All Breaches
April 14, 2025 Verified Healthcare

Optalis Management Solutions Data Breach (13.7 Thousand People Affected)

The Optalis Management Solutions data breach affected 13,723 people after unauthorized network access between April 14 and April 19, 2025 exposed personal and health information.

Optalis provides management services to the Optalis Health & Rehabilitation network of care and rehabilitation facilities. According to the company, the intruder removed a limited amount of personal information from the network during the access period.

What Happened in the Optalis Management Solutions Breach?

Optalis determined that unauthorized access to its network occurred from April 14 through April 19, 2025. The company began an investigation with outside cybersecurity specialists; public documents do not identify the initial access method, exploited vulnerability, or threat actor.

The document review concluded on June 10, 2026, and written notices began on or about June 29, 2026. The HHS record classifies the breach as a hacking or IT incident involving a network server.

What Information Was Affected?

The official notice says full names were involved together with one or more of the following: Social Security numbers, driver's license or state identification numbers, credit or debit card information, financial account information, medical treatment and diagnosis information, or health insurance policy numbers.

The data varied by person, so every listed field should not be assumed to apply to everyone. Optalis said it was not aware of identity fraud or improper use directly resulting from the incident as of the notice date.

How Many People Were Affected?

The official U.S. Department of Health and Human Services breach portal reports 13,723 affected individuals. This figure represents the number of people reported as affected by the incident.

What Should Affected People Do?

Notice recipients should rely on the data types identified in their own letters. If a Social Security number or financial information was involved, they can monitor credit reports and account activity and consider a free credit freeze or fraud alert.

Unexpected payment, insurance, or identity-verification requests using the name of Optalis or an affiliated care provider should be verified through an independent channel. Unrecognized medical, insurance-claim, or service activity should be reported to the relevant provider.

13.7 Thousand
Affected People
9
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

9
Names
Social security numbers
Driver's license numbers
Government issued IDs
Credit cards
Financial account information
Treatment information
Diagnoses
Health insurance information

Additional Information

Added DateJuly 29, 2026
Breach DateApril 14, 2025
Domainoptalishealthcare.com