Nabi Health discovered in August 2026 that a former vendor had kept access to patient intake data, including names and stated reasons for visits submitted through its website portal. The company says Social Security numbers and medical records were not involved. Affected patients should enroll in the free credit monitoring offered and watch for phishing attempts referencing the company.
| Company | Nabi Health |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Stated Reasons for Visits |
| People Affected | Not Publicly Disclosed |
| Attack Method | Third-Party Vendor Breach |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Nabi Health Data Breach?
Nabi Health, a San Francisco-based health company, recently notified patients about a data security incident involving a former vendor. According to the company’s own notification letter, this was not a hacking event in the traditional sense. Instead, a vendor whose relationship with Nabi Health had ended apparently retained access to certain patient information long after that access should have been cut off.
The company says unauthorized access to its network occurred in August 2026, when it discovered that the former vendor still had entry to patient intake data. This data included names and the stated reasons patients gave for their visits, submitted through the company’s website portal. Nabi Health has stated that medical records and Social Security numbers were not part of the exposure.
After making this discovery, Nabi Health reviewed the situation to determine exactly whose information was involved. As a result, the company finalized its list of affected individuals in September 2026. The notification letter does not explain how long the former vendor’s access lasted or how the company first learned of the problem, so key timeline details remain unclear.
Nabi Health also has not disclosed the identity of the vendor involved. In addition, the letter does not describe whether any misuse of the data occurred. The company characterizes the incident as isolated and says it has already remediated the issue by cutting off the vendor’s access entirely.
Who was affected?
Based on the notification letter, the people affected are patients or clients who used Nabi Health’s website portal to provide intake information. This likely includes anyone who filled out a form describing their reason for seeking care through the company’s online system.
The exact number of people affected by the Nabi Health data breach has not been publicly disclosed. The template letter filed with Massachusetts regulators left blank the specific details that would normally appear for each recipient, so a precise total count is not currently available.
Because the incident involves a healthcare-adjacent company, affected individuals could span a wide range of ages and circumstances. However, there’s no indication in the available materials that minors were specifically targeted or excluded. Geographic scope also hasn’t been detailed beyond the company’s San Francisco base.
What Information Was Potentially Exposed?
The scope of exposed data in this incident appears narrower than in many healthcare breaches. Still, the categories involved deserve careful attention from anyone who received a notification letter.
- Full names of patients
- Stated reasons for visits, as entered through the company’s website portal
Nabi Health has specifically stated that medical records and Social Security numbers were not involved. This distinction matters because it limits some of the most severe risks typically associated with healthcare data breaches, such as full-scale medical identity theft or tax fraud using stolen SSNs.
That said, a name paired with a stated reason for a medical visit can still reveal sensitive details. For example, this pairing might expose a health condition, a mental health concern, or a personal situation a patient never intended to share. Because of this, individuals affected by the breach may face privacy harm even without financial data being exposed.
In addition, exposed names could be used in targeted phishing attempts. Scammers often reference real personal details to make fraudulent messages seem legitimate. Someone who knows a patient’s name and the reason they sought care could craft a convincing, and potentially harmful, follow-up message or scam attempt.
What is the company doing?
Nabi Health says it moved quickly once it discovered the vendor’s continued access. According to the notification letter, the company secured the impacted platform and verified the security of its internal systems. It also says it has taken steps to ensure the former vendor no longer has any access to its data.
Looking ahead, the company states it is implementing additional technical safeguards and updated procedures. These changes are meant to reduce the chance of a similar lapse happening again with future vendor relationships. Nabi Health also filed a formal notification letter with Massachusetts regulators, as required under that state’s data breach reporting rules.
As part of its response, Nabi Health is offering affected individuals free access to single-bureau credit monitoring, a credit report, and a credit score service through HaystackID. The offer includes fraud assistance and sends alerts for 24 months from the date someone enrolls. However, recipients must act within 90 days of the date on their letter to take advantage of this offer.
What Should Affected Individuals Do?
Monitor Your Credit Reports Regularly
Even though Nabi Health says Social Security numbers were not exposed, it’s still wise to check your credit reports periodically. You can get free reports from all three major bureaus at annualcreditreport.com. Reviewing these reports helps you catch unfamiliar accounts or inquiries early.
Because identity thieves sometimes combine leaked information from multiple sources, a seemingly minor exposure can still contribute to a larger fraud scheme. Therefore, it’s worth treating this notification seriously, even if the company describes the exposure as limited. Regular monitoring costs nothing and takes only a few minutes each month.
Consider a Fraud Alert or Credit Freeze
Although this breach reportedly did not involve Social Security numbers, placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion adds an extra layer of protection. A fraud alert requires creditors to verify your identity before opening new accounts in your name. This can slow down anyone attempting to misuse your information.
A credit freeze goes a step further by restricting access to your credit file entirely. As a result, it becomes much harder for identity thieves to open new lines of credit. Both options are free and can be lifted temporarily whenever you need to apply for credit yourself.
Watch for Phishing Attempts
Because your name and the stated reason for a visit may have been exposed, be alert to unexpected calls, texts, or emails referencing Nabi Health. Scammers often use real details to make fraudulent messages appear credible. For this reason, never click links or share personal information in response to unsolicited messages.
Instead, if you receive a suspicious message claiming to be from Nabi Health, contact the company directly using a verified phone number or website. In addition, you can report any suspected identity theft to the Federal Trade Commission at identitytheft.gov. Reporting to your state Attorney General’s office is also a good idea.
Keep Your Notification Letter and Enrollment Details Safe
If you received a letter from Nabi Health, keep it along with the envelope and any activation code for the credit monitoring offer. This information is unique to you and will be needed to enroll in the protective services. Losing these details could mean missing out on free monitoring.
Furthermore, your personal letter is the most accurate source of information about what specific data applied to your situation. The publicly posted template left many details blank, so your own copy may contain more specific information. Review it carefully and reach out to the company directly with any questions.
Understand Your Legal Options
If you believe your information was exposed in the Nabi Health data breach, you may have legal options worth exploring. Companies that collect patient information have a responsibility to control who can access it, including after a vendor relationship ends. When that responsibility isn’t met, affected individuals sometimes pursue legal action.
Consulting with a data breach attorney can help you understand whether you qualify to join a potential class action. Many consultations are free, and there’s typically no cost unless your case results in compensation. This can be a straightforward way to learn about your rights without any upfront financial risk.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
