[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc3yA9EH1z1poJB1JlxYgltOWarm0WkwAEVL4cMaBFqU":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":23,"source":24,"isVerified":4,"isSpamList":25,"isSensitive":4,"processingStatus":26,"logoUrl":27,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":28},"6a67638fce7a4eb6c1808711","ArcherHealth2025","Archer Health 2025 Data Breach","archer-health-2025","archerhealthinc.com",{"name":12,"sector":13,"country":14,"website":10},"Archer Health Inc.","Healthcare","United States","2025-09-07T00:00:00.000Z","2026-07-27T13:56:31.394Z",4285,[19,20,21,22],"Names","Dates of birth","Social Security numbers","Limited medical information","\u003Cp>\u003Cstrong>The Archer Health 2025 data breach\u003C\u002Fstrong> was a cybersecurity incident on a third-party IT service provider's server supporting certain systems used by the healthcare organization. Archer learned of the incident September 7, 2025. An unauthorized person accessed patient data stored on the provider's server; the organization specifically said its own systems and networks were not involved.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights portal lists 4,285 affected individuals for Archer Health and classifies the event as a network-server “Hacking\u002FIT Incident.” This official person total is used in pwnCount and totalRecords. importedRecordCount is zero because no raw person-level data was obtained.\u003C\u002Fp>\n\u003Ch2>How Was the Archer Health Incident Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the “Notice of Data Privacy Incident” published on Archer Health's own website. It describes the September 7 date, unauthorized access on a third-party provider server, unaffected Archer systems, possible data fields, identity monitoring, termination of the provider relationship, and the 833-779-5787 assistance line.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR row dated November 6 for 4,285 people. ClaimDepot's incident page connects the same organization notice and HHS total. A ransomware or attacker-group claim on the secondary page is not added to LeakData's description or tags because the official organization text does not confirm it.\u003C\u002Fp>\n\u003Ch2>What Happened at the Third-Party Provider?\u003C\u002Fh2>\n\u003Cp>Archer learned September 7 that an IT service provider supporting certain systems it uses had experienced a cybersecurity incident. An unauthorized person accessed the provider's server where patient data was stored. Archer said it began an investigation with cybersecurity experts and took steps to contain the event and safeguard patient information after learning of it.\u003C\u002Fp>\n\u003Cp>The organization does not disclose the actor's first access date, duration, or technical method. breachDate and dateDiscovered therefore use September 7 as the earliest known official date. November 6 is the notification stage when patient letters began to be mailed and the HHS report was made.\u003C\u002Fp>\n\u003Ch2>Were Archer's Own Systems Affected?\u003C\u002Fh2>\n\u003Cp>The official notice explicitly says the incident did not involve Archer Health's own systems or networks. The affected environment was the third-party IT provider's server. This distinction is important for understanding the technical source of a healthcare breach reported under Archer's name.\u003C\u002Fp>\n\u003Cp>The LeakData record shows the affected organization relationship through Archer patients while identifying the attack surface as a provider server. It does not say that Archer's network was compromised or its systems encrypted. The vendor-originated incident was reported by Archer because patient data associated with its services was affected.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>According to Archer's investigation, files varied by individual but may have included a name, date of birth, Social Security number, and limited medical information about healthcare the patient received. It should not be assumed that every field was present for every person or that all information was misused.\u003C\u002Fp>\n\u003Cp>“Limited medical information” is not divided into narrower diagnosis, medication, procedure, insurance, or billing fields, so LeakData does not add those subtypes without evidence. Individual letters are the primary source for determining which fields were associated with each patient. Additional sensitive information should not be supplied in an unexpected message even when it names the incident.\u003C\u002Fp>\n\u003Ch2>How Should 4,285 People and Zero Imports Be Read?\u003C\u002Fh2>\n\u003Cp>4,285 is the affected-person count published in the HHS\u002FOCR portal; it is not a file, data-row, or provider-account count. pwnCount and totalRecords show this official person total. importedRecordCount 0 means no raw, searchable person records were transferred into LeakData and does not mean the number of affected people is zero.\u003C\u002Fp>\n\u003Cp>The organization notice does not publish an aggregate count, so the official total comes from the federal regulator row. If the same provider incident produces separate notices for other customers, those figures are not added to Archer's total without evidence. Each customer event should be evaluated through its own official regulatory scope.\u003C\u002Fp>\n\u003Ch2>What Did the Organization Do and What Can Recipients Do?\u003C\u002Fh2>\n\u003Cp>Archer said it ended its relationship with the third-party provider and implemented enhanced controls for vendor security and monitoring. Patients whose Social Security numbers may have been involved were offered complimentary identity monitoring. The organization also recommends checking healthcare statements for charges related to services not received.\u003C\u002Fp>\n\u003Cp>The toll-free call center at 833-779-5787 is available weekdays from 6:00 a.m. to 6:00 p.m. Pacific Time. Recipients should check their own letters for monitoring enrollment terms, review healthcare statements, and verify unfamiliar services with the healthcare entity or insurer. A full SSN, password, or one-time code should not be shared.\u003C\u002Fp>","Archer Health official notice, HHS\u002FOCR report, and independent incident reporting",false,"completed","\u002Fuploads\u002Flogo\u002Farcherhealthinc_com.png","Low"]