[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1x48qinsxp9rs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"6a70bd2e95729a8e06c1c56f","SierraVistaHospitalClinics2025","Sierra Vista Hospital & Clinics 2025 Data Breach","sierra-vista-hospital-clinics-2025","svhnm.org","2025-01-14T00:00:00.000Z","2026-08-03T16:09:17.648Z","Official Sierra Vista notice, HHS OCR, and independent breach reporting","https:\u002F\u002Fwww.svhnm.org\u002Fwp-content\u002Fuploads\u002F2025\u002F10\u002Fsierra-vista-notifies-of-data-security-incident.pdf",[14,16],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",75054,"known",null,"people","Medium",[23,24,25,26,27,28,29,30],"Names","Physical addresses","Dates of birth","Social security numbers","Government issued IDs","Driver's license numbers","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The 2025 Sierra Vista Hospital &amp; Clinics data breach\u003C\u002Fstrong> involved unauthorized access to the healthcare provider's network between January 14 and January 31, 2025. The organization detected suspicious activity on January 29. The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) reports 75,054 affected people.\u003C\u002Fp>\u003Cp>The incident concerns Sierra Vista Hospital &amp; Clinics, which provides hospital and clinic services in Truth or Consequences, New Mexico.\u003C\u002Fp>\u003Ch2>How did the Sierra Vista data breach happen?\u003C\u002Fh2>\u003Cp>Incident reviews found that an unauthorized person may have accessed or acquired certain network files between January 14 and January 31, 2025. The organization secured its network and began a forensic investigation with outside cybersecurity specialists.\u003C\u002Fp>\u003Cp>Public documents do not disclose the initial-access method, an exploited vulnerability, or the attacker's identity. The incident is therefore not attributed to an unconfirmed attack technique or threat group.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. Disclosed fields may have included first and last names, addresses, dates of birth, Social Security numbers, state identification or driver's-license numbers, medical information, and health-insurance information.\u003C\u002Fp>\u003Cp>Not every category applied to every individual. The organization's general notice says information in the files may have been accessed or acquired; no public finding says the information was misused.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The official HHS OCR entry reports 75,054 affected individuals for the network-server Hacking\u002FIT Incident. This is the event-specific affected-person total.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Social Security numbers combined with dates of birth and addresses can increase the risk of identity theft, fraudulent account openings, or tax fraud. A driver's-license or state-identification number may also be used in impersonation attempts.\u003C\u002Fp>\u003Cp>Medical and health-insurance information can help an attacker create targeted scams that appear to refer to a real treatment relationship. Accurate health details do not prove that a sender is authorized.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>After its investigation and document review, Sierra Vista determined on August 13, 2025 that personal information may have been involved. The organization began notifying affected people on October 6, 2025.\u003C\u002Fp>\u003Cp>Sierra Vista said it strengthened its network, added malware monitoring and email filtering, and provided additional cybersecurity training to employees.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports, financial accounts, health-insurance statements, and medical bills for unfamiliar activity. If a Social Security number was involved, a credit freeze or fraud alert may be appropriate.\u003C\u002Fp>\u003Cp>For an unexpected message claiming to come from Sierra Vista or another healthcare provider, use contact details from the organization's official website rather than a link or phone number supplied in the message.\u003C\u002Fp>","","Sierra Vista Data Breach (75.1 Thousand People Affected)","The Sierra Vista Hospital & Clinics data breach affected 75,054 people and may have exposed identity, insurance, and medical information.","\u002Fuploads\u002Flogo\u002Fsierra-vista-hospital-clinics-official.png",false,{"name":38,"sector":39,"country":40,"website":41,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":19},"Sierra Vista Hospital & Clinics","Healthcare","United States","https:\u002F\u002Fwww.svhnm.org\u002F"]