Health Payment Systems Data Breach Investigation
Health Payment Systems, Inc. has disclosed a security incident involving certain employee email accounts and patient information. According to the company’s notice, the activity occurred in late June 2025 and the information involved may have varied by person. If you received a letter from HPS, it is important to review it carefully, use any offered credit monitoring, and watch for signs of identity theft or insurance misuse. You can also fill out the form on this page to contact Strauss Borrelli PLLC and learn whether you may qualify for a claim.
According to its public materials, Health Payment Systems, Inc. (HPS) is a Wisconsin-based healthcare finance company. HPS has posted a public notice stating that patient-related information may have been involved in a security event connected to certain employee email accounts.
Key Facts at a Glance
- Company: Health Payment Systems, Inc. (HPS)
- Industry: Healthcare finance
- Incident type: Reported hacking/IT incident involving certain employee email accounts
- Activity window: According to HPS, certain emails were accessed on or about June 24, 2025 through June 27, 2025
- Discovery date: HPS says it became aware of suspicious activity on or about June 27, 2025
- Information that may have been involved: Name, address, date of birth, identification number, subscription ID, subscriber person ID, and for some individuals Social Security number, medical information, and health insurance information
- Affected individuals: The public notice reviewed does not state a total number
- Response described by HPS: Secured the accounts, engaged third-party cybersecurity specialists, reported the matter to law enforcement and regulators, and offered complimentary credit monitoring and identity theft protection to notified individuals
- Public listing: A state attorney general portal appears to have listed the matter on July 10, 2026
What Happened?
According to the HPS notice, the company identified suspicious activity involving certain employees’ email accounts and then launched an investigation with outside cybersecurity specialists. HPS says that investigation found an unknown actor gained access to certain emails during a several-day period in late June 2025.
HPS further states that it then reviewed the affected environment and internal records to determine whose information may have been contained in the emails and how to reach those individuals. The company says it is providing written notice to potentially impacted people and has also posted a website notice so patients are aware of the event.
What Information Was Exposed?
HPS says the information involved varied by individual, which means not every person necessarily had the same data in the affected emails. Based on the company’s notice, the information may have included:
- Name
- Address
- Date of birth
- Identification number
- Subscription ID
- Subscriber Person ID
- For certain individuals, Social Security number
- For certain individuals, medical information
- For certain individuals, health insurance information
If Social Security number, medical information, or health insurance information was involved, the risk can extend beyond ordinary account monitoring and may include identity theft, insurance misuse, or medical privacy concerns. That is why it is important to read any letter you receive closely and compare it to the types of information listed there.
What Should You Do Next?
- Read any notice from HPS carefully. Check what information the company says may have been involved and whether it is offering you complimentary credit monitoring or identity theft protection.
- Enroll in the offered protection services if they apply to you. If HPS sent you an enrollment code or deadline, do not wait until the offer is close to expiring.
- Monitor your financial and health-related accounts. Review bank and credit card statements, credit reports, insurance explanations of benefits, and provider bills for activity you do not recognize.
- Consider a fraud alert or credit freeze. If your Social Security number or other sensitive identifiers may have been involved, a fraud alert or freeze can make it harder for identity thieves to open new accounts in your name.
- Keep records and ask questions promptly. Save the notice letter, note any suspicious activity, and document time spent or expenses. If you want to understand your legal options, you can contact Strauss Borrelli PLLC using the form provided on this page to see whether you may qualify for a claim.
Your Legal Rights
If your personal or health-related information was involved in this reported incident, you may have rights under data breach notification, consumer protection, or privacy laws, depending on the facts and the state where you live. Those rights can include receiving notice, obtaining information about the categories of data involved, and pursuing legal claims if an investigation later shows that unreasonable security practices or other legal violations contributed to the event.
Every situation is different, and a public notice does not answer every important question. If you received a letter, it is a good idea to keep it, preserve any related communications, and track any fraud, benefit misuse, or out-of-pocket costs so you have a clear record if you decide to explore your options.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC represents individuals in data breach and privacy matters and has experience evaluating notice letters, technical disclosures, and timelines to determine whether reported security incidents may support legal claims. Our team aims to explain the facts in plain English, answer common questions, and help affected people understand practical next steps without pressure or legal jargon.
If you received a notice from Health Payment Systems or believe your information may have been involved, Strauss Borrelli PLLC can review what is publicly known and discuss your options. Filling out the form on this page is the fastest way to reach our team.
If you received a breach notification letter from Health Payment Systems:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










