Virta Health Data Breach Exposes PHI and PII Data of 14,636 Patients

Published
June 4, 2026
Updated
July 1, 2026
Virta Health Data Breach Exposes PHI and PII Data of 14,636 Patients
Virta Health

Virta Health Corp. and Virta Medical P.C., collectively referred to as Virta Health in this article, disclosed a data breach that affected approximately 14,636 individuals in the United States.

Between March 19 and March 22, 2026, an unauthorized third party gained access to files stored in a data repository maintained by Virta Health. The company stated that the incident was limited to a data repository that is separate from its current production platform.

One day before Virta Health discovered the breach, on March 23, 2026, a threat actor known as Lapsus-Group posted a claim on the internet, alleging it had leaked data from Virta Health. The group stated its intent to publish the stolen data within six days.

Following a thorough investigation of the impacted data, Virta Health determined that certain personal information may have been exposed during the incident.

The breach exposed a broad range of sensitive personal and health information including first and last names, Social Security numbers, Individual Tax Identification Numbers, dates of birth and contact information, medical diagnosis information, medical condition or treatment information, medical record numbers, health insurance information, clinical information, physician or medical facility information, dates of medical service and other unique health identifiers.

The breach was reported to the California Attorney General and to the U.S. Department of Health and Human Services starting on May 23, 2026. The company has also posted a notice of the data event on its website.

Virta health mailed notification letters to affected individuals on June 17, 2026.

Virta Health's response to the breach

Virta Health is offering 12 months of complimentary single bureau credit monitoring, credit report and credit score services. The company is also providing proactive fraud assistance services for individuals who have questions or who become victims of fraud.

Affected individuals can enroll in the credit monitoring services by visiting the Cyberscout activation page and entering the unique code included in their notification letter. Enrollment must be completed within 90 days of the date of the letter.

Virta Health has also established a dedicated assistance line for anyone with questions about the incident. The call center is available Monday through Friday from 8 a.m. to 8 p.m. Eastern Time, excluding major U.S. holidays.

Individuals may also contact the company by emailing incident@virtahealth.com.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Virta Health
Consumers Notification date
Date of Breach
March 19 to 22, 2026
Breach Discovered Date
March 24, 2026
Total People Affected
14636
Information Types Exposed
  • Individual Tax Identification Number
  • Social Security number
  • Certain medical diagnosis
  • Other unique health identifiers/medical records numbers
  • Certain health insurance information
  • Clinical information
  • Condition
  • Contact information
  • Date of birth
  • Date
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image