Bayada Home Health Care Breach Exposes Patient Data Via Third-Party Vendor
Law firms are investigating after a Doctor Alliance security incident compromised Social Security numbers and medical records for thousands of patients across 22 states.
Bayada Home Health Care is facing legal scrutiny after a data breach at third-party vendor Doctor Alliance exposed sensitive patient information—including Social Security numbers and medical records—for thousands of individuals across 22 U.S. states.
The security incident occurred at Doctor Alliance between October 31 and November 17, 2025. Bayada began mailing notification letters to affected individuals on January 30, 2026.
What Data Was Compromised
According to law firms investigating the incident, the exposed files contained protected health information (PHI), including names, dates of birth, Social Security numbers, health insurance details, and hospital admission and discharge records. The combination of medical data and government identifiers creates significant long-term risks for victims, including medical identity theft and financial fraud.
Uncertain Scope
The total number of affected individuals remains unverified. Law firm filings suggest more than 14,000 people were impacted, while Claim Depot estimates exceed 25,000. Federman Law's filing references 6,097 Vermont residents specifically. No independently confirmed total across all 22 states has been published.
Bayada, a nonprofit home health care provider, operates in 22 U.S. states and six countries, serving approximately 170,000 people annually.
Legal Response
Multiple law firms have announced investigations into the breach and are seeking to organize class-action lawsuits against Bayada. Sources indicate these investigations remain ongoing rather than formally filed suits.
The incident underscores a growing vulnerability in healthcare's third-party supply chain. Even when a breach originates at a vendor, the primary provider remains legally and reputationally accountable for patient data security.
Broader Implications
Healthcare organizations face increasing pressure to implement rigorous third-party risk management and auditing protocols. The Bayada case illustrates how vendor security failures can cascade into significant liability for providers, regardless of where the initial breach occurred.
Affected individuals who received notification letters should monitor their credit reports and medical statements for suspicious activity.