Getting your Trinity Audio player ready...

Doreen was worried when she opened the letter. It was a legal notice saying her private information had been exposed in a data breach at Hawthorn Medical Associates. The list of potentially involved personal data was long: her Social Security number, private medical information, and even bank account numbers could all be compromised.

“Uh-oh,” she thought. Her husband got a notice too.

Their worry quickly turned to confusion. Doreen, who asked that The Light not use her last name, now has two questions for Hawthorn.

“Why was this sent to my husband and I when we’ve never been patients of the practice?” she asks. “And how did you get our name and address?”

Though it’s not clear how, Doreen’s information may have been involved in a sweeping data breach. The personal data of over 290,000 Massachusetts residents’ information was exposed in a “data security incident” at Hawthorn in December, according to state filings and legal notices sent this month.

The breach is the second largest in the state this year, after a separate hack at a dental insurer. Hawthorn’s breach may have exposed a broad set of people’s personal, financial, and medical information. And that data appears to go back years. One woman told The Light she was surprised to receive a letter for her stepfather, a former Hawthorn patient who died 11 years ago.

But the exact details of the breach are unclear. The Dartmouth medical practice has not answered questions on what exactly happened, how such a large amount of data was involved in a single event on a single server, and why it took seven months to notify the people affected.

In notices dated July 16, Hawthorn said it discovered the breach on Dec. 16, 2025. Someone, or something, had gained “unauthorized access” to a “historic file server” between Dec. 15 and 16. 

The notices said Hawthorn couldn’t determine exactly what information was exposed, but in June it determined that a wide range of private data may have been involved, including contact information, Social Security numbers, health insurance, medical information, bills, bank accounts, and credit cards. Even human resources data, such as payroll records, were on the list.

“Not all categories of information were impacted for all individuals,” Hawthorn notes.

Hawthorn employs more than 140 medical professionals across 20 specialties, according to its website. Its three-building complex on Faunce Corner Road in Dartmouth includes an urgent care and lab testing spaces. The practice became an affiliate of Lifespan, now known as Brown University Health, in 2024 — after its previous network, Steward Healthcare, filed for bankruptcy.

Sean Cunniffe, who is identified as vice president of Hawthorn Operations at Brown in a LinkedIn profile and previously had the title of CEO at the practice before Hawthorn became part of Brown, has not responded to repeated calls and emails from The Light. On Monday, a front-desk staffer at Hawthorn told a Light reporter that Cunniffe’s assistant said all media inquiries had to go through Brown University Health.

Jessica A. Wharton, a Brown spokesperson, provided a written statement saying the practice was “notifying potentially affected individuals out of an abundance of caution” and that “there is currently no evidence that any information has been misused.”

Read Brown’s full statement:

In a phone call on Monday, Wharton said she had no other information to share beyond what was in the statement.

State Sen. Mark Montigny said Brown needs to explain why people weren’t notified when the breach happened in December. He said Brown also needs to answer questions about the extent of the breach and how it has been addressed.

“They can stop the bullshit and answer the questions fully,” he said.

The New Bedford lawmaker said he received a breach notification from Hawthorn, even though he couldn’t remember ever being a patient there. He said he had received other breach letters from other organizations in the past, but this one was the broadest and most troubling.

Why so many healthcare data breaches?

Healthcare breaches are on the rise, experts say. The wealth of sensitive information that health systems collect makes them prime targets for hacks.

Breaches are so common now that it’s not a matter of if a healthcare provider is breached, but when, said Mike Levinger, an expert in healthcare cybersecurity and lecturer at Boston University. Hawthorn’s seven-month delay in notifying people affected by the breach isn’t unusual, he said. 

“For all you know, they were really working to understand the situation,” Levinger said.

The practice may have had to conduct a deep forensic investigation to figure out what data might have been exposed, and to be sure that any hackers had been completely expelled from the system without leaving behind any malicious computer code, he said. That can take months.

Police could still be on the case, he said, and they may have advised Brown not to compromise the investigation by revealing too much.

Levinger said it’s encouraging that Brown said there’s no evidence the data has been misused.

“But it’s not definitive, because someone could use it tomorrow,” he added.

Hawthorn’s public notice didn’t go into detail about how it stopped and addressed the breach, but the practice said it was taking the breach “very seriously.”

“We took, and will continue to take, appropriate steps to address this incident,” the notice said, “including re-training our employees and implementing additional technical safeguards to prevent incidents of this nature from occurring in the future.”

