
Tombigbee Healthcare Authority, which operates Whitfield Regional Hospital in Demopolis, Alabama, disclosed a data breach involving unauthorized access to its computer network.
On June 8, 2025, Whitfield Regional Hospital experienced a cybersecurity incident that resulted in unauthorized access to its network.
The hospital launched an investigation with the help of external cybersecurity professionals experienced in handling these types of incidents. The investigation found that unauthorized individuals may have accessed or removed files from the hospital's network between May 15, 2025, and June 8, 2025.
The hospital then conducted a thorough review of the potentially impacted data. On June 26, 2026, more than a year after the breach was first detected, the review was completed.
The types of information exposed varied by individual but included first and last name, date of birth, Social Security number, driver's license number, financial account information, medical information and health insurance information.
The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation on July 17, 2026. The hospital also posted a notice on its website with details about the incident and steps consumers can take.
Whitfield Regional Hospital began notifying affected individuals on July 17, 2026.
The hospital is offering 12 months of complimentary credit monitoring and identity protection through Experian IdentityWorks. Individuals who receive a notification letter will find a personal activation code and enrollment instructions included. The enrollment deadline is Oct. 31, 2026.
Individuals with questions can call the hospital's dedicated and confidential response line at 877-791-2655. The line is available Monday through Friday from 9 a.m. to 7 p.m. Eastern time, excluding major U.S. holidays. The response line will be available for 90 days from the date of the notification letter.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)