Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 1070: Serviceaide AI Platform Implicated in Health Data Exposure Affecting 483,000 Catholic Health Patients

Responded
Description: An AI-linked platform operated by Serviceaide exposed sensitive health data from Catholic Health, affecting 483,000 patients. The breach stemmed from a misconfigured Elasticsearch database used in Serviceaide’s agentic AI infrastructure. Exposed information included medical records, insurance details, and login credentials. While no misuse has been confirmed, the nature of the data has prompted regulatory scrutiny and legal investigations.
Editor Notes: Timeline notes: According to the company's notice (which can be accessed at https://www.serviceaide.com/notices) and third-party reporting, Serviceaide discovered the inadvertent exposure of Catholic Health's Elasticsearch database on November 15, 2024. The exposed data was accessible between September 19 and November 5, 2024. Serviceaide reported the breach to the U.S. Department of Health and Human Services on May 9, 2025 (which is being taken as the incident date for this incident ID), following a months-long investigation and data review. Public disclosure and notification to affected individuals began shortly thereafter.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Serviceaide , Serviceaide agentic AI platform and Elasticsearch database developed and deployed an AI system, which harmed Patients of Catholic Health and Catholic Health.
Alleged implicated AI systems: Serviceaide agentic AI platform and Elasticsearch database

Incident Stats

Incident ID
1070
Report Count
14
Incident Date
2025-05-09
Editors
Daniel Atherton

Incident Reports

Reports Timeline

+1
SERVICEAIDE, INC Notice of Data Security Event May 5, 2025 - Response
Agentic AI Tech Firm Says Health Data Leak Affects 483,000+6
Unsecured Serviceaide Database Exposed Data of 483,000 Catholic Health Patients
+1
Cyberattack on Serviceaide Compromises Data of 480,000 Catholic Health Patients
Serviceaide data breach affected over 480,000 Catholic Health patientsAI Service Provider Faces Class Actions Over Catholic Health Data BreachReported data breach impacts Catholic Health patients
SERVICEAIDE, INC Notice of Data Security Event May 5, 2025

SERVICEAIDE, INC Notice of Data Security Event May 5, 2025

serviceaide.com

Agentic AI Tech Firm Says Health Data Leak Affects 483,000

Agentic AI Tech Firm Says Health Data Leak Affects 483,000

bankinfosecurity.com

Unsecured Serviceaide Database Exposed Data of 483,000 Catholic Health Patients

Unsecured Serviceaide Database Exposed Data of 483,000 Catholic Health Patients

hipaajournal.com

Serviceaide data breach exposed info of 483K Catholic Health patients

Serviceaide data breach exposed info of 483K Catholic Health patients

scworld.com

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

securityweek.com

Serviceaide Leak Exposes Records of 500,000 Catholic Health Patients

Serviceaide Leak Exposes Records of 500,000 Catholic Health Patients

hackread.com

Breaches at Serviceaide, Nationwide Recovery Services expose medical info of more than 500,000 people

Breaches at Serviceaide, Nationwide Recovery Services expose medical info of more than 500,000 people

therecord.media

DATA BREACH ALERT: Edelson Lechtzin LLP Is Investigating Claims On Behalf Of Serviceaide Customers Whose Data May Have Been Compromised

DATA BREACH ALERT: Edelson Lechtzin LLP Is Investigating Claims On Behalf Of Serviceaide Customers Whose Data May Have Been Compromised

fox5sandiego.com

Serviceaide leak impacts over 480K Catholic Health patients

Serviceaide leak impacts over 480K Catholic Health patients

cybernews.com

Cyberattack on Serviceaide Compromises Data of 480,000 Catholic Health Patients

Cyberattack on Serviceaide Compromises Data of 480,000 Catholic Health Patients

gbhackers.com

483k Catholic Health Patients Affected by Serviceaid Data Leak

483k Catholic Health Patients Affected by Serviceaid Data Leak

informationsecuritybuzz.com

Serviceaide data breach affected over 480,000 Catholic Health patients

Serviceaide data breach affected over 480,000 Catholic Health patients

teiss.co.uk

AI Service Provider Faces Class Actions Over Catholic Health Data Breach

AI Service Provider Faces Class Actions Over Catholic Health Data Breach

natlawreview.com

Reported data breach impacts Catholic Health patients

Reported data breach impacts Catholic Health patients

wkbw.com

SERVICEAIDE, INC Notice of Data Security Event May 5, 2025
serviceaide.com · 2025
Serviceaide post-incident response

