Premier Medical Group of the Hudson Valley is notifying more than 280,000 patients that a June 2026 cybersecurity incident exposed their personal and medical information.
What happened
According to SecurityWeek, Premier Medical Group (PMG), a healthcare provider in New York's Hudson Valley, experienced a cyber incident that disrupted some of its IT systems in June 2026.
The company launched an investigation with the assistance of third-party forensic experts after discovering the incident. The investigation found that an unauthorized party accessed certain files on PMG's systems on June 14. Those files contained patients' personal and health information.
PMG reported the incident to the US Department of Health and Human Services (HHS), which lists 282,075 affected individuals on its breach portal. SecurityWeek reported that HHS added the healthcare provider to its breach database in September.
PMG has not disclosed how the attackers gained access to its systems or identified the individuals responsible. There is also no known ransomware or extortion group publicly claiming responsibility for the incident, according to SecurityWeek.
Going deeper
The breach involved files containing protected health information (PHI) and personal identifiers. The information potentially exposed includes:
- Names and contact information
- Dates of birth
- Health insurance information
- Provider names
- Dates of service
- Internal patient identification numbers
- Medication information
- Treatment and diagnostic information
PMG determined the nature of the information involved approximately one month after the unauthorised access occurred. The healthcare provider subsequently reported the incident to the US Department of Health and Human Services (HHS), which was then classified as a hacking/IT incident involving a network server.
What was said
In its breach notice, Premier Medical Group said it “immediately took steps to secure our systems and launched an investigation with the assistance of third-party forensic experts.” The provider also said it “notified law enforcement” as part of its response.
PMG said its investigation determined that “an unauthorized party accessed some of the files on PMG’s systems on June 14, 2026.” The provider subsequently investigated the information contained in those files and determined on July 14 that they “may have included” patients’ names, contact information, dates of birth, health insurance information, provider names, internal patient identification numbers, dates of service, medication information, and treatment or diagnostic information.
The healthcare provider said it “take[s] this matter very seriously” and that it will “continue to implement and evaluate enhanced safeguards and security measures to further protect our systems.” PMG also said it would “continue to provide security training to our employees” to help prevent a similar incident.
PMG advised affected patients to review statements from their healthcare providers and health insurance plans and said they should contact their provider or health plan immediately if they identify services they did not receive. The organization has also established a dedicated incident response line to answer patients’ questions about the breach.
In the know
A hacking/IT incident is a category used by the HHS to describe breaches involving unauthorized access to electronic systems or networks. These incidents can involve methods such as ransomware, malware, phishing, or other forms of unauthorized system access. HHS breach reports show that hacking/IT incidents are a significant source of large healthcare data breaches.
Recent healthcare breaches illustrate the range of incidents that can fall into this category. Averhealth Holdings reported a data breach affecting more than 9,000 individuals after an unauthorized party gained access to its systems. Meanwhile, CareCloud, a healthcare IT platform, investigated an incident involving unauthorized access to files and disclosed information about the incident to the US Securities and Exchange Commission (SEC).
Why it matters
With 282,075 individuals reported as affected, the breach ranks among the larger healthcare data breaches reported to HHS in 2026. The scale of the incident is large, but the types of information involved also raise concerns for affected patients.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
What is a healthcare data breach?
A healthcare data breach occurs when protected health information is accessed, disclosed, or acquired by someone who is not authorized to access it.
Why is healthcare data targeted by cybercriminals?
Healthcare organizations hold large amounts of sensitive personal, medical, and financial information, making their systems valuable targets for cybercriminals.
What can happen after healthcare data is stolen?
Stolen information may be used for identity theft, fraud, phishing, social engineering, or other forms of cybercrime.
