Were you recently affected by a data breach?

Diana Health Data Breach

Diana Health, a women’s healthcare provider partnering with hospitals across several states, reported a data breach involving patients’ Social Security numbers to the Vermont Attorney General’s office in August 2026.

Diana Health
Date of Breach: Reported to the Vermont Attorney General's office in August 2026
CAU logo

Who was affected:

Clients of Diana Health

Impacted Data:

Social Security numbers

Diana Health, a women’s healthcare company that partners with hospitals to provide maternity, gynecology, and wellness services, has reported a data security incident to the Vermont Attorney General’s office. The notice confirms that Social Security numbers belonging to individuals connected to the company were exposed. Healthcare providers that maintain sensitive patient records carry a responsibility to safeguard that information, and any lapse that puts Social Security numbers at risk can expose affected individuals to a lasting risk of identity theft and fraud.

Diana Health’s Data Breach Investigation

According to a filing made with the Vermont Attorney General’s office, Diana Health disclosed a data security incident in August 2026 that resulted in the exposure of Social Security numbers. Vermont’s regulatory filing process does not require companies to publish a detailed narrative of how an incident occurred, so specifics about the method of intrusion, how long unauthorized access may have persisted, or the full scope of individuals affected nationwide have not been made public at this time.

Healthcare organizations remain one of the most frequently targeted sectors for data breaches because the records they maintain are unusually valuable to criminals. A single patient file often bundles together Social Security numbers, dates of birth, insurance details, and medical history, all of which can be resold or used to commit various forms of fraud. This combination makes healthcare providers, including companies like Diana Health that manage patient relationships across multiple hospital systems and states, an attractive target for cybercriminals.

When a Social Security number is exposed in a breach, the risk to the affected individual does not end once the incident is discovered and contained. Social Security numbers are effectively permanent identifiers that cannot be reissued the way a credit card number can, which means the exposure can create risk for years after the original incident. Individuals connected to Diana Health who receive a notification letter about this incident should read it carefully and take the recommended steps to protect their personal information.

Companies that collect and store sensitive personal data, particularly in the healthcare space, are expected to maintain reasonable safeguards to prevent unauthorized access. When those safeguards fail and personal information is exposed, affected individuals may have legal options available to hold the responsible company accountable and seek compensation for the risks created by the exposure.

When Did This Breach Occur?

Diana Health’s data security incident was reported to the Vermont Attorney General’s office in August 2026. The exact date the underlying incident occurred, when it was first discovered, and when affected individuals were notified have not been publicly disclosed as part of the Vermont filing. This page will be updated if additional details about the timeline become publicly available.

What Information Was Breached?

Based on the information filed with the Vermont Attorney General’s office, the data exposed in this incident included Social Security numbers. Diana Health has not publicly disclosed whether additional categories of personal or medical information, such as names, dates of birth, or health insurance details, were also involved. Individuals should review any notification letter they receive directly from Diana Health for a complete and specific list of the information that pertains to them.

What You Can Do

If you have received a notice that your information may have been affected by this breach, consider taking the following steps:

  • Review the notification letter carefully for details specific to your information
  • Place a fraud alert or credit freeze with the three major credit bureaus
  • Monitor your bank and credit card statements for unauthorized activity
  • Enroll in any free credit monitoring or identity protection services offered by Diana Health
  • Watch for phishing emails, calls, or texts referencing this breach
  • File a report with the FTC at IdentityTheft.gov if you notice signs of fraud

File a Data Breach Lawsuit Against Diana Health

If your Social Security number was exposed in the Diana Health data breach, you may be entitled to compensation. Companies that fail to properly secure sensitive personal information can be held legally accountable for the harm that exposure creates.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's office in August 2026
Date of Breach: August 2026
Date of Breach: August 28, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.