NJ law firm cyberattack exposes data of nearly 13K patients

Kimberly Redmond//July 9, 2026//

Circuit board cybersecurity concept

PHOTO: DEPOSIT PHOTOS

Circuit board cybersecurity concept

PHOTO: DEPOSIT PHOTOS

NJ law firm cyberattack exposes data of nearly 13K patients

Kimberly Redmond//July 9, 2026//

Listen to this article

The basics:

  • NJ law firm may have exposed data of nearly 13,000 patients
  • Greenbaum Rowe discovered unauthorized access in November 2025
  • Breach involved a compromised user account, sensitive health data
  • Identity theft protection, call center available to affected individuals

A cyberattack on a New Jersey-based law firm that represents some of the state’s top healthcare systems may have exposed the data of nearly 13,000 patients.

discovered unauthorized access to its systems via a compromised user account in November 2025. After, it “immediately” took steps to secure its systems, according to a notice from the firm.

In addition to resetting passwords and replacing compromised machines, Greenbaum notified law enforcement. It also launched a comprehensive investigation with assistance from experts to determine the cause and scope of the incident.

Completed in April, the probe determined that an unauthorized third party acquired certain information in Greenbaum’s systems between Nov. 25–27, 2025, the notice said. Besides names and addresses, the potentially affected data may have included medical record numbers, medical history, provider details, medical bill costs and health insurance.

“For a subset of individuals, their Social Security Numbers and/or dates of birth may have been included,” Greenbaum said.

According to a notice from the U.S. Department of Health and Human Services, the impacted 12,801 people.

Safeguarding systems

There is no evidence that the stolen information was published or misused. However, the firm said it is notifying impacted patients directly about the incident via mailed letters.

“Greenbaum also enhanced its cybersecurity by adding additional monitoring and detection tools as safeguards against future cyber threats. Greenbaum regularly reviews its physical and electronic safeguards to protect personal information, and it will continue to take appropriate steps to safeguard personal information and its systems,” the notice said.

Gavel and keyboard
DEPOSIT PHOTOS
Tech Intelligence

Carl Mazzanti, president of eMazzanti Technologies in Hoboken, shares cybersecurity tips for law firms here.

The firm will also offer identity theft protection services. It set up a dedicated call center for affected individuals, as well.

A spokesperson for Greenbaum did not immediately respond to a request for comment.

Founded in 1914, the full-service law firm comprises 100 attorneys across three New Jersey offices: Iselin, Roseland and Red Bank.

The firm boasts a highly regarded healthcare department. Its roster of clients includes many of the state’s top systems, hospitals, physician practice groups, dental practices, pharmaceutical companies, home health agencies, nursing homes, managed care organizations, behavioral health organizations, medical device manufacturers, healthcare industry vendors and private equity firms.

Hospitals

According to NJ.com, System, and are among Greenbaum’s clients.

Atlantic Health System did not immediately respond to a request for comment.

A media representative for RWJBarnabas Health-owned Trinitas Regional Medical Center confirmed the network received notification from by Greenbaum that the cybersecurity incident may have affected certain protected health information of some of its providers.

At Hackensack Meridian Health – the largest healthcare system in New Jersey – a spokesperson told NJBIZ, “We were concerned to learn of a data security incident at one of our legal service providers, the law firm Greenbaum Rowe Smith & Davis, which may have involved information belonging to some of our patients.”

They went on, “We know how important this is, and we share the concerns of those who are affected. While this incident did not occur on Hackensack Meridian Health’s systems, we are in close contact with Greenbaum, which is managing the response.”

According to the American Hospital Association, healthcare has become one of the most frequently targeted industries for cybercriminals because of the vast amounts of sensitive patient and financial data it maintains.

The latest breach in New Jersey follows a May 2024 cyberattack on Cooper University Health Care that affected nearly 60,000 patients.