Quantum Health Data Breach: What Members Need to Know

The Quantum Health data breach involved sensitive personal and health information belonging to members of employer health plans. Quantum Health, Inc., a Dublin, Ohio-based healthcare navigation company that states it serves more than 570 employer clients, confirmed that an unauthorized party accessed and took files from its systems. If you received a notification letter from Quantum Health, your information may have been compromised — and you may have legal rights.

What Happened?

According to Quantum Health’s official notice, on June 1, 2026 the company detected a service outage affecting the availability of certain internal and external systems. Upon identifying the outage, Quantum Health secured and isolated its systems, launched an investigation with the support of third-party forensics experts, and reported the incident to federal law enforcement.

The investigation determined that the service outage was related to unauthorized access to Quantum Health’s IT network — access that resulted from a user responding to a vishing call on May 29, 2026. Between May 29, 2026 and June 1, 2026, the unauthorized party accessed and acquired files from certain Quantum Health systems.

On July 8, 2026, the investigation further determined that some of those files contained individuals’ personal information. Quantum Health published its public incident notice on July 31, 2026. The breach was also reported to the Massachusetts Office of Consumer Affairs and Business Regulation, whose filing records list the notice among those received in July 2026.

What Is “Vishing”?

Vishing — short for voice phishing, also called phone spoofing — is a social engineering attack in which a caller pretends to be someone they are not in order to obtain account credentials. In Quantum Health’s own description of the incident, the network compromise began when a user responded to such a call.

This detail matters. According to Quantum Health’s own account, the intrusion did not begin with a technical exploit — it began with a phone call that successfully impersonated a trusted party. Whether the safeguards, training, and verification procedures in place at the time were adequate is the kind of question these cases tend to turn on.

What Information Was Exposed?

Per Quantum Health’s notification letter, the files involved in the incident contained individuals’ names along with one or more of the following:

  • Social Security number
  • Health insurance information — including insurance policy number and claims or benefits information
  • Health information — including medical information, treatment information, diagnoses, prescriptions, provider names, and dates of service
  • Other personal information — including date of birth, email address, mailing address, phone number, and demographic information

The specific combination of data varies by individual and is identified in each recipient’s notification letter. In its public notice, Quantum Health stated that Social Security numbers may have been involved for some individuals.

The categories described are broad. Where diagnoses, prescription records, or treatment dates were involved alongside a Social Security number, the resulting risk can extend past ordinary financial fraud into medical identity theft and health insurance fraud — categories of harm that are generally harder to detect and unwind. Your own notification letter is the only reliable guide to which elements applied to you.

What Is Quantum Health Doing?

Quantum Health stated it is enhancing its existing security protocols and implementing additional security measures to help prevent a similar occurrence. The company also stated that its systems have been restored and are safe for use, and that at this time it has no evidence that impacted information has been publicly posted or exposed on the internet.

Affected individuals are being offered complimentary identity monitoring through Kroll, which includes single-bureau credit monitoring, fraud consultation, and identity theft restoration services. Quantum Health’s public notice also references dark web monitoring.

To enroll, affected individuals should visit Enroll.krollmonitoring.com/redeem and provide the activation code and verification ID included in their notification letter, before the activation deadline stated in that letter. Individuals whose information was involved also receive access to an online portal with further detail about the event and the data involved.

A Second, Separate Quantum Health Incident

Affected individuals should be aware that this is not the only Quantum Health data incident disclosed in 2026.

In a notice dated February 12, 2026 and filed with the Massachusetts Office of Consumer Affairs and Business Regulation, Quantum Health sent notifications on behalf of NTT Health Plan, for which it acts as a business associate providing care coordination and healthcare navigation services. According to that notice, an inadvertent disclosure of personal and protected health information occurred between December 15, 2025 and December 29, 2025 — specifically, a claims report was inadvertently disclosed. Quantum Health notified the health plan of the disclosure on December 29, 2025.

The information contained in that report may have included name, address, Social Security number, member identification number, and certain claim information.

Two details from that notice are worth noting. First, Quantum Health stated that it confirmed with the recipient that the report was deleted and that no information was further disclosed, and that there was no evidence any individual’s information had been misused. Second, affected individuals were offered 24 months of complimentary Experian IdentityWorks membership. The sample notice on file states an enrollment deadline of May 31, 2026 and says identity restoration support runs for 24 months from the date of the letter. If you received that notice, check your own letter for the deadline and code that applied to you, as that window may already have closed.

That earlier incident is distinct from the May–June 2026 network intrusion described above. If you received a notice from Quantum Health or from your health plan, check the dates and description carefully to determine which incident applies to you — you may have been affected by either, or both.

How Many People Were Affected?

Quantum Health has not publicly disclosed the total number of individuals affected by the 2026 network intrusion. The company provides healthcare navigation services to more than 570 employer clients nationwide, and states on its own website that it has guided more than 20 million members through their healthcare journeys — so the potential scope of this incident is significant. Reported counts in incidents of this kind may increase as investigations continue and as filings are made in additional states.

Your Rights After the Quantum Health Data Breach

In at least one 2026 filing, Quantum Health is identified as a business associate under HIPAA, handling protected health information on behalf of a client health plan. Where that role applies, it does not diminish the obligation to safeguard the information in its care, and it does not diminish your rights if that information was involved.

If your information was involved in the Quantum Health data breach, you may be entitled to compensation for:

  • The unauthorized access to and acquisition of your personal and protected health information
  • Costs associated with credit monitoring, credit freezes, and identity protection
  • Actual financial losses resulting from identity theft, medical fraud, insurance fraud, or tax fraud
  • Emotional distress caused by the exposure of sensitive diagnosis, prescription, and treatment information
  • Time and effort spent responding to the breach and protecting your accounts

Contact Wilshire Law Firm for a Free Consultation

If you received a notification letter from Quantum Health about either of these incidents, Wilshire Law Firm wants to hear from you. Our legal professionals can review your situation and help you understand your options at no cost.

We take no fees unless you get paid.

Contact us online to speak with a legal professional today.

LET US HELP