[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_i1pFKuIuW2v8b4x8iw1infZSx4EavuEdJf92JEugeU":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":30,"source":31,"isVerified":4,"isSpamList":32,"isSensitive":4,"processingStatus":33,"logoUrl":34,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":35},"6a675fa74a47ecb95923fdae","BeverlyHillsOncologyMedicalGroup2025","Beverly Hills Oncology Medical Group 2025 Data Breach","beverly-hills-oncology-medical-group-2025","bhcancercenter.com",{"name":12,"sector":13,"country":14,"website":10},"Beverly Hills Oncology Medical Group","Healthcare","United States","2025-02-07T00:00:00.000Z","2026-07-27T13:39:51.182Z","2026-07-27T16:11:12.224Z",57655,[20,21,22,23,24,25,26,27,28,29],"Full names","Social Security numbers","Driver’s license or government identification numbers","Financial account information","Credit or debit card information","Health insurance policy information","Treatment information","Diagnosis information","Prescription information","Other clinical information","\u003Cp>\u003Cstrong>The Beverly Hills Oncology Medical Group 2025 data breach\u003C\u002Fstrong> involved unauthorized access to the cancer-care provider's network between February 7 and 11, 2025. The organization investigated with outside cybersecurity professionals and concluded through an October 13 document review that a limited amount of personal information may have been removed from the network.\u003C\u002Fp>\n\u003Cp>The U.S. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\n\u003Ch2>How Was the Oncology Group Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the “Notice of Data Breach” PDF published through the organization's own asset domain. It describes the February 7–11 access window, investigation with outside professionals, October 13 scope finding, possible data fields, written notices beginning around October 31, complimentary credit monitoring, and the 855-291-2692 assistance line.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR entry dated October 31 for 57,655 people. ClaimDepot's incident page provides an independent cross-check by connecting the same PDF, federal total, and California and other state disclosures.\u003C\u002Fp>\n\u003Ch2>What Happened Between February 7 and 11, 2025?\u003C\u002Fh2>\n\u003Cp>The organization said it discovered unauthorized access to its network between approximately February 7 and February 11. It then investigated with outside cybersecurity professionals who regularly analyze these situations to determine the extent to which information on the network may have been compromised. The public notice does not identify the actor, vulnerability, or initial entry method.\u003C\u002Fp>\n\u003Cp>The comprehensive investigation and document review concluded October 13. It found that a limited amount of personal information may have been removed from the network in connection with the event. Written notices began around October 31 for potentially affected people with a last known home address. These dates represent access, scope determination, and consumer notification stages.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>The official notice says a full name may have appeared with one or more of the following: a Social Security number, driver's license or other government identification number, financial-account information, credit- or debit-card information, and health-insurance policy information.\u003C\u002Fp>\n\u003Cp>Treatment, diagnosis, prescription, and other clinical information are also included in the possible scope. Data types vary by person; it should not be assumed that every field was present for every individual or that every document was removed. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope.\u003C\u002Fp>\n\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\n\u003Cp>57,655 is the affected-person count published for this event in the HHS\u002FOCR portal; it is not a document, file, or leak-row count. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\n\u003Cp>Local resident figures in state attorney-general records are subsets of the nationwide 57,655 total and are not added to it because that would count the same people twice. The October 31 HHS report and notice date is separate from the February access window. This distinction preserves both the actual chronology and the metric represented by each number.\u003C\u002Fp>\n\u003Ch2>What Are the Identity, Financial, and Medical Risks?\u003C\u002Fh2>\n\u003Cp>A name combined with an SSN or government identification number can increase the risk of impersonation and fraudulent accounts. Financial-account and card information may support payment fraud, while treatment, diagnosis, prescription, and insurance data can enable medical identity theft and personalized phishing. The organization said it was not aware at notice time of reports of identity fraud or improper use directly resulting from the incident.\u003C\u002Fp>\n\u003Cp>Recipients should review health-insurance Explanation of Benefits documents in addition to credit reports and financial activity. An unfamiliar treatment, prescription, claim, or payment should be verified directly with the relevant provider. Unexpected communications claiming to represent the organization should not receive a full SSN, identification or card number, password, or one-time code.\u003C\u002Fp>\n\u003Ch2>What Did the Organization Do and What Can Recipients Do?\u003C\u002Fh2>\n\u003Cp>Beverly Hills Oncology Medical Group said it investigated with outside professionals, continually evaluates its security and privacy controls, and offered complimentary credit monitoring to affected people. Written notices included credit-report review, fraud alerts, security freezes, financial-account protections, and measures against medical identity theft.\u003C\u002Fp>\n\u003Cp>The confidential toll-free response line at 855-291-2692 is available weekdays from 9:00 a.m. to 9:00 p.m. Eastern Time. A recipient should rely on their own letter for individual data scope and enrollment instructions, promptly report suspicious financial or medical activity to the relevant institution, and consider a free credit freeze where appropriate.\u003C\u002Fp>","Official organization notice, HHS\u002FOCR report, and state-linked incident reporting",false,"completed","\u002Fuploads\u002Flogo\u002Fbhcancercenter_com.png","Medium"]