June 18, 2026: Michigan federally qualified health center Cherry Health published a preliminary data breach notice—confirming that an unknown actor accessed its network in April 2026 and copied patient and staff data. It is the organization's second major breach in three years, and victim totals remain undisclosed.
Timeline
- April 19, 2026: Cherry Health detects suspicious network activity.
- Investigation: Unauthorized access and data copying confirmed; notification letters not yet ready.
- June 18, 2026: Preliminary website notice published.
- June 22, 2026: DataBreaches.net reports the incident is not yet on the HHS breach portal.
What data was involved?
Cherry Health states affected information may include:
- Names, addresses, phone numbers, dates of birth
- Health insurance information and insurance ID numbers
- Patient ID numbers, provider names, service dates
- Social Security numbers (limited cases)
Both current and former patients and current and former staff may be impacted.
Ransomware?
April 2026 reporting had suggested a ransomware attack, but Cherry Health's June preliminary notice does not confirm encryption, ransom demands, or payment. No threat group has claimed responsibility at catalog time.
2023 déjà vu
In December 2023 Cherry Health suffered a cybersecurity incident. In February 2024 it notified HHS that 181,820 patients were affected by hacking, with overlapping PHI categories including diagnosis/treatment and prescription data from the prior event. Patients and regulators will reasonably ask what preventive controls changed between incidents.
What to do if you're a Cherry Health patient or employee
- Watch for official notification letters—the preliminary notice is not the final individual notice.
- Enable MFA on patient portals and email; beware phishing citing real provider or service dates.
- Consider a credit freeze if you receive notice that your SSN was involved.
- Monitor Explanation of Benefits for fraudulent medical claims.
Bottom line
Cherry Health joins a widening 2026 pattern of healthcare re-victimization—organizations breached twice with similar PHI categories while public transparency (counts, ransomware status, HHS filing) lags behind community reporting.
Canonical record: Cherry Health 2026 breach on BreachHistory.