Skip to main content
Back to overview
High

ConnectOnCall (Phreesia Subsidiary) Data Breach Exposes Nearly 1 Million Americans' Health Records

ConnectOnCall, a doctor-patient communications platform owned by health tech firm Phreesia, experienced a security breach that exposed sensitive personal and health records of nearly a million Americans (914,138 users).

Key points

  • 914,138 users affected.
  • Exposed data includes names, phone numbers, dates of birth, health conditions, treatments, medications, and Social Security numbers.
  • Incident occurred between February 16, 2024, and May 12, 2024.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Potential data exposure

Confidentiality

Published
Dec 21, 2024
Updated
Jul 1, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

PhreesiaData DisclosureConnectOnCallPhreesia SubsidiaryMillion AmericansPhreesiaAmericansExposed

Quick context

Questions about this signal

What happened in this signal?

ConnectOnCall, a doctor-patient communications platform owned by health tech firm Phreesia, experienced a security breach that exposed sensitive personal and health records of nearly a million Americans (914,138 users). The incident, which occurred between February 16, 2024, and May 12, 2024, exposed full names, phone numbers, dates of birth, health conditions, treatments, medications, and Social Security numbers. The firm sent letters to affected users earlier in December 2024, and the breach was reported on December 21, 2024.

When was this signal reported?

Shadow Tier lists Dec 21, 2024 as the signal date.

Which organization is connected to this signal?

Phreesia is the organization connected to this public signal.

Explore Phreesia