
St. Louis Park, Minnesota based health company, Lifespark Management Services Inc., disclosed a data breach after discovering unauthorized access within its email environment.
The breach occurred in Lifespark's email environment, where suspicious activity was detected, according to the company's notice. An investigation into the incident determined that certain information contained within the email environment had been subject to unauthorized access for a limited period of time.
Following the investigation, Lifespark conducted a detailed review of the potentially impacted data. The company described this review as "comprehensive and time-consuming," noting that it required identifying both the specific types of information contained within the affected data and the particular individuals to whom that information related.
Because the email environment contained data involving multiple people, the review required a person-by-person analysis of the potentially impacted information.
The types of personally identifiable information (PII) potentially exposed vary by individual but may include names combined with one or more of the following: dates of birth, driver's license or state ID numbers, financial account information, payment card information, Social Security numbers and passport numbers.
In addition to PII, protected health information (PHI) may also have been compromised, including treatment information, diagnosis information, disability information, medical record numbers, provider information, prescription information and health insurance information. The combination of personally identifiable, financial, medical and government-issued identification information potentially exposed makes this breach broad in scope.
Lifespark discovered the breach on or about Feb. 18, 2026. The company posted a notice of the data event on its website, dated July 24, 2026, providing consumers with information about the incident and guidance on steps they can take to help protect themselves.
Following the completion of its investigation and data review, Lifespark began the process of notifying potentially affected individuals about the breach. Approximately five months passed between the company's discovery of the breach in February 2026 and the publication of its consumer notice in July 2026.
Lifespark has established a dedicated call center for individuals who have questions about the breach or who need additional information. Those who believe they may have been affected can reach the call center at 1-866-898-3999 to learn more about the incident and discuss protective steps.
In its notice, the company encourages individuals to remain vigilant by regularly monitoring their accounts and records for any signs of unauthorized activity. Given the breadth and sensitivity of the information potentially exposed in this breach, affected individuals may want to consider taking protective steps promptly.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)