Check Your Claims
← Settlements/Data Privacy

Secure Healthcare Information Management data breach investigation

SHIM reports unauthorized access to personal and health information in July 2026. Its protection-service enrollment deadline is January 4, 2027, not a settlement claim deadline.

Updated October 8, 2026

Company under investigation
Secure Healthcare Information Management, LLC
Status
Under investigation
Potential compensation
No established cash payment
How to join
Request attorney evaluation; not a settlement claim
Case type
Attorney investigation
Check if you qualify →

Overview

Reported access window
July 6–16, 2026
Individual notices
Mailed October 6, 2026 where addresses were available
Service enrollment
January 4, 2027; not a settlement claim deadline

Secure Healthcare Information Management, LLC, abbreviated SHIM, reports that an unknown actor accessed or acquired certain personal information without authorization between July 6 and July 16, 2026. The company is a billing and medical management service provider for independent physicians and medical institutions in Northeastern Pennsylvania. Patients may encounter the consequences through an incident letter rather than through a familiar medical office's name.

SHIM mailed notices October 6, 2026 and offers eligible people complimentary identity protection through Cyberscout. Its company-issued release gives January 4, 2027 as the service-enrollment deadline. Attorneys are collecting inquiries in an investigation published October 7. The reported incident is supported by SHIM's disclosures; no court-approved settlement or cash payment is established. Sources were reviewed October 8, 2026.

Who the parties are

SHIM handles billing and medical management for healthcare practices and institutions. Its operational role explains why information linked to care, insurance and patient identity may be in its files even when a patient does not directly hire the company. SHIM is the organization reporting this event; the reviewed disclosures do not list every client practice whose patients may be involved.

Cyberscout is the identity protection and fraud-assistance provider identified in SHIM's notice. The company describes it as a TransUnion company specializing in fraud assistance and remediation. TransUnion is a consumer credit-reporting company. These organizations' service roles do not make them settlement administrators for this event.

The U.S. Department of Health and Human Services Office for Civil Rights is the federal office to which SHIM says it reported the incident. Reporting to that office does not establish a regulatory finding. Bryson Harris Suciu & DeMay PLLC sponsors the recruiting investigation listed by ClassAction.org. No named plaintiff, defendant in a verified pleading or assigned court is established in this source record.

What happened

SHIM's October 6 notice gives a dated sequence. It experienced a network disruption July 17, 2026 and began an investigation with cybersecurity experts. It says that investigation found unauthorized access or acquisition at some point between July 6 and July 16. The disruption date and access window are separate facts.

The company then reviewed the affected files to determine whether they contained personal information. On September 18, it confirmed the scope of impact and obtained sufficient information to notify potentially affected people. On October 6, it mailed notices to those for whom it had identifiable addresses. The attorney investigation page appeared October 7. The public materials do not identify the actor, technical entry method, client-by-client breakdown or number of affected people.

What each side says

SHIM says the incident may have involved personal or protected health information. Its possible categories include names, dates of birth, Social Security numbers, driver's license or state identification numbers, medical information and insurance information. The company says it reported the event to the HHS Office for Civil Rights and consumer reporting agencies and implemented measures intended to reduce the risk of similar incidents. It does not describe those measures in enough detail to evaluate them independently.

The recruiting attorneys say they are investigating whether a class action can be filed and seek affected individuals. The page discusses possible compensation if a case is filed and succeeds. No verified complaint supplies a plaintiff's legal allegations here, and SHIM's disclosures do not provide a response to particular legal counts. A company report of unauthorized access is not itself an admission of negligence or a promise to pay damages.

What the court has and has not decided

The notice, release and recruiting page reviewed do not establish a court, case number, certified class, settlement agreement or damages ruling for this investigation. A class action allows claims on behalf of a defined group only through the relevant court procedures. A lawyer's request for inquiries does not supply those decisions.

There is no identified court order approving the service offer as a settlement benefit or giving recipients a right to cash. Nor does the company statement that it reported the incident establish a regulator's finding that a law was violated. The article is limited to the documents reviewed; it does not assert the absence of every possible related filing elsewhere.

Who may qualify

  • You may request an evaluation if your information was potentially involved in SHIM's July 2026 incident.
  • SHIM serves independent physicians and medical institutions in Northeastern Pennsylvania. You may recognize your healthcare provider rather than this billing company.
  • The notice lists possible identifying, medical and insurance information. It does not confirm every category for every person or publish a court-defined class.
  • People without a notification letter must obtain verification through SHIM's call center before enrolling in company-offered services, according to its release.

The current opportunity is an evaluation for people whose information may have been involved in SHIM's incident. A notification letter is useful evidence. The disclosure describes SHIM's healthcare-client role but does not publish a complete list of affected providers or restrict a court-approved class to Pennsylvania residents. Do not assume your residence alone establishes inclusion or exclusion.

SHIM lists possible fields, not a finding that every listed identifier was involved for every person. A personal notice or response from the incident call center may be more specific than the public announcement. No settlement proof-of-loss standard, class period or material exclusion list is established.

For company services, the company-issued release says people without a notification letter must obtain eligibility verification through the call center before enrollment. That service-verification requirement is different from qualifying for legal representation or money.

