All Breaches
September 18, 2025 Verified Sensitive Record Healthcare

IPPC 2025 Data Breach

The IPPC 2025 data breach occurred when an unauthorized actor accessed the technical network of IPPC Inc., IPPC of New York LLC, and Innovative Pharmacy LLC from September 18 through September 19, 2025. The company's consumer letter confirms that files were copied and potentially viewed during that period. The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 133,862 people were affected.

The reviewed files contained a broad set of identity, government-document, Medicare and Medicaid, tax, passport, patient-account, diagnosis, treatment, procedure, prescription, insurance, payment-card, financial-account, billing, claims, provider, and admission-discharge information. Fields differ by person. LeakData imported no pharmacy or patient rows, and importedRecordCount is zero.

How Was the IPPC Data Breach Confirmed?

The primary evidence is IPPC's consumer notification letter dated April 1, 2026. It says the company took systems offline after discovering suspicious technical-network activity and that the investigation found an unknown actor had accessed the network and copied files. The Vermont Attorney General published the notice in its consumer records, providing an official regulatory context for the company's statement.

The HHS OCR row names the three affiliated IPPC entities together and classifies the event under a Healthcare Provider as a Hacking/IT Incident affecting a Network Server. Its scope of 133,862 people, combined with the confirmed file copying in the consumer letter, establishes a genuine healthcare-data breach. HIPAA Journal separately compared and corroborated the access window, file review, and data categories.

What Was the Incident and Notification Timeline?

The forensic investigation determined that an unknown actor accessed the IPPC network between September 18 and September 19, 2025. The breachDate field uses September 18, the first day of the known window. The public letter does not provide a specific calendar date for when the suspicious activity was initially noticed, so this entry does not invent a discovery date.

IPPC performed a detailed review of the copied files to identify the information and people involved, completing that process around February 9, 2026. The organization created its HHS record and web notice later in February and began sending individual letters dated April 1, 2026. The review period is not presented as the amount of time the actor remained in the network.

What Information Was Affected?

Identity fields include names, dates of birth, driver's-license or other government identification numbers, individual taxpayer identification numbers, and passport numbers. Health-program and record fields include Medicare or Medicaid identification numbers and medical-record or patient-account numbers. Not every affected person's file necessarily contained all of these fields.

The clinical and administrative scope includes diagnosis and treatment information, procedure information, prescription information, health-insurance information, billing and claims information, treating or referring provider names, and admission and discharge dates. Payment-card and financial-account information may also be involved. dataClasses contains only the categories expressly listed by reliable sources.

Why Does Confirmed File Copying Matter?

IPPC's letter states that files were copied and potentially viewed, so the incident is not categorized as merely possible access. Copying is stronger evidence that information could be taken outside the organization's network. The sources do not, however, say that every file was publicly released or that every data field was misused.

At notification, the company said it was not aware of identity theft or fraud related to the incident. A lack of known misuse does not eliminate future risks associated with copied prescription, insurance, financial, and patient-account information. LeakData records the confirmed copying while avoiding unsupported conclusions about sale or publication.

How Is the 133,862-Person Scope Used?

The 133,862 values in pwnCount and totalRecords come from the current HHS OCR public row. It is the total number of affected people reported by IPPC to the federal regulator, not a count of copied files, prescriptions, procedures, or accounts. Because three affiliated legal entities appear in one joint notice, they are not multiplied into separate breaches.

Different categories may apply to different subsets, so this entry does not assume that each data class affected 133,862 people. Individual letters identify personal scope, while public sources provide no field-level subtotals. LeakData neither partitions the total nor creates a larger count by adding categories, and it does not calculate unknown overlap among affiliates.

What Should Affected People Do?

IPPC offered affected people 24 months of complimentary monitoring through Cyberscout and instructed recipients to follow the enrollment steps in their letter. It advised reviewing account statements, health-insurance explanations of benefits, and credit reports for suspicious activity. An unfamiliar transaction or prescription should be checked promptly with the relevant organization.

Unexpected payment or identity-verification requests made in the name of a pharmacy, care facility, or insurer should be verified through known official channels. Prescription and patient-account details can make targeted phishing messages more convincing. LeakData does not host copied patient files or financial information; it publishes only verified incident metadata, reliable sources, and practical follow-up guidance.

133.9 Thousand
Affected Accounts
16
Data Types
High
Severity
Yes
Verification

Exposed Data Types

16
Names
Dates of birth
Driver's license and government-issued id numbers
Medicare and medicaid identification numbers
Individual taxpayer identification numbers
Passport numbers
Medical record and patient account numbers
Diagnosis and treatment information
Procedure information
Prescription information
Health insurance information
Payment card information
Financial account information
Billing and claims information
Treating and referring provider names
Admission and discharge dates

Additional Information

Added DateJuly 27, 2026
Breach DateSeptember 18, 2025
Domainippcrx.com
SourceCompany-confirmed unauthorized network access and file copying
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information