Skip to main content
Back to overview
Medium

Kentucky Mountain Health Alliance Discloses Data Breach Affecting SSNs and Medical Records

Kentucky Mountain Health Breach Compromises SSNs and Medical Records Kentucky Mountain Health Alliance Inc.

Key points

  • Disclosure to Massachusetts Office of Consumer Affairs and Business Regulation on June 19, 2026.
  • Unauthorized access to patient data, with some data copied.
  • Exposed data includes driver's licenses, medical records, and Social Security numbers.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 19, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

KmhaData DisclosureKentucky Mountain Health Alliance DisclosesIncHazardKentuckyMassachusetts Office of Consumer AffairsBusiness Regulation andNew Hampshire Attorney GeneralKentucky Mountain Health Alliance

Quick context

Questions about this signal

What happened in this signal?

Kentucky Mountain Health Breach Compromises SSNs and Medical Records Kentucky Mountain Health Alliance Inc. , a private nonprofit health center in Hazard, Kentucky, disclosed a data breach involving sensitive personal and medical information. A total number of 30,830 individuals were affected nationwide . The company disclosed the incident to the Massachusetts Office of Consumer Affairs and Business Regulation and to the New Hampshire Attorney General on June 19, 2026. Kentucky Mountain Health Alliance mailed notification letters to affected individuals. At this time. the details about the specific method of attack, the dates during which the incident took place or when it was discovered remains unknown. The types of information exposed included driver's licenses, medical records and Social Security numbers. Kentucky Mountain Health Alliance's response to the breach Kentucky Mountain Health Alliance has arranged for affected individuals to receive a free, two-year membership to identity monitoring services through Epiq's Privacy Solutions ID program. Affected individuals can enroll by visiting Privacy Solutions ID and entering the unique activation code included in their notification letter. Each letter contains a specific enrollment deadline. Individuals who need help with enrollment or have questions about the monitoring services can call Epiq directly at 866-675-2006, Monday through Friday from 9:00 a.m. to 5:30 p.m. EST. The company also directed affected individuals to the Federal Trade Commission at 1-877-438-4338 and the Massachusetts Office of Consumer Affairs and Business Regulation at 888-283-3757 for additional guidance on identity theft prevention. Kentucky Mountain Health Alliance can be reached at 606-487-9505 and is located at 279 East Main St., Hazard, KY 41701. SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION Affected information types not yet disclosed This browser does not support inline PDFs. Please download the PDF to view it: Download PDF Driver’s license or state identification card numbers Class actions settlements delivered to your inbox. SportsMed Physical Therapy Data Breach Exposes Health Information Trudeau Center Breach Affects 5,630 Individuals Alkegen Data Breach Exposes Personal and Protected Health Information Whitfield Hospital Breach Exposed Medical and Health Information Colorado Health Network; Kentucky Mountain Health Alliance Announce Data Breaches Data security incidents have been announced by the Colorado Health Network and Kentucky Mountain Health Alliance. In both cases, only limited information has been released about the nature of the incidents. Colorado Health Network Inc., a nonprofit organization that provides health and support services to individuals with HIV/AIDS across Colorado, has recently disclosed a data security incident. The breach notification does not state when the breach was detected or for how long the threat actors had access to its network, only that an unauthorized third-party accessed and removed files from its systems. The files have been reviewed and found to contain patient names in combination with one or more of the following: Social Security number, driver’s license/state identification card number, passport number, financial account information, debit/credit card information, health insurance information (which may include Medicaid/Medicare information), and medical information. The medical information may include, but is not limited to, diagnosis, diagnosis code, mental/physical condition, prescription information, and provider’s/location. Colorado Health Network started mailing notification letters to the affected individuals on June 18, 2026, and said it has received no reports to suggest that any of the exposed or copied information has been misused. The affected individuals have been advised to monitor their account statements, free credit reports, and explanation of benefits statements for suspicious activity, and to sign up for the complimentary credit monitoring and identity theft protection services that have been offered. Immediate Delivery of Checklist Link To Your Email Address This appears to have been a ransomware attack by the Cephalus ransomware group. Cephalus claimed on its dark web data leak site on August 28, 2025, that it was behind the attack and obtained more than 900 GB of data. The group’s data leak site is not currently accessible, so it is unclear whether the data was leaked online. The Texas attorney general was informed that 257 Texas residents were affected by the breach. Given that the primary location of business is Colorado, that would suggest that the incident affected more than 500 individuals and should have been reported to the HHS’ Office for Civil Rights (OCR) and added to the OCR data breach portal; however, it is not currently shown on the breach portal. Kentucky Mountain Health Alliance, a Hazard, KY-based nonprofit organization that provides primary and specialty care to the homeless, has disclosed a data breach that involved unauthorized access to patient data, some of which was copied in the incident. While data breach notices should be placed in a prominent location on the home page of the provider’s website under HIPAA, users are required to click on the “more” section and then select the notice from the drop-down menu. The notice states that the information compromised in the includes names plus one or more of the following: Social Security numbers, driver’s license numbers/state identification numbers, passport numbers, financial account information, debit/credit card information, health insurance information, and medical information such as diagnosis, diagnosis code, mental/physical condition, prescription information, provider’s name and location, and health insurance information. Notification letters were issued to the affected individuals on June 12, 2026. As with the data breach at Colorado Health Network (above), the breach notifications do not elaborate further on the nature of the incident, such as who potentially accessed the data (internal/external), when the incident was detected, or for how long the data was exposed. The website notice makes no mention of credit monitoring services; however, the notice issued to the Massachusetts Office of Consumer Affairs and Business Regulation states that 24 months of complimentary credit monitoring and identity theft protection services are being provided through Epiq. The number of affected individuals has yet to be publicly disclosed.

When was this signal reported?

Shadow Tier lists Jun 19, 2026 as the signal date.

Which organization is connected to this signal?

Kmha is the organization connected to this public signal.

Explore Kmha
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence