
Navvis & Company, a St. Louis-based business services firm, disclosed a data breach to the Oregon Attorney General on December 29, 2023. This breach led to unauthorized access to files on their network, compromising sensitive information of SSM Health patients. SSM Health, a prominent healthcare provider, affirmed that patient data, including names, Social Security numbers, birth dates, health plans, and medical details, was accessed by an unauthorized entity.
Navvis initiated an investigation upon detecting suspicious activity in their IT network on July 25, 2023. The probe, aided by cybersecurity experts, revealed a cyberattack between July 12 and July 25, 2023. Hackers breached Navvis’ network, obtaining files containing confidential data linked to SSM Health patients. The compromised information encompassed various personal and medical details, varying among individuals.
SSM Health promptly issued data breach notifications to affected patients on December 29, 2023, outlining the specific compromised information. Notably, the breach did not infiltrate SSM Health’s IT systems, with all compromised data residing solely on Navvis’ network.
SSM Health, a not-for-profit Catholic healthcare system operating across several states, encompasses 23 hospitals, 12 post-acute facilities, and over 300 physician offices, catering to communities in Illinois, Missouri, Oklahoma, and Wisconsin. SSM Health plays a significant role in healthcare delivery, with more than 40,000 employees and an annual revenue of approximately $9 billion.
On the other hand, Navvis & Company collaborates with health plans, health systems, and physician groups, aiming to revolutionize healthcare delivery models. Based in St. Louis, Navvis employs over 267 individuals and generates an estimated annual revenue of $55 million.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543