[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f59pUhP6IDiCd_KnABgLJoM-x9TNl_tEeDxbrD0LSWys":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":23,"source":24,"isVerified":4,"isSpamList":25,"isSensitive":4,"processingStatus":26,"logoUrl":27,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":28},"6a67612bab8b9c02541563f9","CaryPediatricCenter2025","Cary Pediatric Center 2025 Data Breach","cary-pediatric-center-2025","carypediatriccenter.com",{"name":12,"sector":13,"country":14,"website":10},"Cary Pediatric Center, PA","Healthcare","United States","2025-09-19T00:00:00.000Z","2026-07-27T13:46:19.789Z","2026-07-27T16:11:12.376Z",25784,[20,21,22],"Names","Dates of birth","Protected health information in recorded calls","\u003Cp>\u003Cstrong>The Cary Pediatric Center 2025 data breach\u003C\u002Fstrong> was a network-security incident detected by the pediatric practice around September 19, 2025. An unauthorized third party attempted to infiltrate its network environment. According to the organization's investigation, potential impact was limited to recorded audio calls between patients and the office, and the electronic medical-record system was not affected.\u003C\u002Fp>\n\u003Cp>The U.S. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\n\u003Ch2>How Was the Cary Pediatric Incident Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the “Notice of Data Security Incident” PDF on the organization's own website. It describes the September 19 discovery, network containment, specialist forensic review, scope limited to recorded calls, unaffected electronic medical records, possible data fields, 12 months of protection services, and the 855-522-4713 assistance line.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR row dated November 17 for 25,784 people. The organization's current homepage confirms the same entity and domain and directly links to the official incident PDF under “Notice of Data Incident.” This cross-checks the event, person total, and organization identity through two primary records.\u003C\u002Fp>\n\u003Ch2>What Happened on September 19, 2025?\u003C\u002Fh2>\n\u003Cp>Cary Pediatric detected around September 19 that it had been targeted by a network-security incident. When an unauthorized third party attempted to infiltrate the network environment, the organization secured the network and engaged a specialist forensic incident-response firm to determine the scope of possible unauthorized access. The public document does not disclose the initial method or actor identity.\u003C\u002Fp>\n\u003Cp>The investigation found that certain personal information may have been compromised. It specifically says the sensitive data at issue was limited to recorded audio calls between patients and the office and that electronic medical records were not affected. The record therefore does not infer that general patient files or the entire EMR database were exposed.\u003C\u002Fp>\n\u003Ch2>How Was the Date Conflict in the Official PDF Handled?\u003C\u002Fh2>\n\u003Cp>The PDF header says “February 19, 2025,” while the incident text places discovery on September 19, 2025; because the header precedes the event, it cannot form a coherent chronology.\u003C\u002Fp>\n\u003Cp>The organization's September 19, 2025 statement is used for the incident and discovery date, while the HHS\u002FOCR November 17, 2025 row is used for the official person count and regulatory reporting stage. This approach uses verifiable dates without hiding the document's clear inconsistency. No additional date or 2026 year is introduced without evidence.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>The official notice lists potentially exposed fields as names, dates of birth, and protected health information. It says the types differed by individual and that not everyone had every listed element exposed. PHI is not divided into narrower diagnosis, medication, procedure, insurance, or payment fields, so this record does not guess those details.\u003C\u002Fp>\n\u003Cp>The affected medium was recorded telephone calls. Information that may have been spoken during a call is not equivalent to all information stored in an electronic patient file. data categories are therefore limited to the official name, date-of-birth, and PHI wording, and the record does not label electronic medical records as affected.\u003C\u002Fp>\n\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\n\u003Cp>25,784 is the affected-person count published in the HHS\u002FOCR portal; it is not the number of audio recordings, calls, or files. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\n\u003Cp>November 17 in HHS is the regulatory report date, not the day of the incident. The organization does not separately publish a count of mailed recipients or recorded calls.\u003C\u002Fp>\n\u003Ch2>What Did the Organization Do and What Can Recipients Do?\u003C\u002Fh2>\n\u003Cp>Cary Pediatric said it secured the network, investigated with IT specialists, reviewed and enhanced technical safeguards, and arranged 12 months of complimentary credit monitoring and identity-theft protection for all potentially affected individuals. At notice time, it said it had received no reports of information misuse or related identity theft.\u003C\u002Fp>\n\u003Cp>The assistance line at 855-522-4713 is available weekdays from 8:00 a.m. to 8:00 p.m. Eastern Time. A recipient should rely on their own notice for individual scope and enrollment instructions and should not provide a date of birth, health information, password, payment details, or one-time code in an unexpected call or message. Suspicious health records should be verified directly with the practice. If a suspicious message or account event appears, it should be verified through the organization’s current official contact channel without using links in the message.\u003C\u002Fp>","Cary Pediatric official notice, HHS\u002FOCR report, and current organization website",false,"completed","\u002Fuploads\u002Flogo\u002Fcarypediatriccenter_com.png","Medium"]