All Breaches
December 15, 2025 Verified Healthcare

Stockton Cardiology Medical Group Data Breach (90 Thousand People Affected)

The Stockton Cardiology Medical Group data breach affected 90,000 people in an incident that began in December 2025 and involved contact, billing, and limited medical information.

Stockton Cardiology provides cardiac care in California's San Joaquin Valley. Its official notice says certain files maintained for patient care and ordinary business operations were involved in the incident.

What Happened in the Stockton Cardiology Breach?

The company identified and deleted suspicious emails sent to several employees on December 15, 2025. On January 17, 2026, it learned that an unauthorized individual may have accessed and removed certain files from its systems.

Stockton Cardiology began an investigation to determine the scope of the incident and secure its systems. On February 17, 2026, it learned that some of the files had been publicly disclosed; official documents do not identify the confirmed initial access method.

What Information Was Affected?

According to the official notice letter, the potentially affected information included patient names, mailing addresses, email addresses, and billing records that may contain limited medical information associated with services provided.

The data may vary by person, so every field should not be assumed to apply to everyone. The official letter does not list Social Security numbers, passwords, or health insurance numbers among the affected data types.

How Many People Were Affected?

The official U.S. Department of Health and Human Services breach portal reports 90,000 affected individuals. The portal classifies the event as a hacking or IT incident involving a network server.

What Should Affected People Do?

Notice recipients should rely on the data scope in their own letters and review healthcare and billing records for unfamiliar transactions or providers. Any inaccurate entry should be verified with the relevant healthcare organization or payment provider.

Stockton Cardiology offered affected individuals one year of credit monitoring. Unexpected email, payment, or information requests using the organization's name should be verified through an independent channel such as its official website, and suspicious links should not be opened.

90 Thousand
Affected People
4
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

4
Names
Physical addresses
Email addresses
Medical information

Additional Information

Added DateJuly 29, 2026
Breach DateDecember 15, 2025
Domainstocktoncardiology.com