Quick Answer
Photon Health says a zero-day attack on its self-hosted Metabase application may have exposed names, contact details, dates of birth, and prescription medication information. The company says Social Security numbers and financial information were not affected, and it had no evidence of misuse on October 8, 2026. Watch for Photon’s notice, enroll in offered protection, and treat unexpected health-related contacts cautiously.
Key Takeaways
- Photon Health disclosed the network security incident publicly on October 8, 2026.
- The potentially affected data includes prescription medication information, although categories vary by person.
- Photon says Social Security numbers and financial information were not affected.
- The intrusion exploited a previously unknown flaw in a self-hosted Metabase application.
- Affected people will receive 12 to 24 months of free credit monitoring and identity-theft protection.
What happened in the Photon Health data breach?
Photon Health says an unauthorized third party exploited a previously unknown flaw in its self-hosted Metabase business-intelligence application. Photon learned of the intrusion on August 21, 2026, completed its review of affected data on September 4, 2026, and began publicly notifying potentially affected people on October 8, 2026.
Photon Health’s disclosure matters because the potentially affected information includes prescription medication data, which can reveal sensitive details about a person’s healthcare needs. The company said it had no evidence of misuse or attempted misuse when it published its notice, but that finding does not remove the need for affected people to review communications and enroll in available protection.
Photon Health has not said that every person had the same data exposed. The categories of potentially affected information vary by individual, so the most useful source of confirmation is the breach notice sent directly to a potentially affected person. Consumers who have received unrelated breach notices may also want to keep records organized, as explained in TechJournal’s guide to an unauthorized app alert that involved customer contact details.
What personal information may have been exposed?
Photon Health says the potentially exposed information can include names, addresses, phone numbers, dates of birth, and prescription medication information. The company also says it does not collect or store Social Security numbers or financial information, and those categories were not affected. Photon Health’s breach notice identifies the affected categories and explains that the precise data involved differs by person.
Prescription medication information is the most sensitive category named in Photon Health’s notice because it may provide context that an unexpected caller, email sender, or text message could use to appear credible. The practical response is to verify unexpected healthcare-related messages through a known phone number or official patient portal instead of responding through a link or phone number included in the message.
| Information category | Photon Health’s disclosure | Practical response |
|---|---|---|
| Name and contact details | Names, addresses, and phone numbers may have been involved. | Verify unexpected calls, texts, and emails before sharing additional information. |
| Date of birth | Dates of birth may have been involved for some people. | Review account notices and avoid confirming personal details to unverified callers. |
| Prescription medication information | Prescription medication information may have been involved for some people. | Use official pharmacy, provider, or insurer contact methods for follow-up. |
| Social Security and financial information | Photon says it does not collect or store these data types, and they were not affected. | Read the notice carefully, but do not assume other personal details are irrelevant. |
How did the Metabase zero-day attack work?
The Photon Health breach involved a flaw in Metabase, a business-intelligence application organizations use to view and analyze internal data. A zero-day flaw is a vulnerability that is not publicly known or patched before attackers begin exploiting it. Photon says the attacker exploited such a flaw in its self-hosted Metabase environment.
Metabase said its own incident involved a chained zero-day attack that could generate an active session. The company said installations on version 0.58 and later were vulnerable, and patched releases were issued on August 6, 2026. Metabase’s technical incident report describes the attack chain and the company’s response.
Metabase’s security advisory page also lists vulnerabilities involving query validation, permissions, and network exposure, including critical SQL-injection issues. Metabase’s GitHub security advisories provide the vendor’s published vulnerability record. These technical details explain how an attacker could reach protected business data, but they do not identify which specific records were accessed in Photon Health’s incident.
What should affected Photon Health patients do now?
Photon Health patients should read any mailed or emailed breach notice carefully, enroll in the offered protection if eligible, and independently verify unexpected requests for personal information. The company says affected people will receive free credit monitoring and identity-theft protection for between 12 and 24 months, depending on the individual notice.
Do not provide account credentials, insurance details, prescription information, or verification codes to an unsolicited caller or message sender. A person who knows your name, address, or medication information can make an unexpected contact seem legitimate. Contact Photon Health, your provider, pharmacy, or insurer through a known official channel if a message appears urgent or requests additional information.
