[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2k0rzkvn8f6rj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":41,"seoTitle":42,"seoDescription":43,"logoUrl":44,"isVerified":4,"isSensitive":4,"isSpamList":45,"isMalware":45,"company":46},"6a4cfde7cc19ee7d57ce5f47","BlueFishPediatrics2025","Blue Fish Pediatrics 2025 Data Breach","blue-fish-pediatrics-2025","bluefishmd.com","2025-07-11T00:00:00.000Z","2026-07-07T13:23:51.286Z",null,"2026-07-27T16:11:12.266Z","Official provider notice and HHS record confirming unauthorized system access, affected data fields, and 62,150 affected people nationwide","https:\u002F\u002Fcdn.prod.website-files.com\u002F642f23e5f54b794300ac12a6\u002F6a34517a6e0763faa8211fda_Ht2L-Nc7DwkV5blxWpyGHsqexBnFjbAq1yC8AlxplGo.pdf",[16,18],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf",62150,"known","unknown","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"Medium",[30,31,32,33,34,35,36,37,38,39,40],"First and last names","Dates of birth","Driver’s license numbers","State identification numbers","Social Security numbers for a limited number of people","Medical record numbers","Diagnosis or condition information","Laboratory results","Medication information","Healthcare claims information","Clinical or treatment information","\u003Cp>\u003Cstrong>The Blue Fish Pediatrics 2025 data breach\u003C\u002Fstrong> involved an unauthorized party accessing the pediatric practice's computer systems between July 11 and July 17, 2025 and potentially acquiring a limited number of files. The organization detected the activity on or about July 17, contained the incident, and opened an investigation with cybersecurity specialists.\u003C\u002Fp>\n\u003Cp>The current HHS Office for Civil Rights record reports 62,150 affected people nationwide. The previous production figure of 41,485 came from a Texas resident notification and was not the national total.\u003C\u002Fp>\n\u003Ch2>How Was the Blue Fish Pediatrics Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is Blue Fish Pediatrics' “Notice of Data Security Incident” dated June 17, 2026. The organization's letter directly describes the unauthorized access, July 11–17 event window, May 4, 2026 file-review result, reported data fields, credit-monitoring offer, and dedicated assistance line at 1-877-311-3743.\u003C\u002Fp>\n\u003Cp>The second official source is the HHS Office for Civil Rights portal. It identifies Blue Fish Pediatrics as a Texas Healthcare Provider, classifies the case as a Hacking\u002FIT Incident involving a Network Server, and gives 62,150 people and a June 17, 2026 submission date. public breach source is a third cross-check linking to an archived copy of the official letter and the HHS record.\u003C\u002Fp>\n\u003Ch2>What Happened From July 11 Through July 17, 2025?\u003C\u002Fh2>\n\u003Cp>According to the organization's statement, an unauthorized party accessed its computer systems on or about July 17, 2025. Blue Fish Pediatrics immediately contained the incident after detecting the activity. Forensic investigation and manual document review found that a limited number of files were potentially accessed or acquired between July 11 and July 17.\u003C\u002Fp>\n\u003Cp>The file review determined on May 4, 2026 that relevant personal and health information may have been present in those files; individual notices began June 17. The public documents do not disclose the initial-entry method, account or vulnerability used, actor identity, malware, or a ransom demand. LeakData does not infer those details.\u003C\u002Fp>\n\u003Ch2>What Personal Information Was Involved?\u003C\u002Fh2>\n\u003Cp>The official letter lists full names, dates of birth, driver's license numbers, and state identification numbers as personal fields that varied by person. Social Security numbers were also potentially involved for a limited number of individuals. Because not every field applied to everyone, a recipient should rely on the list in their own notification letter.\u003C\u002Fp>\n\u003Cp>The combination of an SSN, birth date, and government identification number can increase the risk of new-account fraud, account takeover, or impersonation. Payment cards, bank accounts, user passwords, and email accounts are not confirmed fields in the official incident list.\u003C\u002Fp>\n\u003Ch2>What Health Information Was Involved?\u003C\u002Fh2>\n\u003Cp>Potential health fields were medical record numbers, diagnoses or condition information, laboratory results, medication information, healthcare claims information, and clinical or treatment information. Because those fields may concern child patients, they can remain sensitive for years and make fake appointment, result, prescription, billing, or insurance messages more convincing.\u003C\u002Fp>\n\u003Cp>Healthcare claims information does not by itself prove that an insurance card or policy number was disclosed. The broad former “health insurance information” class is therefore replaced by the exact “healthcare claims information” field in the official letter. Families should independently verify an unfamiliar provider, service, medication, or claim with the health plan and provider.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and How Did the Organization Respond?\u003C\u002Fh2>\n\u003Cp>The current HHS nationwide total is 62,150 people. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\n\u003Cp>Blue Fish Pediatrics said the event was contained, cybersecurity specialists were engaged, and it continues evaluating its security practices. The organization sent protection guidance to people whose information was in the relevant files, offered complimentary credit monitoring to people whose SSNs were in those files, and established a dedicated response line.\u003C\u002Fp>\n\u003Ch2>What Should Affected Families Do?\u003C\u002Fh2>\n\u003Cp>A parent or guardian who receives a notice should check the fields identified for the child or adult in that letter. If an SSN was involved, consider a credit freeze, fraud alert, and a check for a credit file in the child's name. For health fields, report an unexplained benefit statement, medical bill, laboratory result, or treatment entry to the appropriate provider.\u003C\u002Fp>\n\u003Cp>Do not share a birth date, SSN, identification number, medical record number, password, or one-time code in an unexpected call or message using the Blue Fish Pediatrics name. The official letter lists 1-877-311-3743 for questions, available weekdays from 8:00 a.m. to 5:00 p.m. Central; verify the number independently rather than using an incoming link.\u003C\u002Fp>","Blue Fish Pediatrics 2025 Data Breach (62.2 Thousand Reported Records)","Blue Fish Pediatrics 2025 Data Breach. 62.2 Thousand reported records are reported. Reported data: First and last names, Dates of birth, Driver’s license…","\u002Fuploads\u002Flogo\u002Fblue-fish-pediatrics-2025.png",false,{"name":47,"sector":48,"country":49,"website":10,"websiteArchiveUrl":50,"websiteStatus":50,"websiteCheckedAt":13},"Blue Fish Pediatrics","Healthcare","United States",""]