The medical center, which is affiliated with Brown University Health, recently notified patients of a data breach.
What happened
On July 16th, Lifespan Physician Group of Massachusetts, which does business as Brown Health Medical Group, notified patients of a data breach that took place at its Hawthorn location. According to the notice, a historic file service was accessed by an unauthorized individual between December 15th and 16th, 2025. The practice became aware of the incident on the 16th.
Uniquely, the statement said that they were unable to determine exactly what information was involved, but provided some of the scope, stating that demographic information, health insurance and medical information, payment information, and other personal information like Social Security numbers, ID numbers, and financial account information may have been involved. According to a local news report, the incident impacted over 290,000 Massachusetts residents, some of which are no longer alive.
Going deeper
New Bedford Light, a local publication, found interesting details about the breach that aren’t always released. For instance, one individual expressed confusion about receiving a letter, correctly including her name and address, even though she had never been a patient. Another individual received a notice addressed to her late stepfather, who had died 11 years ago. One lawmaker called the breach one of “the broadest and most troubling,” especially since it’s unclear how some victims are connected to the practice.
The practice has also seen several changes in recent years. In 2024, Hawthorn became an affiliate of Lifespan (known as Brown University Health), after its previous network, Steward Healthcare, filed for bankruptcy.
In a statement from a Brown spokesperson, the affiliate said they were notifying patients “out of an abundance of caution” and that there is “currently no evidence that any information has been misused.”
In the know
In response to the news, state senator Mark Montigny said Brown needed to explain why notifications didn’t come earlier. He also said Brown would need to further explain the extent of the breach and how Hawthorn has responded to prevent other attacks. “Answer the questions fully,” he said.
According to Mike Levinger, a cybersecurity expert and lecturer at Boston University, it’s rarely a matter of “if” a breach will occur but “when.” He added that the delay in breach notifications is fairly normal, and it’s possible that Hawthorn is still investigating the incident or working with police.
The big picture
For Massachusetts, this is the second largest breach in this year alone. DentaQuest, one of the largest administrators of dental benefits in the US, experienced a data breach that impacted at least 15 million individuals across the United States, with some reports stating the number could be closer to 23 million. That breach was claimed by the ransomware group ShinyHunters, who ultimately leaked 234 GB of data that allegedly came from the provider.
While Levinger’s point about being prepared to respond to a breach is important, healthcare organizations shouldn’t take the approach that breaches are inevitable; many incidents can be prevented with the right training and tools. Breaches from employee error, like accidentally clicking on a phishing link, are common but entirely preventable. Tools like the Paubox email suite make it even more fail-safe; the email program automatically quarantines suspicious activity.
FAQs
What is a historic file server?
Generally, a historic file server is just another name for a legacy system, meaning that the system may no longer be used because it’s outdated or no longer effective. It could also mean that the server holds “historic” information, as in past patients from some time ago. The notice did not further elaborate, but either definition would mean that the system is likely not used regularly.
Why would Hawthorn list so much data as being potentially accessed?
Hawthorn listed a plethora of data as being potentially involved in the breach, from things like prescriptions, to credit card information, and general contact information. The vagueness can make it harder for victims to know what data of theirs was actually involved, and shows that Hawthorn may not have a full understanding of what data was accessed for who.
