CardioFit Medical Group, Inc. disclosed that between January 8 and February 5, 2026, protected health information was sent via unencrypted email. The incident was discovered on February 17, 2026. Affected data included names, demographic details, clinical information (diagnosis), and insurance information. No SSNs, bank accounts, or credit cards were involved. The organization strengthened email encryption procedures and provided staff training.