Skip to content

Cherry Health cyber incident disrupts phones and exposes data

Summary

Cherry Health logo

Cherry Health experienced organizationwide technology issues in April 2026 that disrupted its phone system while clinics remained open. The provider later confirmed unauthorized access and copying of network data, and HHS listed the breach as a network-server hacking incident affecting 501 people.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

Incident narrative

Analyst assessment

Our April 28 report documented organizationwide technology issues at Cherry Health, including disruption to the provider’s phone system, while scheduled clinic visits continued. We also reported an employee allegation of ransomware, but could not independently confirm it, and Cherry Health had not publicly identified the cause at that stage.

We assess with high confidence that Cherry Health experienced a malicious cyber incident affecting its network in April 2026. Cherry Health later resolved the core cyber uncertainty in its June 18 data-privacy notice, saying it became aware of suspicious network activity on or about April 19, secured its environment, and determined through an investigation supported by third-party specialists that an unauthorized individual accessed and copied information on its network. That official statement supports confirmed unauthorized access and data exfiltration, but it does not establish the initial access vector, malware family or ransomware.

The U.S. Department of Health and Human Services Office for Civil Rights breach portal lists Cherry Street Services Inc. as a Michigan health care provider that reported a network-server hacking/IT incident June 18 affecting 501 individuals. The portal identifies the case as under investigation. Cherry Health’s preliminary notice said its data review was still underway, so the 501-person figure should not be treated as a confirmed final population.

Operational significance

The incident is operationally significant because Cherry Health is a large Federally Qualified Health Center serving patients through more than 20 locations and multiple clinical service lines. Its organization profile says it provides primary care, dental, vision, behavioral health, pharmacy and other services across six Michigan counties. Its location directory identifies facilities in Grand Rapids, Cedar Springs, Detroit, Greenville, Hastings, Howard City, Muskegon and Wyoming. The April outage affected technology across the organization and disrupted phones, creating a material communications dependency for patients and staff even though Cherry Health said clinics remained open for scheduled visits.

The public record does not establish that emergency care, patient appointments, prescriptions, medical-record access, billing, referrals or other clinical workflows were interrupted. The strongest documented operational effect is the phone-system disruption within a wider technology outage. Because no later public restoration notice gives a definitive all-clear, the incident is treated as presumed resolved based on the elapsed time since the last documented operational impact rather than as positively confirmed resolved.

Confidence and uncertainty

Confidence is high that unauthorized network access occurred because Cherry Health itself disclosed the investigative finding. Confidence is also high that information was copied by the unauthorized individual. Cherry Health said the data review was still underway June 18 and identified potentially involved categories including contact details, dates of birth, health insurance information, patient identifiers, provider names, service dates and, in a limited number of cases, Social Security numbers.

Ransomware remains unconfirmed. Our April report cited an employee who alleged another ransomware attack, but we could not independently confirm the claim. Cherry Health’s later notice did not identify ransomware, encryption, a ransom demand, a threat actor or an extortion channel. We assess that the record supports unauthorized access and copied data without converting the earlier ransomware allegation into a confirmed classification.

Disclosure posture

Cherry Health initially communicated the event publicly as technology issues affecting the organization, including its phone system, without naming a cyber cause. Its June notice later confirmed unauthorized access and copied information after investigation. We assess this as an evolving disclosure posture consistent with an incident whose cyber nature and data scope were clarified over time; the available evidence does not establish intentional concealment.

Analytic gaps

The public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, malware family, attacker dwell time, encryption scope, specific systems accessed, exact volume of copied data, final number of affected individuals, ransom demand or payment, or threat-actor identity. Cherry Health’s June notice said the data review remained in progress, leaving the final affected population and person-specific data categories unresolved.

Organizations involved

Impacted locations

  • Cedar Springs, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists a Cedar Springs facility; no site-specific outage confirmation was found.

  • Detroit, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists a Detroit facility; no site-specific outage confirmation was found.

  • Greenville, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists a Greenville facility; no site-specific outage confirmation was found.

  • Hastings, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists a Hastings facility; no site-specific outage confirmation was found.

  • Howard City, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists a Howard City facility; no site-specific outage confirmation was found.

  • Muskegon, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists a Muskegon facility; no site-specific outage confirmation was found.

  • Wyoming, Michigan

    Medium Confidence

    Cherry Health described technology issues across the organization, and its official directory lists Wyoming facilities; no site-specific outage confirmation was found.

Sources

Cherry Health outage in Michigan investigated as possible cyberattack

Contemporaneous reporting documented organizationwide technology issues at Cherry Health, including disruption of the phone system, while clinics remained open for scheduled visits. An employee alleged ransomware, but the report explicitly said that allegation was not independently confirmed and Cherry Health had not identified the cause.

Cherry Street Services, Inc. - Notice of Data Privacy Event

Cherry Health said it detected suspicious activity relating to its network on or about April 19, secured its environment, and investigated with third-party specialists. The investigation determined that an unauthorized individual accessed and copied certain information on the network; the organization was still reviewing which people and data were involved.

Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information

The HHS Office for Civil Rights portal lists Cherry Street Services Inc. as a Michigan health care provider reporting a hacking/IT incident involving a network server, 501 affected individuals and no business associate. The submission date is June 18, 2026, and the portal lists the case as under investigation.

Cherry Health

Official profile information supporting the public description of Cherry Health.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for grand rapids, howard city, cedar springs, muskegon, wayne, muskegon, detroit, barry, greenville, montcalm, hastings.

See something that needs correction?

Signed-in members can report an error, update, or missing source.