Breached law firm exposes hospital records on 13K patients to hackers

Data from nearly 13,000 patients in New Jersey was exposed as a result of a cyberattack on a law firm that represents some of the state’s largest hospitals, incidentally reminding watchers that sensitive medical information flows between more than just healthcare entities.

Greenbaum Rowe Smith & Davis provided more details in a online notice, revealing that an unauthorized third party gained access to its network in November 2025 after login credentials from a user were successfully compromised. 

The intrusion could have lasted as long as two days, with the firm saying it discovered the intrusion on Nov. 27, 2025. It added that it took “immediate measures to secure its environment," including resetting passwords and notifying law enforcement.

Greenbaum also stated that it outright replaced “compromised machines,” possibly signaling the use of some kind of malware. However, that was not confirmed in the announcement.

As it began to investigate the incident, the firm said it enlisted the support of an outside cybersecurity group. After a comprehensive review to determine the scope of the data breach, it was determined that files from provider groups linked to Greenbaum were compromised, meaning protected health information was likely in the hands of hackers. 

Stolen information included the names and addresses of patients, provider names, medical record numbers, patient medical histories and billing details. Greenbaum added that a "subset of individuals” may have also had their Social Security numbers taken in the breach, along with their dates of birth. 

The investigation concluded in April and the incident was recently reported to the U.S. Department of Health and Human Services’ Office for Civil Rights' healthcare data breach tracker, which pegs the headcount of victims at 12,081. 

Victims will be notified by the firm directly in the form of a mailed letter, the group confirmed. It added that it has seen no evidence that compromised data has been used for identity theft, blackmail or any other nefarious purpose.

As a precaution, it’s offering free identity monitoring services to all victims, should they wish to sign up.

No cybercrime cell has taken credit for the attack, and no data trove stemming from the incident has been discovered on the dark web.

Subscribe to Health Exec News

Bolstering defenses

On its end, Greenbaum said it “enhanced its cybersecurity by adding additional monitoring and detection tools as safeguards against future cyber threats.” 

“Greenbaum regularly reviews its physical and electronic safeguards to protect personal information, and it will continue to take appropriate steps to safeguard personal information and its systems,” the firm wrote. 

Founded in 1914, Greenbaum operates all over the state. Some of its healthcare clients include Trinitas Regional Medical Center and Hackensack Meridian Health. 

It’s unclear what organizations were directly impacted as a result of the breach. 

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Subscribe to Health Exec News

Subscribe to Health Exec News