Hawthorn is offering two years of “complimentary identity restoration and fraud detection services to affected individuals.”

Common causes and consequences of data breaches

Many breaches in healthcare are the result of ransomware, experts say, though it’s not clear whether Hawthorn’s breach was caused by this type of malicious attack.

In a ransomware attack, criminal gangs make their way into a health provider’s computer systems using stolen passwords from other leaks, or by exploiting weaknesses in the computer code that’s supposed to keep private systems secure.

After they sneak in, they usually freeze the provider’s computer system and demand a ransom to unlock it. They might also threaten to sell the sensitive data on the dark web, where it’s valuable to identity thieves.

“They’re looking for a payout,” said John Petrozzelli, director of MassCyberCenter, a state cybersecurity agency.

Healthcare providers have incentives to pay. They need their computer systems to provide critical care, and they want to avoid hurting patients or their own reputation if the data gets out. But Petrozzelli warned that hackers usually keep the data and could still post it to the dark web even if the provider pays a ransom.

If personal data gets into the wrong hands, criminals can use it to steal a person’s identity. They might try to drain their bank account, open credit cards in their name, forge tax returns, or steal government benefits.

Not all breaches are the result of malicious attacks. In healthcare, about one in five breaches are clerical errors, Petrozzelli said. Sometimes an employee accidentally sends sensitive data to someone who shouldn’t have access because of an email typo, for example.

“Not again” was Kathy Brightman’s first thought when she opened her data breach notification from Hawthorn. The Dartmouth resident had already had her identity stolen from a different data breach.

Brightman said she was left wondering how such a large breach could happen, with all the measures healthcare providers are supposed to take to safeguard patient information — and all the money patients are paying for care.

“They charge you $18 for one Tylenol, and you can’t have a better system to protect our information from getting in the wrong hands?” she asked. “I’m very angry. I’m beyond angry.”

Other people who received letters expressed a sense of resignation. To them, data breaches are starting to feel like an unavoidable and increasingly common inconvenience.

What you can do to keep your data safe

Data breaches are a fact of life nowadays, cybersecurity experts say. But there are some things you can do to lower the risk that your data could be used against you.

Petrozzelli recommends using haveibeenpwned.com, a website that monitors for data breaches on the dark web. You can put in your email address and see whether your information has shown up in a breach.

If it has, Petrozzelli says you should change your password on that website and any other website where you use the same or a similar password. It’s harder for hackers to get into your accounts when you use complex, different passwords for each account you have.

You shouldn’t use variations on the same theme, like a different Patriots player’s name for each account, because that makes them easier for hackers to guess, Petrozzelli said. The strongest passwords are long and very random strings of characters.

Password managers can help you keep track of it all, he said. He recommends not storing all your passwords in one physical place, like a list next to your computer, because that could easily be swiped.

Even more secure options now exist, Petrozzelli said. Multifactor authentication tools and passkeys make it even harder for others to access your accounts by relying on multiple devices and biometric data like a fingerprint or face scan.

“Right now, they’re not crackable,” he said.

Email Grace Ferguson at gferguson@newbedfordlight.org.



14 replies on “Hawthorn Medical breach exposes personal data for 290,000 Mass. residents”

  1. Thanks, Grace. I just used the
    haveibeenpwned.com
    website, and I have NOT been. People should check to reassure themselves.

  2. Be careful before going to another website and entering your email address. The web terrorists are watching and waiting. Think about it, signing on to another suggested website is kinda of how this problem got started. Again be very careful and don’t trust anyone with your information.

    1. I don’t usually enter my email in random websites.

      The article states that the haveibeenpwned.com website I used was recommended by

       “ John Petrozzelli, director of  MassCyberCenter, a state cybersecurity agency.” It is a website that monitors for data breaches on the dark web

      About MassCyberCenter
      https://masscybercenter.org/about-masscybercenter

      We are fortunate to have a cybersecurity expert in our state. Many of the federal cybersecurity experts who assist the states have been fired by this administration.

  3. It is troubling that a medical organization is not better organized and trained against this type of attack on the web. My confidence. in this medical group and its doctors is 0 period, and the fact they have gone through financial problems is even more troubling. I would hope that SouthCoast Medical is and remains a flagship in our area.

    1. I do not blame the doctors I have been seeing. I blame the Brown Health organization that took over the failed Steward organization. The doctors and staff at Hawthorne are also dealing with this.

