Silver Summit Medical Corporation Data Breach Exposes Protected Health Information

Published: 19 August 2026
Healthcare data breach illustration
Breach Discovery: July 2026Breach Notification: August 2026

Silver Summit Medical Corporation, operating as Digestive Disease Center and Heart Vascular & Leg Center, discovered in July 2026 that a vendor’s cybersecurity incident exposed patient names and protected health information taken in late November 2025. Affected patients should enroll in the free Cyberscout credit monitoring offered and watch closely for medical identity theft and phishing attempts.

CompanySilver Summit Medical Corporation
IndustryHealthcare
Data Types ExposedFull Names, Protected Health Information
People AffectedNot Publicly Disclosed
Attack MethodThird-Party Vendor Breach
Regulators NotifiedCalifornia Attorney General

What Happened in the Silver Summit Medical Corporation Data Breach?

Silver Summit Medical Corporation, which does business as Digestive Disease Center and Heart Vascular & Leg Center, has told patients about a data security event tied to one of its vendors. The company learned in July 2026 that a third-party vendor experienced a cybersecurity incident. That incident affected personal and protected health information that the vendor held on behalf of Silver Summit Medical Corporation.

According to the notification, unauthorized access to the vendor’s systems actually occurred earlier, between November 27, 2025 and November 30, 2025. This means there was a gap of several months between when the data was taken and when Silver Summit Medical Corporation became aware of it. As a result, patients are only now learning that their information was exposed nearly a year after the fact.

Because the breach happened at a vendor rather than inside Silver Summit Medical Corporation’s own network, the company had to rely on the vendor’s investigation to understand what happened. Once notified, Silver Summit Medical Corporation began its own review to confirm which individuals were affected. The organization then moved to notify potentially impacted patients and file the required regulatory disclosures.

Who was affected?

The people affected by this breach appear to be patients of Digestive Disease Center and Heart Vascular & Leg Center. Because these are medical practices, the exposed data likely includes individuals who received care or diagnostic services through either brand. The exact number of affected individuals has not been publicly disclosed.

It is also unclear whether the exposure is limited to California residents or extends to patients in other states. Because the breach originated at a third-party vendor, the scope could include anyone whose records passed through that vendor’s systems. Patients should not assume they are unaffected simply because they live outside California.

What Information Was Potentially Exposed?

The notification letter confirms that names were involved in the breach, along with other personal and protected health information. While the letter does not spell out every specific data element in the portion available, it does confirm that protected health information was part of the exposure. In healthcare breaches like this one, protected health information often includes details tied to diagnosis, treatment, and insurance.

  • Full names
  • Protected health information
  • Other personal information held by the vendor on behalf of Silver Summit Medical Corporation

When protected health information is exposed, the risk goes beyond typical identity theft. Criminals can use stolen medical details to file fraudulent insurance claims or obtain medical services using someone else’s identity. This type of fraud can be especially hard to detect because it may not show up on a standard credit report.

In addition, exposed personal information can be combined with data from other breaches to build a more complete profile of a victim. This makes phishing attempts more convincing, since scammers may reference real details from a person’s medical history. Because of this, affected patients should treat any unexpected calls or emails referencing their healthcare with real suspicion.

What is the company doing?

Silver Summit Medical Corporation says it takes this event and information security seriously. Upon learning of the vendor incident, the company launched an investigation and worked to determine which individuals needed to be notified. It then sent notification letters to potentially affected patients describing the event and the resources available to them.

The company also filed formal notification with the California Attorney General. As part of its ongoing response, Silver Summit Medical Corporation says it is reviewing its existing policies and procedures. This review is meant to reduce the chance of similar incidents happening again in the future.

In addition, the company is offering credit monitoring and identity restoration services through Cyberscout, a TransUnion company. These services are being provided at no cost for 12 months. However, affected individuals must complete the enrollment process themselves, since the company cannot enroll patients automatically on their behalf.

What Should Affected Individuals Do?

Enroll in the Free Credit Monitoring Offered

Affected patients should sign up for the complimentary credit monitoring and identity restoration services through Cyberscout. This service tracks changes to a credit file for 12 months and sends alerts the same day a change occurs. Enrolling is a simple, no-cost step that adds an extra layer of protection.

Because enrollment is not automatic, patients need to visit the activation site and follow the instructions using their unique code from the notification letter. Taking this step early gives a longer window of protection. Waiting too long could mean missing early warning signs of misuse.

Monitor Financial and Insurance Statements Closely

Patients should review bank and credit card statements regularly for unfamiliar charges. In addition, it’s important to review explanation of benefits statements from health insurers. These documents can reveal whether someone has used a person’s identity to receive medical treatment they did not actually receive.

If anything looks unfamiliar, patients should report it right away to their financial institution, insurance company, or healthcare provider. Acting quickly can limit financial damage and help stop ongoing fraud. Prompt reporting also creates a paper trail that may be useful later.

Watch for Signs of Medical Identity Theft

Because protected health information was involved, patients should stay alert for signs of medical identity theft. This can include bills for services never received, unfamiliar entries in medical records, or denials of insurance coverage due to claims a patient never filed. These warning signs are often subtle and easy to miss.

Requesting a copy of one’s medical records and insurance claim history can help confirm accuracy. If discrepancies appear, patients should contact their insurer and healthcare providers immediately. Correcting a compromised medical record can take time, so starting the process early is important.

Stay Alert for Phishing Attempts

Scammers often use breached information to craft convincing phishing emails, texts, or phone calls. Because personal and health details were exposed, affected individuals should be cautious of messages referencing their medical care or insurance. Legitimate healthcare providers rarely ask for sensitive information through unsolicited contact.

Patients should avoid clicking links or providing information in response to unexpected messages. Instead, they should contact the organization directly using a verified phone number. This simple habit can prevent a second wave of harm following the original breach.

Consider a Fraud Alert or Credit Freeze

Even though the letter does not confirm Social Security numbers were exposed, patients concerned about identity theft may still want to place a fraud alert on their credit file. A fraud alert requires creditors to take extra steps to verify identity before opening new accounts. This adds a layer of security at minimal cost or effort.

For stronger protection, individuals can also request a credit freeze with each of the three major credit bureaus. This makes it harder for anyone to open new credit accounts using a stolen identity. Freezing credit is free and can be lifted temporarily whenever the patient needs to apply for credit themselves.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

See the latest data breaches we're tracking →