Community Health Clinics, Inc. dba Terry Reilly Health Services Data Breach
Community Health Clinics EMR Breach Affects 5,421 Patients
What happened in the Community Health Clinics, Inc. dba Terry Reilly Health Services data breach?
The Community Health Clinics, Inc. dba Terry Reilly Health Services data breach was reported on January 15, 2026 and affected 5,421 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in Idaho. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Community Health Clinics, Inc. dba Terry Reilly Health Services Breach Details
Community Health Clinics Data Breach Report
Incident Overview
Community Health Clinics, Inc., operating under the name Terry Reilly Health Services in Idaho, experienced a significant data breach involving unauthorized access to its Electronic Medical Record (EMR) system. The breach was reported to the Idaho Attorney General on January 15, 2026, affecting 5,421 individuals. This incident represents a hacking or IT-related compromise of protected health information (PHI) stored within the organization's primary clinical data system. The breach occurred through unauthorized access to electronic systems rather than physical theft or loss of documents, indicating a cybersecurity vulnerability in the organization's network infrastructure or application security controls.
Discovery and Response Timeline
The specific discovery date and investigation timeline have not been publicly detailed in available breach notification records. However, standard HIPAA breach notification procedures require that affected individuals be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach. Given the January 15, 2026 submission date to state authorities, the organization likely discovered the unauthorized access in late 2025 or early January 2026. Upon discovery, Community Health Clinics initiated an investigation to determine the scope of the breach, identify which patient records were accessed, and assess what information may have been compromised. The involvement of a business associate in this breach suggests that the organization worked with third-party vendors or service providers who may have had access to the EMR system, complicating the investigation and notification process.
Technical Details and Breach Mechanism
Electronic Medical Record systems are primary targets for healthcare cybercriminals because they contain comprehensive patient health histories, demographic information, and clinical data in a centralized, searchable format. Hacking incidents targeting EMR systems typically involve one or more of the following vectors: exploitation of unpatched software vulnerabilities, weak authentication credentials, phishing attacks targeting staff members with system access, compromised remote access points, or insider threats. The fact that a business associate was involved suggests the breach may have originated through a third-party connection, supply chain vulnerability, or shared access credentials. EMR breaches of this nature often go undetected for extended periods because attackers may maintain persistent access while exfiltrating data gradually, making the exact timeframe of unauthorized access difficult to determine. The hacking classification indicates this was not a case of lost or stolen physical media, but rather a deliberate cyber intrusion into networked systems.
Organizational Context
Terry Reilly Health Services operates as a community health center network in Idaho, providing primary care and preventive health services to underserved populations. Community Health Clinics, Inc. operates multiple clinical locations across Idaho, serving as a safety-net provider for uninsured and underinsured patients. The organization's reliance on electronic medical records for clinical operations means that patient data is stored in digital format across networked systems. The involvement of a business associate indicates the organization uses third-party vendors for services such as cloud hosting, data backup, billing services, or IT support—common arrangements in healthcare organizations of this size. The breach's impact on a regional healthcare provider affects not only individual patients but also the organization's operational capacity and the broader healthcare infrastructure in Idaho.
Patient Impact and Affected Population
Approximately 5,421 individuals had their protected health information potentially accessed during this breach. These patients likely include current and former patients of Community Health Clinics who had electronic medical records maintained in the compromised EMR system. The affected population may span multiple years of patient encounters, as EMR systems typically retain historical records indefinitely. Notification of affected individuals was required under HIPAA's Breach Notification Rule, with Community Health Clinics responsible for providing written notice to each affected patient describing the nature of the breach, the types of information involved, steps the organization is taking to investigate and mitigate the breach, and recommended actions patients should take to protect themselves. The organization was also required to notify major media outlets and the Idaho Attorney General, as the breach affected more than 500 Idaho residents.
Data Exposure and Information Types
Electronic Medical Record systems typically contain comprehensive patient health information, which may have been exposed in this breach. Likely exposed data types include: patient names and contact information (addresses, phone numbers, email addresses); dates of birth and ages; Social Security numbers or other government-issued identification numbers; insurance information and policy numbers; medical record numbers and patient account numbers; diagnoses and medical conditions; medication lists and prescription information; laboratory results and imaging reports; surgical histories and procedures; mental health and behavioral health information; substance abuse treatment records; and billing and payment information. The specific combination of data exposed depends on what information was stored in the compromised portion of the EMR system and what access level the attacker obtained. Some breaches may expose only demographic and insurance information, while others may compromise sensitive clinical details including psychiatric records, HIV status, or addiction treatment information.
HIPAA Compliance and Industry Context
This breach represents a violation of HIPAA's Security Rule, which requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic PHI. The involvement of a business associate raises questions about Business Associate Agreements (BAAs) and the adequacy of vendor management practices. Healthcare data breaches involving hacking or IT incidents have increased significantly in recent years, with the U.S. Department of Health and Human Services Office for Civil Rights reporting hundreds of breaches annually affecting millions of individuals. Hacking incidents now represent the leading cause of healthcare data breaches by volume, surpassing theft and loss. The healthcare industry faces particular vulnerability to cyber attacks because patient data is highly valuable on the dark web, clinical systems often prioritize availability over security, and many healthcare organizations operate with limited IT security budgets. This breach at Community Health Clinics is consistent with broader trends affecting healthcare providers of all sizes across the United States.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Community Health Clinics, Inc. dba Terry Reilly Health Services Breach
Monitor credit reports and consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized account opening. Obtain free annual credit reports at annualcreditreport.com and review them for suspicious accounts or inquiries.
Monitor healthcare accounts and insurance statements for unauthorized charges, claims, or services you did not receive. Contact your insurance provider immediately if you identify suspicious activity and request an explanation of benefits (EOB) for any unfamiliar claims.
Be vigilant against phishing and social engineering attempts. Do not click links or download attachments from unsolicited emails claiming to be from Community Health Clinics or healthcare providers. Verify communications by calling the organization directly using a phone number from official sources.
Consider enrolling in credit monitoring or identity theft protection services, particularly if Social Security numbers were exposed. Many organizations offer free monitoring for a period following a breach. Watch for signs of identity theft including unexpected bills, collection notices, or credit inquiries you did not authorize.
Review your medical records for accuracy and unauthorized entries. Contact Community Health Clinics to request copies of your medical records and verify that all information is accurate and that no unauthorized services or prescriptions appear in your history.
Change passwords for any online patient portals or healthcare-related accounts associated with Community Health Clinics or your insurance provider. Use strong, unique passwords that are not reused across multiple accounts.
Document the breach and your response actions for your records. Keep copies of breach notification letters and any correspondence with the healthcare provider or credit bureaus, as this documentation may be needed if fraud occurs.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Idaho Breaches
Search all breaches reported in Idaho