All Breaches
February 27, 2026 Verified Sensitive Record Healthcare

Dermatology Partners Catonsville 2026 Data Breach

The Dermatology Partners Catonsville 2026 data breach involved an unauthorized individual accessing the data system at the Catonsville, Maryland, office from February 27 through March 10, 2026. Because the organization could not determine which patient records might have been viewed, it notified all patients seen at the 716 Maiden Choice Lane location as a precaution.

Viewable information included patient names, dates of birth, addresses, contact information, medical-record numbers, dates of service, diagnosis and treatment information, and potentially health-insurance information. The organization expressly said it found no evidence that data was copied or removed from the system. It did not publish a total affected-patient count.

How Was the Dermatology Partners Breach Confirmed?

The core primary source is Dermatology Practices's “Privacy Breach – Catonsville” page on dermpartners.com. The substitute notice, posted June 23, 2026, directly confirms the access period, Catonsville address, possible record fields, forensic review, strengthened access controls, and the contact line at 610-871-1816.

A source-linked notice PDF supports the incident account in document form. Claim Depot connects the company notice to the organization and Catonsville location and independently summarizes the dates and data categories. The sources agree that unauthorized access occurred while preserving the important limit that no evidence of copying or removal was found.

What Happened From February 27 Through March 10?

According to the official notice, an unauthorized individual accessed the Catonsville office's data system for roughly twelve days. The organization could not determine exactly which records were touched. Because of that uncertainty, it notified all patients seen at that location as a precaution instead of restricting notice to a known subset of files.

The sources do not disclose whether initial access involved a captured password, phishing, insider access, an exposed remote connection, or a software vulnerability. They name no actor, ransomware family, data volume, or leak site. “Records may have been viewed” does not mean a download or publication was proven, and LeakData preserves that distinction.

What Health and Identity Information Could Be Viewed?

The confirmed possible fields are patient name, date of birth, mailing address, contact information, medical-record number, date of service, diagnosis information, treatment information, and health-insurance information. The source qualifies insurance information as potential. It does not establish that every patient had every category or that every field was actually viewed.

The notice does not separately identify Social Security numbers, driver's licenses, financial accounts, payment cards, passwords, prescriptions, laboratory results, images, clinician notes, or insurance member numbers as confirmed fields. Generic category icons on a secondary page do not replace the official field list. LeakData records only categories expressly stated by the company.

How Many Patients Were Affected?

The organization says it notified all Catonsville patients but does not publish a deduplicated patient count. The clinic's daily appointment volume, office count, companywide patient population, or marketing figures are not incident-victim totals. Accordingly, pwnCount and totalRecords are null rather than zero, and affectedCountStatus is recorded as undisclosed.

The number notified may also differ from the number of records actually viewed because the organization widened notice when it could not identify a precise subset. There is no trustworthy state count or national total from which to calculate a lower bound. LeakData imported no raw patient records; an importedRecordCount of 0 does not describe the number of victims.

How Did the Organization Strengthen Security?

Dermatology Practices said it was actively cooperating with ongoing investigations and conducted a forensic review to assess the incident. It also strengthened access controls and engaged cybersecurity professionals. The substitute notice says it was posted under the HIPAA Breach Notification Rule at 45 C.F.R. §§ 164.404–164.410.

The company notice does not announce complimentary credit monitoring, an identity-protection package, or an enrollment deadline. Patients with questions can contact the organization at 610-871-1816. “No evidence of copying or removal” is not an absolute assurance; it describes the review's findings and must be read alongside the statement that the organization could not identify which records were viewed.

What Should Catonsville Patients Do?

A notified patient should review dates of service, medical-record entries, diagnosis and treatment information, and insurance benefit statements for unfamiliar services. If an unknown visit, provider, procedure, or insurance claim appears, use an independently obtained official number for Dermatology Partners and the insurer. Access and correction rights for a medical record can be discussed directly with the provider.

Criminals may use the clinic name, address, appointment date, or diagnosis context to craft fake billing, record-update, or insurance-verification messages. Open dermpartners.com independently instead of following an inbound link, and confirm payment or document requests through a known number. Do not provide a password, insurance-portal code, or one-time code merely because a caller knows a real patient detail.

0
Affected Accounts
10
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

10
Personal information
First and last names
Dates of birth
Postal addresses
Contact information
Medical record numbers
Dates of service
Diagnosis information
Treatment information
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateFebruary 27, 2026
Domaindermpartners.com
SourceOfficial Dermatology Practices substitute notice confirming unauthorized access to the Catonsville patient data system
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information