All Breaches
November 8, 2025 Verified Sensitive Record Healthcare

Nottingham Village 2025 Data Breach

The Nottingham Village 2025 data breach involved unauthorized individuals accessing the senior living and healthcare organization's network between November 8 and November 9, 2025 and potentially viewing or removing files. The organization detected the access on or about November 9, secured its network, and opened an investigation with outside cybersecurity specialists.

The Indiana Attorney General's official breach table reports 7,919 affected people nationwide. The HHS Office for Civil Rights entry separately lists a 5,240-person healthcare-data subset as a Hacking/IT Incident involving a Network Server. LeakData stores 7,919 as the overall total; no person-level raw data was imported.

How Was the Nottingham Village Breach Confirmed?

The primary evidence is Nottingham Village's sample consumer notice published by the Massachusetts consumer-affairs agency. It directly confirms the November 9 detection, November 8–9 access window, possible access to or removal of files, May 12, 2026 data-review result, the name field, network strengthening, and identity-protection offer.

The second source is the Indiana Attorney General's official June 2026 breach table. The Nottingham Village row separately lists a May 22 notice date, November 8 event date, two Indiana residents, and 7,919 total people. The third source is the HHS portal, which verifies the 5,240-person PHI-reporting subset.

What Happened From November 8 Through November 9, 2025?

Nottingham Village detected unauthorized access to its network on or about November 9. An investigation with outside specialists found that unauthorized individuals may have accessed or removed certain files between November 8 and November 9. The organization then conducted a detailed review of the potentially affected data.

The file review determined May 12, 2026 that the relevant files may have contained personal information, and notices began May 22. The official letter does not disclose the initial-entry method, account or vulnerability used, actor identity, malware, or a ransom demand. Third-party actor claims are not substituted for the organization's confirmed findings.

What Information Was Involved?

The sample consumer letter expressly confirms the recipient's first and last name; the recipient-specific field that follows is redacted in the public version. Names are therefore a confirmed specific field, while other personal information remains variable based on each person's letter. It is not assumed that all 7,919 people had the same data element involved.

The 5,240 people in the HHS entry confirm that part of the incident fell within protected-health-information reporting, but the portal does not name a specific medical, insurance, or prescription field. SSNs, birth dates, driver's licenses, and financial accounts are also not universally visible in the public sample. LeakData does not expand redacted fields as fact.

What Risks Follow From Personal and Health Information?

A name and relationship with the organization can make targeted messages impersonating Nottingham Village or a healthcare provider more convincing. If a recipient's own letter identifies a health, identity, or financial field, protections should be tailored to that field. Independently verify even a message that contains a real resident, service, or facility detail.

The organization said it had no evidence as of the letter date that information had been used for financial fraud or identity theft. That does not mean risk is absent. People in the healthcare subset can review explanation-of-benefits statements and medical bills; those whose notices identify a more sensitive identity field can monitor credit reports and new accounts.

How Many People Were Affected and How Did the Organization Respond?

The verified overall total in the Indiana Attorney General table is 7,919 people; pwnCount and totalRecords carry that figure. HHS's 5,240 people are a separate PHI-reporting subset and are not added to the overall total. importedRecordCount is zero; public affected totals do not mean person records were transferred into LeakData collections.

Nottingham Village said it secured the network, worked with outside cybersecurity professionals, strengthened internal controls, and implemented additional security improvements. It offered eligible people Iris Identity Protection credit monitoring, identity monitoring, identity-fraud insurance, and resolution services; enrollment is available for 90 days from the letter date.

What Should Affected People Do?

A notice recipient should check the specific field listed beside their name and use the code and deadline in their own letter if they want the protection service. If health data was involved, monitor unfamiliar providers, services, or claims; if identity or financial data was involved, review new accounts, inquiries, and transactions.

Do not share a password, full SSN, payment, or one-time code in an unexpected call using the Nottingham Village name. Because the dedicated call-center number is redacted in the public sample letter, LeakData does not guess one. Establish contact through the organization's official domain or the original notice received by the person.

7.9 Thousand
Affected Accounts
3
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

3
Personal information
First and last names
Protected health information for the hhs-reported subset; specific fields not disclosed

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 8, 2025
Domainnottinghamvillage.org
SourceState attorney general consumer notice and breach table plus HHS record confirming network access, 7,919 total people, and a 5,240-person PHI subset
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information