All Breaches
May 21, 2025 Verified Sensitive Record Healthcare

Emanuel Medical Center Georgia 2025 Data Breach

The Emanuel Medical Center Georgia 2025 data breach involved unauthorized access to a portion of the Swainsboro hospital's computer systems. Emanuel Medical Center said it detected suspicious activity on May 22, 2025, secured its systems, and began an investigation with cybersecurity specialists.

The investigation found that an unauthorized third party accessed part of the systems from May 21 through May 24, 2025 and that personal information and protected health information were present in those environments. The U.S. Department of Health and Human Services Office for Civil Rights portal lists 28,963 affected people for Emanuel Medical Center in Georgia.

How Was the Emanuel Medical Center Incident Verified?

The primary source is the updated “Notice of Data Security Incident” PDF dated February 17, 2026 and hosted on Emanuel Medical Center's own emanuelmedical.org domain. It describes the May 22 discovery, May 21-24 access window, data-review process, possible information categories, law-enforcement notice, and the 855-815-3937 assistance line.

The second source is the HHS/OCR federal row reported February 17, 2026 for 28,963 people; it identifies Georgia and classifies the event as a network-server “Hacking/IT Incident.” A secondary page describing a California hospital with the same name was excluded because it confuses the entity. This record belongs only to the Georgia organization.

Incident Timeline

According to Emanuel's official notice, an unauthorized third party accessed part of the systems from May 21 through May 24, 2025. The incident date is based on the earliest technical activity that can be verified from public sources.

The fact that the range ends May 24 does not prove that the actor had continuous access at every moment; the notice provides only the window established by the investigation. After identifying potentially affected files, an outside data-review firm analyzed their contents and related individuals. February 17, 2026 is the public-notice and HHS-report date, not the attack start.

What Information May Have Been Involved?

According to the official PDF, the combination varied by person and may include a full name, date of birth, contact information, a government identification number such as a Social Security or driver's license number, health insurance information, patient identification number, dates of service, and healthcare provider names.

Possible health fields include diagnoses, treatment information, prescriptions, medical histories, and lab reports. The organization explicitly says the categories varied by individual; it should not be assumed that every field applied to all 28,963 people. Each individual notification letter is the primary reference for determining which data types relate to a particular recipient.

How Should the Affected-Person Count Be Interpreted?

28,963 is the official affected-person count published in the HHS/OCR portal for Emanuel Medical Center in Georgia; it is not a number of files, data rows, or patient identifiers. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.

When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.

Identity and Health Privacy Risks

A combination of Social Security number, driver's license, date of birth, and contact information can facilitate targeted identity fraud. Recipients can monitor credit reports and unfamiliar account inquiries and consider a fraud alert or credit freeze. Unexpected communications invoking Emanuel should be verified through the 855-815-3937 line or the organization's known website.

Diagnosis, treatment, prescription, medical history, lab report, and insurance information create persistent privacy and medical identity-theft risks. Users should review insurance statements, services they did not receive, and unfamiliar prescription or laboratory activity. Suspicious records should be reported directly to the healthcare provider and insurer.

Organization Response and User Actions

Emanuel Medical Center said it secured systems after detecting the suspicious activity, investigated with third-party specialists, arranged a review of affected files, and notified law enforcement. Individual letters were mailed to affected people for whom the organization had a current address; the public notice does not identify a specific actor or malware family.

Users should follow their notification letter, review account statements and free credit reports, and report suspicious activity to financial institutions and law enforcement. The 855-815-3937 call center is available weekdays from 9:00 a.m. to 9:00 p.m. Eastern Time. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope. If a suspicious message or account event appears, it should be verified through the organization’s current official contact channel without using links in the message.

29 Thousand
Affected Accounts
13
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

13
Full names
Dates of birth
Contact information
Government identification numbers
Health insurance information
Patient identification numbers
Dates of service
Healthcare provider names
Diagnoses
Treatment information
Prescriptions
Medical histories
Lab reports

Additional Information

Added DateJuly 27, 2026
Breach DateMay 21, 2025
Domainemanuelmedical.org
SourceOfficial Emanuel Medical Center Georgia notice and HHS/OCR breach report
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information