- Read the Photon Health notice and confirm which protection offer applies to you.
- Enroll in the credit monitoring and identity-theft protection before the stated deadline.
- Review healthcare, pharmacy, insurance, and financial account notifications for activity you do not recognize.
- Change a reused password if a Photon-related account shares credentials with another service.
- Verify suspicious calls or messages using a trusted website, patient portal, or printed account statement.
Photon Health lists a dedicated call center at 1-844-772-5746 for questions about the incident. The safest approach is to use that number only after confirming it against the company’s official notice. A unique-password routine also limits the damage from unrelated account compromises, and TechJournal’s comparison of free password manager limits explains what basic plans can provide.
What protection is Photon Health offering affected people?
Photon Health says affected people will receive free credit monitoring and identity-theft protection for between 12 and 24 months. The exact duration and enrollment details depend on the notice received by each person, so the company’s communication is the controlling document for eligibility and deadlines.
Credit monitoring and identity-theft protection can help affected people notice certain account or identity issues, but those services do not prevent every misleading call, text, or email. The protection is most useful when combined with careful account review and skepticism toward unexpected requests for personal details.
Photon Health says Social Security numbers and financial information were not affected because the company does not collect or store those categories. That limitation reduces the scope of the disclosed incident, but affected people should still take prescription and contact information seriously because the data can be used to make a message appear tailored to them.
What risks remain after the Photon Health breach notice?
The main continuing risk is that exposed contact and prescription information could be used in a convincing impersonation attempt. Photon Health said it had no evidence of misuse or attempted misuse when it published its October 8 notice, which is an important limitation. A lack of known misuse at that date does not mean affected people should ignore unfamiliar communications.
Unexpected messages that mention a medication, healthcare provider, address, or date of birth deserve added scrutiny. A legitimate healthcare organization can be contacted through an existing patient portal, insurance card, pharmacy receipt, or official website. Do not use a link in a text or email to verify an urgent request when another trusted contact method is available.
Consumers dealing with more than one incident should keep a dated record of notices, enrollment deadlines, and accounts checked. That habit makes it easier to separate a genuine breach notification from a fraudulent message. Similar caution is useful after an investor data incident, where a company notice may contain details scammers can imitate.
What should healthcare organizations learn from the Metabase incident?
Healthcare organizations using self-hosted analytics software should treat vendor security advisories as operational warnings, not as background reading. Metabase said patched releases were issued on August 6, 2026, and later explained that installations on version 0.58 and later were vulnerable to the chained zero-day attack it investigated.
Metabase environments can contain reporting data that is useful for operations but sensitive if accessed outside authorized workflows. Organizations should review their vendor notices, verify patch status, limit application access, and determine what data each analytics system can reach. The practical goal is to reduce both the opportunity for unauthorized access and the amount of sensitive information available through a single system.
Healthcare organizations should stop and involve their security team, incident-response provider, or software vendor when an intrusion is suspected. Applying patches or changing access settings without preserving evidence can complicate an investigation. A documented response plan is especially important when the system handles patient-related information.
FAQ
Did the Photon Health data breach expose Social Security numbers?
Photon Health says Social Security numbers were not affected because the company does not collect or store them. Photon Health also says financial information was not affected by the incident.
Did the Photon Health breach expose prescription information?
Photon Health says prescription medication information may have been involved for some people. Photon Health says the exact categories of potentially affected information vary by individual.
When did Photon Health discover the Metabase breach?
Photon Health says it learned of the unauthorized access on August 21, 2026. Photon Health completed its review of the affected data on September 4, 2026, and disclosed the incident publicly on October 8, 2026.
Is there evidence that Photon Health data has been misused?
Photon Health said it had no evidence of misuse or attempted misuse when it published its October 8, 2026 notice. Affected people should still verify unexpected contacts and monitor accounts because exposure can create later impersonation risks.
What number can people call about the Photon Health data breach?
Photon Health lists 1-844-772-5746 as its dedicated call center for the incident. Use the number after confirming it against Photon Health’s official notice or another trusted company communication.
