The Excellent Home Care Services 2025 data breach involved the New York home-care provider discovering on November 25, 2025 that an unauthorized third party had briefly accessed an employee email account. According to the company statement, the incident could only have affected people in Bronx, Kings, Nassau, New York, and Queens counties; notification letters were mailed December 17.
The official U.S. Department of Health and Human Services Office for Civil Rights portal lists 16,278 affected individuals, classifies the event as a “Hacking/IT Incident,” and identifies “Email” as its location. pwnCount and totalRecords carry that people count. No person-level data was imported into LeakData, so importedRecordCount is zero; these measurements must not be treated as interchangeable.
How Was the Excellent Home Care Services Breach Confirmed?
The primary incident account is the company statement published on behalf of Excellent Home Care Services on December 18, 2025. It describes the November 25 discovery, the affected employee account, the potential file scope, the December 17 letters, and the 833-918-6974 incident line. The HHS/OCR entry dated December 17 confirms the official total of 16,278 people and the event's connection to email.
A third source is ClaimDepot's incident page, which brings together the announcement and HHS record. It preserves a copy of the company release, links to regulatory material, and reports the same total. This record does not add an attacker name, ransomware label, data-sale claim, or confirmed exfiltration that is absent from the primary text. Verified facts are therefore kept separate from speculation.
What Was Discovered on November 25, 2025?
The company said it discovered November 25 that an unauthorized third party had accessed one employee's email account for a brief period. It immediately secured the account and began an investigation with outside support. The review identified the type of file that could have been reached but could not determine how many files were actually viewed, so everyone whose information might have appeared in that file type was notified as a precaution.
The public statement does not disclose the exact start or end of access, the initial access method, the account owner's identity, or which messages and attachments were viewed. November 25 is therefore used in this record as the discovery and chronology reference; it does not mean access began that day. “Brief period” is also the company's own description, and no unsupported duration is inferred.
What Personal and Health Information May Have Been Involved?
The potentially involved fields disclosed by the company are full names, addresses, phone numbers, dates of birth, gender, Social security numbers, and Medicare or medicaid numbers. Certain medical information related to a person's plan of care may also have appeared in the file type, including diagnoses, medications, and plan-of-care documentation. The statement specifically says not every data element was present for every individual.
Impact to an email account does not mean every listed field was definitely viewed or copied. Because the company could not determine how many files were viewed, this record preserves the “potentially involved” qualification. Email address is not added as a victim data class either: the fact that the event occurred in an email account does not by itself establish that recipients' email addresses appeared in the relevant file.
How Should the 16,278 Figure Be Interpreted?
16,278 is the number of affected individuals published for Excellent Home Care Services, LLC in the HHS/OCR healthcare breach portal. The company statement says the incident could only have affected people in Bronx, Kings, Nassau, New York, and Queens counties. Those counties are the geographic scope of one notification, not separate incidents, and their populations must not be added again.
The figure is not a count of accessed emails, attachments, rows, or accounts, and it does not represent confirmed misuse. In LeakData, pwnCount and totalRecords hold the regulatory people total of 16,278 while importedRecordCount remains 0. Zero does not mean nobody was affected; it means no raw person-level records or searchable account data were ingested into the system.
What Are the Potential Risks and What Should Be Checked?
A combination of name, date of birth, and Social Security number can increase the risk of identity impersonation, new-account fraud, or tax fraud. A Medicare or Medicaid number together with plan-of-care details could support fraudulent medical services, insurance claims, or tailored phishing. A recipient should regularly review credit reports, Explanation of Benefits statements, and unexpected healthcare bills.
An unexpected message may appear to come from the company or a care professional and may even know a diagnosis, medication, or care detail, but that does not make it legitimate. Use a known institutional channel instead of a link or number in the message, and do not share a password, full SSN, Medicare or Medicaid number, or one-time code. Consider a fraud alert or credit freeze if unfamiliar credit activity appears.
How Did the Company Respond and What Can Recipients Do?
Excellent Home Care Services said it secured the account, reset credentials, restricted access, and reviewed and updated its Microsoft 365 security settings. Additional measures included enhanced access controls, geographic restrictions, improved monitoring tools, a full review of email and data-security practices, updated policies and procedures, and more staff training focused on privacy and cybersecurity awareness.
The company offered complimentary identity-monitoring services to everyone potentially affected. Recipients should use their own letters for enrollment terms and may call 1-833-918-6974 from 8:00 a.m. to 5:30 p.m. Eastern, Monday through Friday, with questions. The fields listed in an individualized letter are more useful than the general public notice when assessing a person's actual scope.