Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatmass-credential-exposureunderground-data-leak

Healthcare Data Breaches and Patient Data Exposure Reports

Updated 3mo agoFirst seen Jan 25, 20262 sources

Multiple organizations reported or were alleged to have suffered data breaches involving sensitive personal and health information. Telehealth provider Call-On-Doc was allegedly breached in early December, with a hacking-forum listing claiming exfiltration of 1,144,223 patient records including contact details and highly sensitive visit metadata (e.g., medical category/condition, including STD-related entries), though the company had not publicly commented at the time of reporting. Separately, Laurel Health Centers (a Federally Qualified Health Center network in Northern Pennsylvania) reported unauthorized access to its email environment from July 11–25, 2025; emails and attachments may have been viewed or copied, potentially exposing a wide range of PHI/PII (including SSNs, insurance/Medicare data, diagnostic/treatment information, and some financial data). Laurel stated it took time to confirm the threat actor was fully removed, completed mailbox review by Dec. 30, 2025, and then began notifying affected individuals and offering credit monitoring.

Outside healthcare delivery, the Civil Service Employees Association (CSEA) labor union reported a May intrusion (May 3–31) resulting in theft of data for 47,000+ members, including names and Social Security numbers, and said it took systems offline, reset passwords, and implemented additional security controls; it reported no evidence of misuse but advised vigilance for identity theft. A separate HIPAA Journal item summarized academic research on insider risk—finding many students would hypothetically sell patient data for money—which is not tied to a specific breach incident but underscores the broader threat environment for healthcare data.

Share:
Healthcare Data Breaches and Patient Data Exposure Reports
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 24, 20265mo ago

DataBreaches reports unconfirmed Call-On-Doc breach claim

DataBreaches published details of the alleged Call-On-Doc incident after reviewing a small sample of the purported data and attempting unsuccessfully to obtain comment from the company. As of publication, no public notice or regulator filing had been identified.

Jan 23, 20265mo ago

Laurel Health Centers mails breach notification letters

Following completion of its review, Laurel Health Centers sent notification letters to affected individuals and offered complimentary credit monitoring. The total number of affected people was still unclear at the time of reporting.

Jan 12, 20265mo ago

Modern Health notifies affected individuals by email

Modern Health emailed impacted individuals about the profile-access incident and said it had disabled the affected profiles. The company also reported to the Massachusetts Attorney General that two Massachusetts residents were affected.

Dec 30, 20256mo ago

Laurel Health Centers completes review of impacted accounts

After investigating the July incident, Laurel Health Centers finished reviewing the affected email accounts to determine what information may have been involved. The review was completed on December 30, 2025.

Dec 1, 20257mo ago

Alleged Call-On-Doc breach and data theft occurs

A hacking-forum seller claimed telehealth provider Call-On-Doc was breached in early December 2025 and that 1,144,223 patient records were exfiltrated. The allegedly stolen data included personal information and health-related details, with screenshots and a sample offered as proof.

Nov 1, 20258mo ago

Modern Health discovers unauthorized access to member profiles

Modern Health identified unauthorized access affecting a limited number of member profiles on its behavioral health platform. The company said Social Security numbers and financial information were not exposed.

Jul 25, 202511mo ago

Unauthorized access window at Laurel Health Centers ends

Laurel Health Centers determined the unauthorized access to affected email accounts continued until July 25, 2025. During this period, protected health information may have been exposed.

Jul 14, 202511mo ago

Laurel Health Centers detects unusual email activity

Laurel Health Centers began investigating unusual activity in its email environment, which led to discovery of the security incident. The organization identified suspicious activity on July 14, 2025.

Jul 11, 20251y ago

Unauthorized access begins in Laurel Health Centers email accounts

Laurel Health Centers later determined that an unauthorized third party accessed certain employee email accounts, with possible viewing or copying of emails and files containing patient information. The exposure window was identified as beginning on July 11, 2025.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Organizations
6 linked
DataBreachesCall-On-DocModern HealthModern LifeElevate Tele-Medicine TelehealthLaurel Health Centers
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Healthcare Data Breaches and Patient Data Exposure Reports | Mallory