Hello Cake, Inc. disclosed a data breach involving a single file stored in a cloud-based system that had incorrect access settings following a routine migration. An unauthorized third party accessed and copied the file on July 25, 2025. The file contained personal information including full name, potentially date of birth, and prescription-related information (medication name and identifier) for telehealth consultations. No SSN, driver's license, or financial account information was involved. The company corrected the settings, removed the file, and engaged third-party cybersecurity experts.