Almeida Law Group is investigating a data breach at BAYADA Home Health Care, Inc. The breach occurred on March 2nd, 2026. If you were affected, contact Almeida Law Group.
About BAYADA Home Health Care, Inc.
BAYADA Home Health Care is an international nonprofit organization founded in 1975, headquartered in the Philadelphia, PA area with its Global Support Center at 4300 Haddonfield Road in Pennsauken, NJ. The company provides nursing, rehabilitative, therapeutic, hospice, assistive, companion, and pediatric home health care services across more than 360 offices in 23 U.S. states and several countries, employing more than 28,000 health care professionals and serving nearly 170,000 people per year. Because BAYADA delivers direct patient care and manages clinical records, it holds sensitive health and personal information for a large population of patients and their families.
What Happened?
BAYADA Home Health Care, Inc. was listed in a California Attorney General sample breach notice filed on July 17th, 2026. According to that notice and BAYADA’s own public website disclosure, an unauthorized actor gained access to certain BAYADA systems and copied data between February 18th, 2026 and March 2nd, 2026, when the incident was discovered. BAYADA engaged third-party forensic specialists and, after completing the investigation, retained data review specialists to identify affected individuals. That review was completed on July 1st, 2026, and notification letters were sent on July 17th, 2026 — approximately four and a half months after discovery. BAYADA reported the event to federal law enforcement and the U.S. Department of Health and Human Services. Credit monitoring services are being offered through Cyberscout, a TransUnion company, with a 90-day enrollment window from the date of the notification letter. The total number of persons affected was not specified in the filing.
Potentially affected information, per BAYADA’s own website notice, includes names, dates of birth, diagnosis and treatment information, provider information, health insurance plan information, prescription information, hospital admission and discharge information, disability information, and Social Security numbers. Individual notification letters specify which data elements applied to each recipient.
This is the second BAYADA data breach disclosed in 2026. A separate, earlier incident involved BAYADA’s third-party vendor Doctor Alliance, where an unauthorized actor accessed Doctor Alliance’s systems between October 31st and November 6th, 2025, and again between November 14th and November 17th, 2025, potentially accessing Home Health Certification and Plan of Care forms. That incident affected 9,526 individuals and did not involve BAYADA’s own systems. BAYADA discontinued its use of Doctor Alliance following that event. The current March 2026 breach is a direct compromise of BAYADA’s own systems and is a separate incident. No ransomware group has been publicly linked to the March 2026 breach. Law firms including ClassAction.org (sponsored by Bryson Harris Suciu & DeMay PLLC) and Shamis & Gentile P.A. are publicly investigating the March 2026 breach for potential class action filing, though no complaint had been filed as of the research date.
Key Facts at a Glance
- Company or Organization: BAYADA Home Health Care, Inc.
- Industry: Home Health Care / Healthcare Services (Nonprofit)
- Location: Pennsauken, NJ (Global Support Center); suburban Philadelphia, PA (headquarters); operates in 23 U.S. states and 6 countries
- Incident type: Unauthorized access to company systems; data copied
- Date of breach: February 18th, 2026 (unauthorized access began)
- Date breach discovered: March 2nd, 2026
- Date of consumer notification: July 17th, 2026
- Identity theft protection offered: Single Bureau Credit Monitoring, Credit Report, and Credit Score services via Cyberscout (a TransUnion company)
- Enrollment deadline: 90 days from July 17th, 2026 (on or before October 15th, 2026)
- Prior breach: Yes — separate Doctor Alliance vendor breach (October–November 2025), affecting 9,526 individuals; disclosed January/February 2026
- Litigation status: No class action filed for the March 2026 breach as of research date; attorney investigations underway by Bryson Harris Suciu & DeMay PLLC and Shamis & Gentile P.A.
- Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-626658); BAYADA website breach notice (https://assets.ctfassets.net/i5kkknzh1ywi/1vr35e8sF5YaIsIunkXMvS/50344281e4116d002e7b9b9b9fcf77d5/bayada-notice-of-a-recent-data-privacy-event_.pdf); ClassAction.org investigation (https://www.classaction.org/data-breach-lawsuits/bayada-home-health-care-may-2026)
What Should You Do?
If you received a notification letter from BAYADA, enroll in the free credit monitoring services offered through Cyberscout at https://bfs.cyberscout.com/activate using the unique code provided in your letter — you have 90 days from July 17th, 2026 to enroll. You should also consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to make it harder for someone to open new accounts in your name. Review your free annual credit reports at AnnualCreditReport.com and monitor them regularly for unfamiliar accounts or inquiries. Because health information was involved in this breach, carefully review your Explanation of Benefits statements from your health insurer and check your medical records for any services you do not recognize — this can be an early sign of medical identity theft. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step recovery guidance.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.