2026 Integrative Emergency Services — employee email compromise Jun 16; 2,009 patients
Data compromised
Patient names, medical record identifiers, and certain health information (no SSNs, financial data, or addresses per notice summary)
Technical writeup
Verified practice notification summarized by HIPAA Journal — September 4, 2026. Integrative Emergency Services (Dallas) secured an employee email account after suspicious activity June 16, 2026 (~4 hours of unauthorized access). On July 9, 2026 an email with patient names, MR identifiers, and certain health information was identified as potentially viewed. No SSNs/financials/addresses. 2,009 patients notified; phishing training increased. recordsAffected 2009; companyConfirmed true.
Root cause
Unauthorized access to an employee email account for about four hours on June 16, 2026; July 9 review found a patient-data email that may have been viewed