New Era Technology has notified employees that Quantum Health, the company’s third-party healthcare advocacy vendor, experienced a cybersecurity incident that may have exposed personal information belonging to New Era employees and their dependents. Companies that share employee data with outside vendors have a responsibility to ensure that data is reasonably protected, even when the vendor itself is responsible for the underlying security failure.
New Era Technology’s Data Breach Investigation
New Era Technology is an information technology and audiovisual solutions provider headquartered in New York City. According to a notification letter sent to employees, Quantum Health — New Era’s healthcare navigation and advocacy vendor, which handles health-related services on behalf of New Era’s workforce — experienced a cybersecurity incident that resulted in unauthorized access to its own systems.
New Era’s notification states that the incident occurred within Quantum Health’s environment and was not the result of a security breach of New Era’s own systems, networks, or infrastructure. Based on information Quantum Health provided to New Era, the types of personal information that may have been exposed include employees’ dates of birth, Social Security numbers, and other personal data. The notification did not disclose the exact dates of the incident or the total number of New Era employees affected.
Quantum Health, a Dublin, Ohio-based healthcare navigation company, has separately disclosed that unauthorized access to its systems occurred between May 29, 2026 and June 1, 2026, following an employee’s response to a vishing (voice-phishing) call, and that files containing sensitive personal and health information were accessed as a result. New Era’s notice to its own employees appears to stem from that same underlying Quantum Health incident.
Vendor and third-party breaches like this one illustrate a growing risk in the healthcare-benefits space: an employer’s own security posture may be sound, but if a benefits administrator or navigation vendor it shares employee data with is compromised, employees can still be exposed to identity theft and fraud through no fault of their direct employer. When a Social Security number is exposed alongside a date of birth, the combination is often enough on its own to allow a bad actor to open new financial accounts or file fraudulent tax returns in the victim’s name.
New Era has stated it is actively reviewing Quantum Health’s security practices and infrastructure and is working with Quantum Health to ensure affected employees receive complete notification and remediation support, including credit monitoring through Kroll.
When Did This Breach Occur?
New Era’s employee notification did not specify the exact dates of the incident. Quantum Health has separately disclosed that unauthorized access to its own systems occurred between May 29, 2026 and June 1, 2026, and was discovered on June 1, 2026. New Era’s notice to employees followed in the weeks after.
What Information Was Breached?
According to New Era’s notification, the personal information that may have been exposed includes employees’ dates of birth, Social Security numbers, and other unspecified personal data provided to Quantum Health in connection with healthcare advocacy services.
What You Can Do
If you are a current or former New Era Technology employee and received a notice about this incident, consider taking the following steps:
- Review the notification letter carefully and keep a copy for your records.
- Enroll in the credit monitoring services being offered through Kroll.
- Monitor your credit reports and financial accounts closely for unauthorized activity.
- Consider placing a fraud alert or credit freeze with the major credit bureaus.
- Be alert for phishing attempts referencing this incident, especially calls or texts requesting personal information.
File a Data Breach Lawsuit Against New Era Technology
If you were notified that your information was exposed through New Era Technology’s vendor, Quantum Health, you may have legal options. Employers and the vendors they entrust with employee data have a duty to reasonably safeguard sensitive personal information.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.