2026 BAYADA Home Health Care — direct network intrusion; PHI review ongoing (Feb–Mar)
Data compromised
Per BAYADA website notice: names, DOB, diagnosis/treatment information, provider and insurance data, prescriptions, hospital admissions/discharges, disability information, and/or SSNs; individual review ongoing at disclosure
Technical writeup
Verified direct intrusion — discovered Mar. 2, 2026. BAYADA Home Health Care said it first became aware of a cybersecurity event that day and engaged third-party forensics, determining an unauthorized actor accessed certain BAYADA systems and data between Feb. 18 and Mar. 2, 2026. A data review by third-party specialists was ongoing; BAYADA said it would notify affected individuals upon completion. Potentially exposed categories include names, dates of birth, diagnoses and treatment information, provider and insurance details, prescriptions, hospital admissions/discharges, disability information, and Social Security numbers for some individuals. ClassAction.org reported a filing to HHS OCR but a public affected-individual count had not been published at indexing time. Distinct from BAYADA's earlier Doctor Alliance vendor breach affecting 9,526 clients.
Root cause
Unauthorized actor accessed certain BAYADA systems and data between Feb. 18 and Mar. 2, 2026; discovery Mar. 2, 2026