DSE, formally known as Diversified Services Enterprises Inc., is a Sarasota, Florida-based company that provides support management services to health care organizations. Because DSE works on behalf of health care providers, it can end up holding sensitive personal and medical information belonging not only to its own employees, but to the patients and clients of the organizations it serves. Companies that handle this volume of sensitive data have a responsibility to keep it secure, and DSE’s recent breach disclosure raises questions about whether that responsibility was met.
DSE’s Data Breach Investigation
According to DSE, the company first became aware of suspicious activity within its computer network on April 14, 2025. After discovering the activity, DSE took steps to secure its systems and launched an investigation with the help of third-party forensic specialists to determine the nature and scope of what had occurred. That investigation determined that an unauthorized party had accessed and copied certain files stored on DSE’s network between March 14, 2025 and April 16, 2025.
Once the scope of the intrusion was identified, DSE engaged a separate data review vendor to examine the contents of the affected files in detail. That review determined that a range of personal and medical information had been exposed, including Social Security numbers, driver’s license and state identification numbers, passport numbers, taxpayer identification numbers, financial account and payment card information, medical record numbers, Medicare and Medicaid identification numbers, health insurance information, and medical history information. DSE reported the incident to the U.S. Department of Health and Human Services on June 13, 2025, and posted a notice about the breach on its website, which it later updated on September 10, 2026.
Health care support vendors like DSE are common targets for cybercriminals precisely because of the depth and sensitivity of the data they hold on behalf of their health care clients. A single vendor can act as a data hub for multiple providers, meaning one successful intrusion can expose records belonging to individuals who may never have had a direct relationship with the vendor itself, only with the health care organization DSE supported. The combination of Social Security numbers, government identification numbers, and detailed medical and insurance records exposed here is especially valuable to identity thieves, since it can be used not only for financial fraud but also for medical identity theft and fraudulent insurance claims.
The roughly 14-month gap between DSE’s own discovery of the incident in April 2025 and the notification update in September 2026 is not unusual for breaches involving third-party forensic review and a comprehensive file-by-file assessment of what data was actually contained in the exposed files, a process that can take many months for a large or complex dataset. Attorneys working with Class Action U are continuing to review DSE’s public notice and gather information from affected individuals as more details become available.
When Did This Breach Occur?
DSE has stated that an unauthorized party accessed and copied files on its network between March 14, 2025 and April 16, 2025. The company became aware of the suspicious activity on April 14, 2025, and reported the incident to the U.S. Department of Health and Human Services on June 13, 2025. DSE’s notice about the incident was later updated on September 10, 2026.
What Information Was Breached?
DSE has confirmed that the exposed information included names, dates of birth, driver’s license or state identification numbers, Social Security numbers, passport numbers, taxpayer identification numbers, financial account information, and payment card information. Protected health information exposed in the breach included medical record numbers, Medicare and Medicaid identification numbers, health insurance information, and medical history information.
What You Can Do
If you received a notice from DSE about this data breach, or believe your information may have been affected, there are steps you can take to help protect yourself, including:
- Monitoring your financial accounts and credit reports for unauthorized activity
- Reviewing your health insurance Explanation of Benefits statements for services you did not receive
- Placing a fraud alert or credit freeze with the major credit bureaus
- Being cautious of unsolicited calls, emails, or letters referencing this breach
- Calling DSE’s dedicated assistance line at 844-301-0075 if you have questions about whether you were affected
File a Data Breach Lawsuit Against DSE
Attorneys working with Class Action U are investigating whether individuals affected by the DSE data breach may be entitled to compensation. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.