DataBreachLegalCenter.com
MonitoringOregon AG filing · September 3, 2026

Boston Health Care for the Homeless Program Reports 2025 Data Breach

Boston Health Care for the Homeless Program reported a data breach in September 2026, stemming from an incident in late 2025. The compromise exposed sensitive patient data, including medical and personal identifiers, for individuals in Oregon. This puts those affected at heightened risk for medical identity theft and other forms of fraud.

State
Oregon
Breach date
October 31, 2025
Reported
September 3, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

Boston Health Care for the Homeless Program filed notice in September 2026 regarding a data security incident that occurred on or about October 31, 2025. The organization, which provides medical and supportive services to vulnerable populations, reported this breach to the Oregon Attorney General. This disclosure alerts affected individuals that their private information may have been accessed without authorization.

According to the official filing, the exposed data categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The extensive nature of this exposed data puts individuals at significant risk for various forms of misuse.

The compromise of such sensitive personal and health information can lead to medical identity theft, fraudulent insurance claims, or targeted financial scams. Unlike credit card numbers, these immutable details cannot be easily changed, potentially exposing victims to long-term threats that require constant vigilance.

If you received a data breach notification letter from Boston Health Care for the Homeless Program, carefully review the document for any specific instructions they may provide. It is generally recommended to enroll in any credit monitoring services offered and to regularly review your credit reports, health insurance statements, and explanations of benefits for any unusual or unauthorized activity.

Receiving this notification confirms your confidential information was compromised. Organizations that handle protected health information are legally required to maintain robust security protocols to protect patient data. A breach of this scale often raises questions about whether those safeguards were adequately in place. Understanding your legal options can help protect your rights in the wake of such an incident. If you are concerned about your exposure or potential harm, a free case review can help clarify your situation and discuss any next steps you might consider.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Oregon Attorney General filing

Related data breach cases