SERVICEAIDE, INC Notice of Data Security Event May 5, 2025

Serviceaide,Inc. ("Serviceaide") is providing notice of an incident that may have impacted the privacy of certain individuals' information. Serviceaide is a provider of informationt…

Agentic AI Tech Firm Says Health Data Leak Affects 483,000
bankinfosecurity.com · 2025

Serviceaide, a provider of agentic artificial intelligence-based IT management and workflow software, reported to regulators that an inadvertent exposure of data on the web has affected more than 483,000 patients of client Catholic Health, …

Unsecured Serviceaide Database Exposed Data of 483,000 Catholic Health Patients
hipaajournal.com · 2025

Serviceaide, Inc., a San Jose, California-based business associate that offers agentic AI-powered agents for IT and workflow management, has announced a major data breach affecting almost half a million patients of the six-hospital healthca…

Serviceaide data breach exposed info of 483K Catholic Health patients
scworld.com · 2025

IT services company Serviceaide notified the U.S. Department of Health and Human Services (HHS) on May 9 that the sensitive data of up to 483,126 Catholic Health patients may have been exposed in a breach.

In a letter dated May 5 sent to af…

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak
securityweek.com · 2025

Enterprise management solutions provider Serviceaide has informed the Department of Health and Human Services (HHS) that a data leak impacts the personal and medical information of nearly half a million Catholic Health patients.

California-…

Serviceaide Leak Exposes Records of 500,000 Catholic Health Patients
hackread.com · 2025

A misconfigured database at enterprise IT provider Serviceaide has exposed sensitive health and personal information belonging to approximately 500,000 (483,126) patients linked to Catholic Health, a non-profit healthcare system based in Ne…

Breaches at Serviceaide, Nationwide Recovery Services expose medical info of more than 500,000 people
therecord.media · 2025

The healthcare information of more than a half million people was leaked in two separate breaches impacting large hospital contractors. 

Hospitals tied to the technology provider Serviceaide and the debt collection giant Nationwide Recovery…

DATA BREACH ALERT: Edelson Lechtzin LLP Is Investigating Claims On Behalf Of Serviceaide Customers Whose Data May Have Been Compromised
fox5sandiego.com · 2025

NEWTOWN, Pa., May 19, 2025 /PRNewswire/ -- The Edelson Lechtzin LLP law firm is investigating claims regarding data privacy violations at Serviceaide ("Serviceaide"). Serviceaide learned of suspicious activity on its network on or about Nov…

Serviceaide leak impacts over 480K Catholic Health patients
cybernews.com · 2025

Serviceaide, a software development company, has inadvertently leaked the sensitive information of over 480,000 Catholic Health patients.

In November last year, Serviceaide discovered that information they managed and stored for a US health…

Cyberattack on Serviceaide Compromises Data of 480,000 Catholic Health Patients
gbhackers.com · 2025

Data breach at Serviceaide, Inc., a technology vendor for Catholic Health, exposed sensitive information belonging to approximately 480,000 patients.

The incident, caused by an improperly secured Elasticsearch database, left names, Social S…

483k Catholic Health Patients Affected by Serviceaid Data Leak
informationsecuritybuzz.com · 2025

Nearly half a million patients at New York-based non-profit healthcare system Catholic Health may have had their personal and medical information exposed due to a data leak. According to enterprise management solutions provider Serviceaide,…

Serviceaide data breach affected over 480,000 Catholic Health patients
teiss.co.uk · 2025

Technology service provider Serviceaide said that a data security incident caused by a misconfigured database last year compromised the sensitive personal information of over 480,000 patients affiliated with Catholic Health.

Headquartered i…

AI Service Provider Faces Class Actions Over Catholic Health Data Breach
natlawreview.com · 2025

AI service provider Serviceaide Inc. faces two proposed class action lawsuits from a data breach tied to Catholic Health System Inc., a nonprofit hospital network in Buffalo, New York. The breach reportedly exposed the personal information …

Reported data breach impacts Catholic Health patients
wkbw.com · 2025

BUFFALO, N.Y. (WKBW) — If you're a Catholic Health patient, your private medical information may have been exposed in a data breach.

Tech support company Serviceaide, which handles data services for Catholic Health, said between September a…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?
Previous IncidentNext Incident

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • b3bc8e7