Covenant Health, Inc. Data Breach Exposes Sensitive Patient Records
Covenant Health, Inc. in Montana reported a data breach in January 2026, stemming from an incident in May 2025, that compromised sensitive patient information. This exposure could lead to serious risks for affected individuals, including identity theft and medical fraud.
Received a Covenant Health, Inc. notification letter? Find out in minutes if you qualify for compensation.
Free case review- State
- Montana
- Breach date
- May 18, 2025
- Reported
- January 2, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
Covenant Health, Inc., a healthcare provider operating in Montana, recently disclosed a data breach that began on May 18, 2025. The company officially reported this incident on January 2, 2026, confirming unauthorized access to its network infrastructure.
This security incident led to the exposure of highly sensitive personal and health information. The compromised data includes Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. Such deeply personal details, once exposed, carry significant long-term risks.
The exposure of these specific data types can make individuals vulnerable to various forms of harm. For instance, Social Security Numbers and Full Names are prime targets for identity theft, while compromised health information like Diagnosis and Treatment Information or Health Insurance ID Numbers can be exploited for medical fraud or unauthorized billing, creating enduring problems for victims.
Organizations like Covenant Health, Inc. are entrusted with safeguarding patient data through robust security measures. A data breach of this nature suggests that these critical protections may have been insufficient, leaving confidential health records vulnerable to unauthorized access.
If you have received a notification letter from Covenant Health, Inc. regarding this breach, it confirms that your personal information was indeed compromised. This formal notice provides you with the legal standing to explore your options. Our team is actively investigating claims against Covenant Health, Inc. to assist those affected, and we offer free case reviews to help you understand your legal recourse.
Received the Covenant Health, Inc. notification letter? The Covenant Health, Inc. case file tracks this filing.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Montana Attorney General filing
Related data breach cases
- MemberSource Credit Union
- MemberSource Credit Union
- GrayRobinson P.A.
- GrayRobinson P.A.
- First Advantage Corporation
- County of Murray dba Murray County Medical Center
- County of Murray dba Murray County Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Brett Robinson Vacation Rentals
- Standard Sales Company, LP
- Clackamas Community College