Cherry Health

Cherry Health experienced organizationwide technology issues in April 2026 that disrupted its phone system while clinics remained open. The provider later confirmed unauthorized access and copying of network data, and HHS listed the breach as a network-server hacking incident affecting 501 people.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Our April 28 report documented organizationwide technology issues at Cherry Health, including disruption to the provider’s phone system, while scheduled clinic visits continued. We also reported an employee allegation of ransomware, but could not independently confirm it, and Cherry Health had not publicly identified the cause at that stage.
We assess with high confidence that Cherry Health experienced a malicious cyber incident affecting its network in April 2026. Cherry Health later resolved the core cyber uncertainty in its June 18 data-privacy notice, saying it became aware of suspicious network activity on or about April 19, secured its environment, and determined through an investigation supported by third-party specialists that an unauthorized individual accessed and copied information on its network. That official statement supports confirmed unauthorized access and data exfiltration, but it does not establish the initial access vector, malware family or ransomware.
The U.S. Department of Health and Human Services Office for Civil Rights breach portal lists Cherry Street Services Inc. as a Michigan health care provider that reported a network-server hacking/IT incident June 18 affecting 501 individuals. The portal identifies the case as under investigation. Cherry Health’s preliminary notice said its data review was still underway, so the 501-person figure should not be treated as a confirmed final population.
The incident is operationally significant because Cherry Health is a large Federally Qualified Health Center serving patients through more than 20 locations and multiple clinical service lines. Its organization profile says it provides primary care, dental, vision, behavioral health, pharmacy and other services across six Michigan counties. Its location directory identifies facilities in Grand Rapids, Cedar Springs, Detroit, Greenville, Hastings, Howard City, Muskegon and Wyoming. The April outage affected technology across the organization and disrupted phones, creating a material communications dependency for patients and staff even though Cherry Health said clinics remained open for scheduled visits.
The public record does not establish that emergency care, patient appointments, prescriptions, medical-record access, billing, referrals or other clinical workflows were interrupted. The strongest documented operational effect is the phone-system disruption within a wider technology outage. Because no later public restoration notice gives a definitive all-clear, the incident is treated as presumed resolved based on the elapsed time since the last documented operational impact rather than as positively confirmed resolved.
Confidence is high that unauthorized network access occurred because Cherry Health itself disclosed the investigative finding. Confidence is also high that information was copied by the unauthorized individual. Cherry Health said the data review was still underway June 18 and identified potentially involved categories including contact details, dates of birth, health insurance information, patient identifiers, provider names, service dates and, in a limited number of cases, Social Security numbers.
Ransomware remains unconfirmed. Our April report cited an employee who alleged another ransomware attack, but we could not independently confirm the claim. Cherry Health’s later notice did not identify ransomware, encryption, a ransom demand, a threat actor or an extortion channel. We assess that the record supports unauthorized access and copied data without converting the earlier ransomware allegation into a confirmed classification.
Cherry Health initially communicated the event publicly as technology issues affecting the organization, including its phone system, without naming a cyber cause. Its June notice later confirmed unauthorized access and copied information after investigation. We assess this as an evolving disclosure posture consistent with an incident whose cyber nature and data scope were clarified over time; the available evidence does not establish intentional concealment.
The public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, malware family, attacker dwell time, encryption scope, specific systems accessed, exact volume of copied data, final number of affected individuals, ransom demand or payment, or threat-actor identity. Cherry Health’s June notice said the data review remained in progress, leaving the final affected population and person-specific data categories unresolved.

Cherry Health described technology issues across the organization, and its official directory lists a Cedar Springs facility; no site-specific outage confirmation was found.
Cherry Health described technology issues across the organization, and its official directory lists a Detroit facility; no site-specific outage confirmation was found.
Cherry Health described technology issues across the organization, and its official directory lists a Greenville facility; no site-specific outage confirmation was found.
Cherry Health described technology issues across the organization, and its official directory lists a Hastings facility; no site-specific outage confirmation was found.
Cherry Health described technology issues across the organization, and its official directory lists a Howard City facility; no site-specific outage confirmation was found.
Cherry Health described technology issues across the organization, and its official directory lists a Muskegon facility; no site-specific outage confirmation was found.
Cherry Health described technology issues across the organization, and its official directory lists Wyoming facilities; no site-specific outage confirmation was found.
Contemporaneous reporting documented organizationwide technology issues at Cherry Health, including disruption of the phone system, while clinics remained open for scheduled visits. An employee alleged ransomware, but the report explicitly said that allegation was not independently confirmed and Cherry Health had not identified the cause.
Cherry Health said it detected suspicious activity relating to its network on or about April 19, secured its environment, and investigated with third-party specialists. The investigation determined that an unauthorized individual accessed and copied certain information on the network; the organization was still reviewing which people and data were involved.
The HHS Office for Civil Rights portal lists Cherry Street Services Inc. as a Michigan health care provider reporting a hacking/IT incident involving a network server, 501 affected individuals and no business associate. The submission date is June 18, 2026, and the portal lists the case as under investigation.
Official profile information supporting the public description of Cherry Health.
Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for grand rapids, howard city, cedar springs, muskegon, wayne, muskegon, detroit, barry, greenville, montcalm, hastings.
Signed-in members can report an error, update, or missing source.