Were you recently affected by a data breach?

Minnesota ENT Data Breach

Minnesota ENT (Oakdale Ear Nose & Throat PA) detected unauthorized access to six employee email accounts. An investigation later found one mailbox contained patients’ personal and health information.

Minnesota ENT
Date of Breach: Unauthorized access detected on or about January 16, 2026; impacted mailbox confirmed to contain personal/health information on July 15, 2026
CAU logo

Who was affected:

Clients of Minnesota ENT

Impacted Data:

Personal information and/or health information contained in email accounts and attachments; specific data element list not fully disclosed in the notice

Minnesota ENT, formally known as Oakdale Ear Nose & Throat PA, a Golden Valley, Minnesota ear-nose-and-throat medical practice, has notified patients of a cybersecurity incident that potentially exposed their personal and health information. The practice detected unauthorized access to several employee email accounts and later confirmed that one affected mailbox contained patient information.

Medical practices that maintain patient records, including sensitive health information, have a heightened responsibility to safeguard that data given how damaging exposure of medical details can be for the people they treat. When a breach like this occurs, patients deserve a clear explanation of what happened and meaningful support in protecting themselves going forward.

Minnesota ENT’s Data Breach Investigation

According to a notification letter sent to affected patients, Minnesota ENT detected unauthorized access to six of its employee email accounts on or about January 16, 2026. Upon discovering the intrusion, the practice secured its network, changed the passwords on the affected accounts, and began an investigation with the help of outside cybersecurity professionals. Despite these efforts, the practice could not rule out with full certainty that the contents of one mailbox had been accessed or acquired by the unauthorized individual or individuals responsible for the intrusion.

Minnesota ENT conducted a detailed review of that mailbox’s contents and, on July 15, 2026, roughly six months after the initial intrusion was detected, determined that the mailbox contained emails and attachments including patients’ personal and, in some cases, health information. The practice has stated that it has no evidence to date that any of this information has been used to commit identity theft or financial fraud, but is nonetheless offering complimentary credit monitoring through Experian IdentityWorks as a precautionary measure to affected individuals.

Medical practices are a frequent target for cyberattacks because of the volume and sensitivity of information they hold, including Social Security numbers, insurance details, and detailed health records, all of which can be valuable to criminals seeking to commit identity theft or medical fraud. Email-based intrusions, like the one described here, are a particularly common entry point, since compromised email accounts often provide access to years of accumulated patient correspondence, referrals, and attachments containing protected health information, sometimes without staff realizing the scope of what a single compromised mailbox may hold until a lengthy forensic review is completed.

The roughly six-month gap between the initial detection of unauthorized access in January 2026 and the practice’s confirmation in July 2026 that patient data was actually involved reflects a pattern seen in many similar incidents: distinguishing between mere unauthorized access to an account and confirming that specific sensitive content was exposed can require an extensive, methodical review of email contents, which takes considerably longer than detecting the initial intrusion itself.

When Did This Breach Occur?

Minnesota ENT detected unauthorized access to six employee email accounts on or about January 16, 2026. After securing its network and launching an investigation with outside cybersecurity professionals, the practice determined on July 15, 2026 that one of the potentially impacted mailboxes contained emails or attachments with patients’ personal and/or health information. The practice’s notification letters to affected patients followed this determination.

What Information Was Breached?

Minnesota ENT’s notification letter states that the information potentially accessed included patients’ personal information, and in some cases health information, contained in emails and attachments within the affected mailbox. The letter does not provide a complete itemized list of every specific data element involved for each patient, though the practice is offering credit monitoring services, suggesting the exposed information may include data points such as names in combination with other identifying details.

What You Can Do

If you received a notice from Minnesota ENT or believe you may have been affected by this incident, consider taking the following steps:

  • Enroll in the complimentary Experian IdentityWorks credit monitoring services offered in the notification letter.
  • Review your health insurance Explanation of Benefits statements for any services you do not recognize.
  • Request your free annual credit reports from Equifax, Experian, and TransUnion and review them for suspicious activity.
  • Consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus.
  • Contact Minnesota ENT’s dedicated call center with any questions about your specific notice.

File a Data Breach Lawsuit Against Minnesota ENT

If you were notified that your personal or health information was involved in the Minnesota ENT data breach, you may have legal options available to you. Medical practices that collect and store sensitive patient information are expected to implement reasonable safeguards to protect it, and affected individuals may be entitled to compensation when those protections fail.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 2026 (reported via dark web leak site claim; not confirmed by the company)
Date of Breach: Not publicly disclosed as of August 2026
Date of Breach: May 4, 2026 (date of discovery)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.