Were you recently affected by a data breach?

Secure Healthcare Information Management Data Breach

Secure Healthcare Information Management, LLC (SHIM), an Allentown, Pennsylvania billing company, began mailing breach notices on October 6, 2026. Files accessed between July 6, 2026 and July 16, 2026 may have included Social Security numbers and medical information.

Secure Healthcare Information Management
Date of Breach: July 6, 2026 to July 16, 2026
CAU logo

Who was affected:

Clients of Secure Healthcare Information Management

Impacted Data:

Names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information.

Secure Healthcare Information Management, LLC (SHIM), an Allentown, Pennsylvania billing and medical management company, began mailing data breach notices on October 6, 2026. An unknown actor accessed or acquired files between July 6, 2026 and July 16, 2026, and the files may have included Social Security numbers and medical information.

Secure Healthcare Information Management’s Data Breach Investigation

Secure Healthcare Information Management, LLC, known as SHIM, is based in Allentown, Pennsylvania. According to its public notice, the company provides billing and medical management services for independent physicians and medical institutions in the northeastern part of the state. Companies in this role handle large amounts of patient information on behalf of the practices they serve, which means a single incident can reach people who never dealt with the company directly.

SHIM states that it experienced a network disruption on July 17, 2026 and immediately began an investigation with the help of cybersecurity experts. That investigation found that certain personal information was accessed or acquired without authorization by an unknown actor at some point between July 6, 2026 and July 16, 2026. The company has not publicly identified the actor or described how the intruder got into its network.

After the incident was contained, SHIM reviewed the affected files to determine whether they contained personal information and whose information it was. The company says it confirmed the scope of the incident and gathered enough information to send notice on September 18, 2026. That review step is common after a network intrusion, and it is the reason individuals often hear about an incident months after the underlying events.

SHIM reports that it notified the U.S. Department of Health and Human Services Office for Civil Rights and the consumer reporting agencies, and that it put several measures in place to reduce the risk of a similar incident. The company has not published a detailed description of those measures. On October 6, 2026, SHIM mailed notice letters to the potentially affected individuals for whom it had identifiable address information. The letter explains the incident and lists resources people can use to protect their information.

For eligible individuals, the notice includes an offer of complimentary identity protection services through Cyberscout, a TransUnion company that provides fraud assistance and remediation. SHIM has also set up a toll-free call center that is open Monday through Friday, from 8:00 a.m. to 8:00 p.m. Eastern Time, excluding major U.S. holidays. Anyone who has not received a letter but believes they may be affected can contact the call center to verify eligibility before enrolling. The deadline to enroll in the identity protection services is January 4, 2027.

SHIM has not stated how many people were affected in the sources reviewed for this page, and this page does not estimate a figure. Because SHIM works on behalf of independent physicians and medical institutions, people whose information was involved may recognize the name of their doctor or provider on the notice rather than the name of SHIM itself. If you received a letter from a company you do not recognize, check it against your recent medical visits before dismissing it as junk mail.

The combination of data types involved here is a serious one. Names, dates of birth and Social Security numbers are the core ingredients for opening accounts in someone else’s name, and medical and health insurance information can be used for medical identity theft, such as submitting false claims or obtaining care under another person’s identity. Unlike a credit card number, a Social Security number or a birth date cannot be replaced, so the risk can last for years after the incident.

Healthcare billing and management companies are frequent targets for network intrusions because they hold financial, insurance and clinical details in one place. Under federal health privacy rules, covered entities and their business associates must notify affected people and regulators after a breach of protected health information, and the notice should explain what happened, what information was involved and what steps people can take. Keep any letter you receive, along with the enrollment information it contains, in case you need to refer to it later.

When Did This Breach Occur?

SHIM states that it experienced a network disruption on July 17, 2026. Its investigation found that an unknown actor accessed or acquired certain files without authorization at some point between July 6, 2026 and July 16, 2026. The company confirmed the scope of the impact on September 18, 2026, and began mailing notice letters to potentially affected individuals on October 6, 2026.

What Information Was Breached?

SHIM states that the potentially impacted information may have included names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information. Not every person was necessarily affected in the same way, and the notice letter you receive is the best source for what applies to you.

What You Can Do

If you received a notice from SHIM, or believe you may be affected, consider these steps:

  • Read the notice carefully and enroll in the complimentary Cyberscout identity protection services before the January 4, 2027 deadline if you are eligible. If you did not receive a letter, call the SHIM call center to verify eligibility.
  • Place a free fraud alert on your credit file, or consider a credit freeze, with Equifax, Experian and TransUnion.
  • Review explanation of benefits statements and insurance statements for services you did not receive, and check your credit reports for free at annualcreditreport.com.
  • Be cautious of calls, texts or emails that reference your medical care or insurance and ask for personal details. Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Secure Healthcare Information Management

If you received a notice about this incident, or believe your personal or health information was exposed, you may have legal options. Healthcare billing companies are expected to safeguard the sensitive information entrusted to them, and a class action can help hold them accountable when they fail to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: October 6, 2026 (claimed, unconfirmed)
Date of Breach: April 27, 2025 to April 28, 2025 (vendor PDCM Insurance)
Date of Breach: Not yet disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.