Almeida Law Group is investigating a data breach at Colorado Health Network Inc. The breach occurred on July 26th–29th, 2025 and was discovered on April 28th, 2026. If you were affected, contact Almeida Law Group.
About Colorado Health Network Inc.
Colorado Health Network Inc. (CHN) is a 501(c)(3) nonprofit organization founded in 1983 and headquartered at 6020 E Colfax Ave in Denver, Colorado. It is described as Colorado’s oldest and largest provider of services for people living with or at risk of HIV/AIDS, and it also serves individuals affected by hepatitis C, sexually transmitted diseases, and substance use disorders. CHN provides integrative medical care, behavioral health services, oral health care, case management, housing and nutrition assistance, and free HIV and STI testing across offices in Denver, Fort Collins, Colorado Springs, Grand Junction, and satellite locations in Greeley and Pueblo, serving more than 5,000 clients statewide. Because CHN serves a population whose HIV-related health information carries heightened privacy and discrimination risks beyond those typical of most healthcare providers, the exposure of medical data in this breach is of particular concern.
What Happened?
Colorado Health Network Inc. was listed in a Texas Attorney General data security breach report published on June 25th, 2026. According to that filing, the breach occurred between July 26th, 2025 and July 29th, 2025, and was not discovered until April 28th, 2026—a gap of approximately nine months. CHN began notifying affected individuals on June 18th, 2026, nearly eleven months after the breach took place. A total of 68,212 individuals were affected. The types of information involved include names, addresses, dates of birth, Social Security numbers, driver’s license and state ID numbers, passport numbers, other government-issued identification numbers, financial account and debit or credit card information, medical information, and health insurance information. CHN is offering affected individuals 24 months of complimentary identity monitoring through Epiq’s Privacy Solutions ID program and has established a dedicated phone line at 1-866-659-7097. The breach was also disclosed to the Massachusetts Office of Consumer Affairs and the Vermont Attorney General on June 22nd, 2026.
A threat actor using the name “Cephalus” publicly claimed responsibility for the attack on August 28th, 2025, posting on the Tor network and alleging the theft of more than 900 GB of data from CHN. That public claim predates CHN’s stated discovery date of April 28th, 2026 by roughly eight months, which has raised significant delayed-notice concerns. Multiple law firms—including Bryson Harris Suciu & DeMay PLLC, Shamis & Gentile P.A., Console & Associates P.C., and Strauss Borrelli PLLC—are investigating potential class action lawsuits related to this breach. As of June 25th, 2026, no class action has been confirmed as filed.
Key Facts at a Glance
- Company or Organization: Colorado Health Network Inc.
- Industry: Healthcare – Nonprofit HIV/AIDS Services and Medical Provider
- Location: Denver, Colorado 80220
- Incident type: Ransomware / unauthorized access and data exfiltration
- Date of breach: July 26th, 2025 – July 29th, 2025
- Date breach discovered: April 28th, 2026
- Date of consumer notification: June 18th, 2026
- Total persons affected: 68,212
- Identity theft protection offered: 24 months of complimentary identity monitoring through Epiq’s Privacy Solutions ID program
- Litigation status: Multiple law firms investigating potential class action; no lawsuit confirmed filed as of June 25th, 2026
- Source: Texas Attorney General data security breach report (https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0005130); supplemental reporting at https://www.claimdepot.com/data-breach/colorado-health-network-2026 and https://www.classaction.org/data-breach-lawsuits/colorado-health-network-june-2026
What Should You Do?
If you received a notification from Colorado Health Network Inc., enroll in the 24-month identity monitoring program through Epiq’s Privacy Solutions ID as soon as possible and note any enrollment deadline in your notice letter. Because this breach involved Social Security numbers, financial account information, and detailed medical information, you should also place a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—and monitor your credit reports regularly at AnnualCreditReport.com. Review your bank and credit card statements for any unauthorized transactions. Since health and health insurance information was involved, carefully review your Explanation of Benefits statements and request a copy of your medical records to check for any services you did not receive. If you suspect misuse of your information, report it at IdentityTheft.gov for step-by-step recovery guidance.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.