Healthcare Services Group Data Breach Exposes Social Security Numbers and Health Records

Healthcare data breach illustration
Breach Discovery: October 2024Breach Notification: August 2025

What Happened in the Healthcare Services Group Data Breach?

Healthcare Services Group has agreed to pay $3 million to settle lawsuits stemming from a major data breach. In July 2026, the company reached this settlement to resolve consolidated litigation over the incident. This development matters because it gives affected individuals a concrete path to compensation nearly two years after the original intrusion.

The Healthcare Services Group data breach began when an unauthorized third party gained access to the company’s network in September 2024. According to forensic findings, the intrusion itself occurred in September 2024, though the company did not detect suspicious activity until October 2024. Once the unusual network activity was spotted, the company moved to contain the threat and stop further unauthorized access.

However, the attacker had already exfiltrated files containing sensitive personal and health information before containment occurred. A forensic investigation was launched to determine the scope of the intrusion and identify exactly which files were taken. This investigation confirmed that a wide range of personal and protected health information had been accessed and stolen from the network.

Because thorough forensic reviews take time, affected individuals were not notified until nearly a year after discovery. Notification letters began going out in August 2025. Shortly afterward, the first class action lawsuit was filed, and additional similar lawsuits soon followed across the country.

Who was affected?

The breach affected 624,496 individuals whose personal and health information was stored on Healthcare Services Group’s network. As a provider of environmental, dining, and nutritional support services, the company works with more than 3,000 healthcare facilities across 48 states. This means the exposed data likely includes patients, employees, or contacts tied to a broad swath of the U.S. healthcare system.

Because Healthcare Services Group supports facilities nationwide, the affected population spans a wide geographic area rather than a single region. The source does not specify whether minors were among those affected. Still, given the healthcare facility connections involved, both patients and staff members across many states could realistically be part of the affected group.

What Information Was Potentially Exposed?

The stolen files contained several categories of highly sensitive personal and medical information. This combination of data types makes the breach especially concerning, since it includes both financial and health-related identifiers that criminals often target.

  • Full names
  • Social Security numbers
  • Driver’s license numbers
  • State identification numbers
  • Financial account details
  • Full access credentials (usernames and passwords)
  • Medical and health insurance information

As a result of this exposure, affected individuals face a heightened risk of identity theft and financial fraud. Criminals can use Social Security numbers and financial account details to open new credit lines, file fraudulent tax returns, or drain existing accounts. Because driver’s license and state ID numbers were also exposed, victims may face additional risks like fraudulent government benefit claims or fake identification documents created in their name.

In addition, the exposure of medical and health insurance information raises the risk of medical identity theft. This occurs when someone uses stolen health insurance details to obtain medical care or prescriptions under another person’s name. Because access credentials were also stolen, affected individuals should be cautious about credential reuse across other online accounts, since attackers often test stolen logins on unrelated services.

What is the company doing?

Once Healthcare Services Group identified the suspicious activity, it took prompt action to secure its network and prevent further unauthorized access. The company then conducted a detailed forensic investigation to determine what data had been accessed and which individuals were affected. This investigation ultimately shaped the notification process that followed.

As part of the settlement, Healthcare Services Group has agreed to fund a $3 million payment to resolve the litigation, though it denies any wrongdoing. Under the settlement terms, eligible class members can claim three years of single-bureau credit monitoring, along with identity theft insurance and recovery services. In addition, class members may submit claims for reimbursement of documented, unreimbursed losses up to $5,000, or opt for a one-time cash payment instead.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. Because Social Security numbers and financial account details were exposed, new fraudulent accounts could appear at any time, even months after the breach.

You can request free credit reports from each of the three major bureaus and review them for accuracy. If you notice anything suspicious, report it immediately to the bureau and consider placing a fraud alert on your file.

Consider a Credit Freeze or Fraud Alert

Given that Social Security numbers, driver’s license numbers, and financial data were all exposed, placing a credit freeze offers strong protection. A freeze prevents lenders from accessing your credit file, which stops most attempts to open new accounts in your name.

Alternatively, a fraud alert requires creditors to verify your identity before extending credit. Both options are free and can be requested directly through each credit bureau. Because this breach involved multiple forms of government-issued ID, combining both protections offers the strongest defense.

Protect Against Medical Identity Theft

Since medical and health insurance information was compromised, affected individuals should review recent insurance statements for unfamiliar claims. Medical identity theft can result in incorrect information appearing in your medical records, which may affect future treatment decisions.

Contact your health insurance provider if you spot any billing discrepancies or unrecognized services. Requesting an accounting of disclosures from your insurer can also help you spot unauthorized use of your benefits early.

Enroll in the Offered Identity Protection Services

Eligible class members should take advantage of the three years of credit monitoring and identity theft insurance included in the settlement. These services can help detect fraud early and provide support if your identity is misused.

To enroll, submit a claim before the October 1, 2026 deadline. Because the settlement fund is limited, filing promptly ensures you don’t miss out on available benefits.

Stay Alert for Phishing Attempts

Because full access credentials were among the stolen data, affected individuals should watch for phishing emails or calls that reference the breach. Scammers often use breach news to trick victims into revealing more information.

Never click links or share personal details in unsolicited messages. Instead, verify any communication by contacting the company directly through official channels. If you’re unsure about your rights or eligibility for compensation, consulting a data breach attorney can help clarify your options.



Related Data Breaches