|
Getting your Trinity Audio player ready...
|
Doreen was worried when she opened the letter. It was a legal notice saying her private information had been exposed in a data breach at Hawthorn Medical Associates. The list of potentially involved personal data was long: her Social Security number, private medical information, and even bank account numbers could all be compromised.
“Uh-oh,” she thought. Her husband got a notice too.
Their worry quickly turned to confusion. Doreen, who asked that The Light not use her last name, now has two questions for Hawthorn.
“Why was this sent to my husband and I when we’ve never been patients of the practice?” she asks. “And how did you get our name and address?”
Though it’s not clear how, Doreen’s information may have been involved in a sweeping data breach. The personal data of over 290,000 Massachusetts residents’ information was exposed in a “data security incident” at Hawthorn in December, according to state filings and legal notices sent this month.
The breach is the second largest in the state this year, after a separate hack at a dental insurer. Hawthorn’s breach may have exposed a broad set of people’s personal, financial, and medical information. And that data appears to go back years. One woman told The Light she was surprised to receive a letter for her stepfather, a former Hawthorn patient who died 11 years ago.
But the exact details of the breach are unclear. The Dartmouth medical practice has not answered questions on what exactly happened, how such a large amount of data was involved in a single event on a single server, and why it took seven months to notify the people affected.
In notices dated July 16, Hawthorn said it discovered the breach on Dec. 16, 2025. Someone, or something, had gained “unauthorized access” to a “historic file server” between Dec. 15 and 16.
The notices said Hawthorn couldn’t determine exactly what information was exposed, but in June it determined that a wide range of private data may have been involved, including contact information, Social Security numbers, health insurance, medical information, bills, bank accounts, and credit cards. Even human resources data, such as payroll records, were on the list.
“Not all categories of information were impacted for all individuals,” Hawthorn notes.
Hawthorn employs more than 140 medical professionals across 20 specialties, according to its website. Its three-building complex on Faunce Corner Road in Dartmouth includes an urgent care and lab testing spaces. The practice became an affiliate of Lifespan, now known as Brown University Health, in 2024 — after its previous network, Steward Healthcare, filed for bankruptcy.
Sean Cunniffe, who is identified as vice president of Hawthorn Operations at Brown in a LinkedIn profile and previously had the title of CEO at the practice before Hawthorn became part of Brown, has not responded to repeated calls and emails from The Light. On Monday, a front-desk staffer at Hawthorn told a Light reporter that Cunniffe’s assistant said all media inquiries had to go through Brown University Health.
Jessica A. Wharton, a Brown spokesperson, provided a written statement saying the practice was “notifying potentially affected individuals out of an abundance of caution” and that “there is currently no evidence that any information has been misused.”
Read Brown’s full statement:
“We recently completed an investigation into a December 2025 security incident involving historic IT systems at the Hawthorn location of Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group – MA and we are notifying potentially affected individuals out of an abundance of caution. While there is currently no evidence that any information has been misused, we are offering complimentary identity protection services.”
— Brown University Health spokesperson
In a phone call on Monday, Wharton said she had no other information to share beyond what was in the statement.
State Sen. Mark Montigny said Brown needs to explain why people weren’t notified when the breach happened in December. He said Brown also needs to answer questions about the extent of the breach and how it has been addressed.
“They can stop the bullshit and answer the questions fully,” he said.
The New Bedford lawmaker said he received a breach notification from Hawthorn, even though he couldn’t remember ever being a patient there. He said he had received other breach letters from other organizations in the past, but this one was the broadest and most troubling.
Why so many healthcare data breaches?
Healthcare breaches are on the rise, experts say. The wealth of sensitive information that health systems collect makes them prime targets for hacks.
Breaches are so common now that it’s not a matter of if a healthcare provider is breached, but when, said Mike Levinger, an expert in healthcare cybersecurity and lecturer at Boston University. Hawthorn’s seven-month delay in notifying people affected by the breach isn’t unusual, he said.
