Next Step Healthcare, LLC has experienced a data security incident. On June 5, 2024, Next Step discovered unusual activity on its network where data is stored. The company, which operates 16 nursing and rehabilitation facilities in Massachusetts, initiated an investigation which determined that unauthorized individuals may have accessed or downloaded data from certain Next Step systems.
Next Step Healthcare issued a press release announcing the cybersecurity incident on May 29, 2025. The incident was disclosed on May 29, 2025 to the Massachusetts and Vermont Attorney Generals' offices, with 10,041 individuals affected in Massachusetts. The data breach breach was reported to the New Hampshire Attorney General’s office on May 30, 2025, disclosed that 1,697 individuals in New Hampshire were affected.
Information exposed in the Next Step Healthcare data breach includes names, dates of birth, Social Security numbers, driver’s license numbers, financial account numbers, diagnosis or treatment information, and other health-related details. According the the HHS Breach Portal, the protected health information (PHI) of 12,090 current and former residents were involved in the breach.
In response to the incident, Next Step Healthcare took immediate action to terminate the unauthorized activity and secure its network. Individuals impacted by the data breach were notified by mail on May 29, 2025.
If you have received a notification from Next Step Healthcare, consider taking the following steps:
Next Step Healthcare also established a dedicated, toll-free call center. Individuals with questions or concerns about the incident can reach the call center Monday through Friday from 9:00 am to 9:00 pm Eastern Time at 1-877-674-1598.
More information about the company and its services can be found on the Next Step Healthcare website.