Centric Health Data Breach
Centric Health Data Breach Affects 6,855 California Patients
What happened in the Centric Health data breach?
The Centric Health data breach was reported on December 10, 2025 and affected 6,855 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record, Network Server. This breach occurred in California. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Centric Health Breach Details
Centric Health Hacking Incident Exposes Patient Medical Records
Centric Health, a California-based healthcare provider, experienced a significant data breach involving unauthorized access to its electronic medical record (EMR) systems and network servers. The breach was reported to the California Attorney General on December 10, 2025, affecting approximately 6,855 individuals. The incident represents a hacking or IT-related compromise of protected health information (PHI) stored on the organization's digital infrastructure. This type of breach typically involves exploitation of network vulnerabilities, credential compromise, or other cyber attack vectors that allowed unauthorized actors to gain access to sensitive patient data housed within the EMR platform and associated network storage systems.
Company Response
Upon discovery of the unauthorized access, Centric Health initiated an investigation to determine the scope and nature of the breach. The organization worked to identify which patient records were accessed, what information may have been compromised, and the timeline of the unauthorized access. As required under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, Centric Health began the process of notifying affected individuals without unreasonable delay. The submission date of December 10, 2025, indicates that the organization met its obligation to report the breach to state authorities within the required timeframe. The investigation likely involved forensic analysis of network logs, access controls, and system activity to determine the breach vector and extent of data exposure.
Specific Details
The breach involved Centric Health's electronic medical record system and network servers—critical infrastructure components that typically store comprehensive patient health information. Network server compromises of this nature often result from exploitation of unpatched vulnerabilities, weak authentication mechanisms, or successful phishing campaigns that provide attackers with initial system access. Once inside the network, threat actors may have been able to move laterally through the organization's IT environment to reach the EMR system where patient records are centralized. The fact that both the EMR and network servers were compromised suggests either a sophisticated attack that penetrated multiple systems or a single point of entry that provided broad access to the organization's digital infrastructure. Hacking incidents affecting healthcare organizations have become increasingly common, with attackers targeting the high-value nature of medical records and the critical nature of healthcare operations, which sometimes leads to payment of ransoms or negotiated settlements.
Organizational Context
Centric Health operates as a healthcare provider organization in California, serving patients across the state. The organization maintains electronic medical records and network infrastructure to support clinical operations and patient care delivery. The involvement of a business associate in this breach indicates that Centric Health may have contracted with third-party vendors for services such as billing, claims processing, IT support, or other healthcare-related functions. Business associates are required under HIPAA to maintain the same level of security and privacy protections as covered entities, and they share responsibility for breach notification and remediation. The scale of the organization—affecting nearly 7,000 patients—suggests Centric Health operates multiple facilities or serves a substantial patient population across California's healthcare market.
Patient Impact and Notifications
Approximately 6,855 individuals had their protected health information potentially accessed during this breach. These patients likely received notification letters from Centric Health describing the incident, the types of information that may have been compromised, and recommended steps to protect themselves. Under HIPAA requirements, notification must include a description of the breach, the types of information involved, steps individuals should take to protect themselves, what the organization is doing to investigate and prevent future breaches, and contact information for questions. The notification process for a breach of this size typically occurs in phases, with initial notifications sent to affected individuals, followed by notifications to media outlets and the California Attorney General. Patients should have received information about any complimentary credit monitoring or identity theft protection services that Centric Health may be offering as part of its breach response.
Industry Context and HIPAA Implications
Hacking and IT incidents represent one of the most common categories of healthcare data breaches, accounting for a significant percentage of reported incidents to the U.S. Department of Health and Human Services Office for Civil Rights (OCR). The healthcare industry remains a prime target for cybercriminals due to the high value of medical records on the dark web, the critical nature of healthcare operations (which may increase likelihood of ransom payment), and sometimes inadequate cybersecurity investments relative to other industries. HIPAA's Breach Notification Rule requires covered entities and business associates to notify affected individuals, the media, and the Secretary of Health and Human Services when a breach of unsecured PHI occurs. The rule defines a breach as unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Healthcare organizations are expected to implement administrative, physical, and technical safeguards to protect patient data, including access controls, encryption, audit logging, and regular security assessments. Breaches involving network servers and EMR systems often result in significant regulatory scrutiny and potential enforcement actions if investigations reveal inadequate security measures.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Centric Health Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review Centric Health's notification letter for information about complimentary credit monitoring or identity theft protection services and enroll in these services if offered
Monitor medical records and explanation of benefits (EOB) statements from insurance providers for unauthorized medical services or claims; contact providers immediately if suspicious activity is detected
Change passwords for any online healthcare portals or accounts associated with Centric Health and use strong, unique passwords; enable multi-factor authentication where available
Be vigilant against phishing emails, phone calls, or text messages claiming to be from Centric Health, healthcare providers, or financial institutions; verify communications directly with organizations using official contact information
Consider placing a security freeze with credit bureaus to prevent unauthorized access to credit reports
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if identity theft occurs, and maintain documentation of all fraudulent activity for potential insurance claims or legal action
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More California Breaches
Search all breaches reported in California