Were you recently affected by a data breach?

IES Data Breach

IES notified patients that an unauthorized person accessed an employee’s email account for more than four hours in June 2026, exposing an email containing names, health information, and medical record identifiers. IES secured the account within a day and is notifying affected individuals out of caution.

IES
Date of Breach: June 16, 2026
CAU logo

Who was affected:

Clients of IES

Impacted Data:

Names, health information, and medical record identifiers

IES, the trade name for Integrative Emergency Services, LLC, a Dallas, Texas based physician-owned company that provides healthcare services and staffing solutions to hospitals and healthcare providers, has disclosed a data security event involving patient protected health information (PHI). Because IES supports the clinical operations of the healthcare providers it staffs, it holds and processes patient information on their behalf, and a compromise of that information can carry real consequences for the patients involved.

IES’s Data Breach Investigation

According to IES’s own notice of the incident, the company discovered suspicious activity involving one employee’s email account on June 16, 2026. IES states that it secured the compromised account within 24 hours of discovering the activity and then opened an investigation to determine what had occurred and what information, if any, may have been exposed.

IES’s investigation determined that an unauthorized person had access to the employee’s email account for a window of just over four hours before the account was secured. On July 9, 2026, IES says it learned that at least one email containing protected health information may have been viewed by the unauthorized person during that window of access. IES has stated that, as of the date of its notice, it has no evidence that any exposed information has actually been misused, but the company opted to notify potentially affected individuals out of an abundance of caution.

IES has filed notice of this incident with multiple state regulators, including the Attorneys General of California, Iowa, Maine, Montana, Nebraska, New Hampshire, Oregon, Rhode Island, South Carolina, Texas, Vermont, and Washington, as well as the Massachusetts Office of Consumer Affairs and Business Regulation. Because the incident involves protected health information, it may also be reportable to the U.S. Department of Health and Human Services Office for Civil Rights, which maintains a public breach portal for healthcare-related data security events, and potentially to the U.S. Securities and Exchange Commission depending on the company’s reporting obligations.

In its own notice, IES described the steps it says it has taken in response to the incident, including changing the password on the affected email account and retraining employees on how to recognize and respond to suspicious email activity going forward. These are common remediation steps following a business email compromise, but they do not undo the exposure that already occurred, and they do not guarantee that the same vulnerability could not be exploited again in the future.

Email-based intrusions like the one IES describes are among the most common ways healthcare data is exposed. A single compromised employee inbox can contain months or years of correspondence, referrals, and records for many different patients, meaning even a short window of unauthorized access, such as the roughly four hours IES has disclosed, can potentially touch a meaningful volume of sensitive health data. Under most state breach notification laws, an organization that experiences this kind of incident is required to notify affected individuals within a specific timeframe once the scope of the exposure is understood, and to offer some form of remediation or protective service where required by law.

Health information is considered especially valuable to identity thieves and fraudsters because, unlike a credit card number, it generally cannot be changed or canceled once it has been exposed. Depending on what is contained in a compromised medical record or email, exposed health data can be used to commit medical identity theft, file fraudulent insurance claims in a victim’s name, or target victims with convincing phishing attempts that reference real details about their care or their provider. Healthcare organizations and the staffing and service companies that support them, like IES, are frequently targeted by cybercriminals precisely because the information they hold is so valuable on the black market and so difficult for an individual victim to fully undo once it has been exposed.

Patients who receive a notice from IES, or from a healthcare provider that relied on IES for staffing or services, should treat the notification seriously and take the protective steps outlined below, even though IES has stated that it has not yet found evidence that the information was misused. As is common with early-stage breach disclosures, IES has not yet published a specific count of how many individuals were affected by this incident. This page will be updated if IES or a state regulator releases additional information about the scope of the breach.

When Did This Breach Occur?

Based on IES’s own notice, the company first noticed suspicious activity involving an employee’s email account on June 16, 2026, and secured the account within 24 hours of that discovery. The unauthorized access itself is reported to have lasted just over four hours before the account was locked down. IES states that it did not determine that an email containing protected health information may have been viewed until July 9, 2026, when its investigation into the incident concluded. The gap between the initial discovery, the securing of the account, and the confirmation that PHI may have been exposed is a normal part of a forensic investigation into this type of incident, but it also means that the individuals whose information was involved were unaware of the exposure for several weeks before notices went out.

What Information Was Breached?

According to IES, the information that may have been exposed during the roughly four-hour window of unauthorized access included some combination of patient names, health information, and medical record identifiers. IES has stated that patient addresses, Social Security numbers, and financial account information were not involved in this particular incident. Because the exposure occurred through a single employee email account rather than a broader systems intrusion, the scope of information involved may vary from patient to patient depending on what correspondence happened to be in that inbox during the relevant window.

Even without Social Security numbers or financial details, exposed health information and medical record identifiers can still be misused, including to support medical identity theft or targeted phishing schemes that reference a patient’s real medical history to appear more convincing.

What You Can Do

IES has recommended that individuals who received a notice review their explanation of benefits and any other communications from their healthcare provider or health insurer, and report anything unfamiliar or suspicious. If you believe your information was involved in this incident, consider the following steps:

Monitor your medical records and insurance explanation-of-benefits statements closely for any services, prescriptions, or claims you do not recognize. Contact your healthcare provider directly if you have questions about whether your specific records were involved. Be cautious of unexpected phone calls, emails, or texts that reference your medical care, as scammers sometimes use details from a breach to make phishing attempts appear legitimate. Report any suspected identity theft or fraud to your state Attorney General, the Federal Trade Commission, and local law enforcement. IES has also set up a dedicated phone line, 888-732-8137, available Monday through Friday from 7 a.m. to 7 p.m. Central time, for individuals with questions about the incident or who want to confirm whether their information was involved.

File a Data Breach Lawsuit Against IES

If your personal or health information was exposed as a result of this data security event, you may have legal options available to you. Companies that collect and store sensitive patient information have a responsibility to protect it, and when that information is exposed due to inadequate safeguards, affected individuals may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 18, 2026 (review concluded July 23, 2026)
Date of Breach: May 8-9, 2026 (detected May 22, 2026)
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.