Hamaspik (Choice and Inc.) Data Breach Exposes Protected Health Information

Published: 23 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Hamaspik (Choice and Inc.), a New York health plan, notified HHS in September 2026 that hackers accessed a network server containing protected health information for 8,181 individuals. The breach discovery date hasn’t been disclosed. Affected individuals should watch for a notification letter, monitor credit reports and medical statements, and consider a credit freeze.

CompanyHamaspik (Choice and Inc.)
IndustryHealthcare
Data Types ExposedProtected Health Information, Personal Identifying Information, Health Plan Account Details, Network Server Data
People Affected8,181 individuals
Attack MethodHacking/IT Incident
Regulators NotifiedHHS Office for Civil Rights

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Hamaspik Data Breach?

Hamaspik (Choice and Inc.), a health plan based in New York, has confirmed a data breach involving protected health information. The organization filed a formal notification with the U.S. Department of Health and Human Services Office for Civil Rights in September 2026. This filing revealed that hackers gained unauthorized access to a network server holding sensitive patient data.

According to the filing, the incident is classified as a hacking or IT incident. This means an outside party breached Hamaspik’s network systems rather than losing paper records or a device. The exact breach discovery date has not been publicly disclosed. However, the notification itself was submitted to regulators in September 2026, which set the public disclosure clock in motion.

Because this was a hacking event, a forensic investigation would typically follow to determine the scope of the intrusion. As a result, Hamaspik likely worked with cybersecurity specialists to assess which systems were compromised. The organization’s regulatory filing confirms that patient data stored on its network server was accessed. Details about how the attacker first entered the network have not been made public.

Who was affected?

The breach affected 8,181 individuals, according to the HHS filing. These are likely patients or plan members whose health and personal information was stored on Hamaspik’s network. Because Hamaspik operates as a health plan, those affected are most likely current or former enrollees rather than employees.

The geographic scope appears centered on New York, where Hamaspik is based. However, health plan members can sometimes live outside the state where a company operates. In addition, it’s unclear whether the affected group includes minors, since health plans commonly cover dependents and children. Anyone who received care coordination or insurance services through Hamaspik should consider themselves potentially included in this incident.

What Information Was Potentially Exposed?

The HHS filing does not break down every specific data field involved in the breach. However, because Hamaspik is a health plan and the breach involved protected health information, the exposure likely touches several sensitive categories tied to members’ medical and insurance records.

  • Protected health information (PHI)
  • Personal identifying information tied to health plan enrollment
  • Health plan or insurance account details
  • Information stored on internal network servers

This type of exposure carries real risk. Medical identity theft is a growing concern when health plan data falls into the wrong hands. For example, criminals can use stolen health information to file fraudulent insurance claims or obtain medical services under someone else’s name. This can lead to incorrect information appearing in a victim’s medical file, which can affect future care.

In addition, health plan breaches often expose enough personal detail to enable broader identity theft. Because health records frequently include full names, dates of birth, and sometimes Social Security numbers, affected individuals may also face risks of financial fraud. Phishing attempts targeting breach victims are common in the months following a healthcare data incident, so vigilance matters even if fraud doesn’t appear immediately.

What is the company doing?

Hamaspik took the required step of notifying the HHS Office for Civil Rights about this hacking incident. This filing is a mandatory step under federal law whenever a health plan experiences a breach affecting protected health information. The submission confirms that Hamaspik has acknowledged the incident to regulators.

Beyond the regulatory filing, the source material does not detail specific remediation steps, such as credit monitoring offers or system upgrades. Therefore, individuals affected should watch for a direct notification letter from Hamaspik, which would typically outline any protective services being made available. Hamaspik also filed a formal notification with the HHS Office for Civil Rights, as required for health plans experiencing breaches of this nature.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request free copies of their credit reports from all three major bureaus. Checking these reports regularly helps you catch new accounts or inquiries you didn’t authorize. Because health plan breaches can sometimes lead to financial fraud, this step matters even though the primary exposure involves medical data.

You can access free weekly credit reports through AnnualCreditReport.com. Reviewing your report every few months for the next year is a smart habit after any healthcare data breach. If you notice unfamiliar activity, report it to the credit bureau immediately.

Watch for Medical Identity Theft

Because this breach involves a health plan, medical identity theft is a specific risk worth monitoring closely. Review any explanation of benefits statements you receive from your insurer. If you see services or claims you don’t recognize, contact your health plan right away.

In addition, request a copy of your medical records periodically to check for inaccuracies. Fraudulent claims filed under your name can corrupt your medical history. This could affect future diagnoses or treatment decisions, so catching errors early is important.

Consider a Fraud Alert or Credit Freeze

Given the sensitivity of health plan data, placing a fraud alert on your credit file is a reasonable precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. This step is free and lasts for one year, with renewal options available.

For stronger protection, you can also request a credit freeze, which blocks new accounts from being opened entirely without your explicit approval. Because a freeze must be lifted temporarily whenever you apply for new credit, it takes a bit more effort. However, this extra step offers the strongest defense against identity thieves.

Stay Alert to Phishing Attempts

After a healthcare data breach, scammers often send emails or texts pretending to be the affected organization. These messages may ask you to click links or share personal details. Therefore, never provide sensitive information in response to unsolicited messages, even if they look legitimate.

Instead, contact Hamaspik directly using verified contact information if you receive a suspicious message referencing this breach. Legitimate breach notifications will never ask you to confirm your Social Security number or password over email. When in doubt, verify first before clicking anything.

Consult a Data Breach Attorney

Because protected health information was involved, affected individuals may have legal options worth exploring. Consulting with a data breach attorney can help you understand whether you qualify for compensation. Many attorneys offer free case evaluations, so there’s little downside to asking questions.

An attorney can also help clarify deadlines for filing a claim, which can vary depending on state law and the specifics of the breach. Acting sooner rather than later ensures you don’t miss any applicable filing windows.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from HHS Office for Civil Rights

Related Data Breaches

Check other recent data breach notifications →