2026 Digestive Disease Center / Heart Vascular & Leg Center — third-party vendor PHI exfil
Data compromised
Names with DOB, SSN, DL, financial/payment card, TIN, passport/government IDs; diagnoses, treatment, prescriptions, health insurance
Technical writeup
Verified practice notification summarized by HIPAA Journal — September 4, 2026 roundup. Silver Summit Medical Corporation d/b/a Digestive Disease Center and Heart Vascular & Leg Center (Bakersfield, CA) learned ~July 20, 2026 of a vendor cybersecurity incident. Investigation: unauthorized party accessed the vendor’s systems November 27–30, 2025 and exfiltrated files with PII/PHI including SSNs, government IDs, financial data, diagnoses, and insurance. Patients notified August 19, 2026; credit monitoring offered. OCR count not yet published. recordsAffected 0; companyConfirmed true.
Root cause
Unauthorized access to unnamed third-party vendor systems; file exfiltration