Clinical Registry Solutions Data Breach Investigation

Data Breach Blog

Data Breach

Clinical Registry Solutions Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

July 31, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at Clinical Registry Solutions. The breach occurred on April 9th, 2026. If you were affected, contact Almeida Law Group.


About Clinical Registry Solutions

Clinical Registry Solutions (CRS), formerly known as Cardiac Registry Support, is a healthcare data management company headquartered in Brooklyn, New York, with an additional location in Mississauga, Ontario, Canada. CRS provides clinical data abstraction, medical record abstraction, and registry support services to hospitals, health systems, contract research organizations, and clinical staffing firms across the United States and Canada. The company operates as a business associate under HIPAA, meaning it receives patient information from healthcare provider clients for the purpose of mandated national medical registry reporting. CRS rebranded from Cardiac Registry Support in September 2025 and, in January 2026, expanded its cardiac registry support to more than 100 hospitals through an acquisition.


What Happened?

Clinical Registry Solutions was listed in a California Attorney General sample breach notice filed on July 29th, 2026—approximately 111 days after the incident was discovered.

According to CRS’s notice and reporting by HIPAA Journal, CRS detected a network disruption on April 9th, 2026. The company immediately took its systems offline and retained cybersecurity specialists. The investigation determined that unauthorized access occurred on April 9th, 2026, and that certain files containing patient information may have been taken from the network. CRS confirmed that the compromised data included first and last names, medical record numbers, and procedure dates. The company stated that Social Security numbers, diagnoses, and treatment plans were not involved. HIPAA Journal reported that 8,545 patients of Dignity Health’s St. Mary’s Medical Center were notified. CRS’s notice did not offer credit monitoring or identity theft protection services to affected individuals.

On May 6th, 2026, the Akira ransomware group claimed responsibility for the attack on a Tor-based dark web leak site, alleging it obtained 41 GB of data including employee Social Security numbers, passports, and financial records. These are unverified attacker-side allegations and have not been confirmed by CRS or any independent source. The HIPAA Journal report independently corroborated the April 2026 incident and CRS’s notification to affected patients, but did not confirm the ransomware group’s claims regarding the scope or nature of the exfiltrated data. As of July 2026, no class action lawsuits have been filed, though at least three law firms—Shamis & Gentile P.A., Dapeer Law P.A., and Mason LLP—have announced investigations into potential class actions on behalf of affected individuals.


Key Facts at a Glance

  • Company or Organization: Clinical Registry Solutions (CRS)
  • Industry: Healthcare data management / clinical data abstraction (business associate to hospitals and health systems)
  • Location: Brooklyn, NY (also Mississauga, Ontario, Canada)
  • Incident type: Unauthorized network access; files containing patient information may have been taken
  • Date of breach: April 9th, 2026
  • Date breach discovered: April 9th, 2026
  • Date of consumer notification: July 29th, 2026
  • Total persons affected: 8,545 (patients of Dignity Health’s St. Mary’s Medical Center, per HIPAA Journal)
  • Litigation status: No filed class action complaints; law firm investigations ongoing as of July 2026 (Shamis & Gentile P.A., Dapeer Law P.A., Mason LLP)
  • Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-627299); HIPAA Journal (https://www.hipaajournal.com/clinical-registry-solutions-jason-r-egbert-od-pc-vnc-health-data-breaches/)

What Should You Do?

If you received a notice from Clinical Registry Solutions, review your medical records and Explanation of Benefits statements for any services or procedures you do not recognize, as the compromised data included medical record numbers and procedure dates. Because CRS did not offer credit monitoring or identity theft protection, you should consider placing a free fraud alert or credit freeze with the three major credit bureaus—TransUnion, Experian, and Equifax—on your own. You can request a free annual credit report from each bureau at AnnualCreditReport.com or by calling 1-877-322-8228. Monitor your financial accounts and credit reports regularly for suspicious activity, and if you believe you are a victim of identity theft, visit IdentityTheft.gov for step-by-step guidance.


Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.