A data breach at Brown Health Medical Group-MA has compromised the sensitive personal, medical, and financial information of 311,760 individuals after attackers gained unauthorized access to a legacy file server.

 

What happened

According to Security Affairs, Brown Health Medical Group-MA discovered suspicious activity involving its legacy file server in December 2025. The organization promptly isolated the compromised system and initiated a forensic investigation. On June 22, 2026, investigators determined that cybercriminals had accessed files containing sensitive information.

According to a breach notification submitted to the U.S. Department of Health and Human Services (HHS), 311,760 individuals were affected, including approximately 290,357 Massachusetts residents.

The exposed information varies by individual but may include:

  • Names
  • Contact information
  • Dates of birth
  • Social Security numbers
  • Driver's license and government identification numbers
  • Medical and disability-related information
  • Financial account information
  • Credit and debit card numbers
  • Personnel and payroll information
  • Professional licensure and credentialing records

 

Going deeper

Brown Health Medical Group-MA has not identified the threat actor responsible for the intrusion, and no known ransomware or extortion group has publicly claimed responsibility for the attack.

Following the investigation, Brown Health Medical Group-MA said it implemented additional security measures, strengthened system monitoring, and enhanced employee cybersecurity training to reduce the risk of similar incidents in the future. The breach has also been reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, where it is listed among healthcare breaches affecting more than 500 individuals. Additionally, the organization has started notifying affected individuals.

 

What was said

According to the data breach notice, the organization noted that it “first became aware of a data security incident impacting a historic file server at the Practice on December 16, 2025. We immediately initiated an investigation and isolated the server. Through our investigation, we determined that the unauthorized access to the server occurred between December 15–16, 2025. This incident did not impact the Practice’s electronic health record system.”

Furthermore, Brown Health Medical Group-MA acknowledged that investigators could not determine exactly which files were accessed or which individuals' information was specifically affected, stating, “Due to the nature of the incident, we have been unable to conclusively determine exactly what information was impacted. However, on June 22, 2026, we determined the scope of personal information that may have been impacted by this incident, and we are providing this notice out of an abundance of caution."

The organization said the potentially exposed information may include demographic information (such as names, dates of birth, and contact information), personnel and human resources records (including compensation or payroll information, licensure or credentialing information, and medical or disability-related records), as well as other personal information such as Social Security numbers, driver's license or other government-issued identification numbers, credit or debit card numbers, and financial account information.

Brown Health Medical Group-MA added that “not all categories of information were impacted for all individuals.”

 

In the know

Many healthcare organizations continue to rely on legacy systems to support clinical and administrative operations. While these systems often contain years of valuable patient and business data, they may no longer receive security updates or support, making them attractive targets for cybercriminals. As noted in Paubox's article, When legacy systems become a vulnerability, outdated technology can create security gaps that attackers exploit to gain access to sensitive information, even when core electronic health record (EHR) systems remain secure. Regularly inventorying legacy assets, applying compensating security controls, and retiring unsupported systems where possible are essential steps for reducing cyber risk and safeguarding protected health information (PHI).

 

Why it matters

The Brown Health Medical Group-MA breach affected 311,760 patients, demonstrating how a single cyberattack on a legacy system can expose the sensitive information of thousands of individuals. Although the organization's EHR system was not compromised, the incident shows that older infrastructure storing historical patient data can present significant cybersecurity risks if left unprotected.

The breach also reflects a broader challenge across the healthcare industry. According to a Paubox report, “83% of healthcare IT leaders report that legacy systems disrupt day-to-day operations,” making it more difficult to maintain security, apply updates, and defend against evolving cyber threats. As healthcare organizations continue balancing aging technology with modern security requirements, the incident serves as a reminder that protecting legacy systems is just as important as securing active clinical platforms.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQS

Why are legacy systems a cybersecurity risk?

Legacy systems often run outdated software that may no longer receive security updates, making them more vulnerable to cyberattacks. They can also store years of sensitive patient and administrative data, increasing the potential impact of a breach.

 

Why do healthcare organizations continue using legacy systems?

Many healthcare organizations rely on legacy systems because replacing them can be costly, time-consuming, and disruptive to patient care. Some older medical devices and applications also require legacy software to function.

 

How can healthcare organizations reduce the risk of legacy system breaches?

Organizations can reduce risk by maintaining an inventory of legacy assets, implementing network segmentation, enforcing multi-factor authentication, limiting user access, monitoring for suspicious activity, and developing a plan to modernize or replace unsupported systems.

 

Why is employee cybersecurity training important?

Employees are often the first line of defense against cyber threats. Regular training helps staff recognize phishing attempts, follow secure data handling practices, and respond appropriately to suspicious activity.