2026 RXNT — unauthorized access to EHR platform impacting healthcare clients (March incident; May disclosures)
Data compromised
Patient names, DOB, demographics, contact info, patient IDs; Congress e-prescribing workflow also exposed prescription and pharmacy details per May 2026 disclosures
Technical writeup
RXNT (Networking Technology, Inc.), a U.S. healthcare software vendor providing electronic health record and practice management solutions, confirmed unauthorized access to a hosted solution March 1–3, 2026. HIPAA Journal reported RXNT notified client organizations May 1, 2026 that patient names, dates of birth, demographic/contact data, and patient identifiers were stolen, with per-client counts varying. Follow-up reporting May 15, 2026 disclosed that RXNT software used by the U.S. Office of the Attending Physician for Congress members’ e-prescribing was affected—exposing prescription fulfillment data including names, addresses, DOB, physician names, and pharmacy details (Congress members’ full medical records and SSNs were not in that workflow). RXNT offered to handle HIPAA breach reporting for affected clients via rxntnotification.com; an aggregate nationwide patient tally remained undisclosed at catalog time.
Root cause
Unauthorized access to a hosted healthcare software environment; detailed intrusion vector not stated in indexed consumer-facing summaries