On July 2, 2026, Child Care Resource Center, Inc. reported a phishing incident in which files from October 4, 2016, to October 15, 2025, were forwarded to an external email account.
What happened
Child Care Resource Center, Inc., a California healthcare-sector organization, filed a notice with the California Attorney General disclosing an email phishing incident. The notice does not state how many individuals were affected or specify which categories of personal information may have been involved. In its letter to affected individuals, the company apologized for the incident and outlined steps recipients can take to protect themselves, including enrolling in credit monitoring, placing a fraud alert or security freeze, and obtaining a free credit report.
What was said
In the notice letter, the Child Care Resource Center stated, "Please accept our apologies that this incident occurred." The company also told recipients it has "taken many precautions to safeguard" personal information in its possession. On the topic of medical records specifically, the company wrote, "We have no evidence that your medical information involved in this incident was or will be used for any unintended purposes."
In the know
Under California's Data Breach Notification Law (California Civil Code §§ 1798.29 and 1798.82), organizations must notify affected residents when unencrypted personal information is acquired, or is reasonably believed to have been acquired, by an unauthorized person. In this case, the compromised files reportedly spanned nearly nine years, from October 4, 2016, to October 15, 2025, showing how an email compromise can expose years of stored sensitive information.
Furthermore, if protected health information (PHI) was involved, the incident may be subject to the HIPAA Breach Notification Rule. HIPAA generally requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI.
Depending on the size of the breach, organizations may also be required to notify the U.S. Department of Health and Human Services' Office for Civil Rights (OCR), and breaches affecting more than 500 residents of a state or jurisdiction generally require notification to prominent media outlets.
The big picture
While the Child Care Resource Center's filing does not disclose how many individuals were affected, email-related breaches continue to expose the healthcare sector to major risk. The risk is reflected in 2025 data from the U.S. Department of Health and Human Services (HHS), which recorded 170 email-related healthcare breaches affecting more than 2.5 million individuals. These figures prove exactly how phishing attacks can compromise years of sensitive information and potentially impact large numbers of patients.
Go deeper: 2025 Healthcare Email Security Report
Why it matters
Healthcare organizations, like Child Care Resource Center, rely on email for communication, care coordination, and billing, making phishing one of the most persistent entry points into systems that contain protected health information (PHI).
As a result, these organizations must use a HIPAA compliant solution, like Paubox email, to prevent unauthorized access to individuals’ PHI. Additionally, they must uphold HIPAA’s Breach Notification Rule and notify the affected individuals, explaining the incident, and providing guidance on potential identity theft that may occur.
When organizations submit a public filing that doesn’t clarify the timeline or scope of the incident, it may leave regulators and the public with an incomplete view of how these attacks unfold and what controls might have prevented them.
Learn more: HIPAA Compliant Email: The Definitive Guide
The bottom line
Anyone who received a notice from the Child Care Resource Center should read the letter closely for the specific enrollment deadline, activation code, and any details on what data may have been affected. Affected individuals must enroll in the offered credit monitoring and review their insurance statements for unfamiliar activity.
FAQs
What is phishing?
Phishing is a cyberattack technique that uses deceptive emails or messages to trick recipients into revealing credentials, clicking on malicious links, or downloading malware.
What is medical identity theft?
Medical identity theft occurs when someone uses a person's stolen information to receive healthcare services or insurance reimbursements under that person's name.
How is a fraud alert different from a security freeze?
A fraud alert asks creditors to verify identity before opening new accounts, while a security freeze blocks access to a credit report until the consumer lifts it.
