Gastroenterology & Hepatology of Central New York, P.C., a gastroenterology and hepatology practice serving patients in Central New York, recently notified patients of a data security incident affecting information stored on its network. The notification explains what happened, what the practice is doing in response, and what steps patients can take to protect themselves.
Healthcare providers that maintain sensitive medical records have a responsibility to protect that information from unauthorized access, and patients affected by an incident like this one deserve a clear explanation of what occurred and what options are available to them.
Gastroenterology & Hepatology of Central New York’s Data Breach Investigation
According to a notification letter sent to affected individuals, Gastroenterology & Hepatology of Central New York, P.C. experienced a data security incident in which an unauthorized party accessed certain systems within its network environment on or about March 6, 2026. Upon learning of the issue, the practice states that it immediately took steps to contain the threat, notified local law enforcement and the FBI, and began a thorough investigation with the assistance of outside cybersecurity professionals.
That investigation, along with an extensive review of the practice’s files, concluded on August 28, 2026. At that point, Gastroenterology & Hepatology of Central New York determined that an unauthorized third party had acquired records containing some patients’ personal information and protected health information around the time of the initial intrusion. The gap of several months between the discovery of unauthorized access and the completion of the forensic review is common in incidents involving large volumes of records, since investigators must carefully verify which files were actually accessed or removed before notifying anyone affected.
The practice’s notification letter confirms that a recipient’s full name was involved in combination with other personal information, without spelling out a single universal list of data categories that applied to every patient. Practices sending mass notification letters often rely on a template that is customized per recipient depending on which specific data elements applied to that individual, so the categories actually affected can vary from patient to patient even within the same overall incident.
Separately, a cybercriminal group calling itself Exitium has publicly claimed responsibility for the intrusion and stated that it obtained a large patient database from Gastroenterology & Hepatology of Central New York and its affiliated Digestive Disease Center of CNY, including Social Security numbers, contact information, and clinical details such as diagnoses, medications, and pathology reports. These claims have circulated widely in security-industry reporting, but they have not been independently confirmed by the practice itself, and the exact scope of what was taken for any individual patient is best confirmed through the practice’s own notification letter rather than a hacking group’s public claims.
Healthcare data breaches involving large medical practices are an increasingly common target for cybercriminals, in part because patient records combine identifying information, financial detail, and medical history in a single place, all of which can be valuable to fraudsters. Combinations of Social Security numbers, names, and health information are particularly attractive because they can be used not just for ordinary identity theft but also for medical identity theft, where a criminal uses a victim’s identity to obtain medical services or prescriptions, potentially contaminating the victim’s own medical records in the process.
Patients affected by this kind of exposure often do not learn anything is wrong until they receive an unexpected bill, an insurance denial for services they never received, or a suspicious entry on a credit report. That lag between when data is exposed and when the consequences become visible is one of the main reasons regulators require companies to notify affected individuals and offer monitoring services, even when there is no confirmed evidence of misuse at the time notification goes out.
Because the timeline described in the notification spans from the initial intrusion in March 2026 to a forensic conclusion in late August 2026, affected patients should treat this as an ongoing risk rather than a closed matter, and should watch their accounts, medical statements, and credit reports for warning signs well into 2027.
The multi-month timeline between discovery and full notification also underscores why breach investigations of this scale can take so long to conclude. When a threat actor claims to have exfiltrated a database spanning hundreds of thousands of records, investigators typically must reconstruct exactly which files were accessed, cross-reference that against the practice’s own records systems, and confirm which specific individuals need to be notified under state and federal law, all before a single notification letter goes out. That process is deliberately thorough rather than rushed, because sending inaccurate or incomplete notifications can leave some affected patients unaware of a real risk to their information.
When Did This Breach Occur?
Gastroenterology & Hepatology of Central New York states that the unauthorized access to its network occurred on or about March 6, 2026. The practice says it began investigating immediately after discovering the intrusion, working with outside cybersecurity professionals to determine what happened and what information may have been affected.
The investigation and file review were not completed until August 28, 2026, roughly five and a half months after the initial incident. That is when the practice confirmed that an unauthorized third party had acquired records containing patients’ personal and protected health information, rather than simply gaining access to the network. Notification letters to affected patients followed that confirmation.
What Information Was Breached?
The notification letter confirms that an affected patient’s full name was involved in combination with other personal information, but the version of the letter made available publicly does not spell out a single universal list of data categories that applied to every patient. Because notification letters are often customized per recipient, the specific data elements involved can vary from one patient to the next.
A ransomware group that claimed responsibility for the intrusion has separately stated, without independent confirmation from the practice, that it obtained a large patient database potentially including Social Security numbers, contact details, and clinical information such as diagnoses and medication records. Patients who receive a notification letter directly from the practice should rely on that letter, rather than outside claims, for a full and accurate description of what was involved in their specific case.
What You Can Do
Gastroenterology & Hepatology of Central New York is offering affected individuals a complimentary membership in Epiq Privacy Solutions ID, a service that monitors for potential misuse of personal information and provides identity theft protection. The practice states it has no evidence that fraud or identity theft has resulted from this incident, but recommends that patients take precautionary steps regardless, including:
- Enrolling in the complimentary identity monitoring service described in the notification letter
- Placing a fraud alert or security freeze with the three major credit bureaus
- Requesting a free copy of your credit report at annualcreditreport.com
- Reviewing insurance explanation-of-benefits statements for services you did not receive
- Reporting any suspicious account activity to your financial institution and local law enforcement
File a Data Breach Lawsuit Against Gastroenterology & Hepatology of Central New York
If you received a notification letter from Gastroenterology & Hepatology of Central New York about this data security incident, you may have legal options available to you. Healthcare providers are entrusted with sensitive personal and medical information, and when that information is exposed in an unauthorized intrusion, affected patients can face real risks ranging from identity theft to medical fraud.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.