Silver Summit Medical Corporation (SSMC), which does business as Digestive Disease Center and Heart Vascular & Leg Center in Bakersfield, California, has notified patients that their personal and protected health information was exposed after a cybersecurity event at one of its third-party vendors. The healthcare provider offers digestive health treatment as well as cardiovascular and vein care services to patients throughout Kern County, and this incident potentially compromised highly sensitive medical, financial, and identity information belonging to those it serves.
Companies entrusted with protected health information have a legal responsibility to keep that data secure. When a healthcare provider like SSMC allows a vendor to access patient records, it does not get to outsource its duty to protect that information along with it.
Silver Summit Medical Corporation’s Data Breach Investigation
Class Action U is investigating a data breach affecting patients of Silver Summit Medical Corporation, the parent entity behind Digestive Disease Center and Heart Vascular & Leg Center. According to SSMC’s own notice of data event, on or about July 20, 2026, the company became aware that a third-party vendor’s cybersecurity incident had affected personal and protected health information that the vendor received from SSMC on the company’s behalf. SSMC has stated that data from the vendor’s systems was accessed without authorization between November 27, 2025 and November 30, 2025, meaning affected individuals’ sensitive information sat exposed to unauthorized parties for several months before the breach was discovered and disclosed.
SSMC has not publicly named the third-party vendor involved or disclosed the technical details of how the vendor’s systems were compromised. What is known is that the exposed data originated from records the vendor maintained in connection with services it performed for SSMC, and that the incident was serious enough to trigger notification obligations under both California and federal law, given the presence of protected health information in the affected records.
Individuals who received care at Digestive Disease Center or Heart Vascular & Leg Center, or who otherwise interacted with SSMC as patients, should treat any notice they receive from the company seriously. The information involved in this breach is exactly the kind of data that identity thieves and fraudsters seek out: Social Security numbers, driver’s license numbers, financial account information, and detailed medical records that can be used to commit medical identity theft, file fraudulent insurance claims, open new lines of credit, or file false tax returns in a victim’s name.
SSMC says it is reviewing its internal policies and procedures in an effort to reduce the likelihood of similar incidents in the future, and it is offering twelve months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company, to eligible individuals. While that offer may help some affected patients monitor for signs of misuse, it does not undo the months-long exposure window during which unauthorized parties may have already accessed, copied, or sold this information. Twelve months of monitoring is also unlikely to fully protect against the long-term risks tied to medical and Social Security data, which does not expire the way a compromised credit card number does.
Class Action U believes that patients affected by this incident deserve a full accounting of what happened, how long SSMC’s vendor relationship left their data exposed, and what safeguards, if any, were in place before the breach occurred. Companies that collect sensitive medical and financial information, whether directly or through a vendor, are expected to implement reasonable data security measures and to vet the third parties they trust with that information. When those safeguards fail, the individuals whose data was exposed are the ones left to deal with the fallout, often for years after the company itself has moved on.
This incident is also a reminder that the growing use of third-party vendors in healthcare comes with real risk to patients. When a medical practice like SSMC hands off billing, records management, or other administrative functions to an outside company, patients rarely have any say in that decision, yet they are the ones who bear the consequences if the vendor’s systems are not properly secured. A months-long gap between unauthorized access and public notification, as appears to have happened here, only compounds that risk, since affected individuals had no opportunity to protect themselves during the period their information was actually exposed.
Medical identity theft in particular can be difficult to detect and unwind. Unlike a stolen credit card number, which a bank can quickly cancel and reissue, a stolen Social Security number, date of birth, or health insurance policy number can be used repeatedly over months or years to open fraudulent accounts, file false tax returns, or submit fraudulent medical claims under a victim’s name. Victims often only discover the problem when they are denied credit, receive a bill for services they never received, or are contacted by a collection agency over a debt that was never theirs.
If you received a notice of data event from Silver Summit Medical Corporation, Digestive Disease Center, or Heart Vascular & Leg Center, we encourage you to keep that notice and reach out to discuss your options. Our investigation into this breach is ongoing, and we are working to determine the full scope of what happened and who may be entitled to compensation as a result.
When Did This Breach Occur?
According to SSMC’s notice, unauthorized access to data held by its third-party vendor occurred between November 27, 2025 and November 30, 2025. SSMC states it became aware of the vendor’s cybersecurity event on or about July 20, 2026, meaning several months passed between the unauthorized access and the company’s public notification to affected individuals.
What Information Was Breached?
The information involved in this breach includes affected individuals’ names along with Social Security numbers, driver’s license numbers, financial account or payment card information, dates of birth, medical treatment information, prescription information, diagnoses, health insurance policy numbers, taxpayer identification numbers, and passport or other governmental identification numbers. This is an unusually broad combination of financial, medical, and government-issued identification data, increasing the risk of both financial fraud and medical identity theft for those affected.
What You Can Do
If you received a notice from Silver Summit Medical Corporation, Digestive Disease Center, or Heart Vascular & Leg Center, consider taking the following steps:
- Enroll in the complimentary credit monitoring and identity restoration services SSMC is offering through Cyberscout
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion
- Regularly review your bank, credit card, and insurance explanation-of-benefits statements for unfamiliar activity
- Watch for suspicious medical bills or insurance claims that could indicate medical identity theft
- Keep the notice you received, along with any records of time or money spent responding to the breach
File a Data Breach Lawsuit Against Silver Summit Medical Corporation
If your personal or medical information was exposed in the Silver Summit Medical Corporation data breach, you may have legal options. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach or believe your information was compromised, don’t wait to protect your rights.