Gastroenterology & Hepatology of Central New York is notifying patients about a cybersecurity incident that resulted in unauthorized access to its network and exfiltration of files. The practice identified the incident on March 6, 2026 and engaged cybersecurity and digital forensics specialists to investigate. The affected files contained patients’ names, addresses, phone numbers, dates of birth, Social Security numbers and medical record numbers. Patients were notified on September 17, with complimentary credit monitoring and identity-theft protection offered. The number of affected individuals has not yet been disclosed, and the incident was not listed on the HHS Office for Civil Rights breach portal at the time of the report.
The incident is particularly relevant to GI practices because it illustrates the cybersecurity exposure associated with storing and managing sensitive clinical and personally identifiable information. The broader report also describes breaches involving two hospice/home-care organizations, including one involving an electronic medical record vendor.

