Menu
Browse

Cyber Incident Victim: Hawthorn Medical Associates

Date

Dec 2025

Location

United States of America

Status

Unknown

Timeline
Occurred
Dec 2025
Discovered
Dec 2025
Disclosed
Jul 2026
Resolved
Pending
Summary

A data breach exposed personal information of individuals associated with an unnamed organization after suspicious activity was detected on its network. The compromised data included names, contact details, and other sensitive identifiers, prompting the organization to notify affected individuals and offer credit monitoring services. Investigators determined that unauthorized access occurred through a compromised employee credential, prompting the organization to reset passwords and enhance monitoring controls. Affected individuals were notified and offered credit monitoring services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Hawthorn Medical Associates discovered a data security incident on December 16, 2025, after detecting unauthorized access to a historic file server between December 15 and 16. The breach exposed personal information of over 290,000 Massachusetts residents, according to state filings and legal notices sent in July 2026. Notices indicated that the compromised data could include contact information, Social Security numbers, health insurance details, medical information, bills, bank account numbers, credit card data, and human resources records such as payroll. Hawthorn noted that not all categories of information were impacted for every individual. The organization employs more than 140 medical professionals across twenty specialties and operates a three‑building complex on Faunce Corner Road in Dartmouth that includes urgent care and laboratory services. Hawthorn became an affiliate of Lifespan, now known as Brown University Health, in 2024 after its previous parent, Steward Healthcare, filed for bankruptcy.

Cyber Incident Image

Many recipients of the breach letters expressed confusion because they had never been patients of Hawthorn, with some receiving notices for deceased relatives such as a stepfather who died eleven years prior. State Senator Mark Montigny criticized the seven‑month delay between discovery and notification, urging Brown University Health to provide a full explanation of the breach’s scope and remediation. Cybersecurity experts quoted in the coverage noted that Hawthorn’s incident is the second largest healthcare breach in Massachusetts for the year, following a separate hack at a dental insurer. While experts said that many healthcare breaches involve ransomware, the coverage explicitly stated that it was not clear whether Hawthorn’s incident was caused by such an attack. The reports also mentioned that approximately one in five healthcare breaches result from clerical errors, though no specific cause was identified for this event.

In its public notice, Hawthorn stated that it was notifying potentially affected individuals out of an abundance of caution and that there was currently no evidence that any information had been misused. Jessica A. Wharton, a spokesperson for Brown University Health, echoed that statement, saying she had no additional information to share beyond the written notice. Hawthorn said it was taking the breach very seriously and would continue to take appropriate steps, including re‑training employees and implementing additional technical safeguards to prevent similar incidents. As part of its response, the organization is offering two years of complimentary identity restoration and fraud detection services to those whose data may have been exposed. The notice also acknowledged that Hawthorn could not determine exactly what information was accessed, but in June it concluded that a wide range of private data may have been involved.

Sources
Sources available to members
1 source