[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw6tiumi5h4hm":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":4,"isSpamList":40,"isMalware":40,"company":41},"6a7070f7eac77a379c9c1d2c","CompassionHealthCare2025","Compassion Health Care 2025 Data Breach","compassion-health-care-2025","compassionhealthcare.org","2025-03-17T00:00:00.000Z","2026-08-03T10:44:07.131Z","Official CHC notice, HHS OCR, and independent event reporting","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16],"https:\u002F\u002Fcompassionhealthcare.org\u002Fwp-content\u002Fuploads\u002F2025\u002F05\u002FCompassion-Health-Care-Website-Notice-Final-May-15-2025.pdf",23282,"known",null,"people","Medium",[23,24,25,26,27,28,29,30,31,32,33,34],"Names","Physical addresses","Phone numbers","Dates of birth","Ages","Social security numbers","Driver's licenses","Health insurance information","Medical information","Income levels","Financial account information","Bank account numbers","\u003Cp>\u003Cstrong>The 2025 Compassion Health Care data breach\u003C\u002Fstrong> came to light after the North Carolina healthcare organization detected suspicious activity that caused a network interruption on March 17, 2025. Its investigation found that an unauthorized party may have viewed or downloaded certain patient and employee\u002Fvendor data.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a network-server Hacking\u002FIT Incident affecting 23,282 people. Potentially affected fields include identity, contact, health, income, and banking information.\u003C\u002Fp>\u003Ch2>How was the Compassion Health Care breach confirmed?\u003C\u002Fh2>\u003Cp>CHC's official notice connects the March 17 detection, the March 21 data-scope finding, and the disclosed fields in one event. The HHS OCR entry confirms Compassion Health Care, the North Carolina healthcare provider, the May 16, 2025 report date, and the total of 23,282 people.\u003C\u002Fp>\u003Cp>An independent event summary corroborates the same network incident, sequence of dates, and data categories. Because the start of unauthorized access was not publicly disclosed, March 17 is recorded as the confirmed discovery and network-interruption date, not as a claimed first-access date.\u003C\u002Fp>\u003Ch2>What happened in March 2025?\u003C\u002Fh2>\u003Cp>On March 17, CHC detected suspicious activity on its network and a resulting interruption. The organization began an investigation with an external cybersecurity firm to determine the nature and scope of possible unauthorized access to its systems.\u003C\u002Fp>\u003Cp>On March 21, CHC learned that an unauthorized party may have viewed or downloaded data stored on certain systems. The public notice does not disclose the initial access method, technical vulnerability, first day of access, or access duration, and this record does not infer those details.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Patient records may have included names, addresses, phone numbers, dates of birth or ages, Social Security numbers, driver's license numbers, health-insurance and claims information, and clinical or diagnostic information related to medical services received.\u003C\u002Fp>\u003Cp>Employee or vendor records may have included names, addresses, dates of birth, Social Security numbers, income information, financial-account information, and possibly bank-account and routing numbers. The notice does not say every field applied to every person; email addresses, passwords, and payment cards are excluded because they were not confirmed.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Social Security, driver's license, and bank information can support identity theft, fraudulent accounts, unauthorized transfers, or tax fraud. Some of these identifiers are difficult to change, making long-term credit and account monitoring appropriate.\u003C\u002Fp>\u003Cp>Health-insurance, claims, and clinical details may help an attacker create convincing messages that refer to a real service. Knowing accurate health information does not prove that a sender represents CHC, a physician, a bank, or an insurer.\u003C\u002Fp>\u003Ch2>How did CHC respond?\u003C\u002Fh2>\u003Cp>CHC investigated the event with external cybersecurity specialists and sent written notices to potentially affected patients, employees, and vendors on May 16, 2025. The organization also established a dedicated assistance line for questions about the event.\u003C\u002Fp>\u003Cp>Potentially affected individuals were offered complimentary credit monitoring and identity-theft restoration services. The official notice does not state a definitive conclusion that misuse did or did not occur; the protective measures are intended to reduce possible risk.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports, bank and financial accounts, health-insurance explanations, and tax records for accounts, transactions, services, or claims they do not recognize. Suspicious entries should be reported promptly to the relevant institution.\u003C\u002Fp>\u003Cp>Do not share a Social Security number, banking information, health data, password, or one-time verification code in response to an unexpected email, message, or call. A request claiming to come from CHC should be verified using contact details on the organization's official website rather than links or numbers in the message.\u003C\u002Fp>","","Compassion Health Care 2025 Data Breach (23.3 Thousand People Affected)","The Compassion Health Care data breach may have exposed identity, health, and financial information belonging to 23,282 people.","\u002Fuploads\u002Flogo\u002Fcompassion-health-care-official.png",false,{"name":42,"sector":43,"country":44,"website":45,"websiteArchiveUrl":36,"websiteStatus":36,"websiteCheckedAt":19},"Compassion Health Care, Inc.","Healthcare","United States","https:\u002F\u002Fcompassionhealthcare.org\u002F"]