2026 PIH Health — ransomware; SSNs, PHI, financial data (multi-million record claim)
Data compromised
SSNs, PHI, financial data, insurance info, medical records (scope per official notices)
Technical writeup
PIH Health (Southern California) disclosed a major 2024 cyber incident with public notifications in February–March 2026. Unauthorized activity was detected around December 1, 2024; threat actors claimed very large exfiltration (widely cited figures in the tens of millions of records in media). Confirmed compromised data types included names, addresses, SSNs, driver licenses, DOB, financial account and payment card data, medical records, and health insurance information. Official victim counts may vary by state filing; some reports cite Texas and Rhode Island subsets. Company offered identity protection (e.g., Experian IdentityWorks) and call center support.
Root cause
Ransomware / network intrusion; data exfiltration