2026 Cherry Health — unauthorized network access; patient & staff data copied (preliminary notice)
Data compromised
Names, addresses, phone numbers, dates of birth, health insurance information, health insurance ID numbers, patient ID numbers, provider names, service dates, and limited Social Security numbers—current/former patients and staff may be affected; victim total not yet disclosed; not yet on HHS breach portal at catalog time
Technical writeup
Grand Rapids, Michigan federally qualified health center Cherry Health detected suspicious network activity April 19, 2026. Investigation found an unknown actor accessed its network and copied data. On June 18, 2026 Cherry Health published a preliminary website notice stating notification letters are not yet ready and the incident has not appeared on the HHS public breach tool at catalog time. Data categories may include names, addresses, phone numbers, DOB, health insurance details and ID numbers, patient ID numbers, provider names, service dates, and limited SSNs for current/former patients and staff. April 2026 DataBreaches reporting had suggested ransomware, but the June preliminary notice does not confirm encryption or ransom demands and no threat group has claimed responsibility. Cherry Health's prior December 2023 incident (181,820 patients notified to HHS in February 2024) involved overlapping PHI categories. BreachHistory indexes recordsAffected 0 pending an attested count.
Root cause
Unknown actor gained unauthorized network access and copied data; detected April 19, 2026; ransomware suspected in prior reporting but not confirmed in June preliminary notice