All Breaches
November 27, 2025 Verified Sensitive Record Healthcare

Excelas 2025 Data Breach

The Excelas 2025 data breach involved unauthorized access to certain computer systems used by Ocelot Ventures, LLC under its Excelas trade name for medical-record services. Excelas said it learned of suspicious activity on its network on or about January 28, 2026, and that its investigation found an unauthorized actor had accessed certain systems between November 27 and December 3, 2025.

The Indiana Attorney General's June 2026 year-to-date data breach report lists 2,309 total affected people and 28 Indiana residents for Ocelot Ventures LLC DBA Excelas. The HHS/OCR portal lists the same entity as a healthcare business associate with 2,275 people.

How Was the Excelas Incident Verified?

The primary source is the “Notice of Privacy Incident” published on Excelas's own excelas1.com domain. The organization directly confirms the discovery date, unauthorized-access window, investigation, possible data categories, law-enforcement contact, security enhancements, and the 844-576-3143 assistance line.

The second source is the Indiana Attorney General's official June 2026 report on in.gov; its table shows an Excelas notice sent May 12, 2026, a November 27, 2025 breach date, 28 Indiana residents, and 2,309 total affected people. The third source is the HHS/OCR network-server Hacking/IT Incident row reported May 12 for 2,275 people.

Why Do the 2,309 and 2,275 Counts Differ?

Indiana's official report shows 2,309 in its “Total Affected” column, while HHS/OCR reports 2,275 within the protected-health-information notification system. Both public records refer to the same Ocelot Ventures LLC DBA Excelas event, but their reporting scopes are not identical. Treating the difference of 34 people as another breach would create a duplicate.

The HHS figure of 2,275 is preserved in the source note and explained as the subset reported to the health regulator. This lets users understand why both figures may appear; the counts are not added together and no estimated value is manufactured.

Incident Timeline

According to Excelas's investigation, an unauthorized person accessed certain computer systems between November 27 and December 3, 2025 and may have accessed or taken a limited amount of information. The incident date is based on the earliest technical activity that can be verified from public sources. The notice does not claim that access was continuous throughout the entire range.

The incident date is based on the earliest technical activity that can be verified from public sources. The organization began an investigation with third-party cybersecurity specialists and law enforcement. Indiana's report shows a May 12, 2026 notice date, and the HHS row uses the same federal report date; that notification date is not the attack start.

What Information May Have Been Involved?

According to Excelas's official notice, the combination varied by person and may include a name, date of birth, Social Security number, and government-issued identification. Health-related categories include medical, health, or diagnosis information, medication information, and medical-record images. Insurance information and payment information are also listed as possible categories.

The notice says the actor “may have accessed or taken” a limited amount of information; it does not establish that every field was viewed for all 2,309 people. Passwords, email contents, bank-account numbers, and other fields not separately identified in the official text were not added. An individual's notification is the controlling source for that person's specific scope.

Identity, Health, and Payment Risks

A Social Security number combined with a date of birth and government ID can enable new-account fraud and targeted phishing. Recipients can review free credit reports, watch for unfamiliar inquiries, and consider a credit freeze or fraud alert when appropriate. Unexpected requests invoking Excelas should be verified through known channels.

Diagnosis, medication, medical-record images, and insurance information create persistent privacy and medical identity-theft risks. Users should review insurance statements for services they did not receive, unfamiliar prescriptions, and unexplained payment activity. Suspicious healthcare items should be reported to the provider and insurer, while financial activity should be reported directly to the relevant institution.

Excelas's Response and Steps for Individuals

Excelas said it conducted a thorough investigation with third-party cybersecurity specialists, contacted law enforcement, and was working to enhance system safeguards. Its public notice says it had no evidence that personal information was used to commit identity theft or fraud. The document does not identify a specific actor or ransomware group.

People who believe they may be affected can call 844-576-3143 between 9:00 a.m. and 6:30 p.m. Eastern Time on weekdays and monitor account statements and credit reports. The 2,309 affected people and zero raw-data imports are separate measurements.

2.3 Thousand
Affected Accounts
11
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

11
Full names
Dates of birth
Social security numbers
Government-issued identification
Medical information
Health information
Diagnosis information
Medication information
Medical record images
Insurance information
Payment information

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 27, 2025
Domainexcelas1.com
SourceOfficial Excelas notice, Indiana Attorney General report, and HHS/OCR breach report
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information