[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f332vg1utphjnn":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":4,"isSpamList":39,"isMalware":39,"company":40},"6a70c4a68e75b9f6f2b42d71","HeartlandHealthCenter2025","Heartland Health Center 2025 Data Breach","heartland-health-center-2025","heartlandhealthcenter.org","2025-02-04T00:00:00.000Z","2026-08-03T16:41:09.679Z","Official state-filed notice, HHS OCR, and independent source-linked reporting","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2025-1795-heartland-health-center\u002Fdownload",[14,16],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",43728,"known",null,"people","Medium",[23,24,25,26,27,28,29,30,31,32,33],"Names","Social security numbers","Dates of birth","Driver's license numbers","Financial account information","Usernames","Medical information","Health insurance information","Medical record numbers","Patient IDs","Government IDs","\u003Cp>\u003Cstrong>The Heartland Health Center data breach\u003C\u002Fstrong> was a 2025 security incident in which an unauthorized party accessed the Nebraska healthcare provider's network environment. The organization discovered the incident on February 4, 2025. The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) reports 43,728 affected people.\u003C\u002Fp>\u003Cp>The catalog's February 4 date is the confirmed discovery date, not a claimed first-access date. The public official notice does not disclose when unauthorized access began.\u003C\u002Fp>\u003Ch2>How did the Heartland Health Center data breach happen?\u003C\u002Fh2>\u003Cp>The official notice says an unknown third party gained unauthorized access to Heartland Health Center's network environment. After discovering the incident, the organization engaged forensic specialists, secured its systems, and reviewed files that may have been affected.\u003C\u002Fp>\u003Cp>The investigation found that some data may have been exposed without authorization. The organization completed its file review on June 3, 2025, and sent notices on October 17. Official documents do not disclose the initial-access method or an exploited vulnerability.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. Disclosed information may have included names, Social Security numbers, dates of birth, driver's license numbers, financial account numbers, and usernames and access information for non-financial accounts.\u003C\u002Fp>\u003Cp>Dates of medical service, diagnoses, health-insurance policy numbers, physician or facility information, condition or treatment information, medical-record numbers, Medicare or Medicaid numbers, patient-account numbers, certificate or license numbers, full-face photographs, and referral information may also have been involved. Not every category applied to every person.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The current HHS OCR entry reports 43,728 affected individuals for the network-server incident involving Heartland Health Center. This is the event-specific affected-person total submitted to the federal regulator.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Social Security numbers combined with dates of birth and government-identification details can increase the risk of identity theft and fraudulent accounts. Financial-account and access information can support targeted scams that appear to come from a legitimate organization.\u003C\u002Fp>\u003Cp>Health and insurance information can enable medical-identity scams that reference a real appointment, physician, or policy. Accurate health details do not prove that a message sender is authorized.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>Heartland Health Center said it worked with specialists to investigate the source of the incident, protect its systems, and identify people whose information may have been affected. The organization also offered eligible individuals 12 months of credit monitoring and fraud assistance.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports, bank accounts, health-insurance statements, and medical bills for unfamiliar activity. If a Social Security number was involved, a credit freeze or fraud alert may be appropriate.\u003C\u002Fp>\u003Cp>For an unexpected message claiming to come from Heartland Health Center, a healthcare provider, or an insurer, use contact details from the organization's official website rather than a link or phone number supplied in the message.\u003C\u002Fp>","","Heartland Health Center Data Breach (43.7 Thousand People Affected)","The Heartland Health Center data breach affected 43,728 people and may have exposed identity, financial, and health information.","\u002Fuploads\u002Flogo\u002Fheartland-health-center-official.png",false,{"name":41,"sector":42,"country":43,"website":44,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":19},"Heartland Health Center","Healthcare","United States","https:\u002F\u002Fheartlandhealthcenter.org\u002F"]