Quantum Health data security incident
Greetings,
As stewards of the Benefits Plan of the Presbyterian Church (U.S.A.), the Board of Pensions takes the security and privacy of your personally identifiable information (PII) and protected health information (PHI) seriously. This letter is to inform you of a cyber incident that occurred with Quantum Health, a vendor with which the Board contracts for care coordination and benefits navigation services.
On May 29, 2026, Quantum Health’s system was breached during a cyber attack. The incident triggered a network outage of Quantum Health systems and widespread disruption to its services. On June 9, 2026, Quantum Health provided a preliminary investigation report and an attestation to the Board that a cyber incident had occurred and was being contained. Since then, we have remained in close communication with Quantum Health as they investigated the extent of data compromised. We recently learned that data from approximately 16,000 Medical Plan members was accessed during the breach.
In response to the incident, Quantum Health employed cybersecurity firms CrowdStrike and MOXFIVE to overhaul their cybersecurity infrastructure. Quantum Health continues to work with its cyber consultants to ensure the ongoing security of its systems and the data it manages.
Quantum Health has also retained Kroll to provide breach notification services. Kroll will notify all impacted Board of Pensions members, as well as provide them with credit monitoring services.
Please know that the Board of Pensions’ systems remain secure and unaffected by this incident. Our agency employs leading cybersecurity measures to safeguard PII and PHI data, and we work closely with our vendors to mitigate incidents when they occur. We remain committed to transparency and accountability in our operations, including those of our vendors, and expect Quantum Health to honor its contractual obligations to us.
With gratitude,
Kelly Riley
Executive Vice President, Plan Operations, and Privacy Officer