
Clarinda Health 2025 Data Breach (24.3 Thousand People Affected)
The 2025 Clarinda Health data breach involved files on Clarinda Regional Health Center's network that may have been accessed or acquired without authorization. The organization says it learned of suspicious activity on or around December 15, 2025.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/IT incident involving a network server and reported 24,341 affected individuals.
Verified Incident TimelineClarinda's investigation determined that certain files may have been accessed or acquired without authorization on or around October 23, 2025. The file review and work to obtain contact information for notification were completed on May 21, 2026. The organization published its notice on May 29 and began individual notifications on June 1.
What Information May Have Been Affected?The information varied by person but may have included names, Social Security numbers, dates of birth, medical information, health-insurance information, financial account numbers, driver's license numbers, and taxpayer identification numbers. The notice does not say that every field applied to every person.
How Clarinda Health RespondedThe organization says it investigated with cybersecurity experts to determine the scope of the event and ensure the continued security of its information environment. Clarinda also says it implemented additional security measures to reduce the risk of a similar event occurring again.
What Should Affected People Do?Notice recipients should review health-insurance explanations of benefits, medical records, financial account activity, and credit reports for transactions they do not recognize. People whose notice lists a Social Security number or financial information may also consider a fraud alert or credit freeze, and incident links should be verified through Clarinda's official page.