Blog > Data Breach & Privacy

Alma Family Services Data Breach: A Hacked Network Server

Alma Family Services, an East Los Angeles nonprofit offering mental health and family services, reported a network server hacking incident affecting 2,753 people to federal regulators. It had not posted a notice on its website as of October 5. Here’s what is known and what to do.

Alma Family Services Data Breach: A Hacked Network Server

What Happened at Alma Family Services

A hacking incident reported to HHS on September 10, 2026

Alma Family Services reported a data breach to the U.S. Department of Health and Human Services on September 10, 2026. The federal listing classifies it as a hacking or IT incident, names a network server as the location of the affected information and indicates that no business associate, such as an outside vendor, was involved.

Little else is public. Alma has not described when the intrusion happened, when it was discovered or how the attacker got in, and as of October 5, 2026, we found no notice about the incident on its website.

Information at Issue in the Alma Breach

Health information, with the specifics not yet released

The HHS portal lists breaches of unsecured protected health information that affect 500 or more people, so Alma’s report indicates that health information was involved. The listing does not identify which details, and Alma has not published a list of data types.

That should become clearer once letters arrive. Under HIPAA’s breach notification rule, a provider’s letter to affected individuals must describe the types of information involved, such as whether names, Social Security numbers or diagnoses were included.

An East Los Angeles Provider Since 1975

2,753 people listed, with no breakdown yet

Alma Family Services was founded in 1975 in East Los Angeles by parents seeking multilingual, community-based services for families, including those with special needs. Its website says it operates eight mental health outpatient offices in Long Beach, Walnut, Pico Rivera, El Monte and East Los Angeles, and its programs range from substance abuse services to a preschool and an aquatics center.

The HHS listing shows 2,753 affected individuals but does not say whether they are clients, employees or others. Because Alma serves communities across Los Angeles County, many of those affected may live in California. As of October 5, 2026, no sample notice for this incident appeared on the California Attorney General’s data breach list.

How Alma Family Services Has Responded So Far

No public statement beyond the federal report

Alma has not published a statement about its investigation, the steps it has taken to secure its systems or whether it will offer credit monitoring or identity protection. Organizations usually cover those points in the letters they send to affected individuals.

HIPAA generally requires those letters to go out without unreasonable delay and no later than 60 calendar days after a breach is discovered, unless law enforcement asks for a delay. Alma has not said when it discovered this incident, so public records don’t show when its letters are due.

What You Can Do While Waiting for a Letter

Practical precautions before details are released

Until Alma explains what was involved, these precautions cover the most common risks:

  • Watch your mail for a letter from Alma. It should say which of your details were involved and whether any monitoring is being offered.
  • Check insurance and benefit statements. Claims for visits, prescriptions or services you never received can signal that someone is using your health information.
  • Consider a credit freeze as a precaution. Alma hasn’t said whether Social Security numbers were involved, but a freeze at the three national credit bureaus is free and can be lifted when you need credit.
  • Be careful with anyone who contacts you about the breach. Fraudsters sometimes use real incidents as cover, so verify the caller or sender with contact information you find on your own.

This overview is not legal advice; a legal professional can walk you through what applies to your circumstances.

Talk to Wilshire Law Firm

Worried your Alma Family Services records were exposed?

Have you received care or other services from Alma Family Services, or are you waiting to learn whether your information was on the hacked server? Wilshire Law Firm is based in Los Angeles, and our award-winning, nationally recognized team handles data privacy claims, including health care breaches that are sometimes litigated as class actions. Talk with a legal professional in a free consultation or free case review; we’re available 24/7, and there are no fees unless you get paid.

Reach out today, and we’ll go over what Alma has told you so far.

FAQs

Alma has not said. The only date on record is September 10, 2026, when it reported the breach to the U.S. Department of Health and Human Services.

The HHS listing shows 2,753 affected individuals. Alma has not said how that number breaks down between clients, staff and others.

Alma has not published a list. Because the HHS portal tracks breaches of unsecured protected health information, health information was involved, and the letters sent to affected individuals should describe the specific types.

As of October 5, 2026, we found no notice on Alma’s website and no sample letter on the California Attorney General’s breach list. HIPAA requires written notice to each affected individual, so keep an eye on your mail.

Alma has not said. Check any letter you receive for an offer, and keep in mind that a credit freeze at the three national credit bureaus costs nothing.

It is how Alma’s report to HHS categorizes the breach. It points to unauthorized access to a server on Alma’s network, as opposed to a lost device or a misdirected mailing, but it does not say whether ransomware was involved or whether files were copied.

You may have options, depending on what your letter shows. Alma reported a hacking incident that HHS lists as affecting 2,753 people, and health care breaches of this kind are commonly evaluated as possible class action claims. In California, the Confidentiality of Medical Information Act can also apply when a health care provider fails to protect medical information, depending on the facts. A free case review can help you understand where you stand.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,524 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance