
Virta Health, a Colorado-based healthcare company, said that a data security breach it experienced earlier this year exposed sensitive personal information belonging to nearly 15,000 individuals.
Virta Health is a Denver, Colorado–based digital healthcare provider that specialises in helping patients reverse metabolic conditions such as type 2 diabetes, obesity, and pre-diabetes through personalised nutrition plans and ongoing remote medical support.
In a data security incident notice posted on its website, the healthcare company said that on March 24, it identified unauthorised access to a data repository that operates separately from its active production environment.
Virta Health immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“The investigation revealed that the incident was limited to the data repository where certain files were potentially accessed between March 19, 2026, and March 22, 2026,” Virta Health said.
The compromised data included names, Social Security Numbers, Individual Tax Identification Numbers, dates of birth, health insurance information, medical diagnosis, condition, facility, services dates or treatment information, as well as other unique health identifiers and medical records numbers.
Virta Health reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights, stating that it identified at least 14,636 individuals who were impacted by the cyber security incident.
The healthcare provider has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
The Lapsus$ ransomware group claimed responsibility for the cyberattack on Virta Health, listing the company as a victim on its data leak site. The group claimed it had obtained confidential data stolen from the healthcare provider and threatened to release the information publicly unless its ransom demands were met.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543