
Brown Health Medical Group-MA, a Massachusetts physician practice operating under Lifespan Physician Group of Massachusetts, is notifying more than 311,000 people that their personal, medical and financial information was exposed in a data breach traced to a legacy file server at its Hawthorn location.
The organization first detected the intrusion on December 16, 2025, and its subsequent investigation determined that unauthorized access to the server took place between December 15 and 16 of that year. The practice isolated the compromised server immediately upon discovery. Its electronic health record system was not affected, according to a sample notification letter filed with the Massachusetts Office of Consumer Affairs and Business Regulation.
Investigators said the nature of the breach made it difficult to pin down precisely which records had been accessed. It was not until June 22, 2026, that the organization established the likely scope of the exposure and began notifying those affected as a precautionary measure.
The information that may have been compromised spans several categories: demographic details such as names, dates of birth and contact information; personnel and human resources data including payroll, compensation and licensure or credentialing records; and other sensitive identifiers such as Social Security numbers, driver’s license and government ID numbers, credit and debit card numbers, and financial account information. Medical and disability-related records tied to personnel files were also among the data potentially affected. The organization noted that not every individual had every category of information exposed.
Brown Health Medical Group-MA reported the incident to the U.S. Department of Health and Human Services, listing 311,760 affected individuals in total, of whom 290,357 reside in Massachusetts.
In response, the practice has retrained its employees, added new security safeguards and said it is cooperating with law enforcement. It is also offering affected individuals two years of complimentary identity protection and fraud monitoring through Experian IdentityWorks, and is advising them to keep a close watch on their financial accounts for signs of misuse.
No threat actor has claimed responsibility for the breach, and no ransomware or extortion group is known to have taken credit for the intrusion.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543