Healthcare Software Company Announces Data Breach Involving Congress Members PHI
The healthcare software provider RXNT has recently started notifying clients about a security incident that exposed sensitive data. RXNT provides a full suite of software solutions to healthcare providers under the software-as-a-service model, including EHR, ERX, PM, RCM, & billing software.
According to RXNT, hackers gained access to certain systems from March 1 to March 3, 2026, and potentially exfiltrated data from those systems. The investigation and data review were completed on April 17, 2026, when the types of information involved and the clients affected were determined. The company then started notifying the affected clients and has offered to send breach notification letters on their behalf.
RXNT has yet to publicly disclose the number of clients affected or how many individuals had their personal and protected health information compromised in the incident. One of the affected clients was the Office of the Attending Physician (OAP) of the U.S. Congress. OAP was notified about the data breach almost two months after it was first detected by RXNT. Attending Physician Brian Monahan notified the affected members of Congress last week that some of their protected health information was exposed and potentially compromised in the incident.
OAP used RXNT software for communicating prescriptions to pharmacies for fulfilment. OAP entered the minimum necessary information into the platform to allow prescriptions to be fulfilled, and the breach was confined to the RXNT platform. The breach was limited to names, addresses, dates of birth, physician names, and prescription and pharmacy information. OAP has not yet publicly disclosed the number of Congress members affected by the incident.
RXNT said generally, names, dates of birth, and demographic information such as addresses, contact information, and patient IDs were compromised in the incident, and the affected clients were notified on May 1, 2026. The affected clients may accept RNXT’s offer to send notification letters and handle the reporting of the incident to the HHS’ Office for Civil Rights and state attorneys general, or they may choose to issue their own notification letters. Notifications must be issued within 60 days of discovery of a breach of protected health information to meet the requirements of the HIPAA Breach Notification Rule. As such, it may be two months before the full scale of the data breach is known.