PIH Health Discloses Data Breach Exposing SSNs, Health Information, and More

Published
March 2, 2026
Updated
March 3, 2026
PIH Health Discloses Data Breach Exposing SSNs, Health Information, and More
PIH Health
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

PIH Health experienced a major data breach that affected its digital environment between Nov. 14, 2024, and Dec. 2, 2024. The incident first came to light on Dec. 1, 2024, when the company discovered unusual activity within a portion of its network.

On Dec. 13, 2024, a threat actor known as Dreamer2000 claimed responsibility for the data leak and posted about it on an open web forum, indicating that the breach was the result of a targeted data leak attack. Steps were taken to secure the network, and a thorough investigation was launched with the support of third-party cybersecurity specialists.

The investigation revealed that an unauthorized actor accessed certain files containing personal information. By Dec. 16, 2025, PIH Health confirmed that personal information was present in the compromised files.

The breach exposed both PII and PHI including names, Social Security numbers, driver’s license numbers, financial account information, credit/ debit card numbers, medical information, and health insurance information.

The process of identifying affected individuals and gathering contact information was completed by Feb. 25, 2026.

The breach was publicly disclosed to the California Attorney General and the Texas Attorney General. The company also posted a notice of the incident on its website.

The incident affected individuals across multiple states, including 8,434 Texas residents and 174 Rhode Island residents.

PIH Health's response

To help protect those impacted, PIH Health is offering complimentary identity protection services through Experian IdentityWorks.

Affected individuals are eligible for a free membership for a specified period, which includes credit monitoring, identity restoration support, and up to $1 million in identity theft insurance. Enrollment instructions and activation codes were provided in the notification letters sent to individuals whose information was exposed.

Steps such as placing a fraud alert or security freeze on credit files, as well as obtaining an IRS Identity Protection PIN, are recommended for additional protection.

Individuals with questions or concerns can contact Experian’s customer care team for support and guidance on identity restoration and credit monitoring.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
PIH Health
Consumers Notification date
Date of Breach
December 2, 2024
Breach Discovered Date
on or about December 16, 2025
Total People Affected
Information Types Exposed
  • Name of individual
  • Social Security Number Information
  • Driver’s License number
  • Financial Information (e.g. account number, Social Security numbers, credit or debit card number)
  • Medical Information
  • Health Insurance Information
  • Dates of birth
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image