
Laurel Health Centers, a federally qualified health center network serving Northern Pennsylvania, has confirmed that an unauthorized third party accessed portions of its email environment in July 2025, potentially exposing sensitive patient information.
The organization identified unusual email activity and launched an internal investigation on July 14, 2025. The review determined that an unauthorized party gained access to certain employee email accounts between July 11 and July 25, 2025. During that period, emails and attached files within those accounts may have been viewed or copied.
An examination of the affected email accounts found that they contained patient information. The data involved varies by individual and may include names combined with other personal, financial and health-related details. These may include addresses, telephone numbers, email addresses, dates of birth, Social Security numbers, medical record numbers, dates of service and provider information. Additional data elements may include Medicare and insurance information, diagnostic and treatment details, procedure codes, disability status, dental and denture records, immunization history, behavioral health information, Pennsylvania Account IDs, account numbers, credit card and checking account information, and insurance claim data.
Laurel Health Centers stated that confirming the complete removal of the unauthorized party from its systems required additional time, resulting in a delay between the initial discovery of the activity and final containment of the incident. The review of the affected email accounts was completed on Dec. 30, 2025.
Notification letters were mailed to impacted individuals shortly after the review concluded. Laurel Health Centers has also offered complimentary credit monitoring services to those affected.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543