Brown Health Medical Group-MA says hackers stole sensitive data linked to 311,760 people. Here’s what was taken, why it matters, and how you can reduce your identity theft risk now.
Table of Contents
What Happened?
The incident happened in December 2025 at the group’s Hawthorn location in Massachusetts. Brown Health said its electronic health record system was not affected.
However, investigators confirmed on June 22, 2026, that files containing personal information had been accessed and taken.
Brown Health isolated the server after finding the incident. It also added security safeguards and began retraining employees.
The organization is offering affected people two years of free fraud detection, identity protection, and recovery services.
Stolen Social Security numbers, medical records, and banking details can remain useful to criminals for years. They may support identity theft, fraudulent charges, or convincing messages from trusted organizations.
Many people learn about leaked information only after unusual activity appears. Your data may also have been leaked in another incident you never heard about.
If you are unsure whether your information was leaked elsewhere, automatic monitoring can help you notice problems sooner. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Leaked?
Brown Health told the US Department of Health and Human Services that 311,760 people were affected. This includes 290,357 Massachusetts residents.
The files may have contained:
- Names and contact information
- Dates of birth
- Social Security numbers
- Driver’s license numbers
- Other government ID numbers
- Medical and disability-related records
- Financial account information
- Credit and debit card numbers
- Payroll and compensation information
- Licensing and credentialing records
Brown Health said the exact information varied by person. Therefore, every affected individual did not have every listed detail stolen.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyBrown Health Has Not Explained How Hackers Entered the Server
Brown Health has not publicly shared detailed technical information about how criminals entered the historic file server.
The organization also has not identified the attackers. No known ransomware or extortion group had publicly claimed responsibility when SecurityWeek published its report.
Therefore, it remains unclear whether stolen passwords, a software weakness, or another security gap led to the breach.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
