Notice of Data Security Incident

PR Newswire

NEW YORK, Oct. 8, 2026 /PRNewswire/ — Photon is notifying individuals whose personal information may have been involved in a network security incident. This statement is intended to notify potentially impacted individuals about the incident, steps Photon has taken in response, and resources available to assist and protect individuals.

What Happened? On August 21, 2026, Photon learned that an unauthorized third party exploited a previously unknown security flaw (sometimes called a ‘zero-day’ vulnerability) in Metabase, a third-party application that Photon uses on a self-hosted basis for business intelligence, product metrics, and customer dashboards, to access certain data.  Upon learning of the incident, we took immediate measures to secure the application and engaged a team of cybersecurity experts to assess, contain, and remediate the incident. The investigation revealed that certain data may have been acquired without authorization. After a thorough review of the impacted data, which was completed on September 4, 2026, it was determined that certain personal information may have been impacted. Photon has no evidence of misuse, or attempted misuse, of any potentially affected information.

What Information Was Involved? Please rest assured that Social Security numbers and financial information were not impacted in this incident, as Photon does not collect or store that information. The investigation identified instances of name, address, phone number, date of birth, prescription medication information exposure for certain individuals a result of this incident. Notably, the types of information affected were different for each individual and not every individual had all the above listed elements exposed.

What Are We Doing? Photon takes its responsibility to safeguard information seriously and regrets any concern this incident may have caused. Upon detecting this incident, Photon moved quickly to initiate a response, which included conducting a thorough investigation with the assistance of cybersecurity specialists and confirming the security of its Metabase environment. We are continually reviewing and revising technical safeguards and making enhancements to reduce the likelihood of a similar event in the future. Additionally, Photon is committed to helping those people who may have been impacted by this situation.

The notification letter to the potentially impacted individuals includes steps that they can take to protect their information. In order to address any concerns and mitigate any exposure or risk of harm following this incident, Photon has arranged for complimentary credit monitoring services and identity theft protection services to all potentially impacted individuals at no cost to them for a period of twelve to twenty-four months. Photon recommends that individuals enroll in the services provided and follow the recommendations contained within the notification letter to ensure their information is protected.

For More Information. Individuals seeking more information or with questions about this incident may contact the dedicated call center at 1-844-772-5746 from 8:00 A.M. to 8:00 P.M. ET, Monday through Friday, excluding holidays.

Cision View original content:https://www.prnewswire.com/news-releases/notice-of-data-security-incident-302903069.html

SOURCE Photon Health

About The Author