Somnia, Inc. Data Breach
Somnia, Inc. Email System Compromised in Hacking Incident
What happened in the Somnia, Inc. data breach?
The Somnia, Inc. data breach was reported on February 14, 2025 and affected 19,069 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in New York. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Somnia, Inc. Breach Details
On February 14, 2025, Somnia, Inc., a healthcare entity operating in New York, reported a significant data breach affecting 19,069 individuals. The breach resulted from a hacking or IT incident that compromised the organization's email system, potentially exposing protected health information (PHI) and other sensitive patient data. This incident represents a substantial security failure in the organization's digital infrastructure and has triggered mandatory notification requirements under the Health Insurance Portability and Accountability Act (HIPAA).
Company Response
Upon discovery of the unauthorized access to their email systems, Somnia, Inc. initiated an investigation to determine the scope and nature of the breach. The organization worked to identify all affected individuals and began the process of notifying impacted patients and relevant regulatory authorities. The submission date of February 14, 2025, indicates that the organization met its obligation to report the breach to state authorities within the required timeframe. As part of their response, Somnia likely engaged cybersecurity professionals to investigate the breach vector, secure their systems, and implement remediation measures to prevent future incidents.
Specific Details
Email system compromises represent a particularly serious threat vector in healthcare organizations because email typically contains extensive patient communications, appointment information, billing details, and clinical notes. When a hacking incident targets email infrastructure, threat actors gain access to a centralized repository of sensitive information spanning multiple data categories. The compromise of Somnia's email system suggests that attackers may have exploited vulnerabilities in email security controls, such as weak authentication mechanisms, unpatched software vulnerabilities, or successful phishing campaigns targeting employee credentials. Email-based breaches often result in broad exposure because email systems typically lack the granular access controls found in dedicated clinical databases, meaning attackers may have accessed information across numerous patient records simultaneously.
Organizational Context
Somnia, Inc. operates as a healthcare entity in New York State. Based on the scale of the breach affecting nearly 20,000 individuals, the organization likely operates multiple facilities or serves a substantial patient population across the state. The involvement of a business associate in this breach indicates that Somnia may have contracted with third-party vendors for services such as billing, claims processing, IT support, or other healthcare operations. Under HIPAA regulations, covered entities remain responsible for breaches involving their business associates, and both parties share obligations for notification and remediation. The presence of a business associate in this incident suggests the breach may have involved shared systems or data access arrangements between Somnia and their contracted partner.
Number of People Affected
Approximately 19,069 individuals had their information potentially compromised in this breach. This substantial number indicates that the email compromise was not limited to a single department or facility but rather affected the organization's broader email infrastructure. The affected population likely includes current and former patients, as well as potentially individuals who had contact with Somnia through insurance inquiries, referrals, or other healthcare interactions. Each of these individuals faces potential risks related to identity theft, medical fraud, and privacy violations.
Personal Information Involved
Given that the breach involved email system access, the compromised data likely includes multiple categories of protected health information and personally identifiable information (PII). Typical email-based breaches expose: patient names and contact information (addresses, phone numbers, email addresses); medical record numbers and patient identification codes; dates of birth and ages; insurance information including policy numbers and group numbers; clinical information such as diagnoses, treatment plans, and medication lists; appointment scheduling details and provider communications; billing and payment information; Social Security numbers (if included in patient records or correspondence); and potentially financial account information if billing-related emails were accessed. The specific data elements exposed depend on the content of emails within the compromised system and the retention policies Somnia maintained.
Likely Risks to Patients
Individuals affected by this breach face several significant risks. Identity theft represents a primary concern, as attackers with access to names, dates of birth, Social Security numbers, and addresses possess the key information needed to open fraudulent accounts or apply for credit in victims' names. Medical identity theft is a particular risk in healthcare breaches, where criminals use stolen patient information to obtain medical services, prescription medications, or medical equipment fraudulently, potentially creating false medical records that could interfere with legitimate healthcare. Financial fraud may occur if billing information, insurance details, or financial account numbers were exposed in email communications. Privacy violations and emotional distress result from the unauthorized access to sensitive health information. Phishing and social engineering attacks may increase, as threat actors often use healthcare breach data to craft convincing fraudulent communications targeting victims. Insurance fraud could occur if insurance information was compromised. The 19,069 affected individuals should assume their information may have been accessed and take appropriate protective measures.
Recommended Actions for Patients
Individuals affected by the Somnia, Inc. breach should take the following protective steps: (1) Monitor credit reports and place fraud alerts by obtaining free credit reports from all three major bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and reviewing them for unauthorized accounts or inquiries; consider placing a fraud alert with the bureaus and monitoring credit regularly for the next 2-3 years; (2) Monitor medical records and explanation of benefits (EOB) statements by requesting copies of medical records from Somnia and reviewing them for unauthorized services, and carefully reviewing all EOB statements from insurance providers for claims they did not authorize; (3) Implement identity theft protection measures by considering enrollment in credit monitoring or identity theft protection services (often offered free by the breached entity), using strong and unique passwords for healthcare portals and financial accounts, and enabling multi-factor authentication where available; (4) File a report with the Federal Trade Commission at IdentityTheft.gov if identity theft occurs, and consider filing a police report for documentation purposes; (5) Contact Somnia, Inc. directly to understand what specific information was exposed in their case and what remediation services the organization is offering; (6) Be vigilant against phishing by not clicking links or downloading attachments in unsolicited emails claiming to be from healthcare providers or financial institutions, and verifying any communications by calling organizations directly using numbers from official websites.
What to Do If Your Data Was Part of This Breach
- Request notification details — your provider must notify you within 60 days with specifics about what data was compromised.
- Review your medical records — request copies and check for unfamiliar diagnoses, prescriptions, or procedures.
- Monitor your credit — place a fraud alert with all three credit bureaus and watch for suspicious activity.
- File a complaint with OCR — if you believe HIPAA was violated, you can file a complaint within 180 days.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New York Breaches
Search all breaches reported in New York
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsSomnia, Inc. Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Somnia, Inc.