Were you recently affected by a data breach?

Gastroenterology & Hepatology of Central New York Data Breach

Gastroenterology & Hepatology of Central New York, P.C. notified patients that an unauthorized party accessed its network on March 6, 2026, and confirmed in August 2026 that personal and health information was acquired. Free identity monitoring is being offered.

Gastroenterology & Hepatology of Central New York
Date of Breach: On or about March 6, 2026
CAU logo

Who was affected:

Clients of Gastroenterology & Hepatology of Central New York

Impacted Data:

Full name in combination with other personal and protected health information

Gastroenterology & Hepatology of Central New York, P.C., a gastroenterology and hepatology practice serving patients in Central New York, recently notified patients of a data security incident affecting information stored on its network. The notification explains what happened, what the practice is doing in response, and what steps patients can take to protect themselves.

Healthcare providers that maintain sensitive medical records have a responsibility to protect that information from unauthorized access, and patients affected by an incident like this one deserve a clear explanation of what occurred and what options are available to them.

Gastroenterology & Hepatology of Central New York’s Data Breach Investigation

According to a notification letter sent to affected individuals, Gastroenterology & Hepatology of Central New York, P.C. experienced a data security incident in which an unauthorized party accessed certain systems within its network environment on or about March 6, 2026. Upon learning of the issue, the practice states that it immediately took steps to contain the threat, notified local law enforcement and the FBI, and began a thorough investigation with the assistance of outside cybersecurity professionals.

That investigation, along with an extensive review of the practice’s files, concluded on August 28, 2026. At that point, Gastroenterology & Hepatology of Central New York determined that an unauthorized third party had acquired records containing some patients’ personal information and protected health information around the time of the initial intrusion. The gap of several months between the discovery of unauthorized access and the completion of the forensic review is common in incidents involving large volumes of records, since investigators must carefully verify which files were actually accessed or removed before notifying anyone affected.

The practice’s notification letter confirms that a recipient’s full name was involved in combination with other personal information, without spelling out a single universal list of data categories that applied to every patient. Practices sending mass notification letters often rely on a template that is customized per recipient depending on which specific data elements applied to that individual, so the categories actually affected can vary from patient to patient even within the same overall incident.

Separately, a cybercriminal group calling itself Exitium has publicly claimed responsibility for the intrusion and stated that it obtained a large patient database from Gastroenterology & Hepatology of Central New York and its affiliated Digestive Disease Center of CNY, including Social Security numbers, contact information, and clinical details such as diagnoses, medications, and pathology reports. These claims have circulated widely in security-industry reporting, but they have not been independently confirmed by the practice itself, and the exact scope of what was taken for any individual patient is best confirmed through the practice’s own notification letter rather than a hacking group’s public claims.

Healthcare data breaches involving large medical practices are an increasingly common target for cybercriminals, in part because patient records combine identifying information, financial detail, and medical history in a single place, all of which can be valuable to fraudsters. Combinations of Social Security numbers, names, and health information are particularly attractive because they can be used not just for ordinary identity theft but also for medical identity theft, where a criminal uses a victim’s identity to obtain medical services or prescriptions, potentially contaminating the victim’s own medical records in the process.

Patients affected by this kind of exposure often do not learn anything is wrong until they receive an unexpected bill, an insurance denial for services they never received, or a suspicious entry on a credit report. That lag between when data is exposed and when the consequences become visible is one of the main reasons regulators require companies to notify affected individuals and offer monitoring services, even when there is no confirmed evidence of misuse at the time notification goes out.

Because the timeline described in the notification spans from the initial intrusion in March 2026 to a forensic conclusion in late August 2026, affected patients should treat this as an ongoing risk rather than a closed matter, and should watch their accounts, medical statements, and credit reports for warning signs well into 2027.

The multi-month timeline between discovery and full notification also underscores why breach investigations of this scale can take so long to conclude. When a threat actor claims to have exfiltrated a database spanning hundreds of thousands of records, investigators typically must reconstruct exactly which files were accessed, cross-reference that against the practice’s own records systems, and confirm which specific individuals need to be notified under state and federal law, all before a single notification letter goes out. That process is deliberately thorough rather than rushed, because sending inaccurate or incomplete notifications can leave some affected patients unaware of a real risk to their information.

When Did This Breach Occur?

Gastroenterology & Hepatology of Central New York states that the unauthorized access to its network occurred on or about March 6, 2026. The practice says it began investigating immediately after discovering the intrusion, working with outside cybersecurity professionals to determine what happened and what information may have been affected.

The investigation and file review were not completed until August 28, 2026, roughly five and a half months after the initial incident. That is when the practice confirmed that an unauthorized third party had acquired records containing patients’ personal and protected health information, rather than simply gaining access to the network. Notification letters to affected patients followed that confirmation.

What Information Was Breached?

The notification letter confirms that an affected patient’s full name was involved in combination with other personal information, but the version of the letter made available publicly does not spell out a single universal list of data categories that applied to every patient. Because notification letters are often customized per recipient, the specific data elements involved can vary from one patient to the next.

A ransomware group that claimed responsibility for the intrusion has separately stated, without independent confirmation from the practice, that it obtained a large patient database potentially including Social Security numbers, contact details, and clinical information such as diagnoses and medication records. Patients who receive a notification letter directly from the practice should rely on that letter, rather than outside claims, for a full and accurate description of what was involved in their specific case.

What You Can Do

Gastroenterology & Hepatology of Central New York is offering affected individuals a complimentary membership in Epiq Privacy Solutions ID, a service that monitors for potential misuse of personal information and provides identity theft protection. The practice states it has no evidence that fraud or identity theft has resulted from this incident, but recommends that patients take precautionary steps regardless, including:

  • Enrolling in the complimentary identity monitoring service described in the notification letter
  • Placing a fraud alert or security freeze with the three major credit bureaus
  • Requesting a free copy of your credit report at annualcreditreport.com
  • Reviewing insurance explanation-of-benefits statements for services you did not receive
  • Reporting any suspicious account activity to your financial institution and local law enforcement

File a Data Breach Lawsuit Against Gastroenterology & Hepatology of Central New York

If you received a notification letter from Gastroenterology & Hepatology of Central New York about this data security incident, you may have legal options available to you. Healthcare providers are entrusted with sensitive personal and medical information, and when that information is exposed in an unauthorized intrusion, affected patients can face real risks ranging from identity theft to medical fraud.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Between March 28, 2026, and April 12, 2026 (at vendor Ernst & Young LLP)
Date of Breach: On or about August 26, 2026
Date of Breach: On or about March 6, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.