The EHR and practice-management vendor RXNT has started notifying customers about a cybersecurity incident in which an unauthorised actor accessed its platform between 1 and 3 March 2026 and exfiltrated patient data. Notification letters are dated 1 May 2026 and the incident was publicly disclosed in waves on 6 and 15 May.
The dataset confirmed exposed includes patient names, dates of birth, demographic information (addresses and contact details), patient IDs, physician names, and prescription and pharmacy information. RXNT has stated that Social Security numbers and financial information were not affected for the Congressional customer disclosed so far.
Among the affected customers is the Office of the Attending Physician (OAP), which provides primary care to members of the US Congress, the Supreme Court, and Capitol staff. OAP has not publicly stated how many individuals are involved, and the total breach population across RXNT's other customers is not yet disclosed. HIPAA Journal describes the situation as a developing story.
For digital health, the RXNT case continues a long-running pattern in which the most damaging healthcare breaches happen at SaaS vendors rather than at the providers themselves, because a single compromise propagates across every customer practice using that platform.
Sources
Sources: Congress Members' Prescription Information Compromised in RXNT Data Breach (HIPAA Journal, May 2026); RXNT Healthcare Software Breach Exposes Patient Data Across Multiple Provider Clients (Security Boulevard); RXNT begins notifying healthcare clients after patient data breach exposes records across multiple organizations (teiss).
