
Nephrology Associates, M.D., P.A., a medical practice specializing in kidney care services including kidney disease treatment and dialysis, has disclosed a data breach involving its computer network.
Between Jan. 17, 2026, and April 9, 2026, unauthorized access to the Nephrology Associates network occurred. During that nearly three-month window, data was taken from the company's systems.
Notably, a ransomware group known as Insomnia posted a claim on the Tor dark web network on April 5, 2026. In that posting, the group stated that it had obtained data belonging to Nephrology Associates.
After discovering the unauthorized access, the company launched an investigation with the assistance of outside cybersecurity professionals. The investigation included a comprehensive review of documents stored on the affected systems.
At the conclusion of the investigation, the company confirmed which types of personal information had been taken. The exposed information included full names, dates of birth, driver's license numbers or state identification numbers, other government identification numbers, treatment or diagnosis information and health insurance policy information.
Nephrology Associates discovered the breach on July 1, 2026.
The company began sending written notifications to affected individuals on July 30, 2026. The total number of individuals affected has not been publicly disclosed.
For individuals who have questions about the breach, the company has set up a dedicated, confidential toll-free response line at 888-289-6950. It is available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time, excluding major U.S. holidays.
The company's notification letter also provides guidance on several protective measures, including how to place fraud alerts and security freezes with the three major credit bureaus. It includes information on obtaining free annual credit reports and offers tips for guarding against medical identity theft. The letter lists attorney general contact information for residents of several states, including Iowa, Maryland, Massachusetts, New York, North Carolina and Oregon, as well as Washington, D.C.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)