Advantage Home Health Care told patients and employees that an unauthorized party reached one of its servers on June 9, 2026, and by June 26 the company knew data may have been acquired. Consumer notices and an HHS OCR-facing disclosure followed around August 25, 2026. Public aggregations of those filings put the census near 19,851 people. Fields in the company website notice include Social Security numbers plus patient clinical context and employee HR/benefits data. About a month after the intrusion window, TheGentlemen had already listed the firm on a leak site — BreachHistory first cataloged that claim as unverified; the August notice upgrades it to a verified Advantage Home Health Care data breach.
Canonical record: https://breachhistory.com/advantage-home-health-care/advantage-home-health-thegentlemen2026.
What happened
On June 16 AHHC became aware of unauthorized server access. Investigation pegged first access at June 9 and acquisition awareness at June 26. The company says it contained the activity, hired forensic help, notified federal law enforcement, and later mailed notices with Cyberscout monitoring. That timeline is the company-confirmed spine — not the dark-web marketing copy from July.
What this is not: a published minute-by-minute malware family autopsy, or proof that every Gentlemen-claimed file matched the notice inventory. Treat actor screenshots as unverified color around a verified HR/patient server incident.
Timeline
- June 9, 2026 — Unauthorized access begins (forensic finding in notice).
- June 16 — AHHC detects the incident.
- June 26 — Confirms data may have been acquired.
- ~July 17 — TheGentlemen leak-site listing observed by trackers/class-action monitors.
- August 25 — Consumer notices / HHS OCR disclosure window; Cyberscout offer.
- October 1 reporting — Claim Depot and others circulate the ~19,851 figure from state/OCR aggregations.
What data was exposed
- Patients: name, DOB, SSN, address, phone, medical conditions and care received
- Employees: name, DOB, SSN, address, phone, employment information
- Health-plan enrollees: insurance, enrollment, claims, providers, benefits details
SSN plus care context is enough for medical identity theft and highly targeted phishing that cites real visit history.
Who is at risk
Patients, employees, former staff, and dependents on the employee health plan. If you got a letter, enroll and freeze credit. If you used AHHC services in 2025–2026 and heard nothing, still ask — mail lags.
Action items
- Enroll in Cyberscout using the code in your letter.
- Freeze Equifax/Experian/TransUnion if your SSN was listed.
- Watch medical-billing and “home health aide schedule” phishing.
- Call 1-888-398-2084 only if that number matches your letter.
- Keep the notice for tax-season and dispute files.
Sources
Home-health sector pattern
In-home care agencies concentrate clinical notes and SSNs on aging file servers that ransomware crews love. TheGentlemen’s July listing was an early signal; the August letters were the confirmation patients needed. Related BreachHistory rows include MedImpact and hospital/ransomware claims such as West County Health.
Technical depth and open questions
Public sources rarely ship full packet captures. Readers should separate three layers: (1) what the victim or regulator attested, (2) what reputable press quoted from those attestations, and (3) what actors claimed on leak sites. Mixing the layers is how unverified counts become “facts” in viral posts. For this incident, stick to layer one and two unless a sentence is explicitly marked as an actor claim.
Open questions usually include exact malware family, full population beyond the first filing, whether backups were hit, and whether downstream vendors were entry points. Absence of answers is normal in week one. It is not permission to invent them.
Phishing and social-engineering playbook to expect
Expect lookalike domains, fake “incident response” WhatsApp accounts, and urgency around deadlines that do not appear in official letters. Ask for a ticket number and hang up; call the number printed on a prior legitimate statement. Do not install remote-support tools. Do not pay cryptocurrency to strangers who claim they can delete your file from a dump.
Employees should treat internal IT tickets that arrive only by SMS as hostile. Vendors should verify purchase-order changes by phone using a known number, not the number in the email signature block.
How this compares to neighboring BreachHistory rows
Cross-read related finance, healthcare, and ransomware claim posts already on BreachHistory for pattern recognition — shared vendor risk, short access windows, and delayed consumer mailings show up again and again in 2026. Use those comparisons to brief executives, not to copy unverified counts from one row into another.
When regulators publish a revised census or the victim issues a post-mortem, the catalog row and this blog’s canonical link are the places to watch. Screenshots age badly; URLs that we update do not.
Checklist for security teams
- Inventory every “non-core” system that still stores customer or patient identifiers.
- Require phishing-resistant MFA on those systems.
- Log and alert on bulk exports.
- Pre-draft customer notice templates approved by counsel.
- Tabletop a 72-hour extortion email scenario with legal and PR in the room.
Those five steps are cheaper than learning them during an all-hands on a national holiday.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.