicious activity within its network. The company stated that it took steps to secure the network and launched an investigation into the nature and scope of the incident.
The investigation found that an unauthorized party accessed CRS's network on that date and that certain files containing patient information from St. Mary's Medical Center were acquired during the intrusion, according to the notification.
On May 6, 2026, the ransomware group known as Akira claimed responsibility for the attack on a Tor-based dark web site. The group stated it had obtained 41 GB of data from Clinical Registry Solutions. According to the dark web posting, the compromised data reportedly includes detailed employee personal information such as passports, driver's licenses, Social Security numbers and health data.
The group also claimed to have obtained client documents, financial records, payment details, contracts, agreements and non-disclosure agreements.
In its notification to affected consumers, CRS described a more limited scope of exposed patient data. The company stated that the patient information involved included first and last names, Socal Security numbers, driver's license numbers, medical record numbers, and procedure dates.
The breach was disclosed to the California Attorney General, to the Massachusetts Attorney General and to the Nebraska Attorney General. The incident was additionally disclosed to the U.S. Department of Health and Human Services.
The total number of individuals affected in the United States was 8,545.
CRS sent notification letters to affected individuals through Cyberscout, a TransUnion company that is managing the breach response on CRS's behalf. The notification included an enclosed document outlining steps consumers can take to help protect their information, such as placing fraud alerts, requesting credit freezes and monitoring credit reports.
The company has also established a dedicated call center through Cyberscout to assist affected individuals with questions about the incident. The call center can be reached at 1-800-405-6108, Monday through Friday from 8:00 a.m. to 8:00 p.m. EST, excluding major U.S. holidays. CRS can also be contacted by mail at 306 Gold St., Suite 31E, Brooklyn, NY 11201.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)