Brookhaven ENT Allergy and Facial Surgery
Incident posture
Linked entities
- Victim
- Brookhaven ENT Allergy and Facial Surgery
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Brookhaven ENT Allergy and Facial Surgery notified 30,403 individuals that some of their personal and protected health information was compromised in a cybersecurity incident involving its third‑party electronic health record provider, CareCloud. The breach exposed names, addresses, dates of birth, Social Security numbers, driver’s license or government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information. CareCloud reported the breach to the HHS Office for Civil Rights, noting that the incident affected approximately 3.75 million individuals across its client base. At the time of notification, no actual or attempted misuse of the exposed data had been identified.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, notified 30,403 individuals that some of their personal and protected health information had been compromised in a recent cybersecurity incident. The incident involved a third‑party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. According to the CareCloud breach listing on the OCR data breach portal, the breach affected approximately 3.75 million individuals. The unauthorized access occurred between March 10, 2026, and March 16, 2026.
A file review of the compromised data determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers or other government ID numbers, financial account numbers, credit or debit card numbers, and medical and health insurance information had potentially been exposed. At the time the notifications were issued, no actual or attempted misuse of the impacted data had been identified. The breach did not involve the organization’s own network but stemmed from the third‑party provider’s systems. The scope of the exposure included both personal identifiers and protected health information.
Brookhaven ENT Allergy and Facial Surgery sent notification letters to the affected individuals informing them of the potential compromise. The organization relied on the breach report submitted by CareCloud to the HHS’ Office for Civil Rights as the basis for its notification. No further details about additional response measures, such as offered credit monitoring or identity protection services, are provided in the source material. The notification process completed the organization’s communicated response to the incident.
Sources
Sources available to members: 1 source.