Premier Medical Group of the Hudson Valley is notifying more than 280,000 patients that a June 2026 cybersecurity incident exposed their personal and medical information.

 

What happened

According to SecurityWeek, Premier Medical Group (PMG), a healthcare provider in New York's Hudson Valley, experienced a cyber incident that disrupted some of its IT systems in June 2026.

The company launched an investigation with the assistance of third-party forensic experts after discovering the incident. The investigation found that an unauthorized party accessed certain files on PMG's systems on June 14. Those files contained patients' personal and health information.

PMG reported the incident to the US Department of Health and Human Services (HHS), which lists 282,075 affected individuals on its breach portal. SecurityWeek reported that HHS added the healthcare provider to its breach database in September.

PMG has not disclosed how the attackers gained access to its systems or identified the individuals responsible. There is also no known ransomware or extortion group publicly claiming responsibility for the incident, according to SecurityWeek.

 

Going deeper

The breach involved files containing protected health information (PHI) and personal identifiers. The information potentially exposed includes:

  • Names and contact information
  • Dates of birth
  • Health insurance information
  • Provider names
  • Dates of service
  • Internal patient identification numbers
  • Medication information
  • Treatment and diagnostic information

PMG determined the nature of the information involved approximately one month after the unauthorised access occurred. The healthcare provider subsequently reported the incident to the US Department of Health and Human Services (HHS), which was then classified as a hacking/IT incident involving a network server.

 

What was said

In its breach notice, Premier Medical Group said itimmediately took steps to secure our systems and launched an investigation with the assistance of third-party forensic experts.The provider also said itnotified law enforcementas part of its response.

PMG said its investigation determined thatan unauthorized party accessed some of the files on PMG’s systems on June 14, 2026.The provider subsequently investigated the information contained in those files and determined on July 14 that theymay have includedpatients’ names, contact information, dates of birth, health insurance information, provider names, internal patient identification numbers, dates of service, medication information, and treatment or diagnostic information.

The healthcare provider said ittake[s] this matter very seriouslyand that it willcontinue to implement and evaluate enhanced safeguards and security measures to further protect our systems.PMG also said it wouldcontinue to provide security training to our employeesto help prevent a similar incident.

PMG advised affected patients to review statements from their healthcare providers and health insurance plans and said they should contact their provider or health plan immediately if they identify services they did not receive. The organization has also established a dedicated incident response line to answer patients’ questions about the breach.

 

In the know

A hacking/IT incident is a category used by the HHS to describe breaches involving unauthorized access to electronic systems or networks. These incidents can involve methods such as ransomware, malware, phishing, or other forms of unauthorized system access. HHS breach reports show that hacking/IT incidents are a significant source of large healthcare data breaches.

Recent healthcare breaches illustrate the range of incidents that can fall into this category. Averhealth Holdings reported a data breach affecting more than 9,000 individuals after an unauthorized party gained access to its systems. Meanwhile, CareCloud, a healthcare IT platform, investigated an incident involving unauthorized access to files and disclosed information about the incident to the US Securities and Exchange Commission (SEC).

 

Why it matters

With 282,075 individuals reported as affected, the breach ranks among the larger healthcare data breaches reported to HHS in 2026. The scale of the incident is large, but the types of information involved also raise concerns for affected patients.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQS

What is a healthcare data breach?

A healthcare data breach occurs when protected health information is accessed, disclosed, or acquired by someone who is not authorized to access it.

 

Why is healthcare data targeted by cybercriminals?

Healthcare organizations hold large amounts of sensitive personal, medical, and financial information, making their systems valuable targets for cybercriminals.

 

What can happen after healthcare data is stolen?

Stolen information may be used for identity theft, fraud, phishing, social engineering, or other forms of cybercrime.