All Breaches
November 25, 2025 Verified Business Services

Greenbaum Rowe Smith & Davis Data Breach (12.8 Thousand People Affected)

The Greenbaum Rowe Smith & Davis data breach affected 12,801 people after unauthorized system access between November 25 and November 27, 2025 involved personal and health information.

Greenbaum, a New Jersey law firm, had access to certain patient information while providing services to hospitals and health systems. Healthcare-provider statements say the incident occurred in Greenbaum's environment, not their own systems.

What Happened in the Greenbaum Rowe Smith & Davis Breach?

Greenbaum personnel discovered unauthorized system access through a compromised user account on November 27, 2025. The investigation found that a third party acquired certain information from Greenbaum's systems between November 25 and November 27.

The firm contained the access, reset passwords, replaced compromised machines, and notified law enforcement. Its review to identify the affected information concluded on April 15, 2026.

What Information Was Affected?

The official incident site lists names, addresses, medical record and account numbers, diagnoses and clinical information, medical histories, treatment or procedure information, providers, dates of service, medical costs, other medical information, and health insurance information.

Social Security numbers or dates of birth may also have been involved for a subset of people. The data varied by person, so every field should not be assumed to apply to everyone. Greenbaum said it was not aware of related identity theft or fraud as of the notice date.

How Many People Were Affected?

The official U.S. Department of Health and Human Services breach portal reports 12,801 affected individuals. Those people may be associated with several healthcare organizations served by Greenbaum; organization-level figures should not be added to this total.

What Should Affected People Do?

Notice recipients should rely on the fields identified in their own letters and review benefit statements, insurance claims, and medical records for unfamiliar activity or providers. Incorrect records should be reported to the relevant healthcare organization.

People whose Social Security numbers were involved can monitor credit reports and consider a free credit freeze or fraud alert. Unexpected requests using the name of Greenbaum or a healthcare organization should be verified independently without using the link or telephone number in the incoming message.

12.8 Thousand
Affected People
11
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

11
Names
Physical addresses
Medical record numbers
Patient IDs
Diagnoses
Medical information
Treatment information
Provider names
Health insurance information
Social security numbers
Dates of birth

Additional Information

Added DateJuly 29, 2026
Breach DateNovember 25, 2025
Domaingreenbaumlaw.com