Loma Linda University Health Data Breach Exposes Medical Record Numbers

Healthcare data breach illustration
Breach Discovery: May 2026Breach Notification: July 2026

What Happened in the Loma Linda University Health Data Breach?

Loma Linda University Health, a nonprofit academic medical system based in Southern California, recently told patients that some of their health information ended up somewhere it never should have gone. A file containing patient details was mistakenly sent to an outside artificial intelligence platform. This happened while staff worked on an Institutional Review Board-approved research study.

According to the organization’s own notice, the exposure took place in May 2026. A staff member working on the research project uploaded a file to a third-party AI tool. That file reportedly contained medical record numbers, dates of birth, and limited clinical notes tied to orthopedic care.

Once the organization discovered the mistake, it acted to contain the damage. Loma Linda University Health says it opened an internal investigation and asked the AI platform to delete the uploaded file. However, once patient data reaches a system outside an organization’s own network, it becomes far harder to guarantee that every copy, backup, or cached version has truly been erased.

The health system has also stated it is reviewing internal policies covering how staff and researchers use outside technology. This includes new training around AI tools specifically. As a result, this incident has become a case study in the risks that come with feeding sensitive data into third-party platforms that an organization does not fully control.

Who was affected?

The people affected by this breach are patients of Loma Linda University Health, particularly those connected to orthopedic care through the research study in question. Loma Linda University Health operates multiple hospitals and clinics in the Loma Linda, California region, so the affected population likely includes patients treated across its network of facilities.

The exact number of patients affected has not been publicly disclosed. What is clear, though, is that this incident stemmed from a specific research study rather than a broad system-wide hack. Because the file was tied to an IRB-approved research project, the affected group is likely narrower than in a typical network intrusion, though the health system has not specified precise figures or geographic boundaries beyond its Southern California service area.

What Information Was Potentially Exposed?

Loma Linda University Health has been fairly specific about what the uploaded file contained, and just as specific about what it did not. This distinction matters for patients trying to gauge their own risk level following this data breach.

  • Medical record numbers
  • Dates of birth
  • Limited clinical information related to orthopedic care

The organization has confirmed that Social Security numbers, financial account information, insurance details, and complete treatment records were not part of this incident. That is meaningfully different from breaches involving full financial profiles, and it narrows the range of harm patients might realistically face.

Even so, medical record numbers carry real value to bad actors. For example, someone with a medical record number could potentially attempt to submit fraudulent insurance claims or gain unauthorized access to a patient’s broader health file. Because the information can be tied back to a real person’s care history, it can also be used to make phishing messages seem more credible.

In addition, combining a date of birth with clinical details creates a foothold for social engineering attempts. A scammer could reference a patient’s orthopedic treatment to appear legitimate while requesting more sensitive information over phone or email. This is why healthcare-related data exposures, even limited ones, are treated seriously under both HIPAA and California’s breach notification laws.

What is the company doing?

Loma Linda University Health says it responded quickly once it learned the file had been uploaded to the AI platform. Its first step was requesting deletion of the data from that outside system. The organization also launched an internal investigation into how the upload occurred in the first place.

Beyond the immediate response, Loma Linda University Health has committed to reviewing its broader policies and procedures. This includes examining how its workforce is trained to handle third-party technology, particularly emerging AI tools used in research settings. The health system posted a public notice describing the incident and began notifying potentially affected patients directly, giving people a chance to ask questions through its Office of Corporate Compliance.

What Should Affected Individuals Do?

Monitor Your Medical Records and Insurance Statements

Patients connected to this incident should regularly check their medical records and insurance statements for anything unfamiliar. Because medical record numbers were involved, watching for unauthorized claims or unfamiliar entries in your health file is a smart precaution.

If you spot a claim you don’t recognize, or a visit listed that never happened, contact your insurance provider immediately. Catching fraudulent medical activity early can prevent tangled billing disputes and protect the accuracy of your actual health record down the line.

Stay Alert for Phishing Attempts

Whenever a healthcare breach becomes public, scammers often follow with phishing emails, texts, or phone calls designed to look official. Be especially cautious of any message claiming to be from Loma Linda University Health or an affiliated research program that asks you to verify personal details.

Legitimate healthcare providers rarely ask patients to confirm sensitive information through unsolicited emails or texts. If you receive a suspicious message referencing this breach, avoid clicking links or replying, and instead contact the organization directly using a verified phone number.

Review Notices and Keep Records

If you receive a written notice from Loma Linda University Health about this incident, keep a copy in a safe place. This document may become useful later if you need to demonstrate that your information was involved in the breach.

You can also reach out to the health system’s Office of Corporate Compliance if you have questions about whether your specific information was part of the exposed file. Getting clarity early can help you decide what protective steps make sense for your situation.

Consider Monitoring Your Broader Identity Footprint

Although Social Security numbers and financial data were not involved in this particular incident, it’s still wise to keep an eye on your overall credit report periodically. This is simply good practice given how frequently personal data circulates after any breach becomes public.

You can request free credit reports from the three major bureaus each year. Reviewing them occasionally helps you catch any signs of identity misuse that might stem from this or any other exposure of your personal information.

Speak With a Data Breach Attorney

Because healthcare organizations carry legal responsibilities to safeguard patient information, affected individuals may have options worth exploring. A consultation with a data breach attorney can help clarify whether you qualify for compensation tied to this incident.

Many attorneys who handle these cases offer free case evaluations, so reaching out costs nothing upfront. This step can also help you understand deadlines that may apply if you decide to pursue a claim related to this breach.



Related Data Breaches

View the full list of tracked data breaches →