Fenway Health’s computer systems went down on Friday and were still down over the weekend. The pharmacy cannot fill prescriptions. The Friday morning sexual health walk-in clinic was canceled. Patients with appointments have been routed to on-call providers, who in some cases are relying on the patient to know their own dosage so an emergency fill can be authorized somewhere else. The health center’s spokesman, Ryan Dunn, said: “Fenway Health has informed our patients that we are managing an interruption to IT systems. In tandem with our external IT experts, we are moving steadily towards returning all systems to full operations. We have taken multiple steps to limit impacts to patient care.”
He did not say what happened, and he did not say when it would end. This article is not about what caused the outage, because nobody outside Fenway Health knows. It is about what the law requires Fenway Health to tell its patients if the cause turns out to be what a three-day outage with “external IT experts” usually is.
What an “interruption to IT systems” can mean
Health care systems go down for ordinary reasons: a failed upgrade, a vendor outage, a power problem. Those are fixed in hours. An outage that runs from Friday into a third day, takes down the pharmacy and the clinical record at once, and brings in outside specialists is the profile of a security incident, in which an organization takes its own systems offline to contain an intrusion or is locked out of them by ransomware. Fenway Health has not said that is what happened, and it may not be. But its patients are entitled to ask, and if it is, they are entitled to be told.
The reason it matters here more than at most clinics is the patient population. Fenway Health is the largest LGBTQ-focused health center in New England and a national center for HIV care and gender-affirming treatment. Its records are among the most sensitive health information held anywhere in Massachusetts.
What Massachusetts law requires
Chapter 93H is the state’s data breach statute. It applies to any person or agency that owns or licenses personal information about a Massachusetts resident, which for a health center means names paired with Social Security numbers, financial account numbers, or driver’s license numbers. When such an organization “knows or has reason to know of a breach of security,” it must give notice “as soon as practicable and without unreasonable delay” to three parties: the Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected resident.
The notice to the resident must state the resident’s right to obtain a police report, how to place a security freeze and that there is no charge for one, and what mitigation services are being provided. If Social Security numbers were exposed, the organization must provide credit monitoring for at least 18 months and certify to the state that it has done so. The Attorney General publishes every breach notice it receives; that list is where a Fenway Health notification would first appear publicly.
Chapter 93H has a gap for health information: it is triggered by financial identifiers, not by diagnoses. A breach that exposed a patient’s HIV status and nothing else would not, on its face, require chapter 93H notice. That is what the federal rule covers.
What federal law requires
Fenway Health is a covered entity under HIPAA. The HIPAA Breach Notification Rule requires notice to affected individuals of any breach of unsecured protected health information “without unreasonable delay and in no case later than 60 calendar days” after discovery. For a breach affecting more than 500 people, the organization must also notify the Department of Health and Human Services within the same 60 days and notify prominent media outlets serving the state. Those large breaches are posted on the HHS Office for Civil Rights portal.
The 60-day clock is an outer limit, not a target, and federal regulators have penalized organizations that treated it as one. It also runs from discovery of the breach, not from the end of the outage, which means that if Friday’s shutdown was the discovery, the clock is already running.
A second federal obligation is narrower and older. Federal regulations protecting the confidentiality of substance use disorder treatment records, and Massachusetts’s own statute protecting HIV test results, chapter 111, section 70F, impose limits on disclosure that a breach does not waive. A patient whose HIV status was exposed in a breach has a claim that a patient whose billing address was exposed does not.
What a patient should do now
- Medications. If a refill is due, call the on-call line rather than the pharmacy, and have the medication name and dosage available. For HIV antiretrovirals and hormone therapy, a missed dose is a clinical problem, and any pharmacy can fill an emergency supply on a provider’s call.
- Appointments. Assume the portal is down and confirm by phone.
- Watch for the notice. If this was a breach, a letter will come. It must tell you what was taken. Read it for the specific data elements, not the apology.
- Freeze your credit now if you want to. It is free under Massachusetts law, takes ten minutes at each of the three bureaus, and does not require waiting for anyone’s letter.
- Keep records. Any prescription paid out of pocket, any appointment missed, any charge that results is a cost the organization may be liable for.
What to watch
Three signals will tell patients what this was before Fenway Health says so. A posting on the Attorney General’s breach list. A posting on the HHS breach portal. And the wording of the next statement: organizations that have been attacked eventually say “cybersecurity incident,” and organizations that have not say what broke.
What happened at Fenway Health?
Its computer systems went offline on Friday, September 11, 2026 and remained down through the weekend. The pharmacy cannot fill prescriptions and at least one clinic was canceled. The health center has described it only as “an interruption to IT systems” and has not stated a cause.
Was patient data taken?
Fenway Health has not said. If a breach of personal information occurred, Massachusetts law requires notice to patients and the Attorney General without unreasonable delay, and HIPAA requires notice within 60 days of discovery.
What must a breach notice tell me?
Under G.L. c. 93H, § 3: your right to a police report, how to place a free security freeze, and what mitigation services are offered. Under HIPAA, what information was involved and what you should do.
How do I get a prescription filled during the outage?
Call the health center’s on-call line with the medication name and dose; a provider can authorize an emergency fill at another pharmacy.
Does HIPAA cover my HIV status in a breach?
Yes. Diagnoses are protected health information under HIPAA, and Massachusetts separately protects HIV test results under G.L. c. 111, § 70F.
Outage details and spokesman’s statement as reported by Universal Hub, September 12 and 13, 2026. Notice requirements from G.L. c. 93H, § 3, read at malegislature.gov, and the HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400 to 164.414. Fenway Health has not stated that a breach occurred; this article describes what would be required if one did. General information about Massachusetts and federal law, not legal advice.
