Were you recently affected by a data breach?

VNS Health Data Breach

VNS Health, a New York City-based behavioral and home health care provider, disclosed a data breach affecting 739 individuals after a phishing attack compromised an employee’s email account. Exposed information may include Social Security numbers, driver’s license numbers, Medicare/Medicaid numbers, and sensitive health details.

VNS Health
Date of Breach: June 12-26, 2025 (discovered June 26, 2025)
CAU logo

Who was affected:

Clients of VNS Health

Impacted Data:

Names, Social Security numbers, driver’s license numbers, Medicare/Medicaid numbers, substance use disorder or psychiatric evaluation information

VNS Health, a New York City nonprofit with more than 130 years of history providing home- and community-based health care, recently notified 739 people that their personal information may have been exposed after a phishing attack compromised an employee’s email account. The organization, formerly known as VNS Behavioral Health Inc., specializes in behavioral health services including crisis intervention, outpatient mental health care, and care management for children, families, seniors, and at-risk populations.

Companies entrusted with sensitive health and financial information have a responsibility to safeguard it against unauthorized access, and when that trust is broken, those affected deserve to understand what happened and what options may be available to them.

VNS Health’s Data Breach Investigation

According to VNS Health’s notification, the organization discovered suspicious activity within one employee’s email account on June 26, 2025. Upon detecting the irregular activity, VNS Health moved to secure the affected account, reset associated passwords, and engaged a third-party forensic security firm to determine the scope of the incident. That investigation determined that an unauthorized party had access to the employee’s email account for a two-week window, between June 12, 2025, and June 26, 2025.

VNS Health then conducted a detailed review of the contents of the affected email account to identify what information may have been viewable or accessible during that window and which individuals’ data was involved. That review concluded that the exposed information varied from person to person, but may have included full names, Social Security numbers, driver’s license numbers, and Medicare or Medicaid numbers. For some individuals, the exposed data also included health-related information, specifically indications relating to substance use disorder treatment or psychiatric evaluations and assessments, given VNS Health’s role as a behavioral health care provider.

VNS Health reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights on February 18, 2026, listing 739 affected individuals. The company also posted a notice describing the incident on its own website. Phishing attacks, in which an employee is deceived into providing login credentials or otherwise granting access to a secure account through a fraudulent message, remain one of the most common entry points for data breaches across the health care sector, since a single compromised employee inbox can expose the records of many patients or clients at once.

The nearly eight-month gap between VNS Health’s discovery of the incident in June 2025 and its notification to regulators and affected individuals in February 2026 is not unusual for breaches of this kind. Organizations typically need time to complete a forensic investigation, determine precisely whose information was accessible, and identify current contact information for every affected person before notifications can be sent. Breach notification laws generally require notice be provided without unreasonable delay once the scope of an incident is understood, but the underlying investigative work, especially for an email-based compromise touching sensitive health records, can itself take months to complete properly.

Health care and behavioral health organizations are frequent targets for these kinds of attacks because the records they maintain, including Social Security numbers, government-issued identification, insurance information, and details about mental health or substance use treatment, are considered especially valuable to criminals and especially sensitive to the people they describe. Unlike a stolen credit card number, which can be canceled and reissued, a Social Security number, driver’s license number, or details about a person’s psychiatric or substance use treatment history cannot simply be replaced, and exposure of that information can carry consequences well beyond typical financial fraud, including the risk of discrimination, targeted scams, or unwanted disclosure of private health conditions.

Individuals whose information was exposed in the VNS Health breach should remain alert for phishing attempts, unexpected medical bills or insurance claims, and unfamiliar accounts opened in their name. This combination of data, government-issued ID numbers paired with health and financial details, is often used by criminals to commit medical identity theft or file fraudulent insurance claims rather than simple financial fraud alone.

Email-based breaches like this one are also notable because they often begin with a single deceptive message rather than a sophisticated technical intrusion. A phishing email designed to look like a legitimate internal communication can be enough to trick even a careful employee into handing over login credentials, after which an attacker may quietly review months of correspondence, attachments, and records before detection. For organizations handling behavioral health records in particular, this creates an added layer of sensitivity: an email account used for routine care coordination can accumulate a wide range of personal and clinical details over time, meaning the scope of what was potentially exposed can extend well beyond what any single message might suggest.

When Did This Breach Occur?

VNS Health has stated that the unauthorized access to the employee’s email account occurred between June 12, 2025, and June 26, 2025, with the suspicious activity first detected on the later date. The company reported the incident to the U.S. Department of Health and Human Services on February 18, 2026, and began notifying affected individuals around the same time.

What Information Was Breached?

The specific information exposed varied by individual, but VNS Health has indicated it may have included full names, Social Security numbers, driver’s license numbers, and Medicare or Medicaid numbers. For some affected individuals, the exposed information also included health-related details, specifically indications relating to substance use disorder treatment or psychiatric evaluations and assessments. VNS Health has not published a single universal list of every data element exposed for every individual, since the information accessible depended on the specific contents of the compromised email account related to each person.

What You Can Do

If you received a notification letter from VNS Health, or believe your information may have been affected by this breach, there are several steps you can take to help protect yourself:

  • Review account statements, health insurance statements, and credit reports regularly for unauthorized or unusual activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus.
  • Watch for phishing emails, calls, or texts referencing VNS Health or claiming to be from a health care provider or insurer.
  • Report any suspected identity theft or fraud promptly to your financial institution, health plan, or local law enforcement.
  • Contact VNS Health’s dedicated toll-free assistance line at 877-421-8797 (Monday through Friday, 9:00 a.m. to 9:00 p.m. Eastern Time) with questions about the incident.

File a Data Breach Lawsuit Against VNS Health

If you were notified that your personal information was involved in the VNS Health data breach, you may have legal options available to you. Companies and organizations that collect and store sensitive personal and health information have a legal responsibility to implement reasonable safeguards to protect that data from unauthorized access.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Suspicious activity detected December 30, 2025; notice filed with the New Hampshire Attorney General on September 1, 2026
Date of Breach: Reported to the Texas Attorney General on September 11, 2026
Date of Breach: Reported to be around May 25, 2026; formally reported to the Texas Attorney General on September 11, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.