All Breaches
August 19, 2025 Verified Sensitive Record Healthcare

Fieldtex Products 2025 Data Breach

The Fieldtex Products 2025 data breach concerns unauthorized activity that the Rochester, New York medical-supply and over-the-counter health-benefits provider detected in its computer systems around August 19, 2025. The company's forensic review determined that a limited amount of protected health information received from health-plan clients may have been accessed or acquired during the attack.

The current breach list maintained by the US Department of Health and Human Services Office for Civil Rights contains five Fieldtex Products reports tied to the same network event. Their populations of 238,615, 5,901, 9,206, 20,641, and 104,071 total 378,434 notification records. pwnCount and totalRecords use this current regulatory sum; LeakData imports no personal health records.

How Was the Breach Confirmed?

Fieldtex said it discovered unauthorized activity in its computer systems, secured the network, and began an investigation with third-party digital-forensics specialists. Its review concluded that a limited amount of protected health information may have been affected in connection with the incident. HIPAA Journal and SecurityWeek reported the organization statement together with the HHS filings.

The HHS list identifies Fieldtex as a business associate, classifies the event as a Hacking/IT Incident, and gives Network Server as the information location. That regulatory classification and the company's finding of possible access or acquisition support a genuine personal-data breach. Because sources do not confirm the initial entry method, this record does not invent phishing, an exploited flaw, stolen credentials, or another vector.

What Was the Incident and Notification Timeline?

Fieldtex detected the unauthorized activity on or around August 19, 2025 and secured its systems to stop further access. The company said it completed its review of the exposed files on September 30, 2025 and notified affected health plans. breachDate is August 19 because that is the publicly disclosed discovery date, not an unverified date when the attacker first entered.

The first large HHS report was submitted on November 20, 2025 for 238,615 people. Three additional December 3 entries list 5,901, 9,206, and 20,641 people, while a later December 12 entry lists 104,071. Different submission dates do not establish separate attacks; they reflect staged reporting by Fieldtex as a business associate acting for health plans.

What Personal Information Was Affected?

The disclosed fields include names, mailing addresses, dates of birth, and gender. Health-plan membership information also included insurance member identification numbers, plan names, and coverage effective dates or terms. These fields were linked to member information supplied by health plans that used Fieldtex's over-the-counter health-benefits program.

Sources do not place Social Security numbers, payment cards, bank accounts, passwords, clinical diagnoses, prescriptions, or detailed treatment records in the confirmed field list. Those categories are therefore excluded. The phrase “protected health information” also does not mean every affected person had every listed field; individual file contents could differ.

How Was the Figure of 378,434 Calculated?

The HHS list accessed on July 27, 2026 contains five open-investigation rows for Fieldtex Products. Adding the populations shown in those rows yields 378,434. In its December 16, 2025 update, HIPAA Journal reported three filings totaling 35,748 in addition to the initial 238,615; the HHS list also currently shows the December 12 submission for 104,071 people.

The public HHS table does not publish a method establishing whether identities were de-duplicated across the five rows. The figure must therefore be read as the sum of reported regulatory populations, not as an independently proven dataset of unique people. This record states that limitation and does not portray the separate client reports as one raw file.

How Is the Attacker Claim Treated?

The Akira ransomware group listed Fieldtex brand E-First Aid Supplies on its leak site in November 2025 and claimed it had taken 14 GB of corporate documents. SecurityWeek reported the assertion and said the files did not appear to have been published at that time. Fieldtex did not name Akira in its public statement, so neither the group nor the 14 GB figure is treated as a company-confirmed finding.

The LeakData entry rests on Fieldtex's forensic conclusion and the HHS reports, not the attacker's statement. It does not conclude that ransomware encrypted systems, a ransom was paid, or every part of the group's claim was accurate. The verified core is that health-plan member information on a network server faced unauthorized access or acquisition.

What Should Affected People Do?

Notice recipients should compare the Fieldtex and health-plan names in the letter with their own plan records, review benefit statements for unfamiliar changes, and report unexpected over-the-counter product orders. Calls or messages requesting an address, birth date, or member identifier should be verified through the health plan's independently obtained official contact channel before any link is used.

Fieldtex said it offered complimentary credit monitoring to eligible people. Even if an enrollment period has passed, reviewing credit reports, reporting unknown accounts, and checking health-insurance explanations remains useful. importedRecordCount is zero; LeakData does not store or publish names, addresses, birth dates, gender, member identifiers, or plan-term information.

378.4 Thousand
Affected Accounts
7
Data Types
High
Severity
Yes
Verification

Exposed Data Types

7
Names
Physical addresses
Dates of birth
Gender
Health insurance member ids
Health plan names
Coverage effective dates

Additional Information

Added DateJuly 27, 2026
Breach DateAugust 19, 2025
Domainfieldtex.com
SourceUnauthorized access to a network server containing health-plan member information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information