Were you recently affected by a data breach?

Silver Summit Medical Corporation Data Breach

Silver Summit Medical Corporation, doing business as Digestive Disease Center and Heart Vascular & Leg Center in Bakersfield, California, notified patients that a third-party vendor breach exposed sensitive personal and health information.

Silver Summit Medical Corporation
Date of Breach: November 27-30, 2025 (discovered by SSMC on July 20, 2026)
CAU logo

Who was affected:

Clients of Silver Summit Medical Corporation

Impacted Data:

Names, Social Security numbers, driver’s license numbers, financial account or payment card information, dates of birth, medical treatment information, prescription information, diagnoses, health insurance policy numbers, taxpayer identification numbers, and passport or other governmental identification numbers

Silver Summit Medical Corporation (SSMC), which does business as Digestive Disease Center and Heart Vascular & Leg Center in Bakersfield, California, has notified patients that their personal and protected health information was exposed after a cybersecurity event at one of its third-party vendors. The healthcare provider offers digestive health treatment as well as cardiovascular and vein care services to patients throughout Kern County, and this incident potentially compromised highly sensitive medical, financial, and identity information belonging to those it serves.

Companies entrusted with protected health information have a legal responsibility to keep that data secure. When a healthcare provider like SSMC allows a vendor to access patient records, it does not get to outsource its duty to protect that information along with it.

Silver Summit Medical Corporation’s Data Breach Investigation

Class Action U is investigating a data breach affecting patients of Silver Summit Medical Corporation, the parent entity behind Digestive Disease Center and Heart Vascular & Leg Center. According to SSMC’s own notice of data event, on or about July 20, 2026, the company became aware that a third-party vendor’s cybersecurity incident had affected personal and protected health information that the vendor received from SSMC on the company’s behalf. SSMC has stated that data from the vendor’s systems was accessed without authorization between November 27, 2025 and November 30, 2025, meaning affected individuals’ sensitive information sat exposed to unauthorized parties for several months before the breach was discovered and disclosed.

SSMC has not publicly named the third-party vendor involved or disclosed the technical details of how the vendor’s systems were compromised. What is known is that the exposed data originated from records the vendor maintained in connection with services it performed for SSMC, and that the incident was serious enough to trigger notification obligations under both California and federal law, given the presence of protected health information in the affected records.

Individuals who received care at Digestive Disease Center or Heart Vascular & Leg Center, or who otherwise interacted with SSMC as patients, should treat any notice they receive from the company seriously. The information involved in this breach is exactly the kind of data that identity thieves and fraudsters seek out: Social Security numbers, driver’s license numbers, financial account information, and detailed medical records that can be used to commit medical identity theft, file fraudulent insurance claims, open new lines of credit, or file false tax returns in a victim’s name.

SSMC says it is reviewing its internal policies and procedures in an effort to reduce the likelihood of similar incidents in the future, and it is offering twelve months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company, to eligible individuals. While that offer may help some affected patients monitor for signs of misuse, it does not undo the months-long exposure window during which unauthorized parties may have already accessed, copied, or sold this information. Twelve months of monitoring is also unlikely to fully protect against the long-term risks tied to medical and Social Security data, which does not expire the way a compromised credit card number does.

Class Action U believes that patients affected by this incident deserve a full accounting of what happened, how long SSMC’s vendor relationship left their data exposed, and what safeguards, if any, were in place before the breach occurred. Companies that collect sensitive medical and financial information, whether directly or through a vendor, are expected to implement reasonable data security measures and to vet the third parties they trust with that information. When those safeguards fail, the individuals whose data was exposed are the ones left to deal with the fallout, often for years after the company itself has moved on.

This incident is also a reminder that the growing use of third-party vendors in healthcare comes with real risk to patients. When a medical practice like SSMC hands off billing, records management, or other administrative functions to an outside company, patients rarely have any say in that decision, yet they are the ones who bear the consequences if the vendor’s systems are not properly secured. A months-long gap between unauthorized access and public notification, as appears to have happened here, only compounds that risk, since affected individuals had no opportunity to protect themselves during the period their information was actually exposed.

Medical identity theft in particular can be difficult to detect and unwind. Unlike a stolen credit card number, which a bank can quickly cancel and reissue, a stolen Social Security number, date of birth, or health insurance policy number can be used repeatedly over months or years to open fraudulent accounts, file false tax returns, or submit fraudulent medical claims under a victim’s name. Victims often only discover the problem when they are denied credit, receive a bill for services they never received, or are contacted by a collection agency over a debt that was never theirs.

If you received a notice of data event from Silver Summit Medical Corporation, Digestive Disease Center, or Heart Vascular & Leg Center, we encourage you to keep that notice and reach out to discuss your options. Our investigation into this breach is ongoing, and we are working to determine the full scope of what happened and who may be entitled to compensation as a result.

When Did This Breach Occur?

According to SSMC’s notice, unauthorized access to data held by its third-party vendor occurred between November 27, 2025 and November 30, 2025. SSMC states it became aware of the vendor’s cybersecurity event on or about July 20, 2026, meaning several months passed between the unauthorized access and the company’s public notification to affected individuals.

What Information Was Breached?

The information involved in this breach includes affected individuals’ names along with Social Security numbers, driver’s license numbers, financial account or payment card information, dates of birth, medical treatment information, prescription information, diagnoses, health insurance policy numbers, taxpayer identification numbers, and passport or other governmental identification numbers. This is an unusually broad combination of financial, medical, and government-issued identification data, increasing the risk of both financial fraud and medical identity theft for those affected.

What You Can Do

If you received a notice from Silver Summit Medical Corporation, Digestive Disease Center, or Heart Vascular & Leg Center, consider taking the following steps:

  • Enroll in the complimentary credit monitoring and identity restoration services SSMC is offering through Cyberscout
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion
  • Regularly review your bank, credit card, and insurance explanation-of-benefits statements for unfamiliar activity
  • Watch for suspicious medical bills or insurance claims that could indicate medical identity theft
  • Keep the notice you received, along with any records of time or money spent responding to the breach

File a Data Breach Lawsuit Against Silver Summit Medical Corporation

If your personal or medical information was exposed in the Silver Summit Medical Corporation data breach, you may have legal options. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach or believe your information was compromised, don’t wait to protect your rights.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: November 27-30, 2025 (discovered by SSMC on July 20, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.