Were you recently affected by a data breach?

Cherry Health Data Breach

Cherry Health (Cherry Street Services, Inc.) disclosed a 2026 data breach after detecting suspicious network activity in April, exposing patient and staff information including names, Social Security numbers, and health insurance details. Affected individuals may have legal options if their personal information was compromised.

Cherry Health
Date of Breach: April 19, 2026 (detected)
CAU logo

Who was affected:

Clients of Cherry Health

Impacted Data:

Names, addresses, phone numbers, dates of birth, health insurance information, health insurance ID numbers, patient ID numbers, provider names, service dates, and Social Security numbers

Cherry Health, the Grand Rapids-based healthcare provider formally known as Cherry Street Services, Inc., has disclosed a data breach that may affect current and former patients as well as current and former staff members. The organization detected suspicious activity on its network in the spring of 2026 and later confirmed that certain data had been accessed and copied by an unauthorized individual.

Companies that provide healthcare services collect and store some of the most sensitive personal and medical information available, and they have a responsibility to keep that information secure from unauthorized access.

Cherry Health’s Data Breach Investigation

According to a notice Cherry Health posted to its website on June 18, 2026, the organization became aware of suspicious activity relating to its network on or about April 19, 2026. Cherry Health says it promptly took steps to secure its systems and launched an investigation with the assistance of third-party specialists to determine the nature and scope of the activity. That investigation determined that certain information stored on Cherry Health’s network had been accessed and copied by an unauthorized individual.

At the time the preliminary notice was posted, Cherry Health said it was still conducting a comprehensive review of the involved data to determine exactly what information was affected and to whom it relates. The organization stated it would notify potentially affected individuals by written letter once that review was complete, and that it has no evidence at this time that any exposed information has actually been used to commit identity theft or fraud. Cherry Health separately reported the incident to the U.S. Department of Health and Human Services’ Office for Civil Rights, which tracks breaches of protected health information affecting 500 or more individuals. According to that filing, approximately 501 individuals in Michigan were affected by this incident.

This is a separate, more recent incident from an earlier breach Cherry Street Services disclosed in 2024 that affected a much larger group of individuals — the two events involve different network intrusions and should not be confused with one another.

Healthcare providers are a frequent target for network intrusions because the records they maintain typically combine a patient’s identity information with medical and insurance details in a single place, making a successful breach unusually valuable to criminals. When Social Security numbers are exposed alongside health insurance identifiers, affected individuals can face risks that go beyond ordinary identity theft, including medical identity theft, in which someone else uses a person’s insurance information to obtain healthcare services or prescriptions in their name. Cleaning up medical identity theft can be more complicated than resolving a typical fraudulent credit card charge, since incorrect information can end up mixed into a victim’s own medical records and take considerable time and paperwork to correct.

Federal and state data breach notification laws generally require an organization to notify affected individuals and, in the case of healthcare entities covered by HIPAA, the Department of Health and Human Services, once it has confirmed that protected health information was compromised. HIPAA’s breach notification rule generally requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days following discovery of a breach, while allowing organizations time to determine the full scope of what was accessed. Cherry Health’s decision to post a preliminary notice while its internal review continues, followed by individual letters once that review concludes, is a common approach organizations take when the scope of a breach is not yet fully known but a notification deadline is approaching.

Beyond the immediate risk of identity theft, individuals affected by a healthcare data breach are also frequently targeted by follow-up phishing attempts. Scammers often use news of a real breach as cover to send fake “identity protection” or “claim your compensation” emails and text messages designed to trick recipients into providing even more personal information, such as login credentials or payment details. Because these messages can closely mimic a legitimate breach notification, affected individuals should be especially cautious about clicking links or providing information in response to unsolicited messages referencing this incident, and should instead contact Cherry Health directly using the phone number or address listed in an official notice.

When Did This Breach Occur?

Cherry Health says it first became aware of suspicious activity on its network on or about April 19, 2026. The organization posted a preliminary notice describing the incident on its website on June 18, 2026, while stating that a full review of the affected data was still underway at that time.

What Information Was Breached?

Cherry Health has stated that the information involved may vary by individual and could include one or more of the following: names, addresses, phone numbers, dates of birth, health insurance information, health insurance ID numbers, patient ID numbers, provider names, service dates, and, in a limited number of cases, Social Security numbers. The company has not yet published a single universal list confirming exactly which data types were involved for every affected person, and says individualized letters will specify what information was involved for each recipient once its review is complete.

What You Can Do

If you received a notice from Cherry Health, or believe you may have been affected by this incident, consider the following steps:

  • Monitor your financial accounts and explanation-of-benefits statements from your health insurer for any unfamiliar activity.
  • Request a free copy of your credit report from each of the three major credit bureaus at annualcreditreport.com and review it for accounts you don’t recognize.
  • Consider placing a fraud alert or credit freeze on your credit file with Equifax, Experian, and TransUnion.
  • Watch for phishing emails, texts, or phone calls from scammers posing as Cherry Health or a related healthcare provider.
  • Keep any notification letter you receive, as it may be useful if you later need to document that your information was involved in this incident.

File a Data Breach Lawsuit Against Cherry Health

If your personal information was exposed as a result of this incident, you may have legal options available to you. Companies that collect and store sensitive personal and medical data have a responsibility to protect it, and when that data is compromised, affected individuals may be entitled to compensation for the risks and burdens they now face.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed (reported to HHS July 6, 2026)
Date of Breach: April 19, 2026 (detected)
Date of Breach: May 29, 2025 (notified customers August 22, 2025)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.