ALN Medical Management Data Breach Affected 1.8 Million People
In March 2024, the Nebraska healthcare revenue cycle management and billing services provider ALN Medical Management fell victim to a hacking incident. According to its breach notification letters, an unauthorized actor accessed certain systems hosted by a third-party service provider between March 18, 2024, and March 24, 2024, and files within those systems were either accessed or acquired. No internal ALN Medical Management systems were affected.
ALN Medical Management said it began “an extensive review of those files and folders to determine whether sensitive information was involved.” In March 2025, one year after the breach occurred, ALN Medical Management notified state attorneys general about the data breach and confirmed the types of data involved; however, the scale of the data breach has only recently been confirmed.
Over the past few days, ALN Medical Management has provided supplemental notices to state attorneys general about the data breach, and the HHS’ Office for Civil Rights has been provided with a new total for the number of affected individuals. The data breach was first reported to OCR on May 23, 2024, using a placeholder figure of 501 affected individuals. OCR has now been informed that the data breach affected 1,823,844 individuals.
The data compromised in the incident includes names, Social Security numbers, driving license numbers, government-issued ID numbers such as passports and state ID cards, financial information such as credit/debit card numbers and bank account numbers, health insurance information, and medical information. ALN Medical Management said it is offering 12 or 24 months of free credit monitoring and identity theft protection services to the affected individuals and has taken steps to improve its security posture to prevent similar incidents in the future.
The data breach is listed in the archive section of the HHS’ breach portal, which contains all resolved breach reports and any reports older than 24 months. Since the breach report is not older than 24 months, it suggests OCR has reviewed the incident and chose not to take any action. The data breach ranks as one of the top 15 healthcare data breaches of 2024 and one of the 10 largest business associate data breaches of the year. Several class action lawsuits have already been filed over the data breach, and many law firms have opened investigations into potential litigation.