Cornerstone Care Center Data Breach Exposes Protected Health Information

Healthcare data breach illustration
Breach Discovery: April 2026Breach Notification: May 2026

What Happened in the Cornerstone Care Center Data Breach?

Sanger Skilled Care, LLC, doing business as Cornerstone Care Center, has notified patients about a data security incident involving protected health information. The Cornerstone Care Center data breach centers on unauthorized activity discovered within a single employee user account. As a result, the nursing facility began an urgent internal review to determine the scope of the intrusion.

According to the notification, Cornerstone became aware of the suspicious account activity on or around April 7, 2026. Once discovered, staff moved quickly to contain the incident. In addition, the facility brought in a third-party forensic firm to investigate exactly what happened and how far the exposure extended.

By April 16, 2026, the forensic investigation had progressed enough for Cornerstone to conclude that an unauthorized third party may have accessed a limited amount of protected health information. This information was reportedly kept in the normal course of business operations. Because the investigation focused on one compromised account, the facility was able to determine the timeline relatively quickly after discovery.

Cornerstone has stated there is currently no evidence that any exposed information has been misused. However, the facility chose to notify affected individuals out of caution. This approach allows patients to take protective steps before any potential misuse could occur, even though no confirmed fraud has been linked to the incident so far.

Who was affected?

The individuals affected by this breach appear to be patients or former patients of Cornerstone Care Center, a skilled nursing facility located in Sanger, California. Because nursing facilities generally serve older adults and individuals with ongoing medical needs, this population may be particularly vulnerable to the consequences of exposed health information.

The notification letter does not include a specific number of affected individuals. Therefore, the total scope of the breach has not been publicly disclosed. Similarly, the letter does not specify whether employees, in addition to patients, were affected. What is clear is that Cornerstone determined the exposure involved data maintained during normal business operations, which suggests the impacted records belong to people who received care at the facility.

What Information Was Potentially Exposed?

The notification letter indicates that certain protected health information may have been accessible to the unauthorized party. Although the letter does not list every specific data element, it confirms that PHI kept during regular business activities was involved.

  • Protected Health Information (PHI) related to patient care
  • Personal information maintained in normal business records
  • Potentially other identifying details tied to patient files

Because health records often include sensitive details such as diagnoses, treatment history, and insurance information, exposure of this type of data carries real risk. For example, criminals can use stolen medical details to commit medical identity theft, which can result in fraudulent insurance claims filed under a victim’s name.

In addition, PHI exposure can lead to broader identity theft if the records include Social Security numbers or other identifying data. As a result, affected individuals should treat this notification seriously, even though Cornerstone has stated there is no current evidence of misuse. Being proactive now can prevent complications later, particularly for older patients who may be less likely to notice unfamiliar account activity right away.

What is the company doing?

As soon as Cornerstone discovered the unauthorized account activity, staff took immediate steps to contain the incident. This included securing the compromised account and limiting further access. Following containment, the facility engaged forensic investigators to determine the full extent of the exposure.

Beyond the investigation, Cornerstone is now offering complimentary credit monitoring services for 12 months through Cyberscout, a TransUnion company. This service allows affected individuals to receive alerts when changes occur on their credit file. Furthermore, Cornerstone is providing proactive fraud assistance to help enrollees address questions or respond if they become victims of fraud. The facility has also set up a dedicated call center to answer questions from concerned patients.

What Should Affected Individuals Do?

Enroll in the Free Credit Monitoring Service

Affected individuals should take advantage of the complimentary 12-month credit monitoring offered by Cornerstone. This service can alert you quickly if suspicious activity appears on your credit file, giving you a chance to respond before serious damage occurs.

To enroll, you must use the unique code provided in your individual notification letter and sign up within 90 days of the letter’s date. Because enrollment requires an internet connection and an email address, those without regular internet access should ask a trusted family member for help completing the process.

Monitor Financial Accounts and Credit Reports Closely

In addition to the offered monitoring service, you should regularly review your own bank statements, credit card activity, and insurance explanation of benefits forms. This extra layer of vigilance helps catch unauthorized transactions or medical claims that automated monitoring tools might miss.

You are entitled to one free credit report annually from each of the three major credit bureaus. You can request these reports through annualcreditreport.com. Because reviewing your report periodically throughout the year can help you catch problems early, consider spacing out requests from each bureau across several months.

Consider a Fraud Alert or Credit Freeze

Since protected health information sometimes accompanies other personal identifiers, placing a fraud alert on your credit file is a reasonable precaution. An initial fraud alert lasts one year and requires businesses to verify your identity before extending new credit in your name.

If you have already experienced identity theft related to this incident, you may qualify for an extended fraud alert lasting seven years. Alternatively, a credit freeze offers stronger protection by blocking new credit accounts from being opened at all. You can request either option directly through Equifax, Experian, or TransUnion.

Watch for Medical Identity Theft and Phishing Attempts

Because this breach involves health information, you should watch closely for unfamiliar medical bills, insurance statements, or collection notices. These could indicate that someone used your information to receive care or file claims fraudulently.

You should also stay alert for phishing emails, calls, or texts that reference this incident. Scammers sometimes use news of a breach to impersonate legitimate companies. If you receive an unexpected message asking for personal details, contact Cornerstone directly using the number provided in your notification letter rather than replying to the message.



More Information

Official data breach notification from California Attorney General

Related Data Breaches