DataBreachSearch.com
MonitoringCalifornia AG filing · August 31, 2026

Virta Health, Virta Medical Report Data Breach to California AG

Virta Health Corp. and Virta Medical, PC officially reported a data security incident to the California Attorney General. The breach, detected by March 19, 2026, exposed various sensitive patient data categories. Individuals affected should review their official notification for specific details and recommended actions.

State
California
Breach date
March 19, 2026
Reported
August 31, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Biometric and Health Log Data

On August 31, 2026, Virta Health Corp. and Virta Medical, PC filed a report with the California Attorney General regarding a data breach. The incident, which Virta Health and Virta Medical state was detected by March 19, 2026, involved unauthorized access to systems containing sensitive patient information. The investigation into the incident is currently ongoing and is being monitored.

The compromised data categories reported to the California Attorney General include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Biometric and Health Log Data.

Exposure of these specific data types can pose significant risks. For instance, a compromised Social Security Number can be used in identity theft schemes. Medical Record Numbers and Health Insurance ID Numbers, combined with Diagnosis and Treatment Information, may lead to unauthorized access to medical services or fraudulent claims. Individuals should be aware of these potential consequences.

As a healthcare provider, Virta Health Corp. and Virta Medical, PC are subject to federal and state regulations, including the Health Insurance Portability and Accountability Act (HIPAA) and California's data privacy laws. These regulations require organizations to implement robust security measures to protect sensitive patient data. The reporting of this breach indicates a security incident occurred despite these requirements.

If you receive a data breach notification from Virta Health Corp. or Virta Medical, PC, it is important to review its contents carefully. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus. Also, monitor your explanation of benefits statements from your health insurer for any unfamiliar services or claims, and regularly review financial account statements for suspicious activity.

Source: California Attorney General filing

More California data breach cases