Project Belle, LLC, a healthcare provider, told federal regulators that an incident involving email exposed protected health information belonging to 840 people. The company has not publicly said what happened, when it happened or what information was involved.
What Project Belle Reported to Federal Regulators
Healthcare providers must report breaches of protected health information affecting 500 or more people to the U.S. Department of Health and Human Services (HHS). HHS posts those reports on its public breach portal.
According to that portal, Project Belle, LLC filed a report on September 17, 2026. The listing shows:
- Type of entity: Healthcare provider
- State: New Hampshire
- People affected: 840
- Type of breach: Unauthorized access or disclosure
- Where the information was: Email
No public notice letter, website notice or press report about the incident has been found.
What the HHS Listing Does and Does Not Say
HHS uses separate categories for hacking incidents and for “unauthorized access or disclosure.” The second category can cover health information sent to the wrong person or viewed by someone who was not allowed to see it. Project Belle has not said which applies here.
The listing does not give the date of the incident, when Project Belle discovered it, or which types of information were involved.
What Information Was Exposed?
Project Belle has not publicly listed the information involved. Because the report was filed with HHS, it concerns protected health information, which can include names, dates of birth, medical records, treatment details and health insurance information. People who received a letter should check it for the exact information that applies to them.
What Is Project Belle Offering?
No public notice describing an offer of credit monitoring or identity protection has been found. People who received a letter should check it for any offer and its enrollment deadline.
Your Information Is at Risk
Health information can be used for medical identity theft, where someone gets care, prescriptions or insurance payments in another person’s name. That can leave false entries in medical records and bills the patient did not run up. Unlike a credit card, a medical history cannot be replaced.
Do You Have Legal Options?
Healthcare providers have a duty under federal and state law to protect patients’ health information and to notify them promptly when it is exposed. When that obligation is not met, affected individuals may have legal rights and remedies worth discussing with an attorney. Emery | Reddy is investigating this incident on behalf of people who received a notice letter.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review. No Fee Unless We Recover.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Frequently Asked Questions
Did Project Belle have a data breach?
Project Belle, LLC reported a breach of protected health information to HHS on September 17, 2026. The report lists 840 people and an unauthorized access or disclosure involving email.
How many people were affected?
840 people, according to the HHS breach portal.
What information was exposed?
Project Belle has not said publicly. The report concerns protected health information. Check your letter for the exact information involved.
When did the breach happen?
Project Belle has not said. The HHS report was filed September 17, 2026, but it does not give the date of the incident.
What are the risks when medical information is exposed?
Medical information can be used for medical identity theft, where someone gets care, prescriptions or insurance payments in your name. Check your Explanation of Benefits statements for care you did not receive.
How do I protect myself from scams that mention the breach?
Be cautious with any call, email or text that mentions Project Belle or the breach. Do not share personal or health information with anyone who contacts you. Use only the contact information printed on your letter.
What should I do if I received a letter?
Take these steps:
- Read the letter for the information involved and any monitoring offer
- Review your Explanation of Benefits statements and medical bills
- Place a free credit freeze with Equifax, Experian and TransUnion
- Be wary of calls, texts or emails that mention the breach
- Keep your letter
Do I have a legal claim?
You may. Healthcare providers have a duty to protect patients’ health information and to notify them promptly when it is exposed. If you received a Notice of Data Breach letter from Project Belle, Emery | Reddy at 916.995.5968 or visit emeryreddy.com for a Free Case Review to see what you may qualify for. No Fee Unless We Recover.