Suntree Internal Medicine, a healthcare provider based in Melbourne, Florida, has notified patients of a data security incident that exposed personal and medical information. Healthcare providers that store patient records have a responsibility to protect that sensitive information, and when that trust is broken, patients deserve a clear accounting of what happened and what is being done about it.
Suntree Internal Medicine’s Data Breach Investigation
According to a notice posted by Suntree Internal Medicine, the practice identified unusual activity within a portion of its digital environment on September 28, 2025. Upon discovering the activity, Suntree Internal Medicine took steps to secure its network and engaged cybersecurity experts to investigate. That investigation determined that certain files may have been accessed or acquired without authorization, and the practice then reviewed those files to determine what information they contained and which patients may have been affected. Suntree Internal Medicine has stated it has no evidence that any potentially affected information has actually been misused.
Separately, the ransomware group Incransom publicly claimed responsibility for a cyberattack on Suntree Internal Medicine on October 1, 2025, just days after the practice says it first identified unusual network activity, and threatened to leak sensitive medical data if the practice did not respond to its demands. Ransomware groups that target healthcare providers typically gain access to a network, copy sensitive files before encrypting systems, and then use the threat of publicly leaking that data as leverage in extortion negotiations. Healthcare organizations remain one of the most frequently targeted sectors for this type of attack, since medical records combine highly sensitive personal details with information that is difficult or impossible for a patient to change, making it especially valuable to criminals and especially damaging when exposed.
The types of information affected were not the same for every patient; Suntree Internal Medicine has stated that not every individual had all of the potentially exposed data elements involved. The practice has also stated that patients’ Social Security numbers, credit card information, and bank account information were not affected by this incident, which distinguishes it from breaches that expose full financial identity information. Even so, exposure of medical treatment details and health insurance information carries its own risks, including medical identity theft, where a criminal uses a victim’s health insurance information to obtain medical services or prescriptions billed to the victim’s account.
When Did This Breach Occur?
Suntree Internal Medicine states that it identified unusual activity within its network on September 28, 2025. The practice has not published the exact date the underlying unauthorized access began, only the date it was discovered and the subsequent investigation timeline. The Incransom ransomware group publicly claimed responsibility for an attack on Suntree Internal Medicine on October 1, 2025.
What Information Was Breached?
Suntree Internal Medicine’s investigation identified instances of patient names, addresses, medical treatment information, and health insurance information that may have been exposed. The practice has specified that the categories of information affected were different for each individual, meaning not every patient had all of these data elements involved. Suntree Internal Medicine has stated that patients’ Social Security numbers, credit card information, and bank account information were not affected by this incident.
What You Can Do
Suntree Internal Medicine recommends several general precautions for potentially affected patients. Only share your health insurance cards with your own healthcare providers and family members covered under your plan. Carefully review any explanation of benefits statement you receive from your health insurance company, and follow up with your insurer or provider about any services you do not recognize. You can also request a year-to-date report of all services billed under your name from your insurance company and check it against your own records. If you notice unfamiliar medical bills, collection notices, or insurance claims, contact your insurer immediately, and consider reporting suspected medical identity theft to your state’s attorney general.
File a Data Breach Lawsuit Against Suntree Internal Medicine
If you are a Suntree Internal Medicine patient and believe your personal or medical information may have been compromised in this incident, you may have legal options available to you. Healthcare providers have a duty to safeguard the sensitive information entrusted to them, and patients affected by a breach can face real consequences, from the burden of monitoring their accounts to the risk of medical identity theft.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.