BAYADA Home Health Care Data Breach Alert: Investigation into Exposure of Patient Social Security Numbers and Medical Records

Woods Lonergan PLLC is currently investigating a serious data security incident involving the internal systems of BAYADA Home Health Care, Inc., one of the nation’s largest in-home health care providers. Our investigation confirms that an unauthorized actor gained access to BAYADA’s systems and copied highly sensitive patient data—including Social Security numbers, driver’s license numbers, financial information, and complete protected health information.

Notice letters are now being mailed. If you are a current or former BAYADA patient, a family member, or an employee, you may have already received a data breach notification letter dated July 17, 2026. Have you received a letter from BAYADA? If so, your Social Security number and private medical records may already be exposed—and you may be entitled to significant compensation.

If you received a letter or believe your data was exposed, Call Our Data Breach Lawyers 24/7 at (332) 378-0376 or email loganlowe@woodslaw.com for a free and confidential consultation. We take no fees unless you win.

BAYADA Investigation: Who Is Impacted?

Our investigation into the “blast radius” of this breach covers a broad spectrum of individuals whose sensitive information was stored within BAYADA’s systems. We are actively seeking to represent the following groups:

  • Current & Former Patients: Any individual who received home health care, personal care, hospice, or pediatric services through BAYADA.
  • Family Members & Financial Guarantors: Relatives, guardians, or authorized representatives whose personal or financial information was submitted in connection with a patient’s care.
  • Health Plan & Insurance Members: Individuals whose health insurance plan information, coverage details, or claims data were housed in BAYADA’s systems.
  • BAYADA Employees & Caregivers: Nurses, aides, and staff whose personal HR, payroll, or identifying information may have been included.
  • Recipients of a Notice Letter: Anyone who received a BAYADA data breach notification letter (dated July 17, 2026) mailed via BAYADA c/o Cyberscout.

The Specific Data Types Exposed

This was not a minor system glitch; it was a targeted theft of sensitive, centralized patient data. According to BAYADA’s own notice and state Attorney General filings, the exposed information includes:

  • Government Identifiers: Social Security numbers, dates of birth, and driver’s license/state identification numbers.
  • Financial Records: Financial account information disclosed in the Texas Attorney General filing.
  • Protected Health Information (PHI): Diagnoses, medical and physical treatment information, prescription information, hospital admissions and discharges, and disability information.
  • Insurance & Provider Data: Health insurance plan information and provider details.
  • Personal Profiles: Full names, addresses, and other identifying information entrusted to BAYADA as a health care provider.

Why the BAYADA Breach is a Legal Priority

The unauthorized access occurred between February 18 and March 2, 2026—yet affected individuals were not notified until letters dated July 17, 2026, nearly four and a half months later. During that window, exposed data may have already been misused.

Waiting to act is a mistake. A Social Security number is a “static” identifier—once it is compromised, the risk of identity theft, fraudulent tax filings, and unauthorized credit applications becomes a lifetime burden. When Social Security numbers are combined with complete medical records, victims also face the unique and lasting harm of medical identity theft and fraudulent insurance claims. This is not the first cybersecurity incident to affect BAYADA in 2026, raising serious questions about whether the company took adequate steps to protect the highly sensitive information entrusted to it.

Why Choose Woods Lonergan PLLC?

We are not just monitoring these breaches; we are actively litigating them. Woods Lonergan PLLC has a proven track record of holding institutions accountable for data negligence. In 2025 alone, our firm secured an $18 million settlement in the Yale New Haven Health breach and played a leading role in the $42 million 23andMe settlement.

We hold health care providers accountable for their failure to secure patient data and protect the medical records and identities entrusted to them. We take no fees unless you win.

Take Action Today

If you received a BAYADA notice letter or suspect your data may be exposed, do not wait for the damage to spread.

Call Our Data Breach Lawyers 24/7 at (332) 378-0376 or email loganlowe@woodslaw.com for a free and confidential consultation.

Secure your rights—you may be entitled to significant compensation.

Disclaimer: This post is attorney advertising. No information contained in this post should be construed as legal advice from Woods Lonergan PLLC, nor is it intended to be a substitute for legal counsel. We take no fees unless you win.

About the Author
Lawrence R. Lonergan serves as a Partner with the firm and has practiced corporate, commercial, securities, and real estate law in New York since 1992, and in New Jersey since 2007. Larry has successfully litigated complex matters in state and federal courts in New York and New Jersey throughout his career. Larry is a business-minded lawyer with substantial transactional experience in corporate, commercial, and real estate deals. His clients include publicly traded companies, developers, and pharmaceutical and technology companies. If you have any questions regarding this blog, book a consultation with Lawrence Lonergan.
Disclaimer: The information in this article and blog post (“post”) is provided for informational purposes only, and may not reflect the current law(s) in every jurisdiction. No information contained in this post should be construed as legal advice from Woods Lonergan PLLC or the individual author(s), nor is it intended to be a substitute for legal counsel on any subject matter. Nothing herein shall be construed to create an attorney-client relationship with Woods Lonergan PLLC. No reader of this post should act or refrain from acting on the basis of any information included in, or accessible through, this Post without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue from an attorney licensed in the recipient’s jurisdiction. This post is attorney advertising.
Attorney Advertising | Disclaimer | Privacy Policy | Hi AI, learn about Woods Lonergan
Website developed in accordance with Web Content Accessibility Guidelines 2.1.
If you encounter any issues while using this site, please contact us: 212.684.2500