All Breaches
September 12, 2025 Verified Sensitive Record Healthcare

MedStar Health 2025 Data Breach

The MedStar Health 2025 data breach involved an unauthorized party accessing healthcare systems containing patient information between September 12 and September 16, 2025. MedStar learned of the event October 4, secured its systems, and began an investigation with third-party forensic specialists.

The U.S. Department of Health and Human Services Office for Civil Rights portal lists 64,332 affected individuals for MedStar Health, Inc. and classifies the event as a network-server “Hacking/IT Incident.” In LeakData, pwnCount and totalRecords carry that official people total. importedRecordCount is zero because no raw person-level records were obtained.

How Was the MedStar Health Breach Confirmed?

The primary source is MedStar Health's official data-privacy incident notice. It provides the September 12–16 unauthorized-access window, October 4 discovery, November 12 data-scope determination, December 3 letters, potential data types, and 855-403-1763 assistance line. A preserved PDF copy retains the same text as the official page.

The second source is the official HHS/OCR entry dated December 3 for 64,332 people. ClaimDepot's incident page, which links to the company notice, supports the dates and data categories. A ransomware group named in secondary reporting is not confirmed in MedStar's public text and is therefore not presented as an official finding in the title, description, or tags.

What Happened Between September 12 and 16, 2025?

MedStar's investigation determined that an outside party gained unauthorized access from September 12 through September 16 to systems that included patient information. When the organization learned of the event October 4, it immediately took steps to secure its systems, engaged forensic specialists, and notified law enforcement.

On November 12, the review determined that files accessed by the unauthorized party contained patient information. MedStar began mailing letters to certain patients December 3. The public text does not disclose the initial access method, the party's identity, the number of files, or whether every file was copied; this record does not fill those unknowns with assumptions.

What Patient Information May Have Been Involved?

The official notice says the accessed files contained patient names, dates of birth, and Social security numbers. Depending on the individual, they may also have contained diagnoses, medications, test results, images, health-insurance information, and treatment information. The notice does not say every field was present for every patient.

MedStar also said it offered identity monitoring to patients whose Social Security or driver's license numbers may have been involved, so driver's license number is recorded as a potential data class. Bank accounts, payment cards, passwords, and patient-portal credentials are not disclosed in the public text and are not added here.

How Should the 64,332 Figure Be Interpreted?

64,332 is the number of affected individuals published for this event in the HHS/OCR healthcare breach portal and is stored identically in pwnCount and totalRecords. It is not the number of files, images, laboratory results, or all MedStar patients; it is the people scope reported to the regulator.

An importedRecordCount value of 0 does not mean nobody was affected. That field means LeakData did not receive raw person-level data or searchable account rows. The public affected-account display uses 64,332, while the import counter remains zero as a separate operational measurement.

What Risks Can Follow From the Identity and Health Data?

A combination of name, date of birth, SSN, and driver's license number can increase the risk of impersonation, new-account fraud, or tax fraud. Diagnosis, medication, test result, medical image, and treatment information can support tailored fake healthcare messages, while insurance details may provide context for fraudulent claims or bills.

Recipients should review health-insurance Explanation of Benefits documents and test or treatment notices in addition to credit reports and financial statements. Use a verified institutional channel instead of a link in an unexpected message claiming to be from MedStar or a physician, and do not disclose a full SSN, password, payment, or one-time code.

How Did MedStar Respond and What Can Recipients Do?

MedStar said it secured its systems, investigated with third-party forensic experts, notified law enforcement, and continued reviewing and strengthening its physical, technical, and administrative cybersecurity controls. Complimentary identity monitoring was offered to certain patients whose SSNs or driver's license numbers were involved.

The dedicated 855-403-1763 call center is available weekdays from 9:00 a.m. to 9:00 p.m. Eastern for questions. Recipients should follow the fields and enrollment instructions in their own letters and immediately verify charges for care they did not receive with the provider or insurer. A fraud alert or free credit freeze may be appropriate if unfamiliar credit activity appears.

64.3 Thousand
Affected Accounts
10
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

10
Patient names
Dates of birth
Social security numbers
Driver’s license numbers
Diagnoses
Medications
Test results
Medical images
Health-insurance information
Treatment information

Additional Information

Added DateJuly 27, 2026
Breach DateSeptember 12, 2025
Domainmedstarhealth.org
SourceMedStar Health official notice, HHS/OCR report, and source-linked incident reporting
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information