- State
- VA
- Covered entity type
- Business Associate
- Individuals affected
- 91,331
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Guidehouse, reported that its secure file transfer device experienced a cyber-attack that affected the protected health information (PHI) of approximately 91,331 individuals. The PHI involved included, names, dates of birth, diagnoses/conditions, and claims information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE applied a critical patch shortly after the cyber-attack which mitigated the vulnerability. Additionally, the CE discontinued use of the file transfer device and transitioned to another network.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.