Lifespan Physicians Group of Massachusetts, Inc. Data Breach Exposes Social Security Numbers and Health Records

Published: 12 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

Lifespan Physicians Group of Massachusetts, Inc., doing business as Brown Health Medical Group-MA, disclosed in July 2026 that a data breach exposed patients’ Social Security numbers, financial account codes, credit and debit information, government ID numbers, and health records. The number of affected individuals hasn’t been publicly disclosed. Anyone who received care from this provider should monitor their credit reports and consider a credit freeze immediately.

CompanyLifespan Physicians Group of Massachusetts, Inc.
IndustryHealthcare
Data Types ExposedSocial Security Numbers, Financial Account Codes, Credit and Debit Account Information, Government ID Numbers, Health Records
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Lifespan Physicians Group of Massachusetts, Inc. Data Breach?

Lifespan Physicians Group of Massachusetts, Inc., which does business as Brown Health Medical Group-MA, has confirmed a data breach involving sensitive patient information. The organization filed a formal notification about the incident in July 2026. This filing alerted state regulators and affected individuals to the exposure of personal and health-related data.

According to the notification, the breach involved unauthorized access to systems containing patient records. The exact discovery date has not been publicly disclosed. However, the notification confirms that specific categories of sensitive data were compromised as a result of the incident.

As part of its response, the medical group appears to have conducted an internal review to determine which individuals and data types were affected. This process typically involves forensic analysis to trace how the intrusion occurred. In addition, organizations in this position usually work to determine whether the exposed data was viewed, copied, or removed from their systems. The notification to Vermont’s Attorney General suggests this review has reached a stage where the company felt confident enough to describe the specific data categories involved.

Who was affected?

The breach potentially affects patients who received care through Lifespan Physicians Group of Massachusetts, Inc., also known as Brown Health Medical Group-MA. Because this is a medical group, those affected are likely current and former patients whose records were stored in the organization’s systems. The exact number of affected individuals has not been publicly disclosed.

Given that healthcare providers often maintain records for patients across a wide age range, it’s possible that minors are among those affected. Additionally, because medical practices often serve patients over many years, individuals who haven’t visited the practice recently could still be impacted. The geographic scope of affected patients has not been detailed in the notification, though the filing with Vermont’s Attorney General indicates at least some Vermont residents were involved.

What Information Was Potentially Exposed?

The notification identifies several categories of sensitive personal and financial data that were involved in this breach. Because this incident involves a medical group, the exposed data spans both healthcare and financial information. This combination raises the stakes for anyone affected.

  • Social Security Numbers
  • Financial Account Codes
  • Credit and Debit Account Information
  • Government ID Numbers
  • Health Records

This mix of data creates significant risk for those affected. For example, Social Security numbers combined with financial account codes and government ID numbers give criminals nearly everything needed to open new credit lines or file fraudulent tax returns. As a result, affected individuals could face long-term identity theft risks that extend well beyond a single fraudulent charge.

Health records add another layer of concern. Because medical information can be used to commit healthcare fraud, such as submitting fake insurance claims or obtaining prescription medications under someone else’s name, victims may not immediately notice the misuse. In addition, exposed health data can lead to targeted phishing attempts, since scammers often reference real medical details to appear credible.

What is the company doing?

In response to the breach, Lifespan Physicians Group of Massachusetts, Inc. filed official notification paperwork describing the incident and the categories of data involved. This step is a required part of breach response under state data breach notification laws. The company also notified the Vermont Attorney General of the incident, as confirmed in its formal filing.

Beyond regulatory notification, organizations facing this type of breach typically take steps to secure affected systems and prevent further unauthorized access. This can include resetting credentials, patching vulnerabilities, and increasing monitoring of network activity. Companies handling healthcare data often also review compliance with federal privacy rules following such incidents, since breaches involving medical records carry additional regulatory obligations.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request a free copy of their credit report from each of the three major credit bureaus. Reviewing these reports regularly helps catch unauthorized accounts or inquiries early. Because Social Security numbers were exposed in this breach, this step is especially important.

You can space out your requests throughout the year to maintain ongoing visibility into your credit activity. If you notice unfamiliar accounts or hard inquiries, dispute them immediately with the credit bureau involved. Consulting a data breach attorney for a free case evaluation can also help you understand what remedies may be available.

Consider a Fraud Alert or Credit Freeze

Because this breach exposed Social Security numbers, financial account codes, and government ID numbers, placing a fraud alert or credit freeze is a strong protective measure. A fraud alert requires lenders to verify your identity before extending new credit. A credit freeze goes further by blocking most access to your credit file entirely.

Both options are free to set up and can be requested directly through the credit bureaus. Although a freeze requires a few extra steps when you need to apply for credit yourself, it offers the strongest defense against identity thieves opening accounts in your name.

Watch for Signs of Medical or Insurance Fraud

Since health records were among the data exposed, affected individuals should review any insurance statements or medical bills carefully. Look for treatments, prescriptions, or services you don’t recognize. Unexplained charges could indicate someone else used your identity to obtain care.

If you spot suspicious activity, contact your health insurance provider right away to report it. You should also request a copy of your medical records to confirm accuracy. This helps ensure incorrect information doesn’t affect your future care or insurance coverage.

Stay Alert for Phishing Attempts

Because attackers now possess real personal and health details, they may use this information to craft convincing phishing emails, calls, or texts. Be cautious of unsolicited messages that reference your medical history or ask you to verify sensitive information. Legitimate healthcare providers rarely request sensitive data through unsecured channels.

If you receive a suspicious message, don’t click any links or provide personal details. Instead, contact the organization directly using a verified phone number or website. This simple habit can prevent scammers from gaining further access to your accounts.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Check other recent data breach notifications →