
Pines of Sarasota 2025 Data Breach (1.3 Thousand People Affected)
The 2025 Pines of Sarasota data breach was a security incident in which an unauthorized actor accessed and acquired personal or protected health information belonging to certain current and former patients.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/information-technology incident involving email and reported 1,258 affected individuals.
Verified Incident TimelinePines of Sarasota detected unusual activity disrupting access to certain systems on February 5, 2025. Its investigation found that information was accessed and acquired without authorization on or about January 31, 2025 and concluded on March 1, 2025. Notices were mailed on March 4, 2026 to people whose addresses could be identified.
What Information May Have Been Affected?The scope may vary by person. The company's announcement lists names, addresses, phone numbers, dates of birth, Social Security numbers, diagnoses or conditions, and other medical treatment information. It specifically says that not every data element was affected for every individual.
How the Organization RespondedPines of Sarasota says it secured its network, investigated with independent digital-forensics specialists, and notified the FBI and the federal health authority. It reported no evidence of information misuse at the time of notice and offered free identity-protection services to affected individuals.
What Should Affected People Do?Recipients should rely on the data types identified in their individual notice. People whose health information was involved can review statements and service records for unfamiliar activity, while those whose Social Security numbers were involved can monitor credit reports for unfamiliar accounts. Incident-related communications should be verified through the organization's official channels before recipients respond.