Premier Medical Group data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
Premier Medical Group of the Hudson Valley, a multi-specialty practice based in Poughkeepsie, New York, said an incident disrupted some of its IT systems, after which it secured its network, hired outside forensic experts, and notified law enforcement. The investigation found that an unauthorized party accessed some files on June 14, 2026.
On July 14, 2026, the practice determined that those files may have held patient personal and clinical information. It began mailing letters to affected patients on August 21, 2026, and reported the breach to the U.S. Department of Health and Human Services the same day as affecting 282,075 people. The federal listing classifies it as a hacking or IT incident involving a network server, with no business associate involved. SecurityWeek reported the breach when it appeared on the HHS portal in mid-September and said it had seen no ransomware or extortion group claim responsibility.
Premier Medical Group has not named an attacker or described how the intruder got in. Its notice offers a dedicated call line and advises patients to review statements from providers and insurers; it does not offer credit monitoring or identity protection.
Sources
What data was exposed
The following types of personal data may have been involved. The practice said the specific fields vary by individual.
- Patient names
- Contact information
- Dates of birth
- Health insurance information
- Provider names
- Internal patient identification numbers
- Dates of service
- Medication information
- Treatment or diagnostic information
Premier Medical Group's notice does not list Social Security numbers or payment card numbers, and no state or federal filing we could retrieve contradicts that. Law firm pages advertising investigations into this breach do claim Social Security numbers and other documents were exposed, without citing a source. Go by the letter you receive.
Breach details
| Detail | Value |
|---|---|
| Breach name | Premier Medical Group of the Hudson Valley |
| Date | June 14, 2026 |
| Disclosed | August 21, 2026 (patient letters and HHS report) |
| Accounts affected | 282,075 (reported to HHS) |
| Domain | premiermedicalhv.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Premier Medical Group; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- Review statements from your providers and your health plan, and report care you did not receive. This is the practice's own first recommendation.
- Watch your Explanation of Benefits statements for unfamiliar visits, prescriptions, or procedures, and watch for collection notices about care you never had.
- Treat calls, texts, or emails that cite your name, a Hudson Valley clinic, or your insurance details as possible phishing. Use a number from your mailed letter or the practice's own website.
- Keep the letter you were sent. It records what was involved for you, which matters if you need to dispute a charge later.
- If a notice you receive names your Social Security number or financial account details, place a free credit freeze with all three bureaus. Don't assume fields that aren't in your letter.
- For questions, call the practice's incident line at 888-650-4197 (Monday to Friday, 9am to 9pm Eastern, except major holidays).
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
- What to do after a data breach
- Aesto Health breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.