[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5vmahc5g6nlc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":13,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":34,"seoTitle":8,"seoDescription":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a4cf05d98207b5b0ace5f47","McLeod Physician Associates II - Dillon Family Medicine 2025","McLeod Physician Associates II - Dillon Family Medicine 2025 Data Breach","mcleod-physician-associates-ii-dillon-family-medicine-2025","mcleodhealth.org","2025-10-17T00:00:00.000Z","2026-07-07T12:26:05.495Z",null,"2026-07-18T23:21:46.344Z","Manual reviewed breach record","",[],19553,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":9},{"slug":9},"Medium",[29,30,31,32,33],"Names","Dates of birth","Social security numbers","Personal health data","Health insurance information","\u003Cp>McLeod Physician Associates II - Dillon Family Medicine 2025 data breach is an unauthorized access incident detected on a single server belonging to the Dillon Family Medicine unit within the South Carolina-based healthcare network, which is in the process of being decommissioned. The organization announced on March 5, 2026 that a suspicious file was found on this server and that it started an investigation. As a result of the investigation, it was announced that on April 14, 2026, it was learned that an unauthorized party accessed the server containing Dillon Family Medicine patient information between October 17, 2025 and October 18, 2025. It was stated that the incident did not involve live McLeod Health systems such as the institution's existing electronic health record system, but was related to a limited server.\u003C\u002Fp>\u003Cp>This record has been kept separate to show that the incident is not just a technical system access, but a health data breach that poses a high risk in terms of patient identity and health privacy. Affected files may have included names, dates of birth, social security numbers, and information related to patient care. The official statement listed diagnoses, medication information, test results, medical images, health insurance information and treatment information as examples. Taken together, these data sets pose a critical risk of identity theft, health insurance abuse, fraudulent healthcare claims, targeted fraud, and personalized social engineering attacks.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>Supported data classes for this event are names, dates of birth, social security numbers, personal health data, and health insurance information. Detailed clinical fields such as diagnosis, medication, test results, medical images and treatment information are evaluated within the scope of personal health data instead of separate canonical classes in the system. This choice was not made to hide the clinical nature of the event, but to keep the data classes consistent and verifiable with the existing classification structure. It should not be taken for granted that the same areas are present in every patient; The scope described shows that the fields that may be kept in the relevant files may vary on a per-person basis.\u003C\u002Fp>\u003Cp>Social security number and date of birth are fields that are difficult to change, increasing the risk of identity theft. When used in conjunction with the name, this information may pose risks such as loan applications, opening a fake account, tax or utility fraud, and bypassing identity verification processes. Beyond financial harm, health insurance and clinical care information can lead to medical identity theft. With this information, an attacker can create a fraudulent healthcare claim, misuse an insurance account, or conduct believable personalized call, email, and text message attacks. Privacy risk is also more sensitive for individuals with medical images, test results or diagnostic information.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>The timeline of the incident is supported by the official agency announcement. The suspicious file was noticed on March 5, 2026, and it was learned as a result of the investigation on April 14, 2026 that the unauthorized access took place between October 17, 2025 and October 18, 2025. It was announced that notification letters began to be sent to certain Dillon Family Medicine patients as of June 4, 2026. The total number of affected people in the health violation notification is 19,553. The South Carolina state list shows a breakdown of 16,788 state residents; This value is considered as local notification coverage rather than the total number of affected persons.\u003C\u002Fp>\u003Cp>This record does not imply that all McLeod Health-wide systems are affected. The official announcement states that the incident is limited to the Dillon Family Medicine server, which is in the process of being decommissioned, and does not involve live enterprise systems, such as the existing electronic health record system. This limitation is important; because it accurately identifies the nature of the affected data store without increasing the scope of the incident. However, when patient ID, social security number, and health care information are kept together on a single server, the risk level remains high. The numbers and fields in the record should be evaluated within this narrow scope.