
ProxyCare Data Breach (45.2 Thousand People Affected)
The ProxyCare data breach affected 45,196 people after a cybersecurity incident discovered on August 22, 2025 involved identity and health information.
ProxyCare provides personalized pharmacy services to long-term care organizations. According to the company's official notice, certain systems in its network environment were affected and an unauthorized party may have accessed or acquired files.
What Happened in the ProxyCare Breach?ProxyCare learned of the incident affecting certain network systems on August 22, 2025 and began an investigation with outside cybersecurity specialists. Public documents do not identify the initial access method, exploited vulnerability, or threat actor.
Following a forensic investigation and document review, ProxyCare determined on January 29, 2026 that the files contained personal health information. Notices to affected individuals began on March 23, 2026.
What Information Was Affected?Official notices and the healthcare-sector record list names, dates of birth, Social Security numbers, driver's license numbers, and personal health information among the affected data.
The data varied by person, so every field should not be assumed to apply to everyone. ProxyCare said it had no indication of fraud resulting directly from the incident as of the notice date and offered credit monitoring to people whose Social Security numbers were involved.
How Many People Were Affected?The official U.S. Department of Health and Human Services breach portal reports 45,196 affected individuals. This figure represents the nationwide total reported for the incident.
What Should Affected People Do?Notice recipients should rely on the data fields identified in their own letters and review benefit statements, prescription activity, and insurance records for unfamiliar transactions or providers. Incorrect records should be reported to the relevant healthcare organization or insurer.
People whose Social Security numbers were involved can monitor credit reports and consider a free credit freeze or fraud alert. Unexpected requests using the name of ProxyCare or a pharmacy should be verified independently, and passwords or one-time codes should not be shared.