Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationmass-credential-exposureransomware-group-operation

Multiple Healthcare Data Breaches Impacting U.S. Medical Providers

Updated 3mo agoFirst seen Dec 12, 20253 sources

Several U.S. healthcare organizations have disclosed significant data breaches involving unauthorized access to patient and employee information. MedStar Health reported that an unauthorized third party accessed internal systems containing sensitive patient data, including names, dates of birth, Social Security numbers, and medical information. The Rhysida threat group claimed responsibility for this attack, alleging the exfiltration and leak of over 7 million pieces of patient data. Brevard Skin and Cancer Center also confirmed a cyberattack in which the Pear threat group claimed to have stolen 1.8 terabytes of data, affecting both patient and employee records with information such as Social Security numbers, health conditions, and billing details. Both organizations have offered complimentary credit monitoring and identity theft protection to affected individuals and are reviewing their cybersecurity measures.

Henry Ford Health in Michigan disclosed an insider data breach affecting nearly 2,000 patients, resulting in the termination of the responsible employee and notification to those impacted. While details on the specific data accessed were not provided, credit monitoring services have been offered. These incidents highlight the ongoing risks faced by healthcare providers from both external threat actors and insider threats, emphasizing the need for robust security policies and continuous evaluation of protective measures to safeguard sensitive health information.

Share:
Multiple Healthcare Data Breaches Impacting U.S. Medical Providers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Dec 12, 20256mo ago

Rhysida claims MedStar Health breach and data leak

The Rhysida ransomware group claimed responsibility for the MedStar Health incident, alleging it exfiltrated 3.7 TB of data, including more than 1.8 million files and over 7 million pieces of patient data, and leaked the material on its dark web portal. This added public attribution and impact claims to the breach narrative.

Pear claims Brevard Skin and Cancer Center attack

The Pear threat group claimed responsibility for the Brevard Skin and Cancer Center breach, saying it stole 1.8 TB of data in a data-theft-and-ransom operation without encryption. The claim newly attributed the incident to a specific threat actor.

Henry Ford Health reports insider data breach affecting 1,984 patients

Henry Ford Health disclosed an insider data breach affecting 1,984 patients after an employee improperly accessed a desktop computer. The employee was terminated, affected individuals were notified, and credit monitoring was offered; the breach was also listed on the HHS OCR portal.

Dec 3, 20257mo ago

MedStar Health begins notifying affected individuals

MedStar Health began sending breach notifications on December 3, 2025. The health system offered complimentary credit monitoring and identity theft protection to affected people.

Nov 18, 20257mo ago

Wilmington Community Clinic completes breach notifications

By November 18, 2025, Wilmington Community Clinic had completed notifications to affected individuals about the August incident. The clinic also offered 12 months of credit monitoring and identity theft protection and reported the matter to regulators.

Oct 14, 20258mo ago

Brevard Skin and Cancer Center detects September attack

Brevard Skin and Cancer Center first detected the cyberattack on October 14, 2025. The organization engaged cybersecurity experts and began response and remediation efforts.

Oct 4, 20259mo ago

MedStar Health detects the cyberattack

MedStar Health identified the cyberattack on October 4, 2025, after the earlier period of unauthorized access. The incident led to a breach review and later patient notifications.

Sep 28, 20259mo ago

Brevard Skin and Cancer Center breached

Attackers gained unauthorized access to Brevard Skin and Cancer Center's environment on September 28, 2025 and exfiltrated patient and employee data. Stolen information included personal, billing, and protected health information such as names, Social Security numbers, and health data.

Sep 12, 20259mo ago

MedStar Health systems accessed in cyberattack

An unauthorized third party accessed MedStar Health internal systems containing sensitive patient data between September 12 and September 16, 2025. Potentially exposed information included names, dates of birth, Social Security numbers, and possibly medical and insurance details.

Aug 13, 202510mo ago

Wilmington Community Clinic suffers network intrusion

Wilmington Community Clinic experienced a cybersecurity incident involving unauthorized access to its network on August 13, 2025. Potentially compromised data included names, health insurance IDs, medical information, dates of birth, and driver's license or state ID numbers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Threat actors
2 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple Healthcare Data Breaches Impacting U.S. Medical Providers | Mallory