At Home Medical, Inc., a New Jersey healthcare provider, confirmed a data breach after an unauthorized party accessed employee email accounts containing patient information. The incident affected 1,091 individuals and was reported to HHS in September 2026. Affected patients should watch for medical billing errors, monitor credit reports, and remain alert for phishing emails referencing their care.
| Company | At Home Medical, Inc. |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Names, Protected Health Information, Health Insurance or Billing Details, Contact Information |
| People Affected | 1,091 individuals |
| Attack Method | Unauthorized Access/Disclosure |
| Regulators Notified | HHS Office for Civil Rights |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the At Home Medical, Inc. Data Breach?
At Home Medical, Inc., a healthcare provider based in New Jersey, recently disclosed a data breach involving patient information. The company filed a formal notification with the U.S. Department of Health and Human Services Office for Civil Rights in September 2026. This filing confirms that an unauthorized party gained access to sensitive data tied to the organization’s patients.
According to the regulatory filing, the breach involved unauthorized access or disclosure connected to email accounts. In other words, someone outside the organization was able to reach into email systems that held patient information. The exact discovery date of the intrusion has not been publicly disclosed. As a result, it remains unclear how long the unauthorized access may have continued before it was caught.
Because this incident falls under HIPAA reporting rules, At Home Medical was required to investigate the scope of the exposure before notifying regulators. This type of review typically involves forensic analysis of affected email accounts. It also usually includes a careful review of what specific patient data was stored inside those accounts. The HHS Office for Civil Rights filing indicates that this review has concluded, since the company reported a specific number of affected individuals.
Who was affected?
The breach affected 1,091 individuals, according to the notification filed with HHS. These individuals appear to be patients of At Home Medical, Inc., a healthcare provider serving the New Jersey area. Because the exposed data lived in email accounts, the breach may also touch on information tied to caregivers or family members mentioned in patient communications.
At this time, the company has not publicly released further demographic detail about the affected population. Therefore, it isn’t clear whether the breach disproportionately affected any specific group, such as elderly patients or those receiving long-term home medical equipment or services. However, because the organization provides home medical care, many affected individuals may be managing chronic health conditions. This makes the protection of their health information especially important.
What Information Was Potentially Exposed?
The HHS filing identifies the location of the breached information as email. This means the unauthorized access was centered on email accounts used by the organization. While the filing does not provide an exhaustive data inventory, breaches of this kind at healthcare providers typically involve a mix of personal and medical details.
- Patient names
- Protected health information related to care or treatment
- Health insurance or billing details referenced in email communications
- Contact information such as addresses, phone numbers, or email addresses
Because this breach involves a healthcare provider, the exposed information likely relates directly to patient care. For example, emails at a home medical provider often include details about medical equipment, prescriptions, or appointment scheduling. This kind of information can reveal sensitive facts about a person’s health status.
When health information is exposed, affected individuals may face risks beyond typical identity theft. For instance, criminals sometimes use stolen medical details to commit healthcare fraud, such as billing insurers for services never received. This can create confusing and time-consuming problems for patients trying to correct their medical records.
In addition, if personal identifiers like names and contact details were included, affected individuals could also face increased phishing attempts. Scammers sometimes use real medical details to craft convincing fraudulent messages. Because the stolen information appears legitimate, these scams can be harder to spot than generic phishing emails.
What is the company doing?
At Home Medical, Inc. filed its breach notification with the HHS Office for Civil Rights in September 2026, formally confirming the incident to federal regulators. This filing is a required step under HIPAA whenever a breach affects 500 or more individuals. The company also filed formal notification with the HHS Office for Civil Rights, as confirmed by the public breach report listing.
Beyond the regulatory filing itself, the source material does not provide additional detail about specific remediation steps. It is common for healthcare organizations to strengthen email security controls following this type of incident. However, no further company statements about notification letters, credit monitoring, or other protective services have been publicly disclosed at this time.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. You can request free copies from each of the three major credit bureaus. Reviewing these reports often helps catch fraudulent activity early, before it causes lasting damage.
Because this breach involved a healthcare provider, fraud may not always show up as a typical credit card charge. Instead, watch for unusual medical bills or insurance statements. These can be early signs that someone used your information to receive care or services under your name.
Consider a Fraud Alert or Credit Freeze
If your personal information was part of this breach, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to take extra steps to verify your identity before approving new credit. This can slow down or stop identity thieves trying to open accounts in your name.
For stronger protection, you can also request a credit freeze. This restricts access to your credit file entirely until you choose to lift it. Because freezes are free by law, this is a low-cost way to reduce your risk of new-account fraud.
Protect Your Medical Identity
Because protected health information may have been exposed, it’s wise to request an itemized list of benefits from your health insurer. Review these statements closely for services or equipment you never received. This step helps catch medical identity theft before it affects your actual care.
In addition, keep a record of your own medical history and current prescriptions. If errors appear in your records due to fraudulent claims, having your own documentation makes it easier to correct them with your provider and insurer.
Stay Alert for Phishing Attempts
Because email accounts were involved in this breach, affected individuals should be especially cautious with unexpected messages. Scammers often use real details from breaches to make phishing emails look legitimate. Avoid clicking links or downloading attachments from unfamiliar senders, even if the message references your medical provider.
Instead, if you receive a suspicious message claiming to be from At Home Medical, Inc., contact the provider directly using a verified phone number. This simple step can help you confirm whether a message is genuine before you respond or share any information.
Consult a Data Breach Attorney
If you received a notification letter about this breach, it may be worth speaking with an attorney who focuses on data breach cases. Many offer free consultations to help you understand your rights. This can also help you learn whether you may qualify for compensation related to this incident.
Because healthcare data breaches often involve sensitive personal and medical details, legal options may be available depending on how your information was used or exposed. An attorney can review the specific facts of your situation and explain possible next steps.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
View the public data breach notification listing from HHS Office for Civil Rights