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk group is people who have a patient relationship with Dillon Family Medicine and whose information may have been included in the files subject to notification. It appears that those affected by the agency's notice are certain Dillon Family Medicine patients. For this reason, it would not be correct to consider people who received service in another unit of the McLeod Health network but are not recorded in Dillon Family Medicine files within the same scope. Individuals who are unsure of their situation should check whether they have received a notification letter, correspondence that may have been sent to their old address, and health insurance records.\u003C\u002Fp>\u003Cp>Patients with a social security number are at higher risk for identity theft. For patients with diagnosis, medication, test results, medical images, or treatment information, the risk is not just financial; Consequences such as incorrect health records, unrecognized transactions appearing in insurance statements, damage to medical privacy, or personal pressure attempts may occur. People with health insurance information should pay particular attention to unfamiliar health care requests and unusual movements in their insurance accounts. If the identity and health areas are affected together, the risk level should be considered critical.\u003C\u002Fp>\u003Ch2>Urgent Measures to be Taken\u003C\u002Fh2>\u003Cp>People who receive notifications should first carefully review the identity protection and support line information in the letter. If there is an identity protection service offered, it should be evaluated before the registration deadline. People whose social security numbers may have been affected should make it difficult to open new accounts by using credit freeze or fraud alert options. If an unrecognized application, address change, new account or collection record appears in the credit reports, a written objection should be made to the relevant institutions and the records should be kept.\u003C\u002Fp>\u003Cp>On the healthcare side, insurance statements, billing statements, patient portal records and healthcare requests should be checked regularly. If an unrecognized exam, prescription, imaging, test, procedure, or insurance claim is discovered, the health insurance provider and relevant healthcare provider should be contacted promptly. Be wary of authentication requests received by phone, e-mail or text message; Even if the caller says the name of the institution correctly, social security number, date of birth or insurance information should not be shared through the link. Information should only be confirmed directly using the institution's official communication channels.\u003C\u002Fp>\u003Ch2>Long Term Security Strategies\u003C\u002Fh2>\u003Cp>In this case, the risk is not limited to the period when the notification letter is sent. Social security number and date of birth are permanent identification fields; Health information is privacy data that does not lose its value over time. Affected individuals should check their credit reports periodically, be wary of fraudulent refund applications ahead of tax season, and continue to monitor their health insurance records over an extended period of time. Symptoms of medical identity theft may be noticed later than financial identity theft; Therefore, even small transactions that are not recognized in insurance disclosures should be taken into consideration.\u003C\u002Fp>\u003Cp>On the corporate side, security monitoring of servers that are decommissioned or in transition is also important. When retired systems are not monitored as frequently as live production systems, remaining patient files can become targets for attackers. Healthcare organizations' data inventory, access records, backup deletion processes, system shutdown procedures and third-party review steps should be regularly audited. System shutdowns, especially without knowing which patient files, which identity fields and which clinical documents remain on old servers, may delay post-event notification and risk assessment.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>Users who see the McLeod Physician Associates II - Dillon Family Medicine 2025 record on Leakdata should consider the result in the context of Dillon Family Medicine. Although the registry bears the McLeod Health name, the official reported scope of the event is a specific Dillon Family Medicine server. If the user has been a patient in this unit, they should check their old mailing addresses, notification letters, insurance disclosures, and credit reports together. The data fields specified in the notification letter have individual priority; It should not be assumed that the same clinical or identity areas exist for everyone.\u003C\u002Fp>\u003Cp>The date in this record is based on the start date of October 17, 2025, when the event occurred; detection period is due on March 5, 2026, verification of unauthorized access is due on April 14, 2026, and patient notifications are due on June 4, 2026. Users should pay attention to this date distinction when evaluating the results. If signs of abuse are detected, the bank, credit bureau, health insurance provider and healthcare provider should be contacted without delay; Objection, freezing, notification and support line conversations must be recorded in writing. This creates a stronger and more verifiable defense against both financial and medical identity risk.\u003C\u002Fp>","McLeod Physician Associates II - Dillon Family Medicine 2025 Data Breach. 19.6 Thousand reported records are reported. Reported data: Names, Dates of birth…","\u002Fuploads\u002Flogo\u002Fmcleod-physician-associates-ii-dillon-family-medicine-2025.png",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":13},"McLeod Physician Associates II \u002F Dillon Family Medicine","Healthcare \u002F Family Medicine","United States"]