The Northwoods Surgery Center 2025 data breach was a confirmed health-data security event identified through unauthorized activity in the computer network of a Minnesota outpatient surgical center. According to the official notice, information may have been accessed between July 11 and September 8, 2025; Northwoods discovered the activity on September 8.
The U.S. Department of Health and Human Services Office for Civil Rights lists the Northwoods Surgery Center event as a Hacking/IT Incident affecting 5,385 people. LeakData imported no patient or person rows, and importedRecordCount is zero. This entry is verified through the official company PDF, federal HHS report, and a reliable incident summary linking the sources.
How Was the Northwoods Surgery Center Breach Confirmed?
The primary source is the Notification of Data Security Incident PDF dated November 7, 2025 and published on Northwoods Surgery Center's own website. It directly describes the discovery date, possible access window, investigation with third-party specialists, possible health-data fields in the files, security improvements, and protective services.
The HHS OCR record classifies the organization as a Minnesota healthcare provider and reports 5,385 people, an April 29, 2026 submission date, a network-server location, and a hacking/IT incident type. Claim Depot presents the official timeline and information classes alongside the federal record and supports public verification of the event.
What Happened Between July 11 and September 8?
Northwoods learned of unauthorized network activity on or around September 8, 2025 and immediately acted to secure the network and prevent further access. An investigation with third-party specialists found that a limited amount of information may have been accessed by an unauthorized party between July 11 and September 8.
The official notice says analysis was ongoing when published and that possible access to the information could not be ruled out. The source does not state that files were definitively copied or exfiltrated and does not identify the attacker or initial entry method. LeakData does not add an unverified ransomware, data-theft, or threat-group attribution.
What Identity and Insurance Information May Have Been Affected?
Possible fields include patient names, addresses, dates of birth, health-insurance information, and medical-record numbers. This combination may create risks involving targeted phishing, insurance fraud, and medical-identity impersonation. The official text says files may have contained PHI for a limited number of patients.
The source does not list Social Security numbers, driver's licenses, bank accounts, payment cards, passwords, or passports, and LeakData does not add those fields. The HHS total of 5,385 does not mean every information class applied to every person. Combinations may vary, and the number of files has not been disclosed.
What Medical Information Was Involved?
The official list includes a doctor's name, practice type, medical date of service, medication information, diagnosis and treatment information, and medical claims or billing information. These fields may associate a patient with a particular provider, procedure, and care history and are sensitive from a health-privacy perspective.
The notice does not say that the entire electronic health-record system or complete patient files were affected. A practice type and date of service do not establish a specific surgery, detailed clinical note, or imaging result. LeakData records only the health categories expressly identified in the official text.
How Did Northwoods Respond?
Northwoods secured the network, stopped access, and engaged third-party specialists for forensic review. It says it worked with specialists to evaluate and reinforce existing security measures across its network and facilities. At the time of notice, there was no evidence of actual or attempted fraudulent misuse of information.
Potentially affected people were offered credit-monitoring and identity-protection services. A weekday assistance line at 1-833-833-6099 was published for incident information and enrollment support. Because the public notice does not state a service duration, LeakData does not invent a term or provider package.
What Should Affected People Do?
Patients should review health-insurance explanation-of-benefits statements, medical bills, prescription histories, and patient portals for unknown services or claims. If an unfamiliar doctor, date of service, medication, diagnosis, treatment, or charge appears, the relevant provider and insurer should be notified through a verified channel.
Dates of birth, insurance details, or medical-record numbers should not be shared in unexpected email, text messages, or calls claiming to represent Northwoods; only the assistance line in the official notice should be used. LeakData does not host, distribute, or make searchable any potentially affected files, patient records, insurance information, or medical identifiers.