Church Pension Group (CPG) has notified members of The Episcopal Church Medical Trust health plans about a data security incident involving Quantum Health, a health benefits services provider.

According to CPG, Quantum Health determined that unauthorized access to its IT network occurred after an employee responded to a vishing (voice phishing) call on May 29, 2026. Between May 29 and June 1, an unauthorized party accessed and acquired files from certain Quantum Health systems.

Some of the files may have contained names along with health insurance information, medical information, and other personal information, including dates of birth, email and mailing addresses, phone numbers, and demographic information. For some individuals, Social Security numbers may also have been involved.

Quantum Health has retained Kroll to manage notifications to individuals whose information was affected. Impacted individuals will receive additional information about the incident and available support, including complimentary credit monitoring, dark web monitoring, and identity theft restoration services.

Members with questions about the incident can contact the Quantum Health Incident Response Line at 844-958-8913, Monday through Friday, 9 a.m.–6:30 p.m. ET, excluding major U.S. holidays.

CPG encourages members to remain vigilant about protecting personal information and to review available online resources for additional guidance on cybersecurity and fraud prevention.