[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1y6ewni9r0y7j":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a7058c046e1fa31a308d018","GaylordSpecialtyHealthcare2024","Gaylord Specialty Healthcare 2024 Data Breach","gaylord-specialty-healthcare-2024","gaylord.org","2024-12-16T00:00:00.000Z","2026-08-03T09:00:48.364Z","HHS OCR report, official state-filed notification, and independent regulatory-filing summary","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16,17,18],"https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2025-1656-gaylord-specialty-healthcare\u002Fdownload","https:\u002F\u002Fmm.nh.gov\u002Ffiles\u002Fuploads\u002Fdoj\u002Fremote-docs\u002Fgaylord-specialty-healthcare-20250929.pdf","https:\u002F\u002Fwww.gaylord.org\u002F",62232,"known",null,"people","Medium",[25,26,27,28,29,30,31,32],"Names","Physical addresses","Dates of birth","Social security numbers","Government issued IDs","Health insurance information","Medical information","Financial account information","\u003Cp>\u003Cstrong>The 2024 Gaylord Specialty Healthcare data breach\u003C\u002Fstrong> came to light after the Connecticut healthcare organization experienced a cyber incident that disrupted network connectivity in December 2024. A forensic investigation found that personal data may have been acquired without authorization between December 16 and December 19.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a network-server Hacking\u002FIT Incident affecting 62,232 people. The organization's later notice says the event involved personal and health information, while independent reporting described it as a ransomware attack attributed to the SafePay group.\u003C\u002Fp>\u003Ch2>How was the Gaylord Healthcare breach confirmed?\u003C\u002Fh2>\u003Cp>Gaylord Specialty Healthcare's official notice, published through state authorities, connects the December 19, 2024 network disruption, the possible December 16–19 data-acquisition window, and completion of the scope determination on August 25, 2025. The HHS OCR entry confirms Gaylord Hospital, the Connecticut healthcare entity, and the total of 62,232 people.\u003C\u002Fp>\u003Cp>An independent event summary, citing the official notice and regulatory filings, reports the access window, disclosed data types, and September 24, 2025 notification date. The initial HHS report on February 28 and the later completion of the document review represent different stages; the dates are not combined into a single claimed access day.\u003C\u002Fp>\u003Ch2>What happened in December 2024?\u003C\u002Fh2>\u003Cp>Around December 19, 2024, Gaylord detected a cybersecurity event affecting connectivity to its network and began an investigation with external cybersecurity specialists. The investigation concluded that personal data may have been acquired without authorization between December 16 and December 19.\u003C\u002Fp>\u003Cp>Independent reporting said the SafePay group claimed responsibility and alleged that it had taken 160 GB of data. The organization's official letter confirms possible unauthorized data acquisition, but it does not independently confirm the initial access method, technical vulnerability, or the group's volume claim.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Depending on the person, potentially affected information could include names, addresses, dates of birth, Social Security numbers, driver's license or other government identification numbers, health insurance information, medical records, and financial account information.\u003C\u002Fp>\u003Cp>Recipient-specific fields in the public notice template are blank for security, but the event summary based on state filings lists these categories. Passwords and email addresses are not included in this record because the public incident disclosures do not confirm those fields.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Identity numbers exposed together with financial and health information can increase the risk of identity theft, fraudulent accounts or insurance claims, and targeted scams. Social Security and driver's license numbers are difficult to change, so careful monitoring may be necessary over the long term.\u003C\u002Fp>\u003Cp>Someone who knows a real health service, insurance detail, or account fact may craft a convincing message. Possessing those details does not prove that a sender represents Gaylord, a physician, a bank, or an insurer, and unexpected requests should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>Gaylord conducted a forensic investigation and comprehensive document review with external cybersecurity specialists, secured its systems, and said it was enhancing internal controls. The review to identify affected people was completed on August 25, 2025, and notification letters began on September 24.\u003C\u002Fp>\u003Cp>Eligible individuals were offered credit monitoring, a credit report, and fraud-assistance services. The organization said its public notice found no evidence of financial fraud or identity theft related to the event; that statement does not guarantee that misuse cannot occur later.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>People who received a notice should regularly review credit reports, financial accounts, and health insurance explanations for unfamiliar accounts, transactions, services, or claims. Suspicious entries should be reported to the relevant financial institution, health insurer, and appropriate authorities when necessary.\u003C\u002Fp>\u003Cp>Social Security numbers, health information, passwords, and one-time verification codes should not be shared in unexpected emails, messages, or calls. A request claiming to come from Gaylord should be verified using contact information on the official website rather than a link or phone number in the message.\u003C\u002Fp>","","Gaylord Specialty Healthcare 2024 Data Breach (62.2 Thousand People Affected)","The Gaylord Specialty Healthcare breach may have exposed identity, financial, and health data belonging to 62,232 people.","\u002Fuploads\u002Flogo\u002Fgaylord-specialty-healthcare-official.svg",false,{"name":40,"sector":41,"country":42,"website":18,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Gaylord Specialty Healthcare","Healthcare","United States"]