
Alabama-based Bradford Health Services said a data security incident it suffered in 2023 compromised the sensitive personal information of more than 20,000 patients and staff.
On May 30, in a data security incident notice published on its website, Bradford Health said that on December 8, 2023, it detected unusual activity within its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“The investigation determined that certain files stored on the network may have been accessed and acquired without authorisation. After a thorough review of those files, which concluded on May 15, 2025, Bradford Health determined that certain individuals’ personal and/or protected health information may have been affected,” Bradford Health said.
The compromised data included names, Social Security numbers, driver’s license numbers, dates of birth, medical information (including diagnosis and treatment information, physician names, and Medical Record numbers), health insurance information, financial account numbers, passport numbers and payment card numbers.
On May 30, in a filing with the Office of Maine Attorney General, Bradford Health said it has identified at least 22,465 individuals impacted by the incident.
“Bradford Health has implemented additional measures to enhance network security and minimise the risk of a similar incident occurring in the future. Bradford Health also reported the incident to the law enforcement,” the healthcare provider added.
While Bradford Health found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
In January last year, the Hunters International group claimed responsibility for the cyber attack on Bradford Health and listed it as a victim on its data leak site. The group claimed to be in possession of 769.7 GB of data, consisting of 626,837 files, including agreements, medical records, SQL backups, employee data, and business-related data and threatened to publish it unless their ransom demands were fulfilled.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543