Dermatology Partners, a privately owned dermatology group with more than 30 offices across Pennsylvania, Delaware, and Maryland, has notified patients of a data security incident affecting its Catonsville, Maryland location. The company reported that an unauthorized individual accessed its data system for nearly two weeks earlier this year, though it could not rule out that patient records were viewed during that window. Healthcare providers hold some of the most sensitive personal and medical information that exists, and patients trust that this data will be kept secure.
Dermatology Partners’ Data Breach Investigation
According to a notice posted on the company’s website, Dermatology Partners determined that between February 27, 2026, and March 10, 2026, an unauthorized individual gained access to the data system used by its Catonsville office, located at 716 Maiden Choice Lane. The company’s investigation reportedly found no direct evidence that any data was actually copied or removed from the system during the period of unauthorized access. However, Dermatology Partners also acknowledged that it could not determine with certainty which specific patient records may have been viewed while the unauthorized individual had access. Because of this uncertainty, the company chose to notify all patients who had been seen at the Catonsville location, rather than limiting notice to a smaller subset of confirmed victims.
Dermatology Partners posted its notice of the incident on June 23, 2026, roughly three months after the intrusion window closed. The company has not disclosed the exact total number of patients affected by the breach. It stated that it is cooperating with ongoing investigations, conducted a forensic review of the incident, and has since implemented enhanced access controls and engaged outside cybersecurity professionals to help prevent a similar event in the future.
Healthcare organizations like dermatology practices remain a frequent target for cybercriminals because the data they store, including names, birth dates, Social Security numbers in some cases, insurance details, and detailed medical histories, is uniquely valuable on the black market. Unlike a stolen credit card number, which can be canceled and reissued, information like a patient’s diagnosis history, medical record number, or Social Security number cannot simply be replaced, making healthcare data breaches especially damaging for long-term identity theft and medical fraud risk.
The nearly two-week window during which the unauthorized individual had access to Dermatology Partners’ systems is also notable. Longer periods of undetected access generally raise the risk that more data was viewed or exfiltrated than a company can definitively confirm, which is precisely the uncertainty Dermatology Partners cited as its reason for notifying its full Catonsville patient population rather than a narrower group. This kind of broad, precautionary notification is common in healthcare breaches where forensic logs cannot conclusively rule out access to specific records.
The combination of medical record numbers, treatment and diagnosis information, and contact details exposed in this incident is particularly useful to bad actors seeking to commit medical identity theft, file fraudulent insurance claims, or craft convincing phishing messages that reference a patient’s actual provider and treatment history. Patients affected by breaches involving this kind of information are frequently targeted with follow-up scam calls, emails, or letters that appear to come from a legitimate medical provider or insurer, making it especially important to verify the authenticity of any unexpected communication referencing this breach.
The multi-month gap between the discovery of unauthorized access in early March 2026 and the public notification posted in late June 2026 is also consistent with a broader pattern seen across many healthcare data breaches. Forensic investigations into unauthorized system access often take weeks or months to complete, particularly when a company must determine the scope of an intrusion, identify which records may have been exposed, and coordinate legal review before notifying patients under state and federal breach notification laws. While these timelines can feel long to affected individuals, they typically reflect the complexity of confirming exactly what happened rather than an attempt to delay disclosure.
Because Dermatology Partners has stated it cannot determine with certainty which specific patient files were accessed, individuals who received a notification letter or who were treated at the Catonsville office during the identified window should treat the incident as a genuine risk to their personal and medical privacy, even without direct confirmation that their own file was viewed. Proactive monitoring of financial accounts, insurance statements, and any communications referencing the breach is a reasonable precaution regardless of whether a specific record was confirmed as accessed.
When Did This Breach Occur?
The unauthorized access to Dermatology Partners’ Catonsville office data system occurred between February 27, 2026, and March 10, 2026. The company did not post its public notice of the incident until June 23, 2026, several months after the intrusion was contained.
What Information Was Breached?
Dermatology Partners stated that the information that may have been viewable during the incident includes patient names, dates of birth, home addresses, contact information, medical record numbers, dates of service, diagnosis and treatment information, and potentially health insurance information. The company has not disclosed the exact total number of patients affected.
What You Can Do
If you received a notification letter from Dermatology Partners or believe you may have been a patient at its Catonsville office between February 27, 2026, and March 10, 2026, consider taking the following steps:
- Review any statements from your health insurance provider for services you do not recognize.
- Monitor your credit reports and consider placing a fraud alert or credit freeze with the major credit bureaus.
- Be cautious of unsolicited calls, emails, or letters referencing this breach, your medical history, or your provider, as scammers often exploit breach notifications for phishing attempts.
- Keep any notification letter you received, as it may be useful in documenting your inclusion in the breach.
File a Data Breach Lawsuit Against Dermatology Partners
If you were notified that your personal or medical information may have been exposed in the Dermatology Partners data breach, you may have legal options. Companies that collect and store sensitive patient data have a responsibility to protect it with reasonable security safeguards, and when that data is compromised, affected individuals may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.