Data Breach Summary
On June 2, 2025, Highlands Oncology Group PA (Highlands) confirmed that it was the victim of a cyberattack that impacted its computer systems and compromised sensitive data. The breach occurred over a period of time between January 21, 2025, and June 2, 2025, and was discovered on June 2. Highlands Oncology Group has since been working diligently to secure its systems, notify affected individuals, and mitigate future risks. The breach has affected a total of 113,575 individuals, including six residents of Maine.
While there is no confirmed evidence that the exposed data has been used for identity theft or fraud, the compromised files may include a significant amount of sensitive personal information. Highlands’ investigation into the breach revealed that the Medusa ransomware gang has claimed responsibility for the attack.
The investigation into the breach determined that an unauthorized entity accessed Highlands’ network at various times between January 21 and June 2, 2025. During this period, the hackers encrypted several files, and it is believed they may have acquired sensitive personal data stored in the system.
The Medusa ransomware group is a known cybercriminal organization notorious for its targeted attacks on healthcare institutions and organizations. Highlands confirmed that this attack was part of a broader pattern of attacks involving ransomware, where the malicious actors hold files hostage and demand payment for their release. While the breach was discovered in June, the hackers had gained access months earlier, and the full extent of the data exposed is still being investigated.
Based on the forensic investigation, Highlands Oncology has determined that the compromised information may include sensitive data such as:
Full names
Dates of birth
Social Security numbers
Driver’s license/state ID numbers
Passport numbers
Financial details
Medical treatment information
Health insurance data
These types of information, if exposed, could significantly impact those affected by the breach, potentially leading to identity theft, fraud, or unauthorized use of their financial and health data.
Highlands is also offering affected individuals a one-year membership to Experian IdentityWorksSM Credit 3B at no charge, which will provide credit monitoring and identity theft protection services.
On August 1, 2025, Highlands began notifying individuals whose personal information may have been affected by the breach via mail, where possible. This notification provides instructions on how to activate the complimentary identity protection services and guidance on additional steps to protect against identity theft or fraud.
If your personal information has been breached, it’s important to take immediate and proactive steps to minimize the potential impact and protect yourself from identity theft or fraud. Here are some general actions that you should consider taking:
Monitor Credit Reports: Check your credit reports regularly for suspicious activity.
Place a Fraud Alert or Credit Freeze: Set up a fraud alert or freeze your credit to prevent unauthorized access.
Monitor Financial Accounts: Review bank and credit card statements for unfamiliar transactions.
Watch for Phishing Scams: Be cautious of unsolicited requests for personal information.
Change Passwords: Update passwords for online accounts and use strong, unique ones.
Enable Two-Factor Authentication: Add an extra layer of security to online accounts.
Review Health and Insurance Info: Check for fraudulent charges if health data was exposed.
If you were impacted by the Highlands Oncology Group data breach, you may have the right to seek compensation for the potential harm caused. Class Action U is dedicated to helping data breach victims connect with skilled attorneys who specialize in this area of law and can guide you through the legal process.
Individuals whose personal information was exposed may have valid grounds to join a class action lawsuit, allowing them to pursue restitution.
If your data was compromised, you could be entitled to compensation for:
Loss of privacy
Time spent resolving the breach
Out-of-pocket expenses
Emotional distress
By pursuing a class action lawsuit, you not only have the opportunity to recover damages but also help hold Highlands Oncology Group accountable, potentially prompting them to strengthen their security measures. Reach out to Class Action U today to find out if you qualify for a data breach class action and learn more about the compensation you may be entitled to.
©2024 ClassActionU