Kaniksu Community Health Reports Data Breach to Oregon AG
Kaniksu Community Health disclosed a data breach to the Oregon Attorney General on September 15, 2026, following an incident on December 2, 2025. The breach exposed sensitive patient information, including medical and personal identifiers, which could lead to identity theft and medical fraud for affected individuals.
- State
- Oregon
- Breach date
- December 2, 2025
- Reported
- September 15, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
Kaniksu Community Health, a healthcare provider, reported a data security incident to the Oregon Attorney General on September 15, 2026. The company stated that this incident, which they are currently monitoring, occurred on December 2, 2025.
The information reported as exposed in this breach includes Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. This type of information is highly sensitive due to its deeply personal nature.
Exposure of these specific data categories can lead to significant risks for individuals. This includes potential for identity theft, fraudulent medical billing, or unauthorized access to health services using compromised details. Unlike financial account numbers, much of this medical and personal data cannot be easily changed or replaced.
Individuals who receive notification of this breach should remain vigilant. It is advisable to carefully review explanation of benefits (EOB) statements, medical bills, and any financial statements for unfamiliar charges or services. Placing a fraud alert or credit freeze with the major credit bureaus can also help protect against potential financial identity theft.
Source: Oregon Attorney General filing