2026 Healthcare Interactive (HCIactive) — ~3.06M individuals (benefits/insurance platform intrusion)
Data compromised
PHI and PII: SSNs, insurance and claims data, diagnoses, treatment, prescriptions, labs, medical images, demographics
Technical writeup
Healthcare Interactive, Inc. (HCIactive / HCI Active), a Maryland-based vendor of AI-oriented insurance enrollment and benefits administration software, disclosed a major breach after suspicious activity on its network. Public timelines cited unauthorized access and file copying around July 8–12, 2025 (broader windows cited in some state filings). Regulatory submissions listed approximately 3,056,950 affected individuals nationwide. Data classes described in reporting included names, addresses, phones, emails, dates of birth, Social Security numbers, health plan and member identifiers, claims-related and billing information, and extensive medical content (diagnoses, treatment, prescriptions, labs, images, providers). HHS OCR reporting and multi-state attorney general notices rolled through late 2025 into 2026; consumer-facing coverage intensified in March 2026.
Root cause
Unauthorized network access; data exfiltration from internal systems