All Breaches
March 21, 2025 Verified Sensitive Record Healthcare

Coastal Carolina Health Care 2025 Data Breach

The Coastal Carolina Health Care 2025 data breach resulted from unauthorized access to the CCHC network from March 21 through March 27, 2025. An official regulatory letter filed with the New Hampshire Attorney General confirms that personal and protected health information was accessed and acquired by an unknown actor. The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 110,304 people were affected.

The fields expressly confirmed in public records are names, Social security numbers, driver's-license or state identification numbers, personal information, and protected health information. The combination varies by person, and personal fields are redacted in the public sample letters. LeakData imported no patient rows, and importedRecordCount is zero.

How Was the CCHC Data Breach Confirmed?

The primary evidence is a March 24, 2026 notification sent to the New Hampshire Attorney General by counsel for Coastal Carolina Health Care. It says CCHC identified unusual activity disrupting access to certain systems on March 28, 2025 and opened an investigation with an independent cybersecurity firm. The review found not merely possible access but that certain information had been accessed and acquired without authorization.

The HHS OCR row lists the organization as a Healthcare Provider, categorizes the event as a Hacking/IT Incident, and identifies Network Server as the information location. Its total of 110,304 people supplies the regulatory scope not stated nationally in the state letter. SecurityWeek independently reported the CCHC event by comparing the HHS total and state filing.

What Was the Incident and Notification Timeline?

The investigation found that an unknown actor accessed and acquired personal and health information between March 21 and March 27, 2025. The breachDate field uses March 21, the first day of the confirmed window. CCHC noticed the unusual activity on March 28, secured its network, and began a forensic investigation to determine the nature of the event.

The organization then used a third-party review service to identify the affected data set and notice population. CCHC confirmed the scope of impact and obtained sufficient contact information on February 26, 2026. Consumer letters were mailed on March 23, 2026; the roughly one-year interval represents file and identity review, not the duration of the actor's access.

What Information Was Affected?

The regulatory correspondence describes the affected data as personal information and protected health information. For New Hampshire residents, it expressly says names may have appeared with Social security numbers. CCHC also offered dedicated identity-protection services to people whose Social security numbers or driver's-license and state identification numbers were affected.

Because person-specific fields in the public sample letter are redacted, this entry does not infer diagnoses, treatments, insurance details, medical-record numbers, or financial accounts. dataClasses contains only the five categories directly supported by the sources. It also does not assume that every field was present for all 110,304 people.

Why Does Unauthorized Acquisition Matter?

The official text says sensitive information was accessed and acquired, not merely that it might have been seen. That finding provides strong forensic support that data could enter the actor's control and distinguishes the event from a simple system outage. The filing does not, however, confirm that files were publicly released or that all fields were sold.

At notification, CCHC said it had no evidence that data involved in the incident had been misused. A lack of known misuse does not eliminate future risks associated with acquired identity and health information. LeakData records the confirmed acquisition without adding unsupported claims about the actor's identity, publication, or sale.

How Is the 110,304-Person Scope Used?

The pwnCount and totalRecords fields use the current HHS OCR total of 110,304 people. The 34 New Hampshire residents in the state regulatory letter are a small state subset of that national total, not a separate incident or an additional victim count. The subset is not added to the national number.

The person total is not a count of acquired files or data fields. Social Security, driver's-license, and state identification numbers may apply only to relevant subgroups, whose sizes were not publicly disclosed. LeakData does not invent field totals, duplicate state notices, or calculate a larger scope by adding data categories.

What Should Affected People Do?

CCHC offered people whose Social Security or driver's-license and state identification numbers were affected 12 months of complimentary credit monitoring, identity restoration, and identity-theft insurance through Cyberscout. Notice recipients should follow the deadline and activation instructions in their letter. The organization also notified the FBI and implemented additional security controls.

Credit reports, financial accounts, and health-insurance explanations of benefits should be checked regularly for unfamiliar transactions, services, or claims. Unexpected payment or verification messages presented in the name of CCHC or a healthcare provider should be confirmed through a known official channel. LeakData does not host acquired patient data; it provides only verified incident metadata and practical follow-up guidance.

110.3 Thousand
Affected Accounts
5
Data Types
High
Severity
Yes
Verification

Exposed Data Types

5
Personal information
Protected health information
Names
Social security numbers
Driver's license and state identification numbers

Additional Information

Added DateJuly 27, 2026
Breach DateMarch 21, 2025
Domaincchchealthcare.com
SourceRegulator-filed notice confirming unauthorized access and acquisition
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information