Were you recently affected by a data breach?

Current Data Breaches

Featured Data Breaches

Date of Breach: Reported to the Vermont Attorney General's Office on September 23, 2026

Social Security numbers, government-issued ID numbers, financial account codes, and credit or debit account information

Date of Breach: Capital Family Physicians reported the breach to the U.S. Department of Health and Human Services Office for Civil Rights, affecting 2,545 individuals in North Carolina. A ransomware group calling itself cmdorganization separately claimed responsibility, listing the practice on its leak site on or around May 29, 2026.

Protected health information, which may include names, medical records, and billing information; the practice has not publicly detailed the complete list of affected data elements

Date of Breach: AngMar discovered unusual activity on its network on July 20, 2026, and completed its review of affected data on September 10, 2026. Notification letters were mailed to affected individuals beginning September 22, 2026.

Name, address, date of birth, Social Security number, patient ID, medical record number, health insurance information, service date, diagnosis/condition information, provider name, prescription information, and/or medical history information

Date of Breach: The underlying incident occurred on or about December 18, 2025, at Aesto, LLC, a third-party vendor to Marana Health Center. Marana Health Center was notified by Aesto on or around June 26, 2026, and mailed notification letters to affected individuals beginning September 23, 2026.

Full name, date of birth, Social Security number, medical record number

Date of Breach: Azure Standard reported the incident to the Vermont Attorney General on September 21, 2026. A specific breach date has not been publicly disclosed.

Financial account numbers, credit and debit card information

Date of Breach: Disclosed September 22-23, 2026

The company has not yet disclosed a specific list of affected data categories, stating its investigation is ongoing to determine whether patient, employee, credentialed provider, or other business information was accessed

Date of Breach: Reported to HHS OCR on September 6, 2026

The company has not published a specific itemized list of affected data categories for this incident, though as a health plan Hamaspik typically holds names, contact information, health plan enrollment details, and medical records

Date of Breach: December 15-19, 2025

The company has not published a specific list of affected data categories, and has stated it is currently unaware of any personal information having been released

Date of Breach: Detected June 2026

The company has not published a specific list of affected data categories for this incident, though pharmacy benefit records like those WellDyne manages typically include names, contact information, insurance details, and prescription history