FOR IMMEDIATE RELEASE
STOCKTON CARDIOLOGY MEDICAL GROUP ANNOUCES DATA SECURITY INCIDENT
Stockton, CA – March 19, 2026 – Stockton Cardiology Medical Group ("Stockton Cardiology") recently learned that certain information it maintains was accessed by an unauthorized individual. This media notice is being provided by Stockton Cardiology to inform affected individuals of the incident in accordance with their obligations under the Health Insurance Portability and Accountability Act ("HIPAA") and applicable California privacy laws.
What Happened? On December 15, 2025, Stockton Cardiology identified suspicious emails that had been sent to several employees. Although the emails were promptly deleted as part of our initial remediation efforts, on January 17, 2026, we discovered that certain files maintained in the ordinary course of business and patient care may have been accessed and removed from our systems by the unauthorized individual. Immediately thereafter, we started our investigation to determine the scope of the breach and to restore the integrity of our system. On February 17, 2026, we learned that some of these files have since been publicly disclosed. The files involved may include personally identifiable information, protected health information, and certain company business records.
What information was involved? The information potentially involved in this incident may have included patient names, mailing addresses, email addresses, and billing records that may contain limited medical information associated with services provided.
What is Stockton Cardiology Medical Group doing to help? Stockton Cardiology is offering affected individuals one (1) year of complimentary credit monitoring services through our partner vendor, Epiq. These services are intended to help monitor potential misuse of personal information.
What has Stockton Cardiology done since the breach to rectify the issue: We have taken a number of steps to investigate this breach and prevent any potential harm to affected patients including retaining an independent security firm to assist in the investigation of the breach, making several improvements to the security configuration of our information systems, shutting down an older remote access service used by our staff, adding MFA (multi-factor authentication) to certain internal systems, resetting all passwords on all of our systems, and reviewing our policies for data retention, so that fewer "working" files are retained.
What can you do? Affected patients may consider registering fraud alert with a credit bureau such as Experian, TransUnion, or Equifax, and ordering their credit reports. Affected patients are also encouraged to monitor their bank and credit card statements.
Contact Information
We understand that this incident may cause concern or inconvenience, and we sincerely regret that it occurred. If you have any questions about this notice or need assistance, please contact Stockton Cardiology Medical Group at (209) 944-5750 Monday through Friday between 8 am-5 pm or email at response@stocktoncardiology.com
March 17 2026
LYRK0479543