All Breaches
December 3, 2025 Verified Sensitive Record Healthcare

Evergreen Healthcare Group 2025 Data Breach

The Evergreen Healthcare Group 2025 data breach involved unauthorized activity detected in a cloud-based healthcare platform operated by Couve Healthcare Consulting, LLC under the Evergreen Healthcare Group (EHG) trade name. EHG said it became aware of the activity on or about December 3, 2025, activated its incident response plan, and found evidence that an unauthorized party may have accessed certain files.

The U.S. Department of Health and Human Services Office for Civil Rights portal lists Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group in Washington with 11,795 affected people. The federal row identifies EHG as a business associate, classifies the event as a Hacking/IT Incident, and lists Electronic Medical Record as the location. importedRecordCount is zero because no raw person-level data was obtained.

How Was the Evergreen Healthcare Group Incident Verified?

The primary source is the “Notice of Data Breach” PDF dated February 25, 2026 and hosted on EHG's own evergreenhcg.com domain. In EHG's own words, it describes the December 3 discovery, the cloud-based healthcare platform, possible file access, reviewed data types, security measures, and the 855-522-1474 assistance line.

The second source is the HHS/OCR federal row reported February 24, 2026 for 11,795 people. The third is the Couve Healthcare Consulting DBA Evergreen Healthcare Group document published as matter “2026-272” in Massachusetts's official mass.gov notice archive. The sources are consistent about the entity, nature of the incident, and notification process.

Scope Between Golden Sonora Care Center and EHG

The PDF on EHG's website is a substitute notice issued on behalf of Golden Sonora Care Center and in EHG's capacity as its business associate. It therefore represents a customer-specific notice connected to the incident on EHG's platform. The federal HHS row instead names Couve Healthcare Consulting DBA Evergreen Healthcare Group as the reporting entity and identifies its business-associate status.

The 11,795 figure is the total in the HHS/OCR row for EHG; the official PDF does not say that every one of those people belongs only to Golden Sonora Care Center. This record centers on the EHG event without merging the entities, identifies Golden Sonora as the customer covered by the notice, and does not invent a customer allocation or facility-level count that the sources do not provide.

Incident Timeline

EHG says it learned of unauthorized activity in its cloud-based healthcare platform on or about December 3, 2025 and immediately implemented its incident response plan. The public notice does not disclose the actor's first entry date or the length of access. breachDate, dateOccurred, and dateDiscovered therefore use December 3, the earliest reliable public time marker.

The organization then reviewed potentially impacted files to identify the information present and related individuals. After completing the review, it notified affected people by U.S. First Class Mail on February 24, 2026. The February 25 website document is a substitute notice intended to reach people who could not receive direct notice; neither notification date is presented as the attack start.

What Information May Have Been Involved?

According to EHG's official notice, information potentially subject to unauthorized access included names, Social security numbers, dates of birth, and medical information. The document says the files “may have been accessed” and that information “may have been subject to unauthorized access”; it does not claim that every field was viewed for every individual.

The combination may vary by person. A Social Security number combined with a date of birth can increase identity-fraud risk, while medical information can create longer-lasting privacy and medical identity risks. This record is limited to the four categories named in the official document; bank accounts, passwords, and other fields were not added because the cited sources do not substantiate them.

What Do 11,795 People and Zero Imports Mean?

11,795 is the affected-person total published for EHG in the HHS/OCR portal and is copied directly into pwnCount and totalRecords. It is not a number of files, documents, medical records, or rows downloaded by an actor. The HHS row also connects the hacking/IT incident to an electronic medical record environment.

importedRecordCount 0 means LeakData did not receive raw person-level records such as names, Social security numbers, or health data. It must not be confused with the affected-person count: the incident volume shown to users is 11,795 people, while the number of searchable raw records in the system is zero. Zero imports do not make the incident unreal.

Organization Response and Steps for Individuals

EHG said it secured the impacted platform, verified the security of internal systems, and began implementing additional technical safeguards, enhanced security measures, and updated procedures. It offered affected individuals complimentary credit monitoring and identity theft restoration services. At the time of the notice, EHG said it had received no reports of related misuse of personal information.

Recipients should follow enrollment instructions in their letter, monitor credit reports and financial accounts, and review unfamiliar healthcare activity. Suspicious communications invoking EHG can be verified through evergreenhcg.com or the 855-522-1474 line, available weekdays from 8:00 a.m. to 8:00 p.m. Eastern Time. This record was prepared by comparing EHG's notice, the HHS/OCR row, and Massachusetts's official archive.

11.8 Thousand
Affected Accounts
4
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

4
Full names
Social security numbers
Dates of birth
Medical information

Additional Information

Added DateJuly 27, 2026
Breach DateDecember 3, 2025
Domainevergreenhcg.com
SourceOfficial Evergreen Healthcare Group notice, HHS/OCR breach report, and Massachusetts filing
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information