Cyber Incident Victim: Brown Health Medical Group-MA
Timeline
Summary
Brown Health Medical Group-MA reported that a breach of its historic file server at the Hawthorn location exposed personal, medical, and financial information of over 311,000 individuals. The compromised data included names, contact details, dates of birth, Social Security numbers, driver’s license numbers, government IDs, medical and disability records, financial account information, credit/debit card numbers, and personnel records such as payroll, compensation, and licensure details. After isolating the affected server and implementing additional safeguards, the organization notified the Department of Health and Human Services that 311,760 people were affected, including 290,357 Massachusetts residents, and is offering two years of free fraud detection and identity protection services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In December 2025, a data breach occurred at the Hawthorn location of Lifespan Physician Group of Massachusetts, which operates as Brown Health Medical Group‑MA. The breach involved a historic file server that was accessed by unauthorized actors, while the organization's electronic health record system remained unaffected. Brown Health Medical Group‑MA did not become aware of the intrusion until June 22, 2026, when it determined that attackers had accessed files containing personal information. Upon discovery, the organization began the process of notifying affected individuals and relevant authorities.

The potentially compromised data included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, government ID numbers, medical and disability‑related records, financial account information, and credit or debit card numbers. Personnel and human resources records, such as payroll, compensation details, and licensure or credentialing information, were also exposed. Brown Health Medical Group‑MA noted that not every category of information was impacted for each individual, meaning the scope of exposure varied across the affected population. The organization reported to the U.S. Department of Health and Human Services that 311,760 individuals were affected, of whom 290,357 are residents of Massachusetts.
After identifying the breach, Brown Health Medical Group‑MA immediately isolated the affected file server to prevent further unauthorized access. The organization subsequently implemented additional safeguards on its systems and initiated retraining programs for employees to improve security awareness. To support those impacted, Brown Health Medical Group‑MA is providing two years of free fraud detection and identity protection and restoration services. These actions constitute the organization's response to the incident and its efforts to mitigate potential harm to the affected individuals.
