2025 Whitfield Regional Hospital — unauthorized network access; patient PHI notices (Jul 2026)
Data compromised
Names, DOB, SSNs, driver’s license numbers, medical information, financial account information, health insurance — aggregate count unpublished
Technical writeup
Verified hospital disclosure — notices began mailing July 17, 2026. Whitfield Regional Hospital (Demopolis, Alabama; Tombigbee Healthcare Authority) detected a cybersecurity incident June 8, 2025; forensics confirmed unauthorized access between May 15 and June 8, 2025 to parts of the network storing patient information. Data review completed June 26, 2026. Confirmed data types included first and last names, dates of birth, Social Security numbers, driver’s license numbers, medical information, financial account information, and health insurance information. Complimentary credit monitoring and identity-theft protection were offered. Aggregate affected count not yet publicly disclosed. recordsAffected 0 pending OCR/state AG tally.
Root cause
Unauthorized access to network areas storing patient information May 15–June 8, 2025