
Cherry Health, formally known as Cherry Street Services Inc., has disclosed a data breach that may affect certain current or former patients as well as current or former staff members. The organization first detected the breach on or about April 19, 2026, and posted a preliminary notice on its website dated June 18, 2026.
The total number of individuals affected has not yet been disclosed. Cherry Health stated that a comprehensive review of the data involved is still ongoing.
According to the organization’s notification, Cherry Health launched an investigation with the support of third-party specialists after detecting suspicious activity on its network, in order to determine the nature and scope of the activity. The organization said it promptly took measures to secure its environment.
The investigation determined that certain information stored on Cherry Health’s network was accessed and copied by an unauthorized individual. Cherry Health is now conducting a comprehensive review of the involved data, in partnership with third-party specialists, to determine exactly what information was at issue and to whom it relates. That review had not been completed at the time the notice was posted.
The types of information that may have been exposed include names, addresses, phone numbers, dates of birth, health insurance information, health insurance ID numbers, patient ID numbers, provider names, service dates, and Social Security numbers. The notification stated that the potentially impacted information varies by individual, with some people having had several of these data types exposed and others only one.
Cherry Health said it takes the event and the security of the information in its care very seriously, and that it is working to implement additional safeguards to reduce the likelihood of a similar incident in the future, as part of its ongoing commitment to protecting privacy.
The organization stated it presently has no evidence that any of the involved information has been used to commit identity theft or fraud. Cherry Health said it is nonetheless providing information about the event and resources to help individuals protect their information from possible misuse, and encouraged individuals to remain vigilant and take proactive steps to safeguard their personal information.
Cherry Health said it will notify potentially affected individuals by written letter once its data review is finalized, with the website notice serving as a preliminary alert in the meantime. Once the review is complete, the letters will inform each person which specific types of their information were involved, and call center representatives will be available to answer questions once the letters are sent.
The notification, which included detailed guidance on steps individuals can take to protect their personal information, was published in both English and Spanish. Individuals seeking more information about the incident may call 888-204-2407 or write to Cherry Health at 100 Cherry St. SE, Grand Rapids, MI 49503. The organization noted that the notice was not delayed by law enforcement.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543