[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ft9GIiTzOShZ7DXZHNXvLsB4VFVKPKrBZ0LU2sBYxPxI":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":29,"source":30,"isVerified":4,"isSpamList":31,"isSensitive":4,"severity":32,"processingStatus":33,"logoUrl":34,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66c81decf09881d767ff75","QualDermPartners2025","QualDerm Partners 2025 Data Breach","qualderm-partners-2025","qualderm.com",{"name":12,"sector":13,"country":14,"website":10},"QualDerm Partners, LLC","Healthcare","United States","2025-12-23T00:00:00.000Z","2026-07-27T02:53:17.318Z",3433965,[19,20,21,22,23,24,25,26,27,28],"Names","Email addresses","Dates of birth","Dates of death","Doctor names","Medical record numbers","Diagnoses","Treatment information","Health insurance information","Government-issued IDs","\u003Cp>\u003Cstrong>The QualDerm Partners 2025 data breach\u003C\u002Fstrong> involved unauthorized access and file exfiltration from the dermatology and skin-health management organization's network on December 23–24, 2025. QualDerm detected unusual network activity on December 24, secured its systems, and opened an investigation with third-party cybersecurity specialists. The review confirmed that the attacker removed files containing sensitive data from the network.\u003C\u002Fp>\n\u003Cp>The current list maintained by the US Department of Health and Human Services Office for Civil Rights shows 3,433,965 affected individuals for QualDerm Partners LLC. pwnCount and totalRecords use the latest total in that single federal report. Because QualDerm provides management services to many dermatology practices, the population includes patients of different organizations; LeakData imports no personal patient records.\u003C\u002Fp>\n\u003Ch2>How Was the Incident Confirmed?\u003C\u002Fh2>\n\u003Cp>QualDerm said unauthorized activity was identified in its computer network and that access lasted from December 23 through December 24, 2025. The forensic investigation found that files containing sensitive information were exfiltrated during that short window. The record therefore rests on acquisition confirmed by the organization rather than only an assumption that data might have been viewed.\u003C\u002Fp>\n\u003Cp>HHS OCR lists the event as a Hacking\u002FIT Incident, the affected location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal reviewed the company notice, Oregon regulator filing, and HHS entry together, corroborating the timeline, data fields, and multimillion-person scope. Their shared findings establish genuine network access, exfiltration, and affected patient information.\u003C\u002Fp>\n\u003Ch2>What Was the Breach and Notification Timeline?\u003C\u002Fh2>\n\u003Cp>Verified access began on December 23, 2025 and ended when QualDerm discovered unusual activity on December 24. breachDate is December 23, the beginning of the access window. The organization then secured its network and computer systems and worked with outside specialists to determine the nature and scope.\u003C\u002Fp>\n\u003Cp>QualDerm said file review was continuing and that notices would be mailed on a rolling basis to avoid unnecessary delay. The first public figure covered 174,837 Texas residents, followed by an Oregon and HHS count of 3,117,874. The 3,433,965 people now shown by HHS is newer, so older interim figures are not added to it.\u003C\u002Fp>\n\u003Ch2>What Personal and Health Information Was Affected?\u003C\u002Fh2>\n\u003Cp>Depending on the person, affected fields may include names, email addresses, dates of birth, and dates of death. Doctor names and medical record numbers were also in the disclosed scope. Diagnoses, treatment information, and health-insurance data show that the incident affected protected health information as well as identity details.\u003C\u002Fp>\n\u003Cp>QualDerm said government-issued identification information such as driver's-license numbers may also have been involved for a very small subset. Sources do not list Social Security numbers, payment cards, bank accounts, or account passwords among the confirmed fields. The entry therefore uses only published classes and does not assign every category to every person.\u003C\u002Fp>\n\u003Ch2>How Should the Scope of 3,433,965 Be Read?\u003C\u002Fh2>\n\u003Cp>The HHS OCR open-investigation list currently shows 3,433,965 individuals in the QualDerm Partners LLC row submitted on February 22, 2026. This value updates the earlier regulatory figure of 3,117,874 reported in news coverage. pwnCount and totalRecords use only the latest federal value; Texas, Oregon, and older HHS figures are not added again.\u003C\u002Fp>\n\u003Cp>QualDerm had said it served 158 dermatology and skin-care practices across 17 states in a network reaching more than 15 million patients annually. That operating scale is not the breach population. LeakData does not use a 15 million estimate, invent practice-level counts, or exceed the verified HHS notification total of 3,433,965.\u003C\u002Fp>\n\u003Ch2>What Were the Risks and Organization Response?\u003C\u002Fh2>\n\u003Cp>QualDerm said it had not identified evidence that patient data was misused when the incident was disclosed and offered affected people complimentary credit monitoring and identity-theft protection. A lack of known misuse does not reverse confirmed exfiltration or remove future fraud risk. The organization also said it was reviewing data-security policies, procedures, and protocols.\u003C\u002Fp>\n\u003Cp>Public sources do not confirm the attacker's identity, initial entry method, ransom demand, or file volume. LeakData therefore does not associate the incident with a particular ransomware group or invent a root cause such as phishing, credential theft, or a vulnerability. The entry is limited to confirmed network access, file exfiltration, and the disclosed information classes.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Patients receiving a notice should compare the named dermatology practice and doctor relationship with their own records. An unfamiliar diagnosis, treatment, provider, or insurance claim in medical statements should be reported through the health plan and practice's official privacy channels. Messages requesting a medical-record number or identity document should be verified independently before any link is opened.\u003C\u002Fp>\n\u003Cp>People in the small group whose government identification was involved can ask the issuing agency about added protection or replacement and should check the monitoring-offer deadline. importedRecordCount is zero. LeakData does not store or publish names, emails, birth or death dates, doctor names, medical-record numbers, diagnoses, treatment, insurance, or identity-document data.\u003C\u002Fp>","Unauthorized network access and confirmed exfiltration of patient files",false,"Critical","completed","\u002Fuploads\u002Flogo\u002Fqualderm_com.png"]