Almeida Law Group is investigating a data breach at Cherry Street Services, Inc. The breach occurred on an unspecified date and was discovered on an unspecified date. If you were affected, contact Almeida Law Group.
About Cherry Street Services, Inc.
Cherry Street Services, Inc. operates as Cherry Health, a nonprofit Federally Qualified Health Center (FQHC) based in Grand Rapids, Michigan. Founded in 1988, Cherry Health is the largest FQHC in Michigan, serving patients across Barry, Kent, Montcalm, Muskegon, Ottawa, and Wayne counties through more than 20 locations. It offers a broad range of services including primary care, behavioral health, dental, pharmacy, and substance use treatment, among others, and employs more than 800 staff. Because Cherry Health provides integrated medical and behavioral health services to a large patient population, it handles substantial volumes of sensitive personal and health information.
What Happened?
Cherry Street Services, Inc. was listed in an HHS Office for Civil Rights breach portal report submitted on June 18th, 2026, identifying a hacking/IT incident affecting a network server. According to Cherry Health’s preliminary notice, the organization detected suspicious activity on its network on or about April 19th, 2026. An investigation conducted with third-party specialists determined that an unauthorized individual accessed and copied certain information stored on Cherry Health’s network. According to Cherry Health’s preliminary notice as reported by teiss and ClassAction.org, data potentially exposed includes names, addresses, phone numbers, dates of birth, health insurance information, health insurance ID numbers, patient ID numbers, provider names, service dates, and Social Security numbers. Both current and former patients and staff may be affected. The specific information involved varies by individual, and the review remains ongoing.
The 501-person count reported to HHS appears to be a regulatory placeholder; Cherry Health’s own notice states the full scope has not yet been determined. Local reporting cited by ClassAction.org describes a days-long network outage suspected to have resulted from a ransomware attack, but Cherry Health’s preliminary notice does not confirm ransomware and no threat actor has publicly claimed responsibility for this incident. This is Cherry Health’s second reported breach in roughly two and a half years. A prior incident occurring on December 21st, 2023 — confirmed as a ransomware attack by a Maine Attorney General filing — was reported to HHS in February 2024 and affected 181,820 patients, exposing an extensive set of personal, health, and financial data. As of June 2026, attorneys at ClassAction.org and ClaimDepot are investigating potential class action lawsuits related to the June 2026 disclosure; no class action has been confirmed as filed.
Key Facts at a Glance
- Company or Organization: Cherry Street Services, Inc. (operating as Cherry Health)
- Industry: Healthcare — Federally Qualified Health Center (FQHC) / Community Health Center
- Location: Grand Rapids, Michigan
- Incident type: Hacking/IT Incident — Network Server
- Date of breach: April 19th, 2026
- Date breach discovered: April 19th, 2026
- Date of consumer notification: June 18th, 2026
- Total persons affected: 501 (reported to HHS; likely a placeholder pending full review)
- Prior breach: Yes — December 21st, 2023 ransomware attack affecting 181,820 patients
- Litigation status: Class action investigations underway at ClassAction.org and ClaimDepot; no filed lawsuit confirmed as of June 2026
- Source: HHS Office for Civil Rights breach portal report; teiss; ClassAction.org; DataBreaches.Net
What Should You Do?
If you received a notice from Cherry Health or believe you may be affected, consider enrolling in any identity theft protection offered by the company before the deadline. You should also place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and monitor your credit reports for unfamiliar accounts or inquiries. Free annual credit reports are available at AnnualCreditReport.com. If your information is misused, report it at IdentityTheft.gov for a personalized recovery plan. Because health information was involved, review your Explanation of Benefits statements and request copies of your medical records to check for any services you did not receive or authorize.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.