← Greenbaum Rowe Smith & Davis LLP

2025 Greenbaum Rowe Smith & Davis — compromised account; ~12.9K hospital patients' PHI

2025 12.9K records affected Share on X

Data compromised

Names, addresses, medical record numbers, diagnoses, clinical histories, treatment details, providers, dates of service, medical costs, health insurance information; subset Social Security numbers and dates of birth

Technical writeup

Verified law-firm disclosure — Greenbaum Rowe Smith & Davis LLP, a Woodbridge, New Jersey firm serving healthcare clients including Atlantic Health System, detected unauthorized access through a compromised user account on November 27, 2025. Forensics placed access between November 25 and November 27, 2025. The firm contained the incident, reset credentials, replaced affected machines, notified law enforcement, and engaged IDX for identity monitoring via response.idx.us/grsd-a7f3k9q2m8l4/. A multi-month file review found protected health information was acquired, including names, addresses, medical record and account numbers, diagnoses, clinical and treatment data, provider details, dates of service, costs, and insurance information, with Social Security numbers and dates of birth for a subset. NJ.com (July 2026) reported nearly 13,000 patients affected across hospital clients. Greenbaum stated it saw no evidence of misuse or public posting at notification time. BreachHistory uses the ~12,900 patient figure from contemporaneous reporting pending a formal regulator tally.

Root cause

Unauthorized access via compromised user account November 25–27, 2025; law firm provides legal services to New Jersey healthcare providers including Atlantic Health System

References