[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPkpzLxvRGWLXy6M1GSonmj1B5x54M9dG8WoRLsRI3jc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":28,"source":29,"isVerified":4,"isSpamList":30,"isSensitive":4,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":33},"6a6754ebda367b1d0e1a5250","BrevardSkinAndCancerCenter2025","Brevard Skin and Cancer Center 2025 Data Breach","brevard-skin-and-cancer-center-2025","brevardskin.com",{"name":12,"sector":13,"country":14,"website":10},"Brevard Skin and Cancer Center","Healthcare","United States","2025-09-28T00:00:00.000Z","2026-07-27T12:54:03.356Z",54570,[19,20,21,22,23,24,25,26,27],"Full names","Dates of birth","Home addresses","Social Security numbers","Phone numbers","Diagnosis and clinical information","Email addresses","Billing and claims information","Health conditions in FMLA forms","\u003Cp>\u003Cstrong>The Brevard Skin and Cancer Center 2025 data breach\u003C\u002Fstrong> is the incident the Florida dermatology provider detected October 14, 2025 involving protected health and personal information. The investigation found that an unauthorized third party had accessed some data systems on or around September 28 and exfiltrated certain data.\u003C\u002Fp>\n\u003Cp>The official U.S. Department of Health and Human Services Office for Civil Rights entry dated December 12, 2025 reports 54,570 affected individuals and classifies the event as a “Hacking\u002FIT Incident” involving a “Network Server.” In LeakData, pwnCount and totalRecords carry that people total. importedRecordCount is zero because no raw person-level data was obtained.\u003C\u002Fp>\n\u003Ch2>How Was the Brevard Skin and Cancer Center Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary incident account is Brevard's public security notice. Although the original company page returned 404 when reviewed, a preserved PDF confirms the October 14 discovery, approximate September 28 access, data classes, FBI notification, and IDX assistance line. The text expressly says that certain data was exfiltrated from the systems.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR record for 54,570 people. A December 26 consumer letter published by the Massachusetts Attorney General independently supports the patient data types, incident dates, and 24 months of IDX services. The official texts do not confirm an attacker name or a 1.8-terabyte volume, so those secondary claims are excluded.\u003C\u002Fp>\n\u003Ch2>What Happened Between About September 28 and October 14, 2025?\u003C\u002Fh2>\n\u003Cp>After discovering the event October 14, Brevard retained cybersecurity experts, took steps to contain the incident, and began remediating its electronic environment. The inquiry determined that an unauthorized third party had accessed some data systems on or around September 28. The company said it continued analyzing the material to identify affected people and the information types accessed.\u003C\u002Fp>\n\u003Cp>The public text does not disclose the exact end of access, the initial access method, or the unauthorized party's identity. It does, however, confirm exfiltration of certain data, distinguishing the event from one described only as possible access. The notice also says the incident did not disrupt services and would not interfere with patient care.\u003C\u002Fp>\n\u003Ch2>What Information Was Involved for Patients and Employees?\u003C\u002Fh2>\n\u003Cp>For current or former patients, potential fields are full name, date of birth, home address, Social Security number, phone number, diagnosis and clinical information, email address, and billing and claims information. The Massachusetts consumer letter lists the same patient categories. Not every field should be assumed to have been present for every person.\u003C\u002Fp>\n\u003Cp>For current or former employees, the potential scope includes full name, date of birth, home address, SSN, phone number, a health condition in an FMLA form, and email address. Brevard separately said the information was not believed to include financial account numbers, banking information, or credit or debit card details; those excluded fields are not presented here as exposed data.\u003C\u002Fp>\n\u003Ch2>Why Is 54,570 Used Instead of 53,255?\u003C\u002Fh2>\n\u003Cp>54,570 is the current official people total published in the HHS\u002FOCR portal on December 12, 2025. The 53,255 figure appears in a secondary incident page first published December 10, two days before the HHS entry. Because the later healthcare regulator record is authoritative for the present total, pwnCount and totalRecords are set to 54,570.\u003C\u002Fp>\n\u003Cp>The two figures are not added together and do not create separate breach entries; they are scope measurements for the same event at different points in time. 54,570 is also not a count of files accessed or accounts uploaded to LeakData. importedRecordCount of 0 means raw person-level data is absent, not that nobody was affected.\u003C\u002Fp>\n\u003Ch2>What Risks Follow From the Identity and Health Information?\u003C\u002Fh2>\n\u003Cp>A combination of name, date of birth, address, and SSN can raise the risk of impersonation, new-account fraud, tax fraud, or benefits fraud. Diagnosis, clinical, billing, and claims details can support convincing fake healthcare messages. Recipients should monitor credit reports as well as Explanation of Benefits documents and unexpected medical bills.\u003C\u002Fp>\n\u003Cp>A message that appears to come from Brevard or a known clinic employee is not automatically legitimate even if it cites a real diagnosis or billing detail. Use the provider's known website or phone number instead of a link in the message, and do not share a password, full SSN, payment, or one-time code. A fraud alert or free credit freeze may be appropriate if unfamiliar credit activity appears.\u003C\u002Fp>\n\u003Ch2>How Did Brevard Respond and What Can Recipients Do?\u003C\u002Fh2>\n\u003Cp>Brevard said it contained and secured its environment, worked with IT and cybersecurity teams to review affected systems, evaluated data integrity, and implemented heightened security protections. It reported the matter to the FBI and relevant regulators. The company also reviewed privacy and security policies and procedures while considering further network safeguards.\u003C\u002Fp>\n\u003Cp>Affected people were offered 24 months of three-bureau credit monitoring, CyberScan, identity recovery, and other protection through IDX. The general notice lists February 13, while the later Massachusetts individual letter lists March 26, 2026 as the enrollment deadline, so recipients should follow their own letter. The 1-833-779-4803 line is available weekdays from 9:00 a.m. to 9:00 p.m. Eastern.\u003C\u002Fp>","Brevard public notice, HHS\u002FOCR report, and Massachusetts Attorney General consumer letter",false,"completed","\u002Fuploads\u002Flogo\u002Fbrevardskin_com.gif","Medium"]