Were you recently affected by a data breach?

Elixir Medical Data Breach

Elixir Medical Corporation discovered that an unauthorized party accessed its computer network between July 20 and July 21, 2026. Human resources files containing sensitive information about current and former employees, consultants, and their beneficiaries were involved.

Elixir Medical
Date of Breach: Unauthorized access occurred July 20-21, 2026; affected data identified August 11, 2026
CAU logo

Who was affected:

Clients of Elixir Medical

Impacted Data:

Names, Social Security numbers, and for some individuals driver’s license numbers, credit or debit card numbers, medical information, and direct deposit bank account information

Elixir Medical Corporation, a medical device company, has notified current and former employees, consultants, and their beneficiaries or dependents that an unauthorized party gained access to its computer network. Any organization that maintains sensitive personal and financial information about the people who work for it has a duty to keep that information secure, and a network intrusion of this kind can put a wide range of personal data at risk.

Elixir Medical’s Data Breach Investigation

According to a notice filed with the California Attorney General’s office, Elixir Medical learned that an unauthorized party had gained access to its computer network and immediately began an investigation with the assistance of third-party cybersecurity experts. Law enforcement was also notified. The investigation determined that the unauthorized access occurred between July 20, 2026 and July 21, 2026. On August 11, 2026, Elixir Medical determined that the files potentially accessed during this window contained human resources information relating to current and former employees and consultants, along with information tied to some of their beneficiaries and dependents.

The notice explains that the affected files contained each individual’s name and Social Security number, and, depending on what had been provided to human resources, may also have included a driver’s license number, credit or debit card number, medical information, or direct deposit bank account information. Because this incident involves internal human resources records rather than customer or patient data, it highlights a less-discussed but still serious category of data breach risk: the sensitive information companies collect about their own workforce.

Breaches involving payroll and human resources systems are an increasingly common target for cybercriminals because these records often combine several categories of high-value data, such as Social Security numbers, banking details for direct deposit, and government-issued identification numbers, in one place. That combination can be used to file fraudulent tax returns, redirect payroll deposits, open new lines of credit, or commit medical identity theft, depending on which specific data elements were exposed for a given individual.

Elixir Medical has stated that it is offering a complimentary membership to Experian’s IdentityWorks credit monitoring and identity restoration service to individuals affected by this incident, and that it has taken steps to further strengthen its network security and employee security training following the breach. The company also established a dedicated call line for affected individuals with questions about the incident.

When Did This Breach Occur?

Elixir Medical’s investigation determined that an unauthorized party accessed its computer network between July 20, 2026 and July 21, 2026. The company identified which files and individuals were affected on August 11, 2026, and began notifying impacted individuals shortly afterward.

What Information Was Breached?

The files involved in this incident contained names and Social Security numbers for affected individuals, and for some people also included driver’s license numbers, credit or debit card numbers, medical information, and direct deposit bank account information, depending on what had been provided to Elixir Medical’s human resources department.

What You Can Do

If you are a current or former employee, consultant, or beneficiary/dependent of someone in those categories and receive a notice from Elixir Medical, consider the following steps:

  • Enroll in the complimentary Experian IdentityWorks credit monitoring offered in the notice letter
  • Monitor your bank accounts and payroll deposits for unauthorized changes or withdrawals
  • Request a free credit report from Equifax, Experian, or TransUnion and review it for suspicious activity
  • Consider placing a fraud alert or credit freeze on your credit files
  • Watch for phishing attempts referencing this incident, especially any asking you to confirm banking or personal details

File a Data Breach Lawsuit Against Elixir Medical

If you are a current or former employee, consultant, or dependent affected by this breach and are concerned your personal information may have been compromised, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Unauthorized access occurred July 20-21, 2026; affected data identified August 11, 2026
Date of Breach: Detected July 22, 2026; notice issued August 11, 2026
Date of Breach: Reported to HHS OCR August 7, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.