Brown Health Medical Group Data Breach Exposes Sensitive Information of Over 311,000 Individuals
Brown Health Medical Group-MA has reported a data breach affecting over 311,000 individuals, with sensitive personal, medical, and financial data compromised.

Lifespan Physician Group of Massachusetts, operating as Brown Health Medical Group-MA, is in the process of notifying more than 311,000 individuals about a significant data breach that resulted in the theft of their personal, medical, and financial information. The incident, which occurred in December 2025 at the organization's Hawthorn location, involved a historic file server.
While the group's electronic health record system remained unaffected by the breach, Brown Health Medical Group-MA confirmed on June 22, 2026, that unauthorized actors had gained access to files containing a wide array of sensitive data. This potentially compromised information includes names, contact details, dates of birth, Social Security numbers, driver's license numbers, government ID numbers, medical and disability-related records, financial account information, and credit or debit card numbers.
Further complicating the breach's impact, personnel and human resources records were also accessed. This includes sensitive information such as payroll and compensation details, as well as licensure or credentialing information. The organization has clarified that not all categories of information were impacted for every individual affected by the incident.
Upon discovering the breach, Brown Health Medical Group-MA stated it took immediate action to isolate the affected server. The organization has since implemented additional security safeguards and is conducting re-training for its employees to reinforce security protocols. The breach was reported to the US Department of Health and Human Services (HHS), which indicated that 311,760 individuals were affected, with 290,357 of those being residents of Massachusetts.
To mitigate the potential harm to those affected, Brown Health Medical Group-MA is offering two years of complimentary fraud detection and identity protection services, including restoration assistance. The identity of the threat actor responsible for the attack has not been disclosed, and no known ransomware or extortion groups have publicly claimed responsibility for the incident.
This incident highlights the persistent vulnerability of healthcare organizations to data breaches, even when core systems like EHRs are not directly compromised. The reliance on legacy systems or historical data storage can still present significant security risks, as demonstrated by the compromise of the "historic file server" in this case.
The breach also underscores the broad spectrum of sensitive data that can be exposed in healthcare cyberattacks, ranging from personal identifiers and medical histories to financial details and employment records. The sheer volume of affected individuals, over 311,000, emphasizes the widespread potential impact on patient privacy and financial security.
As investigations continue, the full ramifications of this breach will become clearer. However, the immediate response from Brown Health Medical Group-MA, including offering identity protection services and implementing enhanced security measures, reflects standard practice in addressing such significant data security incidents within the healthcare sector.