All Breaches
August 26, 2025 Verified Healthcare

Coastal Carolina Urology (Rivertown) 2025 Data Breach

The 2025 Coastal Carolina Centers of Urology and Surgery data breach involved unauthorized access to systems at the Conway, South Carolina ambulatory surgery organization from August 26 through September 2, 2025. According to the organization's official notice, the investigation found that data containing patient information may have been accessed and acquired by an unauthorized party.

The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a Hacking/IT Incident involving a network server and reported 2,886 affected individuals. The Indiana Attorney General's 2026 report identifies the same organization, an August 26 occurrence date, and the same nationwide total; the two Indiana residents in that report are a subset of the 2,886.

Verified Incident Timeline

The official consumer notice says the unauthorized party accessed systems between August 26 and September 2, 2025. Around April 24, 2026, the investigation determined that patient-related information may have been accessed and acquired in the event. Regulatory notifications followed in May 2026.

The public documents do not identify the initial access method, a specific vulnerability, whether ransomware was used, or the responsible actor. This entry therefore uses only HHS's published network-server and hacking/information-technology classifications and does not add an unverified threat group or technical method.

What Information May Have Been Affected?

The official notice confirms that the event involved patient information and protected health information, but the public text does not provide a detailed field list that applies to everyone. Names, Social Security numbers, financial data, or particular medical fields should not be assumed to have been involved for every person. An individual's notification letter is the most specific source for that person's scope.

Health information can make phishing attempts more convincing when a message refers to a medical service or billing detail. Notice recipients should not provide additional health information, a password, a one-time code, or payment details in an unexpected call or email. Contact the organization through a channel verified independently from the message.

How Should the 2,886-Person Total Be Read?

The HHS record and Indiana Attorney General report agree on a nationwide total of 2,886 affected individuals. The Indiana report also identifies two Indiana residents, but that figure is included in the national total and is not added to it. Because the public records do not provide counts by data field, the total does not establish that every person had the same information involved.

The organization also appears under the Rivertown Surgery Center trade name in the official CMS registry. That name refers to the same legal organization's ambulatory surgery center and does not represent a separate breach or an additional affected population. The similarly named Coastal Carolina Health Care incident belongs to a different organization and event.

What Should Affected People Do?

The notice says identity-monitoring support through Kroll was made available to eligible people. Recipients should use their letter to confirm the enrollment period, activation code, and data fields identified for them. Only the verified website and contact details in the notice should be used during enrollment.

Patient portals, health-insurance explanation-of-benefits statements, and medical bills can be reviewed for an unfamiliar service, provider, or contact-detail change. If an individual letter expressly lists a Social Security number or financial information, the recipient can also review credit reports and consider a free fraud alert or credit freeze. A field that is not disclosed in the public summary should not be treated as affected.

2.9 Thousand
Affected People
1
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

1
Protected health information