Greenbaum Rowe Smith and Davis LLP says a compromised employee login led to the exposure of sensitive patient records, prompting a monthslong investigation and new security measures.

Greenbaum Rowe Smith and Davis LLP, a New Jersey law firm with a substantial healthcare practice, has disclosed a data breach that exposed personal and medical information belonging to 12,801 people, according to a notice filed with the U.S. Department of Health and Human Services Office for Civil Rights.
The firm identified unauthorized access to its network through a compromised employee account, with the intrusion occurring between Nov. 25 and Nov. 27, 2025. Upon discovering the breach, Greenbaum Rowe reset passwords across its systems, replaced compromised computer equipment and notified law enforcement. It then engaged outside cybersecurity specialists to determine the cause and scope of the incident.
That investigation, completed April 15, found that an unauthorized third party had obtained a range of patient information from the firm’s systems. The exposed data included patients’ names, home addresses, medical record numbers, treatment histories, provider information, billing amounts and health insurance details. For a subset of individuals, Social Security numbers and dates of birth were also involved.
Federal regulations require health data breaches affecting 500 or more people to be publicly logged with the Department of Health and Human Services, which is how the incident became part of the public record.
Founded in 1914, Greenbaum Rowe employs roughly 100 attorneys across three New Jersey offices, in Iselin, Roseland and Red Bank. The firm’s healthcare department represents hospitals, physician groups, dental and behavioral health practices, nursing homes, pharmaceutical companies, medical device manufacturers and managed care organizations.
Greenbaum Rowe said it has found no indication that the compromised information has been published or misused. The firm is notifying affected individuals directly by mail and is offering identity theft protection services along with a dedicated call center to field questions. Those seeking assistance can call 1-844-685-6447 or visit response.idx.us/grsd/. The deadline to enroll in the identity protection services is Sept. 29.
Following the breach, Greenbaum Rowe said it strengthened its cybersecurity defenses by adding monitoring and detection tools, and stated it will continue reviewing its physical and electronic safeguards to protect personal information and its systems.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543