Brown Health Medical Group-MA disclosed a data breach affecting 311,760 individuals after unauthorized activity was discovered on a legacy file server at its Hawthorn location in December 2025. The organization said the intrusion was limited to that historic file server and did not affect its electronic medical record or electronic health record systems, but a June 22, 2026 review found that files on the server had been accessed.
The exposed information potentially included names, contact details, dates of birth, Social Security numbers, driver’s license and other government ID numbers, medical and disability records, financial account information, payment card data, and employment-related records. Brown Health Medical Group-MA reported the incident to the HHS Office for Civil Rights and state authorities in Massachusetts and Vermont, said no threat actor had been publicly identified or linked to a ransomware or extortion claim, and is offering affected individuals 24 months of credit monitoring, fraud detection, and identity theft protection services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A file review completed on June 22, 2026 determined that accessed files contained personal, medical, financial, and employment-related information. Brown Health said not all data types were affected for every individual.
On December 16, 2025, Brown Health Medical Group-MA discovered unauthorized activity on the legacy file server, isolated the system, and launched an investigation. The organization later said the breach was confined to that server.
Brown Health Medical Group-MA said an unauthorized third party accessed a legacy file server at its Hawthorn location between December 15 and December 16, 2025. The incident did not involve the organization's electronic medical record system.
Following the breach, Brown Health Medical Group-MA said it implemented enhanced technical safeguards and additional security measures. The organization also said it was retraining employees in response to the incident.
Brown Health Medical Group-MA began notifying more than 311,000 individuals about the breach and the categories of exposed information. The organization offered 24 months of complimentary credit monitoring, fraud detection, and identity protection or restoration services.
Brown Health Medical Group-MA reported the incident to the Vermont and Massachusetts Attorneys General and notified the US Department of Health and Human Services. Its HHS filing said 311,760 individuals were potentially affected, including 290,357 Massachusetts residents and 86 Vermont residents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcehipaajournal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.