Virta Health, Virta Medical Report Data Breach to California AG
Virta Health Corp. and Virta Medical, PC officially reported a data security incident to the California Attorney General. The breach, detected by March 19, 2026, exposed various sensitive patient data categories. Individuals affected should review their official notification for specific details and recommended actions.
- State
- California
- Breach date
- March 19, 2026
- Reported
- August 31, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Biometric and Health Log Data
On August 31, 2026, Virta Health Corp. and Virta Medical, PC filed a report with the California Attorney General regarding a data breach. The incident, which Virta Health and Virta Medical state was detected by March 19, 2026, involved unauthorized access to systems containing sensitive patient information. The investigation into the incident is currently ongoing and is being monitored.
The compromised data categories reported to the California Attorney General include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Biometric and Health Log Data.
Exposure of these specific data types can pose significant risks. For instance, a compromised Social Security Number can be used in identity theft schemes. Medical Record Numbers and Health Insurance ID Numbers, combined with Diagnosis and Treatment Information, may lead to unauthorized access to medical services or fraudulent claims. Individuals should be aware of these potential consequences.
As a healthcare provider, Virta Health Corp. and Virta Medical, PC are subject to federal and state regulations, including the Health Insurance Portability and Accountability Act (HIPAA) and California's data privacy laws. These regulations require organizations to implement robust security measures to protect sensitive patient data. The reporting of this breach indicates a security incident occurred despite these requirements.
If you receive a data breach notification from Virta Health Corp. or Virta Medical, PC, it is important to review its contents carefully. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus. Also, monitor your explanation of benefits statements from your health insurer for any unfamiliar services or claims, and regularly review financial account statements for suspicious activity.