A cybersecurity incident at a vendor’s system happened in late November 2025. Silver Summit Medical Corporation says it did not learn about it until July 2026, and patients are only now finding out their health information may be at risk.
Silver Summit Medical Corporation, which does business as Digestive Disease Center and Heart Vascular & Leg Center in Bakersfield, California, has notified patients of a data breach that exposed their personal and health information. The company says a third-party vendor’s cybersecurity event affected personal or protected health information that the vendor received from SSMC. According to the notice, an unauthorized party acquired data from the vendor’s systems between November 27 and November 30, 2025.
SSMC states it became aware of the incident on or about July 20, 2026, roughly seven and a half months after the vendor breach occurred. The company sent notice to affected patients and reported the incident to the California Attorney General on August 19, 2026, about one month after it says it learned of the problem.
A Long Gap Between the Breach and the Notice
The most striking fact in this case is the timeline. Data was taken from a vendor’s systems in late November 2025. Patients did not receive any notice until nearly nine months later, in August 2026. SSMC’s own account splits that gap into two parts: about seven and a half months before the company says it found out about the vendor’s breach, and about one more month between that discovery and the notice patients received.
A delay of this length matters because it leaves patients unable to watch for fraud, medical identity theft, or suspicious account activity connected to the breach for most of that time. Patients have no way to know whether their information was misused during the months before they were told anything was wrong.
What Information Was Exposed?
The version of the notice letter posted to the California Attorney General’s website leaves the list of exposed data categories blank, a placeholder field that was not filled in before the sample was published. What the letter does confirm is that the exposed information includes each patient’s name, along with personal information and protected health information tied to their care at SSMC’s practices. SSMC has not made the specific data categories, such as Social Security numbers, dates of birth, insurance details, or diagnosis codes, publicly available at this time.
- Name (confirmed in the notice)
- Personal and/or protected health information connected to care at Digestive Disease Center or Heart Vascular & Leg Center (specific categories not itemized in the posted notice)
What Is Silver Summit Offering?
SSMC is offering twelve months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company. Patients who want to enroll must do so within 90 days of the date on their notice letter by visiting bfs.cyberscout.com/activate and entering the unique code included in their letter. Patients with questions can call SSMC’s assistance line at 1-833-851-8539, Monday through Friday from 8:00 a.m. to 8:00 p.m., or write to 1400 Easton Drive, Suite 106, Bakersfield, CA 93309.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
Do You Have Legal Options?
Healthcare providers and the vendors they rely on have a legal duty to safeguard patient information. Patients affected by this breach may have rights and remedies under California and federal law, including claims tied to the length of time it took SSMC to learn about and disclose the incident.
If you are a patient of Digestive Disease Center or Heart Vascular & Leg Center and believe your information was affected, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.
Frequently Asked Questions
How many people were affected by the Silver Summit Medical Corporation breach?
SSMC has not disclosed a total number of affected patients. The breach was reported to the California Attorney General as part of the state’s routine notification process, but no population figure has been made public as of this writing.
What happened, and when?
A third-party vendor’s systems were accessed without authorization between November 27 and November 30, 2025. SSMC says it became aware of the incident on or about July 20, 2026, and notified affected patients and the California Attorney General on August 19, 2026.
Why did it take so long to notify patients?
SSMC has not publicly explained why nearly eight months passed between the vendor incident and the company’s stated discovery date. The gap between SSMC’s own awareness and the notice to patients was about one month.
What should I do if I received this notice, or if I am a patient of these practices?
Consider enrolling in the free credit monitoring services SSMC is offering before the 90-day enrollment window closes. Watch your financial accounts, insurance statements, and credit reports for unfamiliar activity. Keep a copy of your notice letter, and consider speaking with a data breach attorney about your options.
Do I have a legal claim?
You may. Healthcare providers and their vendors are required by law to protect patient data, and a lengthy delay in discovering or disclosing a breach can be relevant to that obligation. Contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or emeryreddy.com for a Free Case Review. No Fee Unless We Recover.