Healthcare

Healthcare data breaches expose some of the most sensitive personal information that exists: medical records, Social Security numbers, insurance details, diagnosis and treatment history, and sometimes genetic or mental health information. These exposures can lead to medical identity theft, insurance fraud committed in a patient’s name, and the unwanted disclosure of private health conditions that can affect employment, relationships, or insurability. Hospitals, clinics, health insurers, and healthcare technology vendors are among the most frequently targeted organizations for ransomware and data theft, in part because medical records are especially valuable on illicit markets and healthcare providers often operate complex, interconnected IT systems. A single breach at a hospital system, health plan, or medical billing vendor can affect hundreds of thousands of patients at once. This page tracks confirmed data breaches at hospitals, clinics, insurers, and other healthcare organizations, including what data was exposed, which companies notified the HHS Office for Civil Rights and other regulators, and what affected patients can do next to protect their medical and financial identity.

Sturgis Hospital Data Breach: What Happened, What Information Was Involved, and What You Can Do

Sensitive information at risk from Sturgis Hospital cybersecurity incident

In December 2024 and June 2025, Sturgis Hospital experienced a data breach that may have exposed patient and employee information, including Social Security numbers, bank details, and medical records. Learn what happened, what information was involved, steps the company is taking, and how you can protect yourself—including when to contact a data breach attorney for legal help.

Sturgis Hospital Data Breach: What Happened, What Information Was Involved, and What You Can Do Read More »

Wayne Memorial Hospital Data Breach

Nacogdoches Memorial Hospital data breach,

Wayne Memorial Hospital Cybersecurity Incident Notice

Wayne Memorial Hospital (WMH) recently experienced a ransomware incident that impacted a limited number of our systems between May 30, 2024, and June 3, 2024. Upon discovery, we immediately secured our network, restored operations from backups, and engaged independent cybersecurity experts to investigate.

The review determined that certain patient information may have been accessed without authorization. While not every individual was affected, the data at risk may include names, Social Security numbers, medical records, insurance details, and other personal information.

On August 27, 2025, WMH mailed written notices to all affected individuals and provided guidance on how to protect their personal information. Data security remains one of our highest priorities, and we have implemented enhanced safeguards to prevent future incidents.

Wayne Memorial Hospital Data Breach Read More »

Highlands Oncology Data Breach Exposes Sensitive Patient Information

Highlands oncology data breach

Highlands Oncology Group discovered a cyberattack on June 2, 2025, exposing sensitive patient data including Social Security numbers, medical records, and financial information. The breach affected systems between January and June 2025. Highlands is offering free 12-month credit monitoring through Experian to those impacted. Learn how to protect your identity and enroll in complimentary protection services.

Highlands Oncology Data Breach Exposes Sensitive Patient Information Read More »

McKenzie Data Breach Exposes Sensitive Information

Nacogdoches Memorial Hospital

McKenzie, a healthcare company, suffered a data breach after an unauthorized actor accessed its network between April 14 and 15, 2025, potentially exposing full names, Social Security numbers, and financial account information. Affected individuals were notified by letter starting July 24, 2025. Anyone who received a notification should immediately enroll in the free identity protection

McKenzie Data Breach Exposes Sensitive Information Read More »

Myrtue Medical Center Data Breach

Myrtue Medical Center Data Breach

Myrtue Medical Center detected unusual network activity on June 13, 2025, later found to involve unauthorized access to sensitive files containing patients' names, driver's license numbers, identification numbers, Social Security numbers, and direct deposit information. Anyone whose data was handled by the medical center could be affected. Impacted individuals should place a fraud alert or

Myrtue Medical Center Data Breach Read More »

Western Montana Mental Health Center Data Breach Exposes Sensitive Patient Information

Western Montana Mental Health Center data breach

On September 15, 2024, Western Montana Mental Health Center (WMMHC) discovered a data breach exposing sensitive personal and health information. Impacted individuals are urged to enroll in complimentary identity protection services through IDX by October 17, 2025. Learn what happened, what information was involved, and how to protect yourself from potential identity theft.

Western Montana Mental Health Center Data Breach Exposes Sensitive Patient Information Read More »

Community Health Network Data Breach: What Indiana Residents Need to Know and Do Now

CCI Financial Data Breach

Community Health Network has confirmed a data breach affecting patients across Indiana. Sensitive information—including Social Security numbers, medical records, and insurance details—may have been exposed. Learn what happened, who’s at risk, and what urgent steps you should take to protect your identity. Legal options may also be available for those affected.

Community Health Network Data Breach: What Indiana Residents Need to Know and Do Now Read More »

Data Breach Alert: Texas Centers for Infectious Disease Associates (TCIDA) Notifies Patients of Security Incident

Healthcare professional in full PPE adjusting safety glasses for optimal protection indoors.

Texas Centers for Infectious Disease Associates (TCIDA) has announced a significant data security incident that may have exposed the personal and protected health information of its current and former patients. The breach, which was discovered on July 19, 2024, stemmed from unusual activity in TCIDA’s network related to an incident experienced by their former third-party billing vendor.

Data Breach Alert: Texas Centers for Infectious Disease Associates (TCIDA) Notifies Patients of Security Incident Read More »

Rocky Mountain Oncology Care Data Breach

Woman resting in bed wearing a scarf, using her phone during cancer treatment.

A phishing attack against Integrated Oncology Network, which manages Rocky Mountain Oncology Care, allowed hackers to access email and SharePoint accounts between December 13-16, 2024, exposing patients' names, dates of birth, Social Security numbers, medical records, and financial information. Anyone treated at the facility may be affected. Affected patients should immediately place a fraud alert

Rocky Mountain Oncology Care Data Breach Read More »