Blog > Data Breach & Privacy

Brown Health Medical Group-MA Data Breach: What Patients Need to Know

Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, reported that an unauthorized party accessed a historic file server at its Hawthorn location in December 2025, with more than 311,000 individuals listed as affected. Here is what has been disclosed and what patients can consider doing.

Brown Health Medical Group-MA Data Breach: What Patients Need to Know

What Happened in the Brown Health Medical Group-MA Data Breach

Unauthorized access to a historic file server in December 2025

According to a substitute notice issued by Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA, the practice first became aware on December 16, 2025, of a data security incident affecting a historic file server at its Hawthorn location. The practice states that it immediately began an investigation and isolated the server, and that the investigation determined the unauthorized access occurred between December 15 and December 16, 2025. According to the notice, the incident did not impact the practice’s electronic health record system.

The practice reports that, because of the nature of the incident, it was unable to conclusively determine exactly what information was impacted, and that on June 22, 2026, it determined the scope of personal information that may have been involved. Notification letters and the public substitute notice followed on July 16, 2026, the same date the incident was reported to the U.S. Department of Health and Human Services. As with many incidents of this kind, details reported at this stage may be refined as the review continues.

What Information May Have Been Involved

Demographic, medical, insurance, financial, and personnel records

In its notice, the practice states that the categories of information that may have been impacted include demographic information such as name, date of birth, and contact information; health insurance information; medical information; billing, claims, and payment information; and other personal information such as Social Security numbers, driver’s license numbers or other government-issued identification numbers, credit or debit card numbers, and financial account information.

For a subset of individuals, the practice reports the impacted information may also have included personnel and human resources records, such as compensation or payroll information, licensure or credentialing information, and medical or disability-related records, indicating that employees as well as patients may be affected. The notice emphasizes that not all categories of information were impacted for all individuals. Where identifiers such as Social Security numbers and payment card data may have been exposed alongside health information, there can be an elevated risk of identity theft, medical identity theft, and financial fraud.

Who May Be Affected by the Brown Health Medical Group-MA Breach

More than 311,000 individuals listed by federal regulators

The U.S. Department of Health and Human Services Office for Civil Rights breach portal lists 311,760 individuals as affected by the incident, categorized as a hacking/IT incident involving a network server and submitted on July 16, 2026. The Vermont Attorney General’s office lists 86 Vermont residents among those notified, and reporting on the practice’s filing with the Massachusetts Attorney General indicates roughly 290,000 Massachusetts residents were affected, though the practice itself has not published a state-by-state breakdown.

Brown Health Medical Group-MA is the Massachusetts physician-practice arm of Brown University Health, the system formerly known as Lifespan, and the notice ties the incident to its Hawthorn location. Individuals potentially affected may include current and former patients of the practice as well as employees whose personnel records were maintained on the affected server. If you received a letter from Lifespan Physician Group of Massachusetts or Brown Health Medical Group-MA referencing this incident, that notice may indicate your information was among the data reported to have been affected.

How the Practice Responded and What Protections Are Offered

Two years of complimentary identity restoration and fraud detection services

The practice reports that it isolated the affected server, investigated the incident, notified law enforcement, re-trained its employees, and implemented additional technical safeguards intended to prevent incidents of this nature from recurring. It states that it is providing complimentary identity restoration and fraud detection services to affected individuals for two years.

According to the notice, individuals with questions about the incident can call a dedicated line between 9:00 a.m. and 9:00 p.m. Eastern Time, Monday through Friday, excluding major holidays. If you received a notification letter, it should include instructions for enrolling in the offered services; reviewing that letter closely can help you take advantage of them before any stated deadline.

Steps You Can Take to Protect Yourself

Practical precautions while the situation is reviewed

Given the breadth of information the practice reports may have been involved, affected individuals may wish to consider a few precautionary steps:

  • Enroll in the offered services. If your letter includes enrollment instructions for the two-year identity restoration and fraud detection services, consider activating them.
  • Consider a credit freeze or fraud alert. Both are free through Equifax, Experian, and TransUnion, and a freeze can help prevent new accounts from being opened with a stolen Social Security number.
  • Review your payment cards and financial accounts. Because credit or debit card numbers and financial account information may have been involved, watch for unfamiliar charges and consider asking your bank about replacing affected cards.
  • Monitor your Explanation of Benefits statements. Watch for medical claims or services you did not receive, which can be a sign of medical identity theft.
  • Stay alert to phishing. Be cautious of unexpected emails, calls, or texts referencing the incident, and verify communications through official channels before sharing information.

This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.

Talk to Wilshire Law Firm

Were you affected by the Brown Health Medical Group-MA data breach?

If your health information or personal data may have been involved in the Lifespan Physician Group of Massachusetts / Brown Health Medical Group-MA data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.

Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.

FAQs

According to the practice’s notice, it first became aware of the incident on December 16, 2025, and its investigation determined the unauthorized access to the file server occurred between December 15 and December 16, 2025. The scope of affected information was determined on June 22, 2026, and notices were issued on July 16, 2026.

The practice reports that an unauthorized party accessed a historic file server at its Hawthorn location. Federal regulators categorize the incident as a hacking/IT incident involving a network server. The practice states its electronic health record system was not impacted.

The practice reports the information may have included names, dates of birth, contact information, health insurance information, medical information, billing and payment information, Social Security numbers, driver’s license or government ID numbers, credit or debit card numbers, and financial account information, and for a subset of individuals, personnel and human resources records. Not all categories applied to all individuals.

The HHS Office for Civil Rights breach portal lists 311,760 individuals as affected. The Vermont Attorney General lists 86 Vermont residents, and reporting on the Massachusetts filing indicates roughly 290,000 Massachusetts residents.

Yes. The notice was issued by Lifespan Physician Group of Massachusetts, Inc., which does business as Brown Health Medical Group-MA. Lifespan is the former name of the health system now known as Brown University Health.

The practice reports that it is providing complimentary identity restoration and fraud detection services to affected individuals for two years. Enrollment instructions are included in the notification letters.

Individuals who believe they were affected may have legal options, and data breaches involving Social Security numbers, payment card data, and health information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,519 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance