Were you recently affected by a data breach?

Dermatology Partners Data Breach

Dermatology Partners, a dermatology group with offices across Pennsylvania, Delaware, and Maryland, disclosed that an unauthorized individual accessed its data system at the Catonsville, Maryland office in early 2026, potentially exposing sensitive patient information.

Dermatology Partners
Date of Breach: February 27, 2026 - March 10, 2026
CAU logo

Who was affected:

Clients of Dermatology Partners

Impacted Data:

Patient names, dates of birth, addresses, contact information, medical record numbers, dates of service, diagnosis and treatment information, health insurance information

Dermatology Partners, a privately owned dermatology group with more than 30 offices across Pennsylvania, Delaware, and Maryland, has notified patients of a data security incident affecting its Catonsville, Maryland location. The company reported that an unauthorized individual accessed its data system for nearly two weeks earlier this year, though it could not rule out that patient records were viewed during that window. Healthcare providers hold some of the most sensitive personal and medical information that exists, and patients trust that this data will be kept secure.

Dermatology Partners’ Data Breach Investigation

According to a notice posted on the company’s website, Dermatology Partners determined that between February 27, 2026, and March 10, 2026, an unauthorized individual gained access to the data system used by its Catonsville office, located at 716 Maiden Choice Lane. The company’s investigation reportedly found no direct evidence that any data was actually copied or removed from the system during the period of unauthorized access. However, Dermatology Partners also acknowledged that it could not determine with certainty which specific patient records may have been viewed while the unauthorized individual had access. Because of this uncertainty, the company chose to notify all patients who had been seen at the Catonsville location, rather than limiting notice to a smaller subset of confirmed victims.

Dermatology Partners posted its notice of the incident on June 23, 2026, roughly three months after the intrusion window closed. The company has not disclosed the exact total number of patients affected by the breach. It stated that it is cooperating with ongoing investigations, conducted a forensic review of the incident, and has since implemented enhanced access controls and engaged outside cybersecurity professionals to help prevent a similar event in the future.

Healthcare organizations like dermatology practices remain a frequent target for cybercriminals because the data they store, including names, birth dates, Social Security numbers in some cases, insurance details, and detailed medical histories, is uniquely valuable on the black market. Unlike a stolen credit card number, which can be canceled and reissued, information like a patient’s diagnosis history, medical record number, or Social Security number cannot simply be replaced, making healthcare data breaches especially damaging for long-term identity theft and medical fraud risk.

The nearly two-week window during which the unauthorized individual had access to Dermatology Partners’ systems is also notable. Longer periods of undetected access generally raise the risk that more data was viewed or exfiltrated than a company can definitively confirm, which is precisely the uncertainty Dermatology Partners cited as its reason for notifying its full Catonsville patient population rather than a narrower group. This kind of broad, precautionary notification is common in healthcare breaches where forensic logs cannot conclusively rule out access to specific records.

The combination of medical record numbers, treatment and diagnosis information, and contact details exposed in this incident is particularly useful to bad actors seeking to commit medical identity theft, file fraudulent insurance claims, or craft convincing phishing messages that reference a patient’s actual provider and treatment history. Patients affected by breaches involving this kind of information are frequently targeted with follow-up scam calls, emails, or letters that appear to come from a legitimate medical provider or insurer, making it especially important to verify the authenticity of any unexpected communication referencing this breach.

The multi-month gap between the discovery of unauthorized access in early March 2026 and the public notification posted in late June 2026 is also consistent with a broader pattern seen across many healthcare data breaches. Forensic investigations into unauthorized system access often take weeks or months to complete, particularly when a company must determine the scope of an intrusion, identify which records may have been exposed, and coordinate legal review before notifying patients under state and federal breach notification laws. While these timelines can feel long to affected individuals, they typically reflect the complexity of confirming exactly what happened rather than an attempt to delay disclosure.

Because Dermatology Partners has stated it cannot determine with certainty which specific patient files were accessed, individuals who received a notification letter or who were treated at the Catonsville office during the identified window should treat the incident as a genuine risk to their personal and medical privacy, even without direct confirmation that their own file was viewed. Proactive monitoring of financial accounts, insurance statements, and any communications referencing the breach is a reasonable precaution regardless of whether a specific record was confirmed as accessed.

When Did This Breach Occur?

The unauthorized access to Dermatology Partners’ Catonsville office data system occurred between February 27, 2026, and March 10, 2026. The company did not post its public notice of the incident until June 23, 2026, several months after the intrusion was contained.

What Information Was Breached?

Dermatology Partners stated that the information that may have been viewable during the incident includes patient names, dates of birth, home addresses, contact information, medical record numbers, dates of service, diagnosis and treatment information, and potentially health insurance information. The company has not disclosed the exact total number of patients affected.

What You Can Do

If you received a notification letter from Dermatology Partners or believe you may have been a patient at its Catonsville office between February 27, 2026, and March 10, 2026, consider taking the following steps:

  • Review any statements from your health insurance provider for services you do not recognize.
  • Monitor your credit reports and consider placing a fraud alert or credit freeze with the major credit bureaus.
  • Be cautious of unsolicited calls, emails, or letters referencing this breach, your medical history, or your provider, as scammers often exploit breach notifications for phishing attempts.
  • Keep any notification letter you received, as it may be useful in documenting your inclusion in the breach.

File a Data Breach Lawsuit Against Dermatology Partners

If you were notified that your personal or medical information may have been exposed in the Dermatology Partners data breach, you may have legal options. Companies that collect and store sensitive patient data have a responsibility to protect it with reasonable security safeguards, and when that data is compromised, affected individuals may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: The exact incident date has not been publicly disclosed by the company.
Date of Breach: The exact incident date has not been publicly disclosed by the company.
Date of Breach: January 16-19, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.