Paradigm Healthcare Services recently notified individuals that a data security incident may have impacted protected health information the company maintains on behalf of California’s Medicaid program. Paradigm serves as a third-party service provider that processes Medi-Cal billing and maintains Medi-Cal member identification numbers under a Data Use Agreement with the California Department of Health Care Services.
Companies entrusted with processing health information on behalf of government programs take on a responsibility to safeguard that data, and when an incident like this occurs, affected individuals deserve clear answers about what happened and what steps they can take next.
Paradigm Healthcare Services’s Data Breach Investigation
According to a notification letter filed with the California Attorney General’s Office, Paradigm became aware of unauthorized access to its local network on October 13, 2025. Immediately upon detecting the activity, the company took steps to mitigate the incident, including taking certain systems offline and notifying law enforcement. Paradigm also engaged outside professionals experienced in handling incidents of this kind to investigate what information may have been affected.
On August 18, 2026, roughly ten months after the initial network intrusion, Paradigm determined that protected health information belonging to certain individuals was potentially accessed by an unauthorized party between October 8, 2025, and October 15, 2025. The company states it has no evidence that any of the affected information has been used to commit fraud or identity theft as a result of this incident, but is notifying individuals out of an abundance of caution.
Data breaches involving Medicaid billing vendors and other healthcare administrative service providers are a growing concern because these companies frequently maintain large volumes of government program identification numbers alongside basic identifying details like name, date of birth, and gender. Even without a Social Security number or financial account number in the mix, this combination of information can be misused to attempt fraudulent billing activity or to impersonate an affected individual when contacting government or healthcare programs.
The extended gap between the October 2025 intrusion and the August 2026 determination that health information was affected reflects a pattern seen across many healthcare-sector breaches, where forensic investigators must review large volumes of affected systems and records in detail before a company can confidently identify which specific individuals and data elements were involved. Regulatory notification laws generally require notice to affected individuals within a set window after this determination is made, not from the date of the original intrusion.
Because Paradigm processes Medi-Cal billing information under an agreement with a state health agency, individuals affected by this incident may include Medi-Cal beneficiaries across California who interacted with a healthcare provider or program that relied on Paradigm’s billing services, rather than individuals who had a direct customer relationship with Paradigm itself. This is a common feature of third-party vendor breaches: the affected individuals often never chose to share their information with the breached company directly, since it was collected and processed on behalf of another organization.
For individuals whose Medi-Cal member identification number was exposed, it is worth noting that this type of identifier is generally used to verify eligibility and process healthcare claims, meaning unauthorized possession of it could theoretically be used to attempt fraudulent billing or service claims, even though Paradigm states it has no current evidence of such misuse.
When Did This Breach Occur?
Paradigm Healthcare Services states that unauthorized access to its network occurred between October 8, 2025, and October 15, 2025, and that it discovered the activity on October 13, 2025. The company completed its investigation and determined that protected health information was potentially accessed on August 18, 2026, after which it began notifying affected individuals.
What Information Was Breached?
The notification letter identifies the following categories of information as potentially accessed: name, date of birth, gender, and Medi-Cal member identification number.
What You Can Do
If you received a letter from Paradigm Healthcare Services about this breach, consider taking the following steps:
- Review your Medi-Cal explanation of benefits statements for services you do not recognize and follow up with your provider or the Department of Health Care Services about any discrepancies.
- Monitor your email, phone, and mail for suspicious contact attempts referencing your personal details.
- Be cautious of unsolicited messages asking you to click a link, download an attachment, or provide additional personal information.
- Review your financial accounts and credit reports for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
- Keep a copy of your notification letter and any related correspondence in case you need it later.
File a Data Breach Lawsuit Against Paradigm Healthcare Services
If you received a data breach notification letter from Paradigm Healthcare Services, or if you believe your personal information was exposed as a result of this incident, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.