Were you recently affected by a data breach?

Sanford Health Data Breach

A data security incident at imaging vendor DMS Health Technologies exposed information belonging to 21,211 Sanford Health patients. An unauthorized party had access to the DMS network between March 27 and April 24, 2023. Names, dates of birth, dates of service, physician names and exam types were involved.

Sanford Health
Date of Breach: March 27 - April 24, 2023
CAU logo

Who was affected:

Clients of Sanford Health

Impacted Data:

Names, dates of birth, dates of service, physician names, exam types

Sanford Health, the largest rural health system in the United States, has notified more than 21,000 patients that their personal and medical information may have been exposed in a data security incident at one of its imaging vendors. The incident did not occur inside Sanford Health systems. It happened at DMS Health Technologies, the company that supplies and operates the mobile heart screen trucks Sanford Health patients use for cardiac screening.

Patients who trust a health system with their medical histories rarely know how many outside companies handle that same information along the way. When a hospital or clinic shares patient data with a vendor, the obligation to keep that information secure travels with it, and both the provider and the vendor are responsible for protecting it.

Sanford Health’s Data Breach Investigation

The investigation centers on DMS Health Technologies, a West Fargo, North Dakota company that provides mobile imaging services to hospitals and health systems across the region. DMS owns and operates fleets of mobile MRI, CT, PET/CT and nuclear medicine units, and Sanford Health contracts with the company for the mobile heart screen trucks it sends into rural communities. Because DMS handles patient information in order to perform those screenings, records belonging to Sanford Health patients were stored on the DMS network at the time of the incident.

According to information released by DMS, the company became aware of suspicious activity affecting certain computer systems on April 23, 2023. DMS launched an investigation with the assistance of third-party forensic specialists and determined that an unauthorized party had access to its network between March 27 and April 24, 2023. During that window, the intruder had the ability to access information stored on the network. DMS then conducted a review of the files at risk to determine whose information was involved, a process that took several months to complete before individual notifications went out.

Sanford Health publicly disclosed its share of the incident on September 15, 2023, confirming that 21,211 of its patients would be notified. The affected patients are spread across the health system’s rural footprint: 10,334 in North Dakota, 4,967 in Minnesota, 2,685 in South Dakota, 1,058 in Iowa, and smaller numbers across 36 additional states. Sanford Health serves more than one million patients across roughly 250,000 square miles, operating 46 medical centers and employing about 2,800 physicians and advanced practice providers.

Sanford Health was not the only health system affected. DMS contracts with multiple providers, and at least two others disclosed related breaches in the same period. Avera reported roughly 1,500 affected patients and Monument Health reported roughly 2,500, with all three systems headquartered in South Dakota. DMS, rather than the individual health systems, took responsibility for mailing notification letters to affected patients and for offering identity monitoring services through Kroll to some of them, depending on the specific information exposed in each case.

Incidents like this one illustrate why third-party vendors have become such a significant source of risk in healthcare. A single imaging contractor, billing company or records vendor can hold data belonging to patients of many unrelated hospitals, which means one intrusion can cascade into breach notifications across several states and several health systems at once. Rural health systems are particularly dependent on shared mobile and contracted services, because the patient volume in any single community rarely justifies permanently installed imaging equipment.

The categories of information involved here are less immediately dangerous than a Social Security number or a financial account number, but they are far from harmless. Names paired with dates of birth are durable identifiers that do not change and cannot be reissued after a breach the way a payment card can. Combined with a date of service, a physician name and an exam type, they also reveal that a specific person sought a specific kind of medical care on a specific date, which is sensitive on its own terms and can be used to make fraudulent contact appear credible.

That last point is the practical risk for most people affected. Someone holding this combination of details can call or email a patient, correctly reference the screening they had and the physician who ordered it, and use that accuracy to request a Social Security number, an insurance policy number or a payment. Health systems and their vendors do not typically ask for that information by unsolicited phone call or email, and patients who receive such a request after a breach notification should treat it with suspicion regardless of how well informed the caller seems.

Breach notification timelines are also worth understanding. Federal and state laws generally require notice within a set number of days after a breach is discovered, but the clock and the practical reality often diverge, because determining exactly whose records were in an affected system can take months of file review. That gap between the intrusion and the letter is normal in the sense that it is common, but it also means affected patients may be exposed for a considerable period before they learn anything happened.

When Did This Breach Occur?

The unauthorized access to the DMS Health Technologies network took place between March 27 and April 24, 2023. DMS became aware of suspicious activity on its systems on April 23, 2023, near the end of that window, and moved to secure the network.

DMS published its public notice of the data event on June 16, 2023, while it was still working to identify the individuals whose information was involved. Sanford Health announced its own patient impact on September 15, 2023, nearly five months after the intrusion ended. Avera disclosed on September 6, 2023, and Monument Health disclosed on the same day as Sanford Health.

The staggered dates reflect a sequence common to vendor breaches. The vendor detects and investigates first, then determines which client organizations had data on the affected systems, and only then can each health system tell its own patients how many were involved.

What Information Was Breached?

The information potentially involved varies by individual, but according to the notice it was generally limited to names, dates of birth, dates of service, physician names and exam types.

DMS has stated that the exposure typically did not extend beyond those categories. Where the specific information involved warranted it, DMS offered complimentary identity monitoring services through Kroll, with the details included in each individual notification letter. That approach indicates the company assessed the risk as varying from person to person rather than being uniform across everyone affected.

Notice of the incident was also provided to federal law enforcement and to the U.S. Department of Health and Human Services, the standard path for an incident involving protected health information.

What You Can Do

If you received a notification letter from DMS Health Technologies about this incident, or you were a Sanford Health mobile heart screen patient during the relevant period, there are several steps worth taking.

  • Read the notification letter closely to see which categories of your information were involved and whether identity monitoring through Kroll was offered to you.
  • Enroll in any monitoring service offered, since there is no cost to you and enrollment deadlines apply.
  • Review explanation of benefits statements from your health plan for services you did not receive, which can be a sign of medical identity theft.
  • Request your free annual credit reports from the three major bureaus and check for accounts you did not open.
  • Consider placing a fraud alert or a security freeze on your credit file, both of which are free.
  • Be skeptical of unsolicited calls, texts or emails referencing your medical care, even when the caller knows accurate details about your exam or your physician.

You can also contact DMS directly at 866-373-7164 to ask whether your information was affected by this incident.

File a Data Breach Lawsuit Against Sanford Health

Patients whose protected health information is exposed through a vendor relationship they never chose, and may not have known existed, have grounds to ask how that data was protected and whether reasonable safeguards were in place. Legal claims arising from breaches of this kind commonly examine the security measures a company had implemented, how quickly an intrusion was detected, and how long affected individuals waited before they were told.

Speaking with an attorney costs nothing and does not obligate you to file anything. It is simply a way to understand what options exist, particularly if you have already seen suspicious activity following the notice.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: On or around July 7, 2025 (investigation concluded July 17, 2026)
Date of Breach: March 27 - April 24, 2023
Date of Breach: Not publicly disclosed; notification letters dated August 3, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.