
Clinic Service Corporation 2025 Data Breach (82.3 Thousand People Affected)
The 2025 Clinic Service Corporation data breach involved unauthorized access to the network of a medical billing and practice-management company. The official notice says access may have occurred between August 10 and August 17, 2025.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/information-technology incident involving a business associate's network server and reported 82,331 affected individuals.
Verified Incident TimelineClinic Service detected unusual activity on its network on August 17, 2025, and began an investigation with computer specialists. The investigation found that an unauthorized party may have accessed certain information between August 10 and August 17. The company completed its data review on December 8 and began notifying affected clients. The sample letter published by the Massachusetts Attorney General is dated January 27, 2026.
What Information May Have Been Affected?The scope may vary by person and by the organization served by Clinic Service. The official sample letter sent on behalf of Children's Eye Physicians lists names, addresses, phone numbers, email addresses, payment-card information, dates of birth, diagnosis and treatment information, dates of service, patient and medical-record numbers, Medicare or Medicaid numbers, health-insurance information, claim and policy numbers, and treatment-cost information.
How the Organization RespondedClinic Service says it began an investigation, notified law enforcement, and reviewed its data-privacy policies and procedures. The notice says potentially affected individuals were offered access to complimentary credit-monitoring and identity-protection services.
What Should Affected People Do?Notice recipients should monitor credit reports, financial-account activity, and health-insurance explanation-of-benefits statements for an unfamiliar transaction or service. People whose payment-card or insurance information was affected may contact the relevant card issuer or insurance provider based on the scope stated in their own notice.