Lakes Region Visiting Nursing Association Data Breach Exposes Patient Health and Personal Information

Published: 2 October 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Lakes Region Visiting Nursing Association, a New Hampshire home healthcare provider, confirmed hackers accessed an employee email account containing patient information, exposing data belonging to 1,274 individuals. The breach was reported to HHS Office for Civil Rights in September 2026. Affected patients should watch for official notification letters and immediately begin monitoring their credit reports and medical statements for signs of fraud.

CompanyLakes Region Visiting Nursing Association
IndustryHealthcare
Data Types ExposedPatient Names, Contact Information, Health and Treatment Information, Medical Record Details, Healthcare Service Information
People Affected1,274 individuals
Attack MethodHacking/IT Incident
Regulators NotifiedHHS Office for Civil Rights

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Lakes Region Visiting Nursing Association Data Breach?

Lakes Region Visiting Nursing Association, a home healthcare provider serving patients in New Hampshire, has confirmed a data breach affecting more than a thousand people. The organization filed a formal notification with the U.S. Department of Health and Human Services Office for Civil Rights in September 2026. This filing disclosed that hackers gained unauthorized access to an email account containing sensitive patient information.

According to the regulatory filing, the breach was classified as a hacking or IT incident. The exposed data was located within an email system used by the organization. As a result, the incident falls into a common category of healthcare breaches where attackers compromise a single employee account to reach stored patient communications and records.

The exact date the intrusion occurred has not been publicly disclosed. However, the notification itself was filed in September 2026, which indicates the organization had completed at least an initial internal review by that point. In response to the discovery, Lakes Region Visiting Nursing Association appears to have launched an investigation into how the email account was accessed and what information it contained.

Because email accounts often store years of correspondence, these incidents can expose far more information than attackers originally intended to steal. Therefore, the forensic review process for this type of breach typically takes time, since investigators must manually determine which messages and attachments contained personal or medical details.

Who was affected?

The breach affected 1,274 individuals, according to the organization’s filing with HHS Office for Civil Rights. Given that Lakes Region Visiting Nursing Association provides home health and nursing services, those affected are most likely patients who received care or services from the organization.

It remains unclear whether employees, caregivers, or other third parties were also swept up in the exposed email account. In addition, the filing does not specify whether minors were among those affected, though home nursing and hospice providers often serve patients across a wide age range, including elderly individuals who may be especially vulnerable to fraud.

The geographic scope of the breach appears centered on New Hampshire, where the organization operates. Because healthcare data often includes highly sensitive details, even a relatively modest number of affected individuals can represent a significant privacy risk for each person involved.

What Information Was Potentially Exposed?

The breach notification identifies the compromised information as being stored within an email account rather than a structured database. This means the type of data exposed could include anything patients, families, or staff members communicated about over email, along with any attachments containing records.

Based on the nature of home healthcare communications and the categories typically involved in similar HHS filings, the data potentially exposed may include:

  • Patient names
  • Contact information
  • Health and treatment-related information
  • Medical record details
  • Information related to healthcare services received

Because this breach involves a healthcare provider, the exposure of medical details raises distinct risks beyond standard identity theft. For example, stolen health information can be used to commit medical identity fraud, where criminals use a patient’s identity to obtain treatment, prescriptions, or medical equipment under someone else’s name.

In addition, exposed contact and personal details can be used for targeted phishing attempts. Scammers often pose as healthcare providers or insurers to trick victims into revealing further sensitive information. This risk is especially concerning for elderly patients, who are frequently targeted by scammers posing as medical or insurance representatives.

What is the company doing?

Lakes Region Visiting Nursing Association responded to the incident by filing a formal breach notification with federal regulators. This filing confirms the organization identified the breach, assessed the number of people affected, and reported the incident as required under federal healthcare privacy law.

As part of this regulatory process, the organization also filed notification with the HHS Office for Civil Rights, which oversees compliance with patient privacy protections nationwide. This step is required whenever a healthcare provider confirms that patient data covered under federal law has been compromised.

Beyond the regulatory filing, the publicly available details do not specify additional remediation steps, such as whether credit monitoring or identity protection services were offered to affected individuals. Because formal notifications are often accompanied by direct letters to affected patients, individuals who received care through the organization should watch for a notification letter containing more specific guidance.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Affected individuals should request a copy of their credit report and review it carefully for unfamiliar accounts or inquiries. You can obtain free reports through the major credit bureaus and check them at regular intervals throughout the year.

Because stolen personal information can be used months or even years after a breach, ongoing vigilance matters. As a result, setting a recurring reminder to check your credit report can help you catch suspicious activity before it causes lasting financial harm.

Consider a Fraud Alert or Credit Freeze

If your personal details were part of this breach, placing a fraud alert or credit freeze with the three major credit bureaus is a strong protective step. A fraud alert requires lenders to verify your identity before issuing new credit, while a freeze blocks new accounts from being opened entirely.

This step is especially useful when contact or identifying information may have been exposed alongside health records. Because freezing credit is free and can be lifted later, it offers meaningful protection with minimal ongoing cost or effort.

Watch for Medical Identity Theft and Billing Fraud

Since this breach involves a healthcare provider, affected individuals should closely review any insurance statements or medical bills for services they did not receive. Medical identity theft can lead to inaccurate health records, which may affect future treatment decisions.

If anything looks unfamiliar, contact your insurance provider and the healthcare organization directly. In addition, request a copy of your medical records to confirm that no fraudulent treatment history has been added to your file.

Stay Alert to Phishing Attempts

Because exposed contact information can be used to craft convincing scam messages, affected individuals should be cautious of unexpected emails, calls, or texts referencing their healthcare provider. Scammers often use real details from breaches to appear legitimate.

Never click links or share personal information in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website to confirm whether any communication is genuine.

Consult a Data Breach Attorney

Individuals who received a notification letter about this breach may want to speak with a data breach attorney to understand their legal options. Many attorneys offer free consultations and can evaluate whether you qualify for compensation.

Because healthcare data breaches often involve strict legal protections under federal and state law, a qualified attorney can help determine whether the organization met its obligations. This guidance can also clarify any deadlines that may apply to filing a claim.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from HHS Office for Civil Rights

Related Data Breaches

View the full list of tracked data breaches →