Secure Healthcare Information Management Data Breach Investigation

Secure Healthcare Information Management LLC reported a network security incident that may have involved personal and protected health information. According to the company’s notice issued on October 6, 2026, the potentially affected data included identifying, medical, and health insurance information. Strauss Borrelli PLLC is investigating the incident and its impact on affected individuals. People who received a notice may fill out the secure contact form on this page to verify whether they may qualify to pursue a claim.

Secure Healthcare Information Management LLC, also known as SHIM, is a billing and medical management company serving independent physicians and medical institutions in northeastern Pennsylvania.

Key Facts at a Glance

  • Entity Involved: Secure Healthcare Information Management LLC (Healthcare)
  • Incident Type: Hacking/IT incident involving reported unauthorized access or acquisition
  • Date of Incident: July 6, 2026, to July 16, 2026
  • Discovery Date: July 17, 2026
  • Official Notice Date: October 6, 2026
  • Exposed Information: Names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information
  • Affected Population: Not publicly stated in the notice

What Happened?

According to SHIM’s official consumer notice, the company experienced a network disruption on July 17, 2026, and began investigating with assistance from cybersecurity experts. The investigation reportedly determined that an unknown actor accessed or acquired certain personal information without authorization between July 6 and July 16, 2026. SHIM then reviewed the files involved to determine whether they contained personal information and identify the people to whom that information related.

The notice states that SHIM confirmed the scope of the impact and obtained sufficient information to provide notice on September 18, 2026. The company subsequently mailed letters to potentially affected individuals for whom it had identifiable address information. SHIM also reported the matter to the U.S. Department of Health and Human Services Office for Civil Rights and consumer reporting agencies. The publicly available notice does not state how many people may have been affected or identify the unknown actor.

What Information Was Exposed?

SHIM reported that the files may have contained names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information. The particular information involved may differ from person to person, so recipients should review their individual notice carefully.

Healthcare data can create risks beyond conventional identity theft. Depending on the information involved, criminals may attempt medical identity theft, fraudulent patient billing, false insurance claims, prescription-related inquiries, or insurance verification scams. A notice that information may have been involved does not, by itself, establish that it has been misused.

What Should You Do Next?

  1. Review your notice and enroll promptly: Confirm which information may relate to you and follow the enrollment instructions for any complimentary identity protection offered. SHIM reported that eligible individuals could enroll in services through Cyberscout, a TransUnion company.
  2. Check your credit reports: Review reports from Equifax, Experian, and TransUnion for unfamiliar accounts, inquiries, addresses, or other activity. Consider placing a free security freeze with each bureau if your Social Security number or government identification information may have been involved.
  3. Inspect medical and insurance records: Examine explanations of benefits, patient portal records, pharmacy activity, and bills for providers, treatments, prescriptions, or claims you do not recognize. Report discrepancies to the provider and insurer.
  4. Be alert for healthcare scams: Treat unexpected calls, emails, or texts requesting insurance numbers, patient portal credentials, payments, or identity verification as suspicious. Contact the provider or insurer through a trusted telephone number rather than using links in an unsolicited message.
  5. Preserve relevant records: Keep the notification letter, envelopes, credit reports, suspicious communications, fraud reports, and receipts for expenses. These materials may help document the incident’s effect on you.

Your Legal Rights

Individuals whose information may have been involved could have rights under federal or state privacy, consumer protection, or data security laws. Those rights depend on factors such as where the person lives, the information involved, the safeguards used, whether misuse occurred, and whether the person experienced financial loss, lost time, or other harm.

Potentially affected individuals may wish to preserve their notice and document any suspicious activity or out-of-pocket costs. They may also seek a legal review of whether the circumstances support a claim for available remedies. Receiving a notice does not automatically establish liability or guarantee compensation, and general information about this incident is not a substitute for individualized legal advice.

Why Hire Strauss Borrelli PLLC?

Our privacy and data breach attorneys can evaluate the reported incident, explain how potentially applicable laws may affect an individual’s options, and assess whether documented losses or other circumstances may support a claim. A confidential consultation can help notice recipients understand the process without assuming that any particular outcome is guaranteed.

If you received a breach notification letter from Secure Healthcare Information Management:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY