Gastroenterology & Hepatology of Central New York Data Breach Exposes Social Security Numbers and Medical Records

Published: 24 September 2026
Healthcare data breach illustration
Breach Discovery: March 2026Breach Notification: September 2026

Gastroenterology & Hepatology of Central New York discovered in March 2026 that hackers accessed its network and stole files containing patients’ names, addresses, dates of birth, Social Security numbers, and medical record numbers. Notifications went out in September 2026. Affected patients should enroll in the offered free credit monitoring and consider a credit freeze immediately.

CompanyGastroenterology & Hepatology of Central New York
IndustryHealthcare
Data Types ExposedFull Names, Home Addresses, Phone Numbers, Dates of Birth, Social Security Numbers, Medical Record Numbers
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Network Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Gastroenterology & Hepatology of Central New York Data Breach?

Gastroenterology & Hepatology of Central New York, a digestive and liver disease practice with offices in Liverpool and Syracuse, has begun notifying patients about a serious cybersecurity incident. The GHCNY data breach involved unauthorized access to internal systems and the theft of sensitive files. This notification comes after the practice discovered suspicious activity on its network.

According to the practice, unauthorized access to its network occurred in March 2026. The intrusion was first identified on March 6, 2026, prompting the practice to take immediate action to contain the threat. As a result, the incident was stopped before it could spread further into connected systems.

Because the situation involved a potential data theft, GHCNY brought in third-party cybersecurity and digital forensics specialists. These experts investigated the scope of the intrusion. Their findings confirmed that an unauthorized party had accessed certain systems and removed files from the network on or around March 6, 2026.

The forensic review took several months to complete before notifications went out. This is not unusual for healthcare breach investigations, since providers must first determine exactly whose information was affected. Once that review was finished, GHCNY moved forward with formal notification to those impacted.

Who was affected?

The GHCNY data breach primarily affects patients of the gastroenterology and hepatology practice. Because the organization treats digestive disorders and liver disease, the exposed records likely include people who sought care for chronic or sensitive medical conditions. This raises the stakes for privacy given the nature of the treatment history involved.

At this time, the exact number of affected individuals has not been publicly disclosed. The breach has not yet appeared on the HHS Office for Civil Rights breach portal, which normally lists the total patient count once healthcare breaches are formally reported. Therefore, the full scope of the incident remains unclear.

Patients from both the Liverpool and Syracuse locations may be included in the notifications. Since medical record numbers were among the stolen data, it appears the attackers accessed a broad set of patient files rather than a single isolated record. In addition, because dates of birth were exposed, it is possible that both adult and minor patients could be affected.

What Information Was Potentially Exposed?

The forensic investigation determined that specific categories of personal and medical information were included in the stolen files. This data is highly sensitive because it combines identity details with medical record identifiers.

  • Full names
  • Home addresses
  • Phone numbers
  • Dates of birth
  • Social Security numbers
  • Medical record numbers

This combination of data creates significant risk for identity theft. With a name, date of birth, and Social Security number together, criminals can attempt to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. Because this data does not expire or change easily, the risk can persist for years after a breach like this one.

In addition, the presence of medical record numbers raises the possibility of medical identity theft. This occurs when someone uses stolen information to obtain medical services, prescriptions, or insurance reimbursements under another person’s identity. As a result, victims could face incorrect entries in their own medical history, which can complicate future care and billing.

What is the company doing?

Once GHCNY confirmed the exfiltration of files, the practice notified affected patients on September 17, 2026. Alongside the notification, GHCNY made complimentary credit monitoring and identity theft protection services available to those impacted. This step is intended to help patients detect and respond quickly to any misuse of their information.

At the time notifications were issued, GHCNY stated that no misuse of the affected data had been identified. However, the practice continues to encourage vigilance among patients. Because the breach has not yet been listed on the HHS Office for Civil Rights portal, additional regulatory details may still emerge as the investigation and reporting process continues.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. You can request free reports from all three major credit bureaus and review them for signs of fraud. Doing this consistently makes it easier to catch problems early.

Because Social Security numbers were exposed, this step is especially important. Identity thieves often wait months or even years before using stolen data, so ongoing monitoring is more effective than a single check. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Credit Freeze or Fraud Alert

Given that Social Security numbers were part of the stolen data, placing a credit freeze is a strong protective measure. A freeze blocks new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name.

Alternatively, a fraud alert requires lenders to verify your identity before extending credit. Both options are free and can be requested directly through each credit bureau. Because the exposed data included both name and Social Security number together, this step should not be delayed.

Enroll in the Offered Credit Monitoring and Identity Protection Services

GHCNY has offered complimentary credit monitoring and identity theft protection to those affected. If you received a notification letter, it should include instructions for enrolling. Taking advantage of this service costs nothing and adds another layer of oversight over your financial accounts.

These services typically alert you to new account openings or suspicious credit activity. As a result, enrolling promptly gives you a better chance of catching fraud before it causes lasting damage. Be sure to complete enrollment before any deadline listed in your notification letter.

Watch for Medical Identity Theft and Billing Errors

Because medical record numbers were exposed, patients should also review statements from their healthcare providers and insurers. Look closely for services or treatments you do not recognize. This could indicate that someone has used your medical identity fraudulently.

If you spot an error, contact your provider and insurer right away to dispute it. In addition, request a copy of your medical records periodically to confirm accuracy. Catching medical identity theft early can prevent long-term complications with your health records and insurance coverage.

Stay Alert to Phishing Attempts

After a healthcare data breach, scammers often send fake emails, texts, or calls pretending to be from the affected organization. These messages may ask you to confirm personal details or click suspicious links. Because your contact information was exposed, you may be a target for these scams.

Never share sensitive information in response to an unsolicited message. Instead, verify any communication by contacting GHCNY directly using official contact information. Staying cautious can help you avoid becoming a victim of a secondary scam tied to this breach.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →