Integrative Emergency Services Data Breach Investigation
Integrative Emergency Services reported an email security incident that may have affected a limited amount of patient protected health information. The company said an unauthorized person accessed one employee email account and may have viewed one message containing patient data. Strauss Borrelli PLLC is investigating the incident and its potential impact on affected individuals. If you received a notice or believe your information may be involved, fill out the secure contact form on this page to help verify possible claim eligibility.
Key Facts at a Glance
- Entity Involved: Integrative Emergency Services (Healthcare)
- Incident Type: Hacking/IT incident involving unauthorized access to an employee email account
- Date of Incident: June 16, 2026
- Discovery Date: July 9, 2026, when the company says it learned that one email may have been viewed
- Official Notice Date: Not stated in the available company notice
- Exposed Information: Names, health information, and medical record identifiers
- Affected Population: Described as a limited amount of patients; an exact count was not stated
What Happened?
According to the company’s data security notice, Integrative Emergency Services, also known as IES, says it noticed suspicious activity involving one employee email account and secured the account within 24 hours. Its investigation reportedly found that an unauthorized person had access for just over four hours. On July 9, 2026, the company says it learned that one email containing protected health information may have been viewed during that access.
IES described the potentially affected information as limited and said it had no evidence of misuse at the time of its notice. It nevertheless announced notification out of caution. IES also reported changing the account password and retraining employees to recognize and respond to suspicious email activity. The notice does not identify how the unauthorized person obtained access, so the specific entry method should not be assumed.
What Information Was Exposed?
IES reported that the email may have contained some combination of a patient’s name, health information, and medical record identifier. The information involved may therefore vary from person to person. The company’s notice states that patient addresses, Social Security numbers, and financial account information were not impacted.
Even without Social Security or financial account numbers, health information can be sensitive. Potential risks may include fraudulent patient billing, medical identity theft, insurance verification scams, prescription-related inquiries, or phishing messages that impersonate a healthcare provider or insurer. The notice does not establish that any such misuse occurred.
What Should You Do Next?
- Confirm whether you were affected: Review any notice you received and preserve a copy. IES directs people with questions to call 888-732-8137, Monday through Friday from 7 a.m. to 7 p.m. Central Time.
- Review healthcare records: Examine explanations of benefits, patient portals, insurer portals, and medical bills for unfamiliar providers, services, prescriptions, diagnoses, or changes to your contact information.
- Report suspicious medical activity: Contact your healthcare provider and health insurer promptly if you find a service or charge you do not recognize. Ask for the appropriate fraud or privacy department and request written confirmation of any dispute.
- Watch for healthcare phishing: Be cautious of callers, emails, or text messages requesting insurance numbers, portal credentials, payments, or identity verification. Contact the provider or insurer through a trusted telephone number rather than using links in an unexpected message.
- Document suspected misuse: Keep notices, bills, correspondence, screenshots, and records of related expenses. Suspected identity theft may also be reported to the Federal Trade Commission, law enforcement, or your state attorney general.
Your Legal Rights
People whose information may have been involved could have rights under applicable state data breach, consumer protection, privacy, or healthcare laws. Those rights depend on the person’s location, the information involved, whether adequate notice was provided, and whether the incident caused measurable harm. Receiving a notice does not automatically establish a legal claim.
Potentially relevant losses may include unreimbursed expenses, time spent addressing misuse, fraudulent medical charges, or other documented harm. Individuals should preserve the company’s notice and records of suspicious activity because legal deadlines may apply. An attorney familiar with data privacy matters can evaluate the available facts, determine whether a claim may exist, and explain possible options without offering guarantees about an outcome.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC represents individuals in privacy and cybersecurity matters and can evaluate notices, incident facts, and documented losses to determine whether legal options may be available. A confidential consultation can help affected individuals understand the investigation process, applicable deadlines, and practical next steps. No outcome can be promised, and any assessment depends on the specific facts and governing law.
If you received a breach notification letter from Integrative Emergency Services:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










