Community Health Center, Inc.
ent_2f5e542aafe92266d70827ad
Disclosures
18
State AG · HHS OCR · 14 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,060,936
nationwide · State AG RI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Community Health Center, Inc.
- Normalized
- community health center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- chc1.com
Disclosure history (18)newest first
- New Hampshire State AGas reporting2026-08-10
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied protected health information, including names, SSNs, and medical data, between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. One New Hampshire resident was affected. Aesto engaged forensic experts, contained the incident, and notified clients. Credit monitoring services were offered to affected individuals.
- Vermont State AGas victim2026-08-10
Midtown Community Health Center, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-08-10. The reporting organization type is Health Care. 1 Vermont residents were affected. Categories of data breached: Social Security Numbers.
- Massachusetts State AGas victim2026-08-10
Midtown Community Health Center notified patients of a data breach involving their third-party vendor, Aesto, LLC. An unauthorized actor copied protected health information (PHI) and basic identity data from Aesto's AWS infrastructure between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Forensic investigation confirmed data exfiltration. Midtown is offering credit monitoring services to affected individuals.
- Illinois State AGas victim2026-08-01
COMMUNITY HEALTH CENTER OF BUFFALO INC. filed a data-breach notice with the Illinois Attorney General in August 2026 (case 26-08-1390). The register records the breach as discovered on July 20, 2026. Personal information types reported: drivers license, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NEW YORKHHS OCRas victim2026-06-19
Community Health Center of Buffalo Inc. reported to HHS on 2026-06-19 a Hacking/IT Incident affecting 501 individuals. Breached information located on Network Server.
- South Carolina State AGas victim2025-02-03
Community Health Center, Inc. notified patients of a data breach discovered on January 2, 2025, where a hacker accessed systems and exfiltrated personal and health information. The incident was contained within hours. Affected data includes names, SSNs, DOBs, and health records. CHC offered 24 months of credit monitoring via IDX.
- Montana State AGas victim2025-01-31
Community Health Center, Inc. notified patients and guarantors of a data breach discovered on January 2, 2025, where a criminal hacker accessed systems and exfiltrated PHI, SSNs, and financial data. Notices were sent on January 30, 2025, offering 24 months of credit monitoring.
- Massachusetts State AGas victim2025-01-31
Community Health Center, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-01-31. 7,069 Massachusetts residents were affected.
- Rhode Island State AGas victim2025-01-31
Community Health Center, Inc. (CHC) notified the Rhode Island Attorney General of a cybersecurity incident discovered on January 2, 2025. A sophisticated criminal actor accessed CHC's IT systems and exfiltrated electronic health records and personal information, impacting 1,060,936 individuals, including 2,042 Rhode Island residents. Data exposed included names, SSNs, diagnoses, and treatment details. CHC revoked access, engaged forensic investigators, and offered 24 months of identity theft protection to affected individuals.
- New Hampshire State AGas victim2025-01-30
Community Health Center, Inc. (CHC), a federally qualified health center, notified the NH Attorney General of a data breach discovered on January 2, 2025. A sophisticated criminal actor accessed CHC's IT systems and exfiltrated data, likely including the electronic health record database. The actor did not encrypt or delete data. 781 New Hampshire residents were affected. Data included PHI, SSNs, and basic identity information. CHC engaged forensic investigators, contained the breach, and offered identity theft protection services.
- CONNECTICUTHHS OCRas victim2025-01-30
Community Health Center, Inc. reported to HHS on 2025-01-30 a Hacking/IT Incident affecting 1,060,936 individuals. Breached information located on Electronic Medical Record, Network Server.
- California State AGas victim2025-01-30
Community Health Center, Inc. disclosed a data breach where a skilled criminal hacker accessed and exfiltrated patient data, including PHI, SSNs, and health insurance info. The breach occurred on Oct 14, 2024, and was discovered on Jan 2, 2025. The attacker was contained within hours. No ransomware was used. Identity protection services were offered to affected individuals.
- Maryland State AGas victim2025-01-30
Community Health Center, Inc. (CHC), a federally qualified health center, notified the Maryland AG of a cybersecurity incident. On Jan 2, 2025, CHC detected unauthorized access by a sophisticated criminal actor who exfiltrated electronic health records and personal data (including SSNs) from its IT environment. Access was revoked within hours. 752 Maryland residents were affected. CHC retained forensic investigators, notified federal law enforcement, and sent notifications offering 24 months of identity theft prevention services.
- Indiana State AGas victim2025-01-30
Community Health Center Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-14 and was reported on 2025-01-30. 251 Indiana residents were affected. 1,060,936 individuals affected in total.
- Maine State AGas victim2025-01-30
Community Health Center, Inc. reported an external system breach (hacking) occurring on October 14, 2024, discovered on January 2, 2025. The incident affected 1,060,936 individuals nationwide, including 875 Maine residents. Compromised data included PHI, SSNs, names, and financial info. Notices were sent on January 30, 2025, offering 24 months of identity protection.
- Illinois State AGas victim2025-01-01
COMMUNITY HEALTH CENTER, INC filed a data-breach notice with the Illinois Attorney General in January 2025 (case 25-01-116). The register records the breach as discovered on January 2, 2025. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Nebraska State AGas victim2024-01-30
Community Health Center, Inc., a health care entity filed a data breach notification with the Nebraska Attorney General. The breach was discovered on 2024-01-02 according to the AG's register. The breach is dated 2024-10-14. Nebraska residents were notified on 2024-01-30.
- Indiana State AGas victim2022-07-01
Valley Professionals Community Health Center, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-02-26 and was reported on 2022-07-01. 2,785 Indiana residents were affected. 2,806 individuals affected in total.