The security failure originated on January 2, 2026, when an unauthorized actor gained access to the provider's internal systems. Pennyroyal discovered the activity the following day and retained cybersecurity experts to determine the scope of the exposure. A comprehensive file review concluded on July 17, confirming that the breach compromised a wide spectrum of patient data, ranging from basic identification to highly sensitive medical and financial information.
Exposed records include Social Security numbers, driver’s licenses, passport details, and Medicaid IDs, alongside extensive clinical data such as diagnosis codes, treatment locations, mental health history, and payment card information. While Pennyroyal maintains that it has found no evidence of data misuse to date, the breadth of the compromised files necessitates heightened vigilance from those impacted. The organization began issuing formal notices to affected individuals on July 24 and has opened a toll-free call center at 1-833-851-9448 to assist with recovery and security concerns.




Comments (0)
No comments yet. Be the first!