Were you recently affected by a data breach?

TELUS Health (US) Data Breach

TELUS Health (US) Ltd., a provider of employee wellness and behavioral health services, reported a data breach affecting 2,641 individuals to federal health regulators.

TELUS Health (US)
Date of Breach: Reported to HHS Office for Civil Rights, August 2026
CAU logo

Who was affected:

Clients of TELUS Health (US)

Impacted Data:

Protected health information, not publicly detailed by the company

TELUS Health (US) Ltd., which provides employee assistance and behavioral health services to organizations across the country, has reported a data breach affecting 2,641 individuals to the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR). Companies entrusted with employees’ health and wellness information carry a legal responsibility under HIPAA to safeguard that data and to notify affected individuals when it is compromised.

TELUS Health (US)’s Data Breach Investigation

According to the HHS OCR breach portal, TELUS Health (US) Ltd. reported that the breach affected 2,641 individuals connected to the company’s Massachusetts-based operations. As of this writing, the filing does not include a detailed public narrative describing the nature of the incident, such as whether it stemmed from a hacking incident, unauthorized access, or a third-party vendor compromise.

Companies that provide behavioral health and employee assistance program (EAP) services, like TELUS Health, typically maintain sensitive records that can include mental health treatment information, counseling records, and other protected health information (PHI) for employees of the businesses that contract with them. This makes such vendors an attractive target for cybercriminals, since a single breach at one EAP provider can expose the health data of employees across many client companies simultaneously.

HIPAA-covered entities and their business associates are required to notify HHS OCR of breaches affecting 500 or more individuals, and OCR investigates these reports to determine whether the entity maintained reasonable safeguards. Breaches of protected health information are among the most sensitive categories of data breach, since exposed health records cannot be changed the way a compromised password or account number can, and this type of exposure can carry lasting privacy consequences for those affected.

Individuals affected by breaches at EAP or behavioral health vendors are often notified directly by their employer or by the vendor itself, sometimes weeks or months after the underlying incident is first discovered, as the company works to determine the full scope of what data was exposed and who was affected.

When Did This Breach Occur?

TELUS Health (US) Ltd.’s breach report was logged with HHS OCR in August 2026. The exact date the underlying incident occurred or was discovered has not been publicly detailed.

What Information Was Breached?

TELUS Health (US) Ltd. has not publicly disclosed the specific categories of protected health information involved in this incident. Individuals affected should watch for a direct notification letter from the company or their employer describing exactly what information was exposed.

What You Can Do

If you believe you may have been affected by the TELUS Health (US) data breach, consider taking these steps:

  • Watch for an official notification letter describing what information was involved
  • Review any account statements tied to health savings, benefits, or insurance for unusual activity
  • Be cautious of phishing emails or calls referencing this breach that ask for personal information
  • Ask your employer’s HR or benefits department for more information if you participated in an employee assistance program through TELUS Health

File a Data Breach Lawsuit Against TELUS Health (US)

If you were affected by the TELUS Health (US) data breach, you may have legal options available to you. Companies entrusted with employees’ sensitive health information have a responsibility to protect it with reasonable security measures.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to HHS Office for Civil Rights, August 2026
Date of Breach: Reported to HHS Office for Civil Rights, August 2026
Date of Breach: Reported to the Vermont Attorney General on August 21, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.