[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2cmdwknsaqlsq":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"6a703a531971b6524035dfb3","EndueSoftware2025","Endue Software 2025 Data Breach","endue-software-2025","enduesoftware.com","2025-02-16T00:00:00.000Z","2026-08-03T06:50:59.004Z","Official Endue Software data-privacy notice","https:\u002F\u002Fwww.enduesoftware.com\u002Fnotice-of-data-privacy-event",[14,16],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",118028,"known",null,"people","High",[23,24,25,26,27],"Names","Physical addresses","Social security numbers","Dates of birth","Medical record numbers","\u003Cp>\u003Cstrong>The 2025 Endue Software data breach\u003C\u002Fstrong> involved unauthorized access to certain systems and the copying of files at a healthcare software provider. Endue says an unauthorized actor briefly accessed the systems on February 16, 2025.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a network-server breach affecting 118,028 people. The information that may have been involved spans identity and medical-record details.\u003C\u002Fp>\u003Ch2>How was the Endue Software breach confirmed?\u003C\u002Fh2>\u003Cp>Endue's official incident notice describes the unauthorized access, file copying, dates, possible data fields, and notification process. The company confirms that files from certain internal systems were copied during the event.\u003C\u002Fp>\u003Cp>The HHS OCR entry lists the same organization as a business associate, gives the total of 118,028 people, and classifies the event as a Hacking\u002FIT Incident involving a network server. The total does not mean every data field was present for every person.\u003C\u002Fp>\u003Ch2>What happened on February 16 and 17, 2025?\u003C\u002Fh2>\u003Cp>Endue learned of possible unauthorized access to certain systems on February 17, 2025 and moved to secure its environment. It then opened an investigation to determine the nature and scope of the activity.\u003C\u002Fp>\u003Cp>The investigation found that an unauthorized person briefly accessed certain computer systems on February 16 and copied files from some internal systems. The company's notice does not disclose the initial access method, technical vulnerability, or actor identity.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>The official notice says the fields varied by person and may have included full names, addresses, Social Security numbers, dates of birth, or medical record numbers.\u003C\u002Fp>\u003Cp>The complete list should not be assumed to apply to all 118,028 people. Email addresses, passwords, payment cards, bank accounts, diagnoses, and treatment details are not added because the notice does not separately list them.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>A name, address, date of birth, and Social Security number can be combined to support identity theft, fraudulent account opening, credit applications, or tax fraud.\u003C\u002Fp>\u003Cp>A medical record number may make healthcare impersonation messages appear credible or be used in false requests to change a record or bill. Knowing a real record number does not prove that a caller or sender is legitimate.\u003C\u002Fp>\u003Ch2>How did Endue respond?\u003C\u002Fh2>\u003Cp>The company says it secured its environment, investigated the scope, and reviewed the copied files to identify sensitive information and the people involved. It began mailing notices to individuals for whom it had valid addresses.\u003C\u002Fp>\u003Cp>In its April 11, 2025 notice, Endue said it was not aware of actual or attempted identity fraud resulting from the event. That statement is not a guarantee that misuse cannot occur later.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports and financial-account activity for accounts or transactions they do not recognize. People told that a medical record number was involved should also verify unexpected record or billing changes with the relevant provider.\u003C\u002Fp>\u003Cp>Do not provide a Social Security number, password, or verification code in response to an unexpected call or message. People notified that their Social Security number was involved may consider a free credit freeze or fraud alert.\u003C\u002Fp>","","Endue Software 2025 Data Breach (118 Thousand People Affected)","The Endue Software data breach may have affected identity and medical-record information belonging to 118,028 people. Review the incident and safety steps.","\u002Fuploads\u002Flogo\u002Fendue-software-official.svg",false,{"name":35,"sector":36,"country":37,"website":38,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":19},"Endue Software","Healthcare","United States","https:\u002F\u002Fwww.enduesoftware.com\u002F"]