Skip to main content
Jump to a category page

Paradigm Healthcare Services, a company that processes Medi-Cal billing for California schools and health providers, knew intruders were in its systems while the access was still happening — and waited 336 days to notify the people affected.

Paradigm Healthcare Services, a Medi-Cal billing processor that works under a Data Use Agreement with the California Department of Health Care Services, reported a data breach to the California Attorney General on September 14, 2026. According to Paradigm’s own notice letter, unauthorized access to its systems began on October 8, 2025. Paradigm became aware of the intrusion just five days later, on October 13, 2025 — while the unauthorized access was still ongoing. Access ended on October 15, 2025.

Source: California Attorney General breach notification, report sb24-629754, reported 09/14/2026; Paradigm Healthcare Services’ own notice letter (PHS_Redacted_Notice_Letter_40106534v1.pdf).

A 309-Day Gap the Company Can’t Blame on Slow Detection

What makes this case unusual isn’t how long it took to detect the intrusion — Paradigm caught it within days, while it was still happening. What took nearly a year was determining that protected health information was involved. Paradigm didn’t make that determination until August 18, 2026 — 309 days after it first became aware of the breach. Notice to affected individuals followed September 14, 2026, bringing the total gap from awareness to notice to 336 days. Because Paradigm knew about the intrusion from nearly the beginning, this delay can’t be explained away as a detection problem.

What Information Was Exposed?

According to Paradigm’s own notice letter, the exposed information includes:

  • Full name
  • Date of birth
  • Gender
  • Medi-Cal member identification number

A Billing Processor for School-Based Medi-Cal Services

Paradigm Healthcare Services describes its own work as billing support for school-based Medi-Cal services — meaning a meaningful share of the people affected may be children and their families enrolled in Medi-Cal through their school district, rather than adult patients dealing directly with a healthcare provider. Notably, the notice letter attached to Paradigm’s California filing is titled as an adult-version letter, which raises the question of whether a separate notice for minors exists and who is receiving it.

How Many People Are Affected?

Paradigm has not disclosed a total number of affected individuals in its notice letter or in its filing with the California Attorney General. Given that Medi-Cal is California’s Medicaid program serving millions of low-income residents, and Paradigm processes billing on the state’s behalf, the scope could be substantial — but no figure has been made public.

Do You Have Legal Options?

Companies that process Medi-Cal billing and hold sensitive member information have a legal duty to secure it and to notify affected individuals without unreasonable delay — and knowing about an intrusion for nearly a year before notifying anyone is the kind of delay breach-notification laws exist to prevent.

If you or your child received a notice letter from Paradigm Healthcare Services, contact Emery | Reddy today for a Free Case Review.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

Who is affected by the Paradigm Healthcare Services data breach?

Medi-Cal members whose billing information Paradigm processes, including through school-based Medi-Cal billing arrangements. Paradigm has not disclosed a total number of affected individuals.

What information was exposed?

According to Paradigm’s own notice letter, the exposed data includes full name, date of birth, gender, and Medi-Cal member identification number.

Why did it take so long to be notified?

Paradigm became aware of the intrusion on October 13, 2025, while it was still happening, but didn’t determine that protected health information was involved until August 18, 2026 — 309 days later. Notice followed on September 14, 2026, for a total gap of 336 days from awareness to notice.

My child is on Medi-Cal through their school. Could they be affected?

Possibly. Paradigm processes school-based Medi-Cal billing, and the notice letter on file with California regulators appears to be an adult-specific version, which raises questions about whether a separate notice exists for minors. If your child receives Medi-Cal services through their school and you’re unsure whether they’re affected, contact us.

Do I have a legal claim?

Companies that process Medi-Cal billing and hold sensitive member information have a legal duty to secure it and to notify affected individuals without unreasonable delay. If you or your child received a notice letter from Paradigm Healthcare Services, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now