311,760 patients affected by data breach at Brown University Health practice

Advertisement

Providence, R.I.-based Brown University Health is notifying 311,760 patients that their personal information may have been compromised in a data breach involving a legacy file server used by one of its physician practices, according to a July 16 notice submitted to HHS.

The breach, which HHS posted in August, occurred at Brown Health Medical Group, whose location in Dartmouth, Mass., housed the affected server. The health system first became aware of the incident on Dec. 16, 2025, and determined that unauthorized access occurred Dec. 15-16. The practice’s EHR was not affected.

The compromised data may include names, dates of birth and contact information; personnel and human resources records, such as compensation, licensure and medical or disability-related information; and Social Security numbers, driver’s license numbers, credit and debit card numbers, and financial account information, according to the notice. Not every category was affected for every individual.

Brown University Health has not identified who was behind the breach, and no ransomware or extortion group had claimed responsibility as of early August. The health system said it notified law enforcement, retrained employees and added technical safeguards to prevent similar incidents. Affected individuals are being offered two years of complimentary identity protection and fraud detection services.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement