2026 Virta Health — data repository intrusion; 14,636 individuals (Mar)
Data compromised
Per Virta Health notice and ClaimDepot summary: names, SSNs, ITINs, dates of birth, contact information, medical diagnoses/conditions/treatments, medical record numbers, health insurance, clinical and physician/facility information, dates of service, and other health identifiers
Technical writeup
Verified healthcare data breach — disclosed June 2026. Virta Health Corp. and Virta Medical P.C., operators of a virtual diabetes-reversal care platform, disclosed that between March 19 and March 22, 2026 an unauthorized third party accessed files stored in a data repository separate from Virta's current production platform. On March 23, 2026 threat actor Lapsus$Group posted an internet claim alleging a Virta Health leak. Following investigation Virta determined personal and health information may have been exposed for approximately 14,636 individuals and mailed notification letters June 17, 2026, offering 12 months of Cyberscout credit monitoring. California Attorney General and HHS OCR filings were initiated in May 2026. BreachHistory uses Virta's attested 14,636 count.
Root cause
Unauthorized third-party access to files in a data repository separate from Virta Health's production platform between March 19–22, 2026; Lapsus$Group claimed leak March 23