  4. What is going on at Brown Health? Brown University Health physicians now out of network as of July 1, 2026 for UnitedHealthcare’s Medicare Advantage plans
    The following Brown University Health physician offices are now out of network for UnitedHealthcare Medicare Advantage plans, including Group Retiree, as of July 1, 2026:
    I picked UHC in October 2025 and now Brown Health cancels my plan in July of 2026 ? Not fair to Senior Citizens!

    1. I agree with you and I am sorry that this happened. I will do what I can to help you get your plan coverage back. I will write to them and I will lobby our legislators.

    2. Dear Frank,

      I have been looking into this for you.

      It is United Health Care that is terminating coverage of Medicare Advantage Plans.

      This first link describes how it has used its position as the largest health care company in America to abuse patients, independent medical practices and pharmacies. This is really important for all of us to understand. Monopolies can more easily abuse power.

      United Health Care Abuse Tracker
      https://www.economicliberties.us/data-tools/unitedhealth-group-abuse-tracker/

      This second link is a 22 minute Fox News video which really explains what is happening in Minnesota and other states. Some other insurance companies might also be canceling Medicare Advantage coverage. I would really watch this to get a better idea of what you can do.

      Ucare dropping medicare advantage (22 min interview)
      https://www.youtube.com/watch?v=gC8DFFkEbyo

      This third link is from the RI Attorney General’s office about the failure of Brown Medical to reach a contract agreement with United Health Care. Keeping in mind the first two links when you read this one, it seems to me that Brown Medical is refusing to be bullied by an insurance monopoly.

      This last link is about how gigantic a monopoly United Health Care has become
      UnitedHealth Has 2,694 Subsidiaries and Affiliates. Is It Too Big to Manage?
      https://prospect.org/2025/07/16/2025-07-16-unitedhealth-has-2694-subsidiaries-and-affiliates/

      I know that subsidies to the Affordable Care Act (Obamacare) will expire at the end of this year, so policy holders now receiving premium subsidies can expect to see their rates increase in January.

      These are recent efforts to extend the ACA healthcare subsidies:

      House passes bill to extend healthcare subsidies
      https://www.youtube.com/watch?v=Ea7_NDi8Fpw

      But senate fails to extend healthcare subsidies.
      https://www.medicarerights.org/medicare-watch/2025/12/11/senate-fails-to-extend-aca-subsidies-price-hikes-loom

      Heather Cox Richardson relates our current situation to healthcare legislation history in our country.

      Letters from an American July 30, 2026
      https://heathercoxrichardson.substack.com/p/july-30-2026

      You might be interested in recent attempts to prevent monopolies from obtaining excessive power in our country: This one is a bipartisan bill in the Senate.

      The Break Up Big Medicine Act tackles vertical integration in the health care system to lower prices and promote competition.

      https://www.warren.senate.gov/newsroom/press-releases/warren-hawley-introduce-bipartisan-bill-to-break-up-big-medicine/

      Of course, these bills have to get out of committee and on to the floor for a vote. If the committee leaders do not allow the bills out of committee, they can not pass. If the leadership in Congress can change in the November mid-term elections, it could be a different story.

      Hope this is helpful. Good luck with you insurance coverage. I will be asking my legislators to support bills that protect consumers like you and me.

  5. This is a Big Shout Out to Senator Mark Montigny!!!! He is the Best. He really looks out for the people. I’ve know him since I was a teenager and I’m 62 now. We Love You Senator Mark Montigny signed Lori Dahlberg.

    1. Yes, in the past he has introduced a bill to protect the biometric data on our licenses from being misused. He has an interest in this and I believe he could work with his colleagues in the legislature for legislation that offers protection to patients.

  6. I received a letter, my husband received a letter. My mom who passed in 2019 and my father who passed in 2016 were also sent a letter! I am very careful with my information ànd I am sick and tired of medical facilities, and credit bureaus having breaches. I do not use a cloud for storage, I do not use a password monitor because I do not want my info out there!

  7. Too bad Montigny doesn’t take his own advice to “stop the bullshit and answer the questions fully “, regarding his picadillos in office!

  8. This is a disaster no one should be signing up for this site, I went for a medical procedure and had to have my daughter bring me and pick me, she had to give information and a sign a document. She doesn’t even go to Hawthorne or have a doctor their and she got a letter saying she was impacted by this breach. Brown Heath is not doing a good job, customer service is horrible, everything is automated, and they keep directing you this site (no one should be signing up for this site).

    1. It is true that all their computer systems need to be better connected. I am hoping that they can solve this problem. It is not the fault of the doctors or support staff.

Comments are closed.