1 min read

Network breach at Gándara Center exposes 17,000

Network of connected people icons with glowing orange nodes and lines

On October 24, 2024, Gándara Center reported a data security breach that exposed the protected health information (PHI) of current and former patients. 

 

What happened

Gándara Center, a Massachusetts-based behavioral health and substance abuse service provider recently announced a data breach that compromised 17,000 patients’ health data. 

Unusual network activity was first detected on June 20, 2024, and further investigation revealed that an unauthorized third party gained access to patients' names, Social Security numbers, dates of birth, driver's license numbers, medical treatment or diagnosis information, and health insurance information. 

The organization began mailing letters to the affected persons on October 23, 2024 and has offered credit monitoring services and identity protection through Identity Defense to the potentially impacted individuals. The organization also notified relevant regulatory authorities including the FBI and the HHS Office for Civil Rights.

 

What was said

In their security notice, Gándara Center said,The privacy and protection of personal and protected health information is our top priority, and Gándara deeply regrets any inconvenience or concern this incident may cause.”

 

In the know

Protected health information (PHI) is a major target in healthcare cyberattacks, with threat actors exploiting cybersecurity vulnerabilities for financial gain. PHI includes any information on a patient's health status, medical treatment, or payment for healthcare that can identify the individual, such as names, addresses, birthdates, Social Security numbers, medical records, and other personal identifiers tied to healthcare services.

 

Why it matters

Although HIPAA regulations mandate healthcare providers to secure PHI, data breaches often reveal gaps in compliance and readiness. The Gándara Center breach emphasizes that health organizations must improve cybersecurity protocols to protect patient trust and the business’s reputation. 

 

The bottom line

Individuals who received a notification letter from the Gándara Center must use the information provided to protect themselves from potential identity theft and fraud.

 

FAQs

What is a data breach?

A breach occurs when an unauthorized party gains access, uses or discloses protected health information (PHI) without permission. Breaches include hacking, losing a device containing PHI, or sharing information with unauthorized individuals.

See also: How to respond to a data breach

 

What should individuals do if their data has been compromised?

If individuals suspect their data has been compromised, they must monitor their accounts for suspicious activity and report any unauthorized transactions immediately.

 

Are there any costs associated with placing a fraud alert or credit freeze?

No, under U.S. law, consumers are entitled to a free credit report annually from each of the three major credit reporting bureaus, Equifax, Experian, and TransUnion. So, placing a fraud alert or credit freeze does not incur any costs.

Binary code with the word 'BUG' highlighted among digits

Microsoft pays record $17 million in bug bounties

Microsoft paid a record $17 million to 344 security researchers across 59 countries through its bug bounty program between July 2024 and June 2025,...

Read More
Image of a head with flowers coming out of it.

Cincinnati nonprofit Beech Acres exposes medical records of 19,315 individuals

Beech Acres Parenting Center, a 175-year-old Cincinnati nonprofit providing mental health services and foster care support, has disclosed a data...

Read More
Abstract digital numbers and bar chart representing data analysis

People Encouraging People reports data breach affecting over 13K

People Encouraging People (PEP), a Maryland-based nonprofit organization specializing in behavioral healthcare, has reported a data breach that...

Read More