Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatmass-credential-exposureransomware-group-operation

Recent Data Breaches at U.S. Healthcare Providers

Updated 3mo agoFirst seen Dec 17, 20252 sources

Multiple U.S. healthcare organizations have recently disclosed data breaches resulting from unauthorized access to sensitive patient information. Expert MRI, a radiology provider in California, reported that an attacker accessed its network between June and August 2025, exfiltrating data such as names, addresses, dates of birth, diagnoses, and, for some, Social Security numbers. The PEAR threat group claimed responsibility and briefly listed stolen data on its leak site, suggesting a ransom may have been paid. Revere Health in Utah experienced a breach of a third-party payment platform, potentially exposing patient names, dates of birth, addresses, medical record numbers, and partial Social Security numbers, though no evidence of misuse was found. Health Management Systems of America in Michigan disclosed a breach after an employee fell victim to a spear phishing attack, resulting in the unauthorized download of emails containing patient data.

These incidents highlight the ongoing risks faced by healthcare organizations from both targeted ransomware groups and opportunistic phishing attacks. In response, affected providers have reported the breaches to regulators, enhanced their cybersecurity measures, and offered credit monitoring to impacted individuals. The number of affected patients varies by incident, with Revere Health reporting up to 10,800 impacted and Expert MRI yet to disclose a total. The breaches underscore the importance of robust security practices and employee awareness training to mitigate the risk of data compromise in the healthcare sector.

Share:
Recent Data Breaches at U.S. Healthcare Providers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Dec 17, 20256mo ago

McElroy & Associates disclosed email breach and security improvements

McElroy & Associates publicly announced the late-May email compromise in December 2025. The company said it had taken steps to strengthen email security following the incident.

Expert MRI breach was publicly disclosed

Expert MRI's 2025 network intrusion was publicly disclosed in December 2025. The disclosure said sensitive patient data had been stolen and linked the incident to the PEAR threat group.

Dec 15, 20256mo ago

Revere Health disclosed breach and offered protection services

Revere Health publicly confirmed the August 11 breach in December 2025, stating there was no evidence of theft or misuse of the compromised data. The organization offered affected individuals credit monitoring and identity theft protection.

HMSA disclosed spear-phishing email compromise under investigation

Health Management Systems of America disclosed a breach caused by a spear-phishing attack that compromised an employee's email account. The number of affected individuals and the specific data involved were still under investigation at the time of disclosure.

Aug 31, 202510mo ago

Expert MRI intrusion period ended after data theft

By August 2025, the intrusion affecting Expert MRI had concluded after attackers exfiltrated patient information. Reporting indicated the PEAR threat group claimed responsibility and there were signs a ransom may have been paid.

Aug 11, 202511mo ago

Revere Health payment platform was accessed by an unauthorized party

On August 11, 2025, an unauthorized third party accessed a third-party payment platform used by Revere Health. The breach affected up to 10,800 patients and exposed personal and financial information.

Jun 1, 20251y ago

Expert MRI network intrusion began

Expert MRI experienced unauthorized access to its network beginning in June 2025. Attackers remained in the environment through August and exfiltrated sensitive patient data, including Social Security numbers for some individuals.

May 31, 20251y ago

McElroy employee email account was compromised

In late May 2025, an unauthorized party gained access to an employee email account at McElroy & Associates. The incident exposed protected health information tied to 6,633 individuals, including members of the OPEH&W Health Plan.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Threat actors
1 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.