Seattle-based MCG Health, LLC (MCG) provides patient care guidelines to providers and health care plans. According to a observation on their website that was also issued as a pressure release yesterday, on march 25, 2022, they determined that an unauthorized party had previously obtained personal information about some patients and members of certain MCG customers. The affected patient or member data reportedly included some or all of the following data elements: names, Social security numbers, medical codes, postal addresses, telephone numbers, email addresses, dates of birth, and gender. Their full statement can be found on their site (pdf) or on �businesswire.com. Their instruction omits significant details, and DataBreaches has sent an inquiry to them asking them when and how the bad player first gained access to their system, how many people, total, had their data accessed and how many people, total, had their data exfiltrated. DataBreaches also inquired as to whether HHS has been notified, and whether there was any ransom or extortion demand. Although their statement does not mention any data being leaked or sold on the dark web, it may be that they first “determined” the breach in march because data was listed for sale at that time. Hopefully, they will forthrightly confirm or deny that, and will explain whether they will be offering any credit monitoring or identity theft restitution services to those affected. Their press liberate makes no mention of any such offer. No reaction to our inquiries was immediately available, but this carry will be updated as more information becomes available.