[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3l6hij3v1yk57":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":13,"affectedCountUnit":24,"hasEnglishDescription":4,"contentLocale":25,"availableLocales":26,"translations":28,"severity":31,"dataClasses":32,"description":45,"seoTitle":46,"seoDescription":47,"logoUrl":48,"isVerified":4,"isSensitive":4,"isSpamList":49,"isMalware":49,"company":50},"6a4f8aedb6e298a096ce5f47","Kettering Health 2025","Kettering Health 2025 Data Breach","kettering-health-2025","ketteringhealth.org","2025-04-09T00:00:00.000Z","2026-07-09T11:50:03.096Z",null,"2026-07-29T20:49:57.201Z","Official breach notice and federal healthcare breach listing","https:\u002F\u002Fketteringhealth.org\u002Fpatients-visitors\u002Fpolicies-legal-disclaimers\u002Fnotice-of-privacy-incident\u002F",[16,18,19,20,21],"https:\u002F\u002Fketteringhealth.org\u002Fcybersecurity-incident-faq\u002F","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf","https:\u002F\u002Fwww.hipaajournal.com\u002Fkettering-health-ransomware-attack\u002F","https:\u002F\u002Fketteringhealth.org\u002F",1695382,"known","people","en",[25,27],"tr",{"en":29,"tr":30},{"slug":9},{"slug":9},"Critical",[33,34,35,36,37,38,39,40,41,42,43,44],"Names","Social security numbers","Financial account numbers","Driver's license numbers","Medical information","Treatment information","Health insurance information","Billing information","Claims information","Passport numbers","Usernames","Passwords","\u003Cp>\u003Cstrong>The Kettering Health 2025 data breach\u003C\u002Fstrong> covers unauthorized access to the Ohio health system between April 9 and May 20, 2025. The organization's official notice says certain files and folders on the network may have been viewed or acquired without authorization. The updated federal healthcare-breach total is 1,695,382 people. This is an external people count; production has no import job or local patient data associated with the event.\u003C\u002Fp>\n\n\u003Ch2>Event, actor, and operational impact\u003C\u002Fh2>\n\u003Cp>Kettering Health said it detected suspicious activity on May 20, secured the environment, and began a scope review with third-party specialists. Its official incident FAQ associates the attack with the Interlock ransomware group. Some services, including phone and scheduling systems, were affected and were restored in phases. The operational outage is not the same measurement as the personal-data scope.\u003C\u002Fp>\n\n\u003Cp>The federal listing initially carried a temporary value of at least 501 people while the review continued. The later file review and listing update raised the total to 1,695,382 people. The old placeholder is not added to the new total. Threat-actor claims about data volume reported elsewhere are likewise not combined with this people count or treated as local rows or files.\u003C\u002Fp>\n\n\u003Ch2>Which data types were confirmed?\u003C\u002Fh2>\n\u003Cp>The official notice lists the following person-dependent classes: names, Social Security numbers, financial-account numbers, driver's-licence numbers, medical and treatment information, health-insurance information, billing and claim information, passport numbers, usernames, and associated passwords. It should not be assumed that every field applied to every affected person.\u003C\u002Fp>\n\n\u003Cp>The earlier umbrella class “protected health information” has been removed because it repeated the more specific health fields. The incident FAQ's statement that there was then no indication of access to banking information stored in Epic or MyChart is limited to those systems; it does not negate the person-specific financial-account category in the official notice. The exact field scope is provided in an individual's own notification letter.\u003C\u002Fp>\n\n\u003Ch2>Local coverage and notice boundary\u003C\u002Fh2>\n\u003Cp>Production has no import job linked to the Kettering Health identity. The email, username, password, identity, phone, IP, personal-field, sensitive-data, and general breach-data collections all contain zero local associations. The 1,695,382 people are therefore not presented as a local record total or searchable patient corpus, and local co-occurrence of the reported fields is not claimed.\u003C\u002Fp>\n\n\u003Cp>The current Kettering Health site is operational and publishes both the incident notice and FAQ. People who received a notice should rely on the fields in their own letter and verify unexpected healthcare, collection, or payment requests through a separately obtained official channel rather than the phone number or link in the message. The organization's FAQ specifically warns about payment calls that were not arranged in advance.\u003C\u002Fp>","Kettering Health 2025 Data Breach (1.7 Million People Affected)","The Kettering Health 2025 breach affected 1,695,382 people. Review the access window and person-dependent health, identity, and account fields.","\u002Fuploads\u002Flogo\u002Fkettering-health-2025.png",false,{"name":51,"sector":52,"country":53,"website":10,"websiteArchiveUrl":54,"websiteStatus":55,"websiteCheckedAt":56},"Kettering Health","Healthcare","United States","","active","2026-07-29T20:43:00.000Z"]