Were you recently affected by a data breach?

Loma Linda University Health Data Breach

Loma Linda University Health disclosed that a file containing patient information, including medical record numbers and orthopedic care details, was inadvertently uploaded to an external AI platform during a research study, and is notifying affected patients.

Loma Linda University Health
Date of Breach: May 25, 2026
CAU logo

Who was affected:

Clients of Loma Linda University Health

Impacted Data:

Medical record numbers, dates of birth, and limited clinical information related to orthopedic care

Loma Linda University Health (LLUH), a nonprofit academic medical center in Southern California, has notified patients that a file containing their protected health information was inadvertently uploaded to an external artificial intelligence platform during a research study. LLUH says it promptly requested that the platform delete the information once the mistake was discovered.

Healthcare providers that use patients’ medical information for research or operational purposes have a responsibility to ensure that data is handled securely at every step, including when interacting with third-party technology platforms.

Loma Linda University Health’s Data Breach Investigation

Loma Linda University Health operates several hospitals and healthcare facilities in the Loma Linda, California area, providing comprehensive medical care and specialized clinical research. According to the notice LLUH posted on its website, the incident occurred on May 25, 2026, during an Institutional Review Board (IRB)-approved research study, when a file containing limited patient information was inadvertently uploaded to an external AI platform.

Upon discovering the error, LLUH says it promptly initiated an investigation and requested that the information be deleted from the AI platform. The organization has stated that it is reviewing its internal policies, procedures, and workforce training regarding the use of external technologies, including AI tools, in light of the incident.

Incidents like this one highlight a growing risk area for healthcare organizations and research institutions: the increasing use of third-party AI tools to process, summarize, or analyze large volumes of data. Even when an upload is described as inadvertent or accidental, once patient information reaches an external platform outside an organization’s own secure systems, the organization typically loses direct control over how that data is stored, whether it is retained in backups or logs, and whether it could be used to train or improve the AI platform’s own models.

The healthcare sector remains one of the most frequently targeted industries for data exposure incidents of all kinds, whether through outside hacking, insider error, or, as in this case, unintentional data-handling missteps involving new technology. Medical record numbers, even without an accompanying Social Security number, can still be misused to attempt fraudulent insurance claims or to gain unauthorized access to a patient’s broader health records, which is why healthcare-specific data breaches are treated with particular seriousness under both HIPAA and California’s own data breach notification laws.

LLUH has stated that Social Security numbers, financial information, insurance information, and complete treatment records were not involved in this incident. Even so, patients whose medical record numbers and clinical information were exposed should remain alert for phishing attempts or fraudulent communications that may follow public disclosure of a breach like this one, particularly messages that claim to be from LLUH or an affiliated research program asking patients to verify or update their information.

When Did This Breach Occur?

According to LLUH’s own notice, the incident occurred on May 25, 2026, when a file containing patient data was inadvertently uploaded to an external AI platform during an IRB-approved research study. LLUH began notifying potentially affected patients and posted its public notice of the incident on July 27, 2026, approximately two months after the file was uploaded.

What Information Was Breached?

LLUH has disclosed that the information involved may have included a medical record number, date of birth, and limited clinical information related to orthopedic care. The organization has specifically stated that Social Security numbers, financial information, insurance information, and complete treatment records were not part of the information involved in this incident.

What You Can Do

If you believe you may have been affected by this incident, or if you received notice from Loma Linda University Health about this breach, consider the following steps:

  • Review any notice you receive from LLUH and keep a copy for your records.
  • Contact LLUH’s Office of Corporate Compliance with any questions about whether your information was involved.
  • Monitor your medical records and insurance statements for any unfamiliar activity.
  • Be cautious of unsolicited calls, texts, or emails asking you to verify personal or medical information related to this incident.

File a Data Breach Lawsuit Against Loma Linda University Health

Healthcare organizations that handle sensitive patient information, especially when using new technologies like AI platforms, have a legal and ethical responsibility to ensure that data is protected at every stage of use. When a lapse like this occurs, affected patients may have legal options to pursue accountability and compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 27, 2026
Date of Breach: May 25, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.