Quantum Health Data Breach Exposes Social Security Numbers and Health Records

Healthcare data breach illustration
Breach Discovery: June 2026Breach Notification: July 2026

What Happened in the Quantum Health Data Breach?

Quantum Health, an Ohio-based company that helps employer health plans coordinate medical care for their members, has disclosed a data security incident. The company says an employee fell for a vishing scheme, a phone-based scam designed to trick workers into giving up network access. That single call opened the door for an outsider to slip into internal systems.

The company first noticed trouble when internal and external systems experienced a service outage. Quantum Health quickly isolated the affected systems and brought in outside forensic experts to figure out what happened. Their investigation traced the outage back to unauthorized network access that began after the employee responded to the vishing call.

During the window between the phone call and the outage, an unauthorized party accessed and copied files from Quantum Health’s systems. It then took several more weeks for investigators to confirm that some of those files held personal information tied to specific individuals. As a result, Quantum Health only recently began sending out formal notification letters describing the incident.

This gap between the initial intrusion and the final confirmation of exposed data is common in breach investigations. Forensic teams must first contain the threat, then dig through massive volumes of files to determine exactly whose records were involved. Only after that painstaking review can a company responsibly notify the people affected.

Who was affected?

The people affected by this incident are clients of Quantum Health, meaning individuals covered by employer health plans that rely on the company for care coordination. Many of these people may never have directly interacted with Quantum Health themselves. Instead, their employer or health plan simply used the company’s services behind the scenes.

Quantum Health has not publicly disclosed a specific number of affected individuals. However, because the company works with numerous employer health plans across the country, a breach like this can potentially touch a large and geographically dispersed population. Given the nature of employer-sponsored health coverage, the affected group could include employees, retirees, and their covered dependents, potentially including minors.

What Information Was Potentially Exposed?

According to the notification letter, the files accessed during this incident contained a combination of identifying and health-related details. This mix of data is particularly sensitive because it spans both financial identity and medical history.

  • Full name
  • Social Security number
  • Health insurance information, including policy numbers, claims, and benefits details
  • Health information, including medical treatment details, diagnoses, prescriptions, provider names, and dates of service
  • Date of birth
  • Email address
  • Phone number
  • Home address

When Social Security numbers appear alongside health records, the risk extends well beyond typical identity theft. Criminals can use this combination to open new credit accounts, file fraudulent tax returns, or take out loans in a victim’s name. Because the data includes detailed health information, it may also circulate on dark web marketplaces where medical data commands a premium.

In addition to financial fraud, this type of exposure creates a real risk of medical identity theft. Someone could use a victim’s health insurance details to file fraudulent claims or receive medical treatment under a false identity. This kind of fraud is often harder to detect than a stolen credit card, since it may not show up until a victim reviews an insurance statement or gets an unexpected medical bill.

What is the company doing?

Once Quantum Health identified the outage, it acted to secure and isolate its systems right away. The company then brought in third-party forensic specialists to determine the scope and cause of the incident. This investigation ultimately confirmed that unauthorized access had occurred and that certain files contained personal information.

In response, Quantum Health says it is strengthening its security protocols and adding new safeguards to prevent similar incidents going forward. The company is also offering complimentary identity monitoring services through Kroll to affected individuals. These services reportedly include credit monitoring, fraud consultation, and identity theft restoration support.

Because vishing attacks target human judgment rather than technical defenses, companies that experience this kind of breach often respond by retraining staff on verification procedures. While Quantum Health has not detailed every internal change it plans to make, its stated commitment to enhanced security suggests employee awareness training is likely part of that effort.

What Should Affected Individuals Do?

Monitor Your Credit and Consider a Fraud Alert or Freeze

Because this breach exposed Social Security numbers, affected individuals should treat their credit files as a priority. Placing a fraud alert or a credit freeze with Equifax, Experian, and TransUnion makes it much harder for anyone to open new accounts using your identity.

A credit freeze is free and can be lifted temporarily whenever you need to apply for credit yourself. Fraud alerts, on the other hand, require lenders to verify your identity before extending new credit, adding a layer of protection with less hassle. Either step gives you meaningful control over your financial identity while you continue watching for suspicious activity.

Watch Your Health Insurance Statements Closely

Since health insurance information and medical details were part of this breach, affected individuals should review every explanation of benefits they receive. Look for services, providers, or claims you do not recognize, even minor ones.

Medical identity theft can be subtle at first, sometimes appearing only as a small unfamiliar charge or an odd entry in your claims history. Catching these discrepancies early can prevent larger complications, such as incorrect information ending up in your medical records or your insurance benefits being drained by a fraudulent claim.

Enroll in the Complimentary Identity Monitoring Services

Quantum Health is offering identity monitoring through Kroll at no cost to affected individuals. This service typically includes credit monitoring, fraud consultation, and identity restoration assistance if something does go wrong.

Because this offer is free, there is little downside to signing up. Even if you feel confident about your own vigilance, professional monitoring adds another set of eyes watching for signs of misuse across your credit file and other records.

Stay Alert for Follow-Up Phishing and Vishing Attempts

Given that this breach originated from a vishing call, affected individuals should be especially cautious of follow-up scams referencing the incident. Scammers sometimes use news of a breach to craft convincing follow-up calls, texts, or emails pretending to offer help.

Never provide personal information in response to an unsolicited call, text, or email, no matter how official it sounds. If someone claims to represent Quantum Health, your health plan, or a credit bureau, verify their identity independently before sharing any details.

Keep Records and Consider Your Legal Options

Save your notification letter, along with any evidence of suspicious activity tied to this breach, such as unfamiliar charges or unexpected medical claims. This documentation can matter if you experience financial or medical harm later.

Individuals whose sensitive information was exposed because a company failed to adequately secure it may have legal options available. Speaking with a data breach attorney for a free case evaluation can help you understand whether you qualify for compensation and what steps to take next.



Related Data Breaches

Check other recent data breach notifications →