The North East Medical Services 2025 data breach was a cybersecurity incident discovered on October 19, 2025 after suspected unauthorized access to data hosted by UnitedLayer, the community-health-center network's third-party managed service provider. NEMS's notification letter confirms that a limited amount of information in the system may have been accessed by an unauthorized individual.
The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists North East Medical Services as a Healthcare Provider and classifies the event as a Hacking/IT Incident involving a Network Server; 91,513 people were affected. LeakData imported no patient records, importedRecordCount is zero, and this page contains verified incident metadata only.
How Was the NEMS 2025 Breach Confirmed?
The primary source is the three-page incident notification letter sent on behalf of North East Medical Services. It directly identifies the detection date, possible unauthorized access within UnitedLayer's network, the investigation with outside forensic specialists, completion of the data review, and complimentary credit-monitoring services offered to affected people.
The second source is the HHS OCR breach portal; its federal row confirms 91,513 people, the incident category, and the network-server location. A ClassAction.org summary and its linked Massachusetts consumer-affairs report identify Social security numbers and medical records among the potential fields. The company, provider, dates, and event structure align across the sources.
What Happened on October 19, 2025?
On October 19, NEMS detected potential unauthorized access to certain data hosted on the network of its managed service provider, UnitedLayer. The organization immediately began an investigation with third-party specialists to determine the nature and scope of the activity. The review found that an unauthorized individual may have accessed a limited amount of information within the network.
NEMS then performed a comprehensive review to determine the content of the potentially affected data and the people to whom it related. That work concluded on December 17, 2025; the HHS row is dated the following day, December 18. The breachDate field uses October 19, the discovery date disclosed by the organization, rather than estimating when actor access began.
What Information Was Affected?
The general notification template says the affected combination may consist of first and last names plus other recipient-specific fields. Public reporting based on the breach report submitted in Massachusetts specifically identifies Social security numbers and medical records. The entry's dataClasses therefore includes only those three confirmed fields and their broader categories.
NEMS did not say that every data type appeared for all 91,513 people. This entry creates no subgroup counts and does not add undisclosed addresses, dates of birth, driver's-license details, email addresses, passwords, payment cards, bank accounts, or health-insurance identifiers. The sources also do not establish public release or sale of the data or attribution to a particular ransomware group.
What Does the 91,513-Person Scope Mean?
The pwnCount and totalRecords fields use the 91,513 affected-person count in the current HHS OCR public row. The value is not a count of files, medical documents, clinic visits, or data elements. One individual's record may contain multiple fields, and LeakData has not added undisclosed distributions to construct a different total.
North East Medical Services is a nonprofit network of community health centers serving predominantly low-income and underserved populations in the San Francisco Bay Area and Las Vegas. This event is distinct in date, system, incident type, and scope from NEMS's 2015 theft of an unencrypted laptop, which affected 69,246 people.
What Measures Did NEMS Take?
NEMS said it took steps to secure its environment after detecting the potential access and conducted a comprehensive investigation with help from outside forensic specialists. The organization also reviewed the potentially affected information in detail to assess its notification obligations.
Affected people were offered complimentary credit monitoring through Cyberscout, a TransUnion company; the general letter leaves the service length as a recipient-specific field. LeakData therefore does not guess the exact subscription period omitted from the public template. NEMS recommended monitoring account statements, credit reports, and health-insurance explanation-of-benefits forms for suspicious activity.
What Should Affected People Do?
Notice recipients should activate the complimentary monitoring service within the letter's 90-day enrollment window and regularly review credit reports, new-account inquiries, and healthcare service histories. An unfamiliar account, medical procedure, or insurance claim should be reported through a previously known official channel for the relevant institution.
The combination of Social security numbers and medical records increases the risk of identity theft and targeted healthcare fraud. Links in unexpected messages claiming to be from NEMS, UnitedLayer, a credit bureau, or an insurer should not be opened directly; contact should begin through an official site or verified number. LeakData does not host, distribute, or provide search access to stolen personal information.