[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBt-cRNVD0WvAG8UsG9pqQjFjPwFi_2GKKzp_WS4Jw1o":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":29,"source":30,"isVerified":4,"isSpamList":31,"isSensitive":4,"severity":32,"processingStatus":33,"logoUrl":34,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66dddbfc601155bed35006","MidAmericaPhysicianServices2024","Mid America Physician Services 2024 Data Breach","mid-america-physician-services-2024","joco-obgyn.com",{"name":12,"sector":13,"country":14,"website":10},"Mid America Physician Services LLC","Healthcare","United States","2024-11-14T00:00:00.000Z","2026-07-27T04:26:03.714Z",104513,[19,20,21,22,23,24,25,26,27,28],"Personal information","Protected health information","Names","Addresses","Dates of birth","Medical treatment information","Billing information","Health insurance information","Social Security numbers","Financial information","\u003Cp>\u003Cstrong>The Mid America Physician Services 2024 data breach\u003C\u002Fstrong> was a network-security incident affecting the Kansas healthcare provider's information technology systems. MAPS discovered the event on or about November 14, 2024, and a review completed on May 8, 2025 confirmed exposure of certain patient information. The HHS OCR public record shows that 104,513 people were affected.\u003C\u002Fp>\n\u003Cp>The company notice identifies names, addresses, dates of birth, medical treatment, billing, and health insurance information. The Texas Attorney General record also lists Social Security numbers and financial information among the possible data types. The combination may vary by person. LeakData imported no patient rows, and importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the Mid America Physician Services Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary incident narrative is the Notice of Data Security Incident issued for MAPS on July 15, 2025. It explains that the organization discovered a network event, investigated with third-party cybersecurity specialists, and identified exposure of certain patient information as a result. The notice also says law enforcement was informed.\u003C\u002Fp>\n\u003Cp>The HHS OCR row records Mid America Physician Services as a Healthcare Provider, classifies the event as a Hacking\u002FIT Incident, and identifies Network Server as the information location; the exact affected total is 104,513. The Texas Attorney General data-security portal publishes identity and financial categories for the event. Corporate identity is additionally established by Johnson County OB\u002FGYN's official site, which calls itself a division of Mid America Physician Services LLC and displays the official MAPS logo.\u003C\u002Fp>\n\u003Ch2>What Was the Incident and Notification Timeline?\u003C\u002Fh2>\n\u003Cp>MAPS discovered a network incident affecting its information technology systems on or about November 14, 2024. It immediately engaged outside cybersecurity specialists to assess, contain, and remediate the event. Because public materials disclose no earlier start to actor access, the breachDate field uses November 14, the confirmed discovery date.\u003C\u002Fp>\n\u003Cp>The file review concluded around May 8, 2025 and identified the types of exposed patient information. The company published its public notice on July 15, explaining that potentially affected individuals were being notified and given protective resources. The January 13, 2025 date on the HHS row is the federal report date and is not treated as the start of the incident.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The confirmed general list in the MAPS notice consists of names, addresses, dates of birth, medical treatment information, billing information, and health insurance information. The Texas regulatory record adds Social Security numbers and financial information. dataClasses contains the fields supported by those two official channels and does not infer undisclosed passwords, email addresses, or payment cards.\u003C\u002Fp>\n\u003Cp>The organization did not say that every patient had the same combination. Treatment and insurance information can enable medical-identity abuse, while Social Security and financial information can support identity or account fraud. The entry preserves the sources' finding of exposure without claiming that files were publicly released, sold, or acquired by a named threat group.\u003C\u002Fp>\n\u003Ch2>What Does the 104,513-Person Scope Mean?\u003C\u002Fh2>\n\u003Cp>The pwnCount and totalRecords fields use the current HHS OCR value of 104,513 people. That figure represents individuals in the notification scope, not a count of exposed files, rows, or fields. One person may have several data elements involved, while another may have only part of the published list.\u003C\u002Fp>\n\u003Cp>Mid America Physician Services operates through four clinical divisions: Johnson County OB\u002FGYN, Women's Care, Women's Clinic of Johnson County, and Women's Health Associates. Because those brands are part of the same MAPS event, they are not created as separate breach entries. The duplicate guard covers all names so searches for any clinic resolve to one verified incident.\u003C\u002Fp>\n\u003Ch2>What Did the Organization Do After the Incident?\u003C\u002Fh2>\n\u003Cp>After identifying the event, the company worked with outside specialists on assessment, containment, and remediation and notified law enforcement. MAPS said it took additional steps to reduce the likelihood of a similar event but did not publish the technical details of those controls. LeakData does not invent undisclosed security measures.\u003C\u002Fp>\n\u003Cp>The investigation had identified no fraud or identity theft resulting from the incident when the notice was issued. That finding describes the known status at notification and does not guarantee that sensitive identity, health, or financial data will never be misused. The company said it was providing affected people with protective resources and continuing its information-security work.\u003C\u002Fp>\n\u003Ch2>What Should Affected Patients Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should rely on the fields identified in their individual letter and review credit reports, bank accounts, bills, and health-insurance explanations of benefits regularly. If an unfamiliar medical service, treatment, insurance claim, or collection appears, contact the provider and insurer through previously known official contact details.\u003C\u002Fp>\n\u003Cp>People whose Social Security numbers or financial information were involved may consider free fraud alerts and credit freezes. Links in unexpected calls, emails, or payment requests using the names of MAPS or its affiliated clinics should not be opened directly. LeakData does not host exposed patient data; it provides verified incident metadata and practical follow-up guidance.\u003C\u002Fp>","Company notice confirming patient information exposure",false,"High","completed","\u002Fuploads\u002Flogo\u002Fmid_america_physician_services.png"]