Computer Systems Integrated Inc. Data Breach Exposes Prisoner Medical Records

Published: 30 September 2026
Healthcare data breach illustration
Breach Discovery: September 2026Breach Notification: September 2026

Computer Systems Integrated Inc., which runs the EHRs-C medical records system for the Suffolk County House of Correction and Nashua Street Jail, confirmed a cybersecurity incident discovered in September 2026. Prisoner medical and psychiatric records may have been exposed. The number of people affected has not been disclosed. Anyone who received care at these facilities should watch for official notification and monitor their credit reports for signs of fraud.

CompanyComputer Systems Integrated Inc.
IndustryHealthcare
Data Types ExposedFull Names, Medical History and Treatment Records, Mental Health and Psychiatric Records, Medication Information, Health Insurance or Billing Details, Incarceration Dates or Facility Identifiers
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Computer Systems Integrated Data Breach?

Computer Systems Integrated Inc. has confirmed a cybersecurity incident affecting its electronic health record system. The company operates a platform known as EHRs-C, which stores medical records for people held at two Massachusetts jails. This includes the Suffolk County House of Correction and Nashua Street Jail in Boston.

According to the company, unauthorized access to its network occurred in September 2026. Computer Systems Integrated is affiliated with Correctional Psychiatric Services, also known as CPS Healthcare. That organization provides correctional healthcare services for the Suffolk County Sheriff’s Department and several other county jails across Massachusetts, including Bristol, Plymouth, Norfolk, and Middlesex counties.

As a result of the discovery, Computer Systems Integrated said it is aware of the incident and is actively investigating what happened. The company has not yet detailed exactly how the intrusion occurred or how long attackers may have had access to its systems. Because the investigation is still underway, many specifics about the scope of the breach remain unclear at this time.

Both Computer Systems Integrated and Correctional Psychiatric Services are owned by Dr. Jorge Veliz, a psychiatrist and former medical director of Bridgewater State Hospital. This shared ownership means the incident could have implications beyond the two jails named so far. However, no additional facilities have been confirmed as affected at this point.

Who was affected?

The individuals potentially affected by this breach are people who were incarcerated at the Suffolk County House of Correction or Nashua Street Jail and received medical care documented in the EHRs-C system. This population includes current and former detainees whose health information was stored electronically by the platform.

The exact number of people affected has not been publicly disclosed. Because correctional healthcare systems often serve people over many years, the scope could extend to a wide range of individuals who passed through these facilities. In addition, because Computer Systems Integrated and its affiliate serve other Massachusetts jails, there is a possibility that additional individuals could be identified as the investigation continues.

It is also worth noting that incarcerated individuals are often a particularly vulnerable population when it comes to data breaches. Many may have limited ability to monitor their own credit or financial accounts while detained. This makes timely notification and support especially important for this group.

What Information Was Potentially Exposed?

The EHRs-C platform is designed to store detailed medical information for people in custody. Although Computer Systems Integrated has not released a full list of compromised data fields, the nature of the platform suggests certain categories of information were likely stored on the affected system.

  • Full names
  • Medical history and treatment records
  • Mental health and psychiatric records
  • Medication information
  • Health insurance or billing details
  • Dates of incarceration or facility identifiers

If confirmed, exposure of this type of information could create meaningful risks for affected individuals. Medical and psychiatric records are highly sensitive. This is especially true for people who were incarcerated, since public awareness of certain diagnoses or treatments could lead to stigma or discrimination.

In addition, health records can be used for medical identity theft. This occurs when someone uses stolen health information to obtain medical services, prescriptions, or insurance benefits in another person’s name. Because this type of fraud can corrupt a victim’s medical history, it can be difficult to detect and correct.

What is the company doing?

Computer Systems Integrated has confirmed that it is aware of the cybersecurity incident and is investigating it. The company has not publicly detailed a full remediation timeline or specific steps it has taken to secure its systems since the incident occurred.

Because the investigation is still ongoing, further updates from the company may be expected as more facts become available. At this stage, it has not been confirmed whether Computer Systems Integrated has begun notifying affected individuals directly or whether it plans to offer credit monitoring or identity protection services. Individuals who believe they may be affected should watch for official communication from the company or from the correctional facilities involved.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should check their credit reports regularly for signs of unfamiliar activity. You can request free copies of your credit report from each of the three major credit bureaus.

Because identity thieves often open new accounts using stolen personal information, reviewing your reports helps you catch fraud early. If you spot an account or inquiry you don’t recognize, dispute it with the credit bureau right away.

Watch for Phishing Attempts

After a healthcare data breach, scammers sometimes use stolen information to craft convincing phishing emails, texts, or phone calls. These messages may pretend to be from a healthcare provider, insurer, or even a government agency.

You should never click links or share personal information in response to unsolicited messages. Instead, verify any request by contacting the organization directly using a phone number or website you know is legitimate.

Protect Your Medical Identity

Because medical and psychiatric records may have been exposed, affected individuals should request copies of their medical records from healthcare providers to check for inaccuracies. This can help you spot signs of medical identity theft, such as unfamiliar diagnoses or treatments listed in your file.

If you find suspicious entries, report them to your healthcare provider and ask for a formal correction. You may also want to request an accounting of disclosures from your provider to see who has accessed your records.

Consider a Fraud Alert or Credit Freeze

Given the sensitive nature of correctional healthcare data, affected individuals may want to place a fraud alert or credit freeze on their credit files. A fraud alert requires creditors to take extra steps to verify your identity before opening new credit in your name.

A credit freeze goes further by restricting access to your credit report entirely. This makes it much harder for identity thieves to open new accounts using your information, though it does require you to lift the freeze temporarily when you need to apply for credit yourself.

Consult a Data Breach Attorney

If you believe your information was exposed in this incident, it may be worthwhile to speak with a data breach attorney. An attorney can help you understand your legal options and whether you may be eligible for compensation.

Many attorneys offer free case evaluations for individuals affected by data breaches. This means you can learn about your rights without any upfront cost, and it may help you understand deadlines that apply to your specific situation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →