Cyber Incident Victim: Greenbaum Rowe Smith and Davis
Timeline
Summary
Greenbaum Rowe Smith and Davis discovered unauthorized access to its systems through a compromised user account, leading to a breach that exposed protected health information of nearly 13,000 patients served by Atlantic Health System, Hackensack Meridian Health and Trinitas Regional Medical Center. The firm’s investigation concluded that data of 12,801 individuals was accessed, prompting notification of affected individuals, provision of identity‑theft protection services and a call center, and implementation of enhanced cybersecurity measures.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Greenbaum Rowe Smith and Davis discovered unauthorized access to its computer systems on November 27, 2025, after detecting activity linked to a compromised user account. Upon learning of the breach, the firm immediately reset all passwords, reported the incident to law enforcement, and initiated an internal investigation to determine the nature and extent of the intrusion. The firm also began preserving logs and other evidence to support the investigative process. These initial steps were taken to contain the threat and prevent further unauthorized entry while the investigation proceeded.

The investigation, which concluded on April 15, 2026, determined that an unauthorized third party had acquired protected health information from the firm’s systems. According to a notice published by the U.S. Department of Health and Human Services Office for Civil Rights on May 18, 2026, the breach affected a total of 12,801 individuals. The compromised data included names, addresses, Social Security numbers and other personal details associated with patients of the hospitals and health systems that Greenbaum serves. The firm provides legal services to Atlantic Health System, Hackensack Meridian Health and Trinitas Regional Medical Center, and the notice indicated that patients from all three organizations may have been impacted.
Greenbaum began notifying affected individuals directly by mailing letters that describe the breach and outline the steps being taken to assist them. The firm stated that there is no evidence that the stolen information has been published or misused by the unauthorized party. To help those affected, Greenbaum is offering complimentary identity theft protection services and has established a dedicated call center for questions and support. Individuals can reach the call center at 1‑844‑685‑6447 or visit the website https://response.idx.us/grsd/ for assistance, with enrollment in the protective services required to be completed by September 29, 2026.
A spokesperson for Hackensack Meridian Health, the largest healthcare provider in New Jersey, expressed concern upon learning of the incident involving Greenbaum and noted that the health system remains in close contact with the law firm as it manages the response. The spokesperson emphasized that while the breach did not occur on Hackensack Meridian Health’s own systems, the organization shares the concerns of those affected and is cooperating with Greenbaum’s efforts. Greenbaum has reported that it has enhanced its cybersecurity measures following the breach to reduce the risk of similar incidents in the future. The firm continues to monitor the situation and provide updates to affected individuals as needed.