[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2pwsoq9bo2amv":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"6a7037d19c4df8e976c9c275","HealthPaymentSystems2025","Health Payment Systems 2025 Data Breach","health-payment-systems-2025","hps.md","2025-06-24T00:00:00.000Z","2026-08-03T06:40:17.908Z","Official Health Payment Systems security-event notice","https:\u002F\u002Fhps.md\u002Fjune2026-notice-of-security-event\u002F",[14,16],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",9380,"known",null,"people","Low",[23,24,25,26,27,28,29],"Names","Physical addresses","Dates of birth","User IDs","Social security numbers","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The 2025 Health Payment Systems data breach\u003C\u002Fstrong> came to light after the healthcare-payment company detected unauthorized access involving certain employee email accounts. HPS says an unknown person accessed certain emails from approximately June 24 through June 27, 2025.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as an email-system breach affecting 9,380 people. The possible data scope includes identity, subscriber, and health information.\u003C\u002Fp>\u003Ch2>How was the Health Payment Systems breach confirmed?\u003C\u002Fh2>\u003Cp>HPS's official security notice provides the incident timeline, affected environment, possible data fields, and company response. It says certain patient information may have been accessed or acquired by an unknown unauthorized person.\u003C\u002Fp>\u003Cp>The HHS OCR entry lists the same organization as a business associate, gives the total of 9,380 people, and classifies the event as a Hacking\u002FIT Incident involving email. That figure is the affected-person total; it does not establish which fields were present for every person.\u003C\u002Fp>\u003Ch2>What happened from June 24 through June 27, 2025?\u003C\u002Fh2>\u003Cp>HPS became aware of suspicious activity related to certain employee email accounts on or about June 27, 2025 and moved to secure them. The company then investigated the nature and scope of the event with third-party cybersecurity specialists.\u003C\u002Fp>\u003Cp>The investigation determined that an unknown person accessed certain emails from about June 24 through June 27. The catalog date therefore represents the approximate start of the access window; the notice does not disclose an exact time, the method used, or the actor's identity.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>The official notice lists names, addresses, dates of birth, IDs, subscription IDs, and subscriber person IDs. For some people, the information may also have included Social Security numbers, medical information, and health-insurance information.\u003C\u002Fp>\u003Cp>The fields varied by person. Although the incident involved employee email accounts, the notice does not separately list affected individuals' email addresses or account passwords among the exposed fields, so those categories are not added.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>A name, address, date of birth, and Social Security number can be combined to support identity theft, fraudulent account opening, or tax and credit fraud. Identity and subscriber numbers may also be used to make targeted messages appear credible.\u003C\u002Fp>\u003Cp>Medical and health-insurance information may be misused in false service claims, insurance fraud, or messages impersonating a healthcare organization. An accurate subscriber or health detail does not prove that a caller or sender is legitimate.\u003C\u002Fp>\u003Ch2>How did HPS respond?\u003C\u002Fh2>\u003Cp>The company says it secured the relevant accounts, deployed an advanced threat-protection and monitoring tool, reviewed existing security policies, and implemented additional measures. It also reported the event to law enforcement and the required regulators.\u003C\u002Fp>\u003Cp>HPS said it would mail notices to people whose address information it could identify and offer complimentary credit monitoring and identity-theft protection. Eligibility terms and enrollment dates should be checked in the notice received directly.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should review financial-account activity, credit reports, and health-insurance explanation-of-benefits statements for accounts, transactions, or services they do not recognize. Suspicious entries should be reported through independently verified channels to the relevant bank, health plan, or provider.\u003C\u002Fp>\u003Cp>Do not provide a Social Security number, insurance information, password, or verification code in response to an unexpected call or message. People told that their Social Security number was involved may also consider a free credit freeze or fraud alert.\u003C\u002Fp>","","Health Payment Systems 2025 Data Breach (9.4 Thousand People Affected)","The Health Payment Systems data breach may have affected identity, subscriber, and health information belonging to 9,380 people. Review the incident and…","\u002Fuploads\u002Flogo\u002Fhealth-payment-systems-official.png",false,{"name":37,"sector":38,"country":39,"website":40,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":19},"Health Payment Systems, Inc.","Healthcare","United States","https:\u002F\u002Fhps.md\u002F"]