Averhealth Holdings, the parent company of Avertest, Inc., detected unauthorized access to its email environment in January 2026 and is now notifying patients that hackers may have accessed sensitive personal and medical information of 9,909 individuals.

 

What happened

On January 20, 2026, Averhealth detected unusual activity in their email environment. The company immediately contained the incident and launched an investigation, engaging external cybersecurity professionals to assist. That investigation determined an unauthorized party had accessed Averhealth's network between December 19, 2025, and January 21, 2026.

On May 6, 2026, Averhealth discovered the intruder had potentially accessed or acquired files containing names, clinical information, diagnoses, digital or electronic signatures, dates of birth, driver's license numbers, health insurance policy numbers, medical costs, dates of service, medical history, provider names, medical record numbers, treatment and procedure information, mental or physical condition details, minor status, patient account numbers, and Social Security numbers.

Not every affected individual had all categories of information exposed. Averhealth began mailing notification letters to affected individuals on or about July 2, 2026.

 

What was said

In its notification letter, Averhealth said it "detected unusual activity in Avertest's email environment" and responded by immediately containing the incident and starting a "prompt and thorough investigation." The company also stated it has "no evidence of any identity theft or financial fraud related to this incident."

“However, out of an abundance of caution, Averhealth encourages impacted individuals to take actions to help protect their personal information. These actions include placing a fraud alert and/or security freeze on their credit files, and/or obtaining a free credit report,” the company added.

In the know

The classification of the Averhealth breach as a "hacking/IT incident" aligns with the primary trend observed in 2025, where of the 104 email-related breaches reported to the HHS, 81% were categorized as hacking or IT incidents.

Many of these attacks involve third-party vendors and business associates, like Averhealth. In 2025, vendor and business associate email exposure accounted for 28% of all email-related breaches reported to the HHS, making it the most common email breach pattern. These incidents are also among the costliest, with IBM estimating an average breach cost of $4.9 million for organizations affected through third-party vendors.

Learn more: 2025 Healthcare Email Security Report

 

Why it matters

Averhealth offers substance use monitoring and treatment services. As a result, exposed medical records, diagnoses, and treatment information may be tied to substance use treatment history, a category of information many considered sensitive and stigmatizing if disclosed.

Combined with Social Security numbers, driver's license numbers, and medical record numbers, the exposed data set creates risk on two fronts at once, that is, financial identity theft and the potential misuse or exposure of substance use treatment history. For a population already navigating treatment and monitoring programs, that exposure raises the stakes above a normal financial data breach.

 

The bottom line

This breach shows a recurring pattern in healthcare cybersecurity, a months-long gap between initial detection and full discovery of what was actually accessed. Averhealth detected suspicious activity in January 2026 but didn't confirm the scope of compromised files until May, and didn't notify affected individuals until July, nearly six months after the intrusion began.

That, paired with the sensitivity of substance use treatment records, shows why breaches at specialty healthcare providers can carry extreme consequences that carry a greater risk than the standard financial identity theft seen in most data breach incidents.

 

FAQs

What is a data breach?

A breach occurs when an unauthorized party gains access, uses or discloses protected health information (PHI) without permission. Breaches include hacking, losing a device containing PHI, or sharing information with unauthorized individuals.

See also: How to respond to a data breach

 

What is a HIPAA breach notification?

It's the legal requirement under HIPAA for healthcare organizations to notify affected individuals, the Department of Health and Human Services, and sometimes the media, after a breach of protected health information.

Go deeper: Navigating HIPAA’s Breach Notification Rule

 

Can stolen medical information be used for identity theft?

Yes, medical identity theft occurs when someone uses another person's health information to fraudulently obtain medical services, prescriptions, or insurance benefits.