Loma Linda University Health (LLUH), a nonprofit academic medical center in Southern California, has notified patients that a file containing their protected health information was inadvertently uploaded to an external artificial intelligence platform during a research study. LLUH says it promptly requested that the platform delete the information once the mistake was discovered.
Healthcare providers that use patients’ medical information for research or operational purposes have a responsibility to ensure that data is handled securely at every step, including when interacting with third-party technology platforms.
Loma Linda University Health’s Data Breach Investigation
Loma Linda University Health operates several hospitals and healthcare facilities in the Loma Linda, California area, providing comprehensive medical care and specialized clinical research. According to the notice LLUH posted on its website, the incident occurred on May 25, 2026, during an Institutional Review Board (IRB)-approved research study, when a file containing limited patient information was inadvertently uploaded to an external AI platform.
Upon discovering the error, LLUH says it promptly initiated an investigation and requested that the information be deleted from the AI platform. The organization has stated that it is reviewing its internal policies, procedures, and workforce training regarding the use of external technologies, including AI tools, in light of the incident.
Incidents like this one highlight a growing risk area for healthcare organizations and research institutions: the increasing use of third-party AI tools to process, summarize, or analyze large volumes of data. Even when an upload is described as inadvertent or accidental, once patient information reaches an external platform outside an organization’s own secure systems, the organization typically loses direct control over how that data is stored, whether it is retained in backups or logs, and whether it could be used to train or improve the AI platform’s own models.
The healthcare sector remains one of the most frequently targeted industries for data exposure incidents of all kinds, whether through outside hacking, insider error, or, as in this case, unintentional data-handling missteps involving new technology. Medical record numbers, even without an accompanying Social Security number, can still be misused to attempt fraudulent insurance claims or to gain unauthorized access to a patient’s broader health records, which is why healthcare-specific data breaches are treated with particular seriousness under both HIPAA and California’s own data breach notification laws.
LLUH has stated that Social Security numbers, financial information, insurance information, and complete treatment records were not involved in this incident. Even so, patients whose medical record numbers and clinical information were exposed should remain alert for phishing attempts or fraudulent communications that may follow public disclosure of a breach like this one, particularly messages that claim to be from LLUH or an affiliated research program asking patients to verify or update their information.
When Did This Breach Occur?
According to LLUH’s own notice, the incident occurred on May 25, 2026, when a file containing patient data was inadvertently uploaded to an external AI platform during an IRB-approved research study. LLUH began notifying potentially affected patients and posted its public notice of the incident on July 27, 2026, approximately two months after the file was uploaded.
What Information Was Breached?
LLUH has disclosed that the information involved may have included a medical record number, date of birth, and limited clinical information related to orthopedic care. The organization has specifically stated that Social Security numbers, financial information, insurance information, and complete treatment records were not part of the information involved in this incident.
What You Can Do
If you believe you may have been affected by this incident, or if you received notice from Loma Linda University Health about this breach, consider the following steps:
- Review any notice you receive from LLUH and keep a copy for your records.
- Contact LLUH’s Office of Corporate Compliance with any questions about whether your information was involved.
- Monitor your medical records and insurance statements for any unfamiliar activity.
- Be cautious of unsolicited calls, texts, or emails asking you to verify personal or medical information related to this incident.
File a Data Breach Lawsuit Against Loma Linda University Health
Healthcare organizations that handle sensitive patient information, especially when using new technologies like AI platforms, have a legal and ethical responsibility to ensure that data is protected at every stage of use. When a lapse like this occurs, affected patients may have legal options to pursue accountability and compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.