What affected readers can do now

Read and retain your letter, if one arrives, and compare it with SHIM's official notice. SHIM lists 1-833-516-7420 for its incident call center, Monday through Friday, 8 a.m. to 8 p.m. Eastern Time, excluding major U.S. holidays. Ask the verified center about the information involved and service enrollment, particularly if you have not received a letter.

The notice recommends reviewing financial accounts and credit reports, reporting suspicious activity and considering fraud alerts or freezes. A fraud alert asks prospective creditors to take steps to verify identity. A credit freeze restricts access to a credit report. Neither is a settlement filing.

If seeking legal evaluation, use the cited recruiting page and read its terms. This site's inquiry form does not send a claim to SHIM or enroll you with Cyberscout. Keep sensitive identifiers and medical records out of an initial general message; use a verified secure process if documentation is later requested.

What you could receive

Company response

Complimentary Cyberscout services

Eligible affected individuals may enroll in identity protection through Cyberscout. SHIM's release gives January 4, 2027 as the enrollment deadline; people without letters need call-center eligibility verification.

Legal evaluation

No established cash recovery

The investigation seeks potentially affected people. No settlement fund, payment amount or guaranteed representation is established. Service enrollment is not a lawsuit or settlement claim.

The verified company offer is complimentary identity protection through Cyberscout for eligible individuals. SHIM's release says all affected individuals may qualify, subject to verification when no letter has arrived. The reviewed announcement does not state the service duration, every included feature or a cash alternative. Request the actual enrollment terms rather than assuming a standard package.

No cash recovery is established for the investigation. There is no verified settlement fund, individual payment, loss reimbursement limit or option-combination rule. The company service offer is not a damages award. The reviewed disclosures do not provide a release of claims tied to enrollment, so this article does not make a legal conclusion about whether accepting services changes any particular rights.

Important dates and rights

The reported access window is July 6 through July 16, 2026. SHIM noticed a network disruption July 17, confirmed scope September 18 and mailed notifications October 6. Its release specifies January 4, 2027 for enrollment in complimentary identity protection. That date belongs to the company response, not a settlement cash claim, and should not be confused with a lawsuit limitation period.

The reviewed sources identify no claim, objection, exclusion or final approval hearing deadline for a settlement. Opting out means formally excluding yourself from a defined settlement class through the stated process; no such process is established here. Individual legal deadlines can differ. Requesting contact does not stop them, file a case or automatically create an attorney-client relationship.

Definitions

Protected health information is identifying information connected to care or health coverage. A billing and medical management company performs administrative work for providers and can hold information outside the doctor's own office. Unauthorized acquisition means information was obtained without permission; access and acquisition need not describe identical events.

Identity protection is a service offering whose actual scope depends on its terms. Remediation means assistance addressing an identified problem, rather than a guarantee that harm will never occur. A legal investigation assesses possible claims. A certified class is a group a court authorizes to pursue claims collectively under applicable rules; it is not created by completing an online contact form.

What happens next

Potentially affected people can follow SHIM's notification and service instructions before the stated enrollment date. The public materials do not promise when an individual letter will arrive, name every affected provider or establish that every possible data field was involved for every person. The call center is the company-designated path for questions.

The attorneys may assess records and decide whether to bring litigation. Filing, class certification, liability and compensation remain uncertain. Pulse's practical note is to label January 4 as a protection-service enrollment date in your records, not a cash-claim date. Preserve the letter and any documented incident-related issues so a future evaluation rests on your actual circumstances.

Sources and evidence boundaries

SHIM's notice supports its identity, incident sequence, possible fields, reporting and call-center details. Its company-issued release corroborates that account and adds the January 4 enrollment deadline and verification process for people without letters. The attorney page establishes active recruiting and its sponsor. None establishes a court judgment, settlement amount, affected-person total or particular individual's compensable harm.

Class Action Pulse is not a law firm or settlement administrator, does not guarantee eligibility or payment, and directs readers to official materials. This article provides legal information rather than individualized legal advice.

Frequently asked questions

Is January 4, 2027 a settlement claim deadline?

No. SHIM's company-issued release identifies it as the deadline to enroll in complimentary identity protection services. No cash settlement is established.

Can I ask about services without a letter?

Yes. The release says people who have not received a notice must obtain eligibility verification through SHIM's call center before enrolling.

Why might SHIM have information if I never dealt with it?

SHIM provides billing and medical management for healthcare practices and institutions. Its role can place information with a service provider a patient does not directly recognize.

Has a regulator found SHIM liable?

The company says it reported the incident to the HHS Office for Civil Rights and consumer reporting agencies. Reporting is not a finding of a violation, and no such ruling is established in the reviewed sources.

Sources

This is an attorney investigation, not an open settlement claim process. Class Action Pulse is not a law firm. An inquiry requests follow-up; it does not file a claim, guarantee a firm connection or establish representation.

Free Eligibility Check

Do you qualify?

Check your eligibility and get help understanding your claim. It's free and takes under a minute.

Class Action Pulse is not a law firm and does not provide legal advice. Submitting this form does not create an attorney–client relationship. This is attorney advertising.