[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f39n0tqtspjj0y":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":37,"seoTitle":38,"seoTitleEn":39,"seoDescription":38,"seoDescriptionEn":40,"logoUrl":41,"isVerified":4,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"6a70cc1a4ef8ea7ccc705f2a","CardioVascularHealthClinic2025","CardioVascular Health Clinic 2025 Data Breach","cardiovascular-health-clinic-2025","cvhealthclinic.com","2025-02-18T00:00:00.000Z","2026-08-03T17:12:57.469Z","2026-08-03T17:14:22.451Z","CardioVascular Health Clinic, HHS OCR, and Massachusetts Attorney General notice archive","https:\u002F\u002Fcvhealthclinic.com\u002Fnotice-of-data-incident\u002F",[15,17,18],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2025-1999-cardiovascular-health-clinic\u002Fdownload",501,"known",null,"people","Low",[25,26,27,28,29,30,31,32,33,34,35,36],"Names","Physical addresses","Phone numbers","Email addresses","Dates of birth","Social security numbers","Government issued IDs","Financial account information","Medical information","Prescription information","Medical record numbers","Health insurance information","\u003Cp>\u003Cstrong>The CardioVascular Health Clinic data breach\u003C\u002Fstrong> was a 2025 security incident involving unauthorized access to the organization's network. The clinic said the access occurred from February 18 through March 4, 2025 as a result of an incident affecting its cloud services provider. The U.S. HHS Office for Civil Rights reports 501 affected people.\u003C\u002Fp>\u003Ch2>How did the CardioVascular Health Clinic data breach happen?\u003C\u002Fh2>\u003Cp>CardioVascular Health Clinic experienced a network disruption on March 4, 2025 and opened an investigation with third-party specialists. The review determined that an unauthorized individual accessed certain information stored on the clinic's network between February 18 and March 4.\u003C\u002Fp>\u003Cp>The clinic linked the access to a security incident affecting its cloud services provider. Public notices do not identify the provider, disclose the technical method used, or attribute the event to a threat actor.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. The official notice lists names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, driver's-license or state-identification numbers, financial-account information, treatment and diagnosis information, prescription information, provider names, medical-record or case numbers, Medicare or Medicaid identifiers, health-insurance information, and treatment costs.\u003C\u002Fp>\u003Cp>Not every category applied to every person. The clinic said it was reviewing the relevant data to determine which individuals and information may have been affected.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The HHS OCR event entry reports 501 affected individuals for the Oklahoma healthcare provider. The federal entry was submitted on May 3, 2025.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Identity and financial information can support identity theft or account fraud. Diagnoses, prescriptions, insurance details, and medical-record identifiers can increase the risk of healthcare fraud and targeted phishing. A message containing accurate personal details is not necessarily trustworthy.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>CardioVascular Health Clinic said it investigated with third-party specialists, notified law enforcement, and reviewed its policies and procedures. The organization offered notice recipients 24 months of credit monitoring and identity-protection services.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports, bank and insurance activity, and healthcare statements for unfamiliar transactions. For an unexpected message claiming to come from the clinic or another healthcare organization, use contact details from the organization's official website instead of a link supplied in the message.\u003C\u002Fp>","","CardioVascular Health Clinic Data Breach (501 People Affected)","The CardioVascular Health Clinic data breach affected 501 people and may have exposed identity, financial, and health information.","\u002Fuploads\u002Flogo\u002Fcardiovascular-health-clinic-official.png",false,{"name":44,"sector":45,"country":46,"website":47,"websiteArchiveUrl":38,"websiteStatus":38,"websiteCheckedAt":21},"CardioVascular Health Clinic","Healthcare","United States","https:\u002F\u002Fcvhealthclinic.com\u002F"]