Skip to main content
Jump to a category page

Kaniksu Community Health, a federally qualified health center serving rural northern Idaho, reported a data breach to California regulators nearly eight and a half months after the breach occurred.

Kaniksu Community Health, also known as Kaniksu Health Services, is a Federally Qualified Health Center operating clinic sites in Sandpoint, Ponderay, Priest River, and Bonners Ferry, Idaho, providing primary care, dental, and behavioral health services across Bonner and Boundary Counties. Kaniksu reported a data breach to the California Attorney General on September 1, 2026, with a breach date of December 18, 2025.

Source: California Attorney General data-breach notification list (reported 09/01/2026, breach date 12/18/2025).

An Eight-And-A-Half-Month Gap

The roughly eight-and-a-half-month interval between the December 18, 2025 breach date and the September 1, 2026 regulatory filing is a substantial delay on its face. Kaniksu’s filing does not disclose when the breach was discovered, so it’s not yet clear how much of that gap reflects detection time versus notification time. Emery | Reddy is looking into the reason for the delay.

What Information Was Exposed?

Kaniksu’s California regulatory filing does not itemize the specific categories of information involved. As a healthcare provider, the records it maintains typically include names, dates of birth, and medical and insurance information; Kaniksu has not confirmed which specific categories were part of this breach.

How Many People Are Affected?

Kaniksu has not disclosed a total number of affected individuals. The California filing confirms a subset of affected California residents but does not quantify it. Kaniksu serves a rural patient population primarily in Idaho, so the full number of people affected is likely larger than any California-specific figure.

What Is Kaniksu Offering Affected Individuals?

Kaniksu has not publicly disclosed whether it is offering credit monitoring or identity protection services. Anyone who received a notice letter should review it directly for enrollment instructions or contact information specific to the offer made to them.

Your Information Is at Risk

Even without a confirmed list of exposed data categories, healthcare records generally include sensitive personal and medical information that can be used for identity theft or medical identity theft, including someone using your insurance information to obtain treatment in your name. Affected individuals should watch for a notice letter and monitor financial accounts and insurance statements for unfamiliar activity.

Do You Have Legal Options?

Healthcare providers that collect and store patient information have a legal duty to secure that data and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from Kaniksu Community Health.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

Who is affected by the Kaniksu Community Health data breach?

Kaniksu has not disclosed a total number of affected individuals. Its California filing confirms a subset of California residents, but Kaniksu’s patient base is concentrated in Bonner and Boundary Counties, Idaho.

What information was exposed?

Kaniksu’s regulatory filing does not itemize specific data categories. As a healthcare provider, the records it holds typically include personal and medical information; the specific categories involved in this breach have not been confirmed.

When did the breach happen, and why did it take so long to find out?

Kaniksu reported a breach date of December 18, 2025, but did not file with California regulators until September 1, 2026, roughly eight and a half months later. Kaniksu has not disclosed a discovery date or explained the reason for the gap.

Is Kaniksu offering credit monitoring?

That has not been publicly disclosed. If you received a notice letter, check it directly for enrollment instructions or contact information.

Do I have a legal claim?

Healthcare providers that collect and store patient information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you received a notice letter from Kaniksu Community Health, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now