IES, the trade name for Integrative Emergency Services, LLC, a Dallas, Texas based physician-owned company that provides healthcare services and staffing solutions to hospitals and healthcare providers, has disclosed a data security event involving patient protected health information (PHI). Because IES supports the clinical operations of the healthcare providers it staffs, it holds and processes patient information on their behalf, and a compromise of that information can carry real consequences for the patients involved.
IES’s Data Breach Investigation
According to IES’s own notice of the incident, the company discovered suspicious activity involving one employee’s email account on June 16, 2026. IES states that it secured the compromised account within 24 hours of discovering the activity and then opened an investigation to determine what had occurred and what information, if any, may have been exposed.
IES’s investigation determined that an unauthorized person had access to the employee’s email account for a window of just over four hours before the account was secured. On July 9, 2026, IES says it learned that at least one email containing protected health information may have been viewed by the unauthorized person during that window of access. IES has stated that, as of the date of its notice, it has no evidence that any exposed information has actually been misused, but the company opted to notify potentially affected individuals out of an abundance of caution.
IES has filed notice of this incident with multiple state regulators, including the Attorneys General of California, Iowa, Maine, Montana, Nebraska, New Hampshire, Oregon, Rhode Island, South Carolina, Texas, Vermont, and Washington, as well as the Massachusetts Office of Consumer Affairs and Business Regulation. Because the incident involves protected health information, it may also be reportable to the U.S. Department of Health and Human Services Office for Civil Rights, which maintains a public breach portal for healthcare-related data security events, and potentially to the U.S. Securities and Exchange Commission depending on the company’s reporting obligations.
In its own notice, IES described the steps it says it has taken in response to the incident, including changing the password on the affected email account and retraining employees on how to recognize and respond to suspicious email activity going forward. These are common remediation steps following a business email compromise, but they do not undo the exposure that already occurred, and they do not guarantee that the same vulnerability could not be exploited again in the future.
Email-based intrusions like the one IES describes are among the most common ways healthcare data is exposed. A single compromised employee inbox can contain months or years of correspondence, referrals, and records for many different patients, meaning even a short window of unauthorized access, such as the roughly four hours IES has disclosed, can potentially touch a meaningful volume of sensitive health data. Under most state breach notification laws, an organization that experiences this kind of incident is required to notify affected individuals within a specific timeframe once the scope of the exposure is understood, and to offer some form of remediation or protective service where required by law.
Health information is considered especially valuable to identity thieves and fraudsters because, unlike a credit card number, it generally cannot be changed or canceled once it has been exposed. Depending on what is contained in a compromised medical record or email, exposed health data can be used to commit medical identity theft, file fraudulent insurance claims in a victim’s name, or target victims with convincing phishing attempts that reference real details about their care or their provider. Healthcare organizations and the staffing and service companies that support them, like IES, are frequently targeted by cybercriminals precisely because the information they hold is so valuable on the black market and so difficult for an individual victim to fully undo once it has been exposed.
Patients who receive a notice from IES, or from a healthcare provider that relied on IES for staffing or services, should treat the notification seriously and take the protective steps outlined below, even though IES has stated that it has not yet found evidence that the information was misused. As is common with early-stage breach disclosures, IES has not yet published a specific count of how many individuals were affected by this incident. This page will be updated if IES or a state regulator releases additional information about the scope of the breach.
When Did This Breach Occur?
Based on IES’s own notice, the company first noticed suspicious activity involving an employee’s email account on June 16, 2026, and secured the account within 24 hours of that discovery. The unauthorized access itself is reported to have lasted just over four hours before the account was locked down. IES states that it did not determine that an email containing protected health information may have been viewed until July 9, 2026, when its investigation into the incident concluded. The gap between the initial discovery, the securing of the account, and the confirmation that PHI may have been exposed is a normal part of a forensic investigation into this type of incident, but it also means that the individuals whose information was involved were unaware of the exposure for several weeks before notices went out.
What Information Was Breached?
According to IES, the information that may have been exposed during the roughly four-hour window of unauthorized access included some combination of patient names, health information, and medical record identifiers. IES has stated that patient addresses, Social Security numbers, and financial account information were not involved in this particular incident. Because the exposure occurred through a single employee email account rather than a broader systems intrusion, the scope of information involved may vary from patient to patient depending on what correspondence happened to be in that inbox during the relevant window.
Even without Social Security numbers or financial details, exposed health information and medical record identifiers can still be misused, including to support medical identity theft or targeted phishing schemes that reference a patient’s real medical history to appear more convincing.
What You Can Do
IES has recommended that individuals who received a notice review their explanation of benefits and any other communications from their healthcare provider or health insurer, and report anything unfamiliar or suspicious. If you believe your information was involved in this incident, consider the following steps:
Monitor your medical records and insurance explanation-of-benefits statements closely for any services, prescriptions, or claims you do not recognize. Contact your healthcare provider directly if you have questions about whether your specific records were involved. Be cautious of unexpected phone calls, emails, or texts that reference your medical care, as scammers sometimes use details from a breach to make phishing attempts appear legitimate. Report any suspected identity theft or fraud to your state Attorney General, the Federal Trade Commission, and local law enforcement. IES has also set up a dedicated phone line, 888-732-8137, available Monday through Friday from 7 a.m. to 7 p.m. Central time, for individuals with questions about the incident or who want to confirm whether their information was involved.
File a Data Breach Lawsuit Against IES
If your personal or health information was exposed as a result of this data security event, you may have legal options available to you. Companies that collect and store sensitive patient information have a responsibility to protect it, and when that information is exposed due to inadequate safeguards, affected individuals may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.