Premier Medical Group Data Breach Exposes 280,000 Patients' Sensitive Health Information
Premier Medical Group (PMG) has reported a data breach that compromised the personal and medical information of over 280,000 patients, with the incident occurring in June 2026.

New York-based healthcare provider Premier Medical Group (PMG) is in the process of notifying more than 280,000 patients that their sensitive personal and medical data was accessed and stolen during a data breach.
PMG, which offers a wide range of medical services including cardiology, dermatology, gastroenterology, and neurology across multiple locations in the Hudson Valley, detected disruptions to some of its systems in June 2026. A subsequent investigation by the healthcare provider confirmed that unauthorized actors gained access to certain files on June 14.
The compromised data encompasses a broad spectrum of patient information. This includes names, contact details such as addresses and phone numbers, dates of birth, treatment and diagnostic information, medication details, health insurance data, dates of service, names of healthcare providers, and internal patient identification numbers. The breach affects individuals who received care from PMG.
In response to the incident, PMG has advised patients to carefully review all statements received from their healthcare providers and health insurance plans. The group urged patients to immediately contact their provider or insurer if they identify any services that were not rendered, suggesting a potential for fraudulent activity.
The healthcare provider officially reported the incident to the U.S. Department of Health and Human Services (HHS), indicating that 282,075 individuals were impacted. HHS has since added Premier Medical Group to its publicly accessible data breach portal, a common step for healthcare organizations following such incidents.
Details regarding the specific attack vector or the identity of the threat actors responsible for the breach have not yet been disclosed by PMG. To date, no known ransomware or extortion groups have publicly claimed responsibility for the incident, leaving the motive and origin of the attack unclear.
This incident underscores the persistent cybersecurity challenges faced by the healthcare sector, where large volumes of sensitive patient data make organizations prime targets for cybercriminals. The ongoing investigation aims to shed further light on the breach's specifics and to implement measures to prevent future occurrences.