Nabi Health, Inc. has filed a data breach notification letter with Massachusetts regulators, posted in the state’s list of notification letters for October 2026. The letter describes a data security incident tied to a former vendor’s continued access to patient intake information.
If you received this notice, here is what has been made public so far and what you can do about it.
Nabi Health’s Data Breach Investigation
Nabi Health, Inc., which the letter abbreviates as NHI, is based in San Francisco, California. The notice it sent to individuals describes a data security incident that may have affected the security of their personal information. It was mailed through a return processing center operated by HaystackID, the same company the letter names as the provider of fraud assistance and credit monitoring.
According to the letter, the company discovered on August 10, 2026 that a former vendor had kept access to certain personal information. The company describes the information as limited patient intake data, specifically an individual’s name and the stated reason for a visit as entered through the company’s website portal. This is not a typical hacking narrative. The letter does not say an outside criminal broke in, and it does not say the former vendor misused anything. The problem it describes is access that stayed in place after it should have ended.
The company stresses that the incident was limited in scope. It says patient medical records and Social Security numbers were not affected. It also calls the matter an isolated incident that has since been remediated, and says it has taken steps to make sure the former vendor no longer has access to any of its data. Those are the company’s own statements. This page reports them as the company’s position and does not independently confirm them.
After discovery, the company reviewed the affected data to work out which people it related to. The letter says that review was completed and the final list of individuals to notify was set on September 24, 2026. The letter itself is undated in the copy posted by Massachusetts, and it is not clear exactly when the mailing went out, so this page does not give a mailing date.
As a response, the company says it moved to secure the impacted platform and to verify the security of its internal systems. It also says it is putting additional technical safeguards, stronger security measures and updated procedures in place to reduce the chance of a similar problem. The letter does not name the former vendor, does not say how long the vendor’s access lasted, and does not describe how the company learned of it.
The letter also does not state how many people were notified. The Massachusetts posting is a template copy of the letter, and the line listing the information involved for each recipient is blank in that copy. This page therefore does not state a total count, and it does not guess at one.
Even though the company says no medical records were involved, a patient’s name paired with the reason they sought care can still be sensitive. A reason for a visit can reveal a health condition, a treatment interest or a personal circumstance that a person may not want shared. For that reason, people who received this letter may want to treat it seriously, even where the company characterizes the exposure as narrow.
As a measure of relief, the company is offering access to single-bureau credit monitoring, a credit report and a credit score service at no charge, plus fraud assistance, through HaystackID. The letter says the monitoring sends alerts for 24 months from the date of enrollment whenever the person’s credit file changes. To use the offer, recipients must enroll within 90 days of the date on the letter, and they will need the activation code printed in their own copy. Enrollment requires an internet connection and an email address, and the letter says it may not be available to anyone under 18.
Incidents that involve vendors are a recurring theme in breach notices. Companies often rely on outside software and service providers to run intake forms, scheduling and portals, and each provider can hold copies of patient details. When an arrangement with a vendor ends, access should be closed out and any data returned or deleted, but that step can be missed. The letter does not say more than that a former vendor kept access.
If you received a letter, read it closely and keep the envelope, the activation code and the enrollment instructions together. Your own copy is the best source for what applies to you. If you believe you used the company’s website portal but did not receive a letter, you can contact Nabi Health directly to ask whether your information was involved, and you can also watch your accounts and statements for anything unfamiliar.
When Did This Breach Occur?
The letter says Nabi Health discovered on August 10, 2026 that a former vendor maintained access to certain personal information.
It also says the company finished its review and finalized the list of people to notify on September 24, 2026. The posted copy does not say when the vendor’s access began or ended, so the underlying exposure may have started well before the discovery date. The discovery date should not be read as the date your information was accessed.
What Information Was Breached?
The letter describes limited patient intake data: an individual’s name and the stated reason for a visit, as identified through the company’s website portal. The company says patient medical records and Social Security numbers were not impacted.
The posted template leaves the personalized list of information blank, so this page cannot say more about what applied to each recipient. Your own letter is the best source for that detail.
What You Can Do
If you received a notice from Nabi Health or believe you may be affected, consider these steps:
- Read the notice carefully and keep it, along with any enrollment details for protection services it offers.
- Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
- Watch your financial accounts, tax records and any insurance or medical statements for activity you do not recognize.
- Be skeptical of unexpected calls, texts or emails that mention the organization, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Nabi Health
If your personal information may have been exposed in this incident, you may have legal options. Organizations that collect patient details are expected to safeguard them and to control who can reach them, and a class action can help hold a company accountable when it falls short.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.