“For all you know, they were really working to understand the situation,” Levinger said.
The practice may have had to conduct a deep forensic investigation to figure out what data might have been exposed, and to be sure that any hackers had been completely expelled from the system without leaving behind any malicious computer code, he said. That can take months.
Police could still be on the case, he said, and they may have advised Brown not to compromise the investigation by revealing too much.
Levinger said it’s encouraging that Brown said there’s no evidence the data has been misused.
“But it’s not definitive, because someone could use it tomorrow,” he added.
Hawthorn’s public notice didn’t go into detail about how it stopped and addressed the breach, but the practice said it was taking the breach “very seriously.”
“We took, and will continue to take, appropriate steps to address this incident,” the notice said, “including re-training our employees and implementing additional technical safeguards to prevent incidents of this nature from occurring in the future.”
Hawthorn is offering two years of “complimentary identity restoration and fraud detection services to affected individuals.”
Common causes and consequences of data breaches
Many breaches in healthcare are the result of ransomware, experts say, though it’s not clear whether Hawthorn’s breach was caused by this type of malicious attack.
In a ransomware attack, criminal gangs make their way into a health provider’s computer systems using stolen passwords from other leaks, or by exploiting weaknesses in the computer code that’s supposed to keep private systems secure.
After they sneak in, they usually freeze the provider’s computer system and demand a ransom to unlock it. They might also threaten to sell the sensitive data on the dark web, where it’s valuable to identity thieves.
“They’re looking for a payout,” said John Petrozzelli, director of MassCyberCenter, a state cybersecurity agency.
Healthcare providers have incentives to pay. They need their computer systems to provide critical care, and they want to avoid hurting patients or their own reputation if the data gets out. But Petrozzelli warned that hackers usually keep the data and could still post it to the dark web even if the provider pays a ransom.
If personal data gets into the wrong hands, criminals can use it to steal a person’s identity. They might try to drain their bank account, open credit cards in their name, forge tax returns, or steal government benefits.
Not all breaches are the result of malicious attacks. In healthcare, about one in five breaches are clerical errors, Petrozzelli said. Sometimes an employee accidentally sends sensitive data to someone who shouldn’t have access because of an email typo, for example.
“Not again” was Kathy Brightman’s first thought when she opened her data breach notification from Hawthorn. The Dartmouth resident had already had her identity stolen from a different data breach.
Brightman said she was left wondering how such a large breach could happen, with all the measures healthcare providers are supposed to take to safeguard patient information — and all the money patients are paying for care.
“They charge you $18 for one Tylenol, and you can’t have a better system to protect our information from getting in the wrong hands?” she asked. “I’m very angry. I’m beyond angry.”
Other people who received letters expressed a sense of resignation. To them, data breaches are starting to feel like an unavoidable and increasingly common inconvenience.
What you can do to keep your data safe
Data breaches are a fact of life nowadays, cybersecurity experts say. But there are some things you can do to lower the risk that your data could be used against you.
Petrozzelli recommends using haveibeenpwned.com, a website that monitors for data breaches on the dark web. You can put in your email address and see whether your information has shown up in a breach.
If it has, Petrozzelli says you should change your password on that website and any other website where you use the same or a similar password. It’s harder for hackers to get into your accounts when you use complex, different passwords for each account you have.
You shouldn’t use variations on the same theme, like a different Patriots player’s name for each account, because that makes them easier for hackers to guess, Petrozzelli said. The strongest passwords are long and very random strings of characters.
Password managers can help you keep track of it all, he said. He recommends not storing all your passwords in one physical place, like a list next to your computer, because that could easily be swiped.
Even more secure options now exist, Petrozzelli said. Multifactor authentication tools and passkeys make it even harder for others to access your accounts by relying on multiple devices and biometric data like a fingerprint or face scan.
“Right now, they’re not crackable,” he said.
Email Grace Ferguson at gferguson@newbedfordlight.org.

