All Breaches
November 5, 2025 Verified Sensitive Record Healthcare

Columbia Medical Practice 2025 Data Breach

The Columbia Medical Practice 2025 data breach involved an unknown cyber actor accessing part of the Maryland multi-specialty provider's computer network on November 5, 2025. The actor installed a computer virus to lock files on systems and copied files from the network that same day. The organization securely recovered the network and began an investigation.

The U.S. Department of Health and Human Services Office for Civil Rights portal lists 94,131 affected individuals for Columbia Medical Practice and classifies the event as a network-server “Hacking/IT Incident.” In LeakData, pwnCount and totalRecords display that official people total; importedRecordCount is zero because no raw person-level records were obtained.

How Was the Columbia Medical Practice Breach Confirmed?

The primary source is the organization's public cybersecurity notice updated November 26, 2025. It describes the November 5 access, virus used to lock files, same-day copying of files, potential data classes, and separation of the unaffected electronic health record system. The notice also provides the 1-833-974-3375 assistance line.

The second source is the official HHS/OCR entry dated December 5 for 94,131 people. An April 24, 2026 consumer letter published by the Massachusetts Attorney General confirms that the file review finished March 31, the individual notification process, and additional technical measures. An attacker-group name in secondary reporting is absent from the official documents and is therefore excluded.

What Happened on November 5, 2025?

Columbia Medical Practice said an unknown cyber actor accessed part of its network and installed a computer virus that locked files on computer systems. The organization engaged cybersecurity specialists, securely restored the network, and investigated the event. The inquiry determined that the actor copied files from the computer network on that same day.

The organization published its first public notice while the file review was still underway so that it could disclose the event promptly. According to the later consumer letter, the intensive review to identify the people and fields in the copied files was completed March 31, 2026. Direct letters were sent beginning April 24 to individuals for whom address information was available.

What Identity, Health, and Payment Information Was Involved?

Depending on the individual, copied files may have contained a name together with address, phone number, date of birth, Social Security number, driver's license number, passport number, or other government identifier. Health categories include location and dates of services, treatment or condition, diagnosis and diagnosis code, prescription information, medical history, and assigned physician.

Payment and insurance categories include a financial account number without a security code, access code, or password to access the account; a health-insurance subscriber or identification number; and a patient account number. That qualification matters: a financial account number may have been involved, while account-access codes and passwords were not described in the same scope. Not every person had every field.

Was the Electronic Health Record System Affected?

Columbia Medical Practice specifically said its electronic health records platform at the time was maintained in a logically separated computer-network environment and was not affected. This does not mean copied network files contained no health information; it means the central EHR platform was separate from the affected portion of the network.

This record preserves that distinction and does not claim the entire patient-record system was compromised. At the same time, it does not minimize the event as merely an attempted access because the public notice confirms that files were copied. pwnCount and totalRecords represent 94,131 affected people, not the number of copied files or individual data fields.

How Should the Potential Risks Be Assessed?

A combination of SSN, date of birth, and government identification can raise the risk of impersonation, new-account fraud, tax fraud, or benefits fraud. Diagnosis, prescription, physician, and service-date details may support convincing fake healthcare messages. Insurance and patient account numbers can provide context for fraudulent claims, bills, or payment notices.

Recipients should review credit reports and financial statements as well as Explanation of Benefits documents, prescription history, and unexpected patient-account activity. Use a known institutional channel instead of a link in a message claiming to be from Columbia Medical Practice or a physician, and do not disclose a full SSN, password, access code, payment, or one-time code.

How Did the Organization Respond and What Can Recipients Do?

Columbia Medical Practice said it remediated and confirmed the security of its network, reviewed files with cybersecurity specialists, and implemented additional technical measures and processes. It also reviewed cyber-auditing practices, policies, and procedures. The later individual letter says complimentary identity-monitoring services were offered; enrollment details are contained in each recipient's letter.

The public 1-833-974-3375 line is available weekdays from 8:00 a.m. to 8:00 p.m. Eastern for questions. A fraud alert or free credit freeze may be appropriate if unfamiliar credit activity appears, and suspicious healthcare or insurance entries should be verified directly with the provider and insurer. The fields in an individualized letter are more useful than the general list for assessing personal scope.

94.1 Thousand
Affected Accounts
17
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

17
Names
Physical addresses
Phone numbers
Dates of birth
Social security numbers
Driver’s license numbers
Passport numbers
Other government identifiers
Health-service locations and dates
Treatments or conditions
Diagnoses and diagnosis codes
Prescription information
Medical histories
Assigned physicians
Financial account numbers without access credentials
Health-insurance subscriber or identification numbers
Patient account numbers

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 5, 2025
Domaincmpractice.com
SourceColumbia Medical Practice notice, HHS/OCR report, and Massachusetts Attorney General consumer letter
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information