DataBreachCaseFile.com
MonitoringCalifornia AG filing · September 11, 2026

Catalyst Physician Group Reports Patient Data Breach in California

Catalyst Physician Group, operating in California, reported a data security incident on September 11, 2026, stemming from unauthorized access to its digital environment on December 2, 2025. This breach exposed a range of highly sensitive patient information, including medical and identity data. Individuals who receive notification should understand the long-term risks associated with such an exposure.

State
California
Breach date
December 2, 2025
Reported
September 11, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates
  • Billing and Financial Information

Catalyst Physician Group, a healthcare provider network in California, formally reported a data security incident to regulators on September 11, 2026. This report indicated that unauthorized individuals gained access to the organization's internal digital systems, with the breach event occurring on December 2, 2025. The investigation into this incident remains in a monitoring status.

The compromised patient records include highly sensitive categories of personal and health information. Specifically, the data exposed consists of Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, Provider and Treatment Dates, and Billing and Financial Information.

This blend of exposed data types carries significant long-term risks for affected individuals. Unlike payment card details, core identity and medical information cannot be easily changed or replaced. The exposure of details such as Social Security Numbers and Dates of Birth creates potential for various forms of identity theft and financial fraud.

Furthermore, the compromise of Medical Record Numbers, Health Insurance ID Numbers, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates can lead to medical identity theft. This type of fraud can result in criminals using stolen information to obtain healthcare services, make false claims with insurance providers, or even alter an individual's medical history.

Individuals who have received a notification regarding this incident from Catalyst Physician Group are advised to remain vigilant. It is recommended to regularly review explanation of benefits (EOB) statements from health insurers for any unfamiliar services and to monitor credit reports for any suspicious activity. Changing passwords for online health portals or related accounts is also a prudent step.

This documentation of the Catalyst Physician Group data breach is based on public filings and serves to inform affected parties about the reported details of the incident and the types of data confirmed as exposed.

Source: California Attorney General filing

More California data breach cases