← Blog

Campbell University Breach: Cloud PHI Exposure

Share on X

April 1, 2026: Campbell University in North Carolina discovered unauthorized access to a cloud-based data storage platform used by the school. Attackers were inside from March 31 through April 1, according to the university's data notice. The investigation is still running—and so is the count of who was actually in those files.

What Campbell confirmed

Campbell said the incident was isolated to one platform. Other campus systems were not impacted per the school. After discovery the university took the environment offline, reset passwords, rebuilt the platform from backups, brought in forensics, and notified federal law enforcement.

At publication time Campbell had not finished identifying every affected person. It filed with the U.S. Department of Health and Human Services indicating protected health information for at least 500 individuals was involved—the regulatory floor, not the final number. HIPAA Journal summarized the filing in late June 2026 alongside other healthcare-sector disclosures.

What data categories are on the table

Campbell's notice lists an unusually wide menu of possible fields—because investigators found many types of records on the compromised platform, not because every person had every field. Categories disclosed include:

  • Names, addresses, dates of birth, admission/discharge/death dates
  • Medical record numbers, diagnoses, treatments, lab results, prescriptions, mental-health information
  • Social Security numbers, driver's licence or state ID, passport numbers, student IDs
  • Financial account, debit/credit card, and insurance payment history
  • Digital signatures, geolocation, and usernames for non-financial accounts

If you are a student, patient, or employee connected to Campbell health programs, your letter will narrow this list to what was actually present for you.

The Incransom claim — separate from the notice

On April 11, 2026 the Incransom ransomware group claimed Campbell on its leak site and threatened to publish 500 GB of data, per DeXpose. That is an unverified actor marketing post. Campbell's official statement describes confirmed unauthorized access, not a public ransom payment or leak download. BreachHistory tracks both: verified university facts first, actor claims labeled clearly.

What you should do

  1. Read campbell.edu/data-notice and call 910-893-1645 (weekdays 8:30–5 ET) if you have questions.
  2. Monitor credit and Explanation of Benefits if health or financial data may apply to you.
  3. Treat "Campbell legal" or "tuition refund" phishing as suspicious until verified on official channels.

Canonical record

Campbell University 2026 on BreachHistory.

Sources: Campbell University data notice, HIPAA Journal.