Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatthird-party-vendor-breachbreach-disclosure-notificationmass-credential-exposure

Healthcare Sector Data Breaches and Security Risks in Late 2025

Updated 3mo agoFirst seen Jan 8, 20263 sources

A significant reduction in the number of large healthcare data breaches was reported for October 2025, with only 28 incidents affecting 500 or more individuals, the lowest monthly total since May 2020. However, the number of individuals impacted surged by 540% to over 11 million, largely due to a few major breaches still under investigation. The reporting delay was attributed to a government shutdown that created a backlog at the HHS Office for Civil Rights, potentially causing underreporting for the month. Notably, the Bosch Choice Welfare Benefit Plan disclosed a breach affecting 55,000 members, stemming from a business associate's cybersecurity incident that exposed sensitive personal and health information. The affected business associate also notified other covered entities and implemented additional safeguards in response.

Security risks in the healthcare sector remain acute, particularly for small practices with limited IT resources. A technical investigation highlighted the dangers of improper hardware disposal and lack of disk encryption, revealing that sensitive data and password hashes can be easily extracted from discarded computers. Industry experts emphasize that business associates are a major source of breached records, accounting for a disproportionate share of affected individuals despite submitting fewer incident reports. This underscores the need for robust vendor oversight and comprehensive HIPAA compliance strategies, especially for small and mid-sized healthcare organizations.

Share:
Healthcare Sector Data Breaches and Security Risks in Late 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 6, 20266mo ago

Healthcare practice computer discarded with unencrypted patient data

A computer from a small healthcare practice was discarded in a bulk goods disposal area with its hard drive still intact and unencrypted. The drive contained exposed personal, financial, and healthcare records dating from 2013 to 2018, illustrating a secure disposal failure.

Oct 31, 20258mo ago

October 2025 healthcare breach totals show 28 incidents and 11M+ affected

Healthcare organizations reported 28 breaches affecting 500 or more individuals in October 2025, the lowest monthly count since May 2020. Despite the lower incident count, more than 11 million individuals were affected, largely because of the Conduent breach.

Business associate notifies entities and individuals after Bosch-related breach

Following the Bosch Choice Welfare Benefit Plan incident, the affected business associate notified impacted entities and individuals and implemented additional technical safeguards. These actions were part of the response to the vendor-linked breach.

Bosch Choice Welfare Benefit Plan breach reported to HHS OCR

A data breach affecting 55,000 Bosch Choice Welfare Benefit Plan members was reported to the HHS Office for Civil Rights on October 31, 2025. The breach stemmed from a cybersecurity incident at a vendor of a business associate and exposed names, Social Security numbers, dates of birth, claims, insurance details, and diagnoses.

Oct 1, 20259mo ago

SafePay ransomware group claims responsibility for Conduent breach

The SafePay ransomware group publicly claimed responsibility for the Conduent Business Services breach. This provided threat-actor attribution for one of the largest healthcare-related incidents reported in the period.

Conduent Business Services breach impacts millions in healthcare sector

A major breach at Conduent Business Services affected healthcare data on a massive scale and may have impacted up to 14.8 million people in Texas alone. The incident drove a sharp increase in the number of individuals affected by healthcare breaches reported for October 2025.

Aug 1, 202511mo ago

Leidos QTC Health First Rehabilitation Resources email breach begins

In August 2025, Leidos QTC Health First Rehabilitation Resources experienced unauthorized access to its email system, exposing patient data including names, government IDs, Social Security numbers, and medical information. The organization moved to secure systems, brought in third-party cybersecurity experts, and later upgraded security infrastructure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Threat actors
2 linked
Malware
2 linked
Affected products
6 linked
Google DriveOnedriveBitlockerGoogle DriveGoogle DriveGoogle Drive
Organizations
10 linked
Bosch Choice Welfare Benefit PlanTri Century Eye CareConduent Business Services LLCNorth Atlantic States Carpenters Health Benefits FundRevere Health, PCCentral Jersey Medical CenterSierra Vista Hospital & ClinicsHeartland Health CenterSaint Mary’s Home of ErieLeidos QTC Health First Rehabilitation Resources
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Healthcare Sector Data Breaches and Security Risks in Late 2025 | Mallory