Nephrology Associates Data Breach Exposes PHI and PII

Published
July 30, 2026
Updated
July 30, 2026
Nephrology Associates Data Breach Exposes PHI and PII
Nephrology Associates
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Nephrology Associates, M.D., P.A., a medical practice specializing in kidney care services including kidney disease treatment and dialysis, has disclosed a data breach involving its computer network.

Between Jan. 17, 2026, and April 9, 2026, unauthorized access to the Nephrology Associates network occurred. During that nearly three-month window, data was taken from the company's systems.

Notably, a ransomware group known as Insomnia posted a claim on the Tor dark web network on April 5, 2026. In that posting, the group stated that it had obtained data belonging to Nephrology Associates.

After discovering the unauthorized access, the company launched an investigation with the assistance of outside cybersecurity professionals. The investigation included a comprehensive review of documents stored on the affected systems.

At the conclusion of the investigation, the company confirmed which types of personal information had been taken. The exposed information included full names, dates of birth, driver's license numbers or state identification numbers, other government identification numbers, treatment or diagnosis information and health insurance policy information.

Nephrology Associates discovered the breach on July 1, 2026.

The company began sending written notifications to affected individuals on July 30, 2026. The total number of individuals affected has not been publicly disclosed.

Nephrology Associates' response to the breach

For individuals who have questions about the breach, the company has set up a dedicated, confidential toll-free response line at 888-289-6950. It is available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time, excluding major U.S. holidays.

The company's notification letter also provides guidance on several protective measures, including how to place fraud alerts and security freezes with the three major credit bureaus. It includes information on obtaining free annual credit reports and offers tips for guarding against medical identity theft. The letter lists attorney general contact information for residents of several states, including Iowa, Maryland, Massachusetts, New York, North Carolina and Oregon, as well as Washington, D.C.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Nephrology Associates
Consumers Notification date
July 30, 2026
Date of Breach
between January 17, 2026, and April 9, 2026.
Breach Discovered Date
July 1, 2026
Total People Affected
Information Types Exposed
  • full name
  • date of birth
  • driver’s license number or state identification number
  • other government identification number
  • treatment/diagnosis information
  • health insurance policy information
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image