[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgIQi6nYXjMeFZNiPyUgOXRw_RYriHV6SyhMl07Nkzgc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":4,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66e0cfb4b74306600c4dc4","SurvivalFlight2025","Survival Flight 2025 Data Breach","survival-flight-2025","survivalflightinc.com",{"name":12,"sector":13,"country":14,"website":10},"Survival Flight, Inc.","Healthcare","United States","2025-07-17T00:00:00.000Z","2026-07-27T04:38:39.105Z",97217,[19,20,21,22,23,24],"Personal information","Protected health information","Names","Addresses","Medical treatment information","Health insurance information","\u003Cp>\u003Cstrong>The Survival Flight 2025 data breach\u003C\u002Fstrong> was a cybersecurity incident affecting the emergency air-medical transportation provider's information technology systems and discovered on July 17, 2025. Survival Flight's official notice confirms that names, addresses, medical treatment information, and health insurance information belonging to certain patients were likely exposed as a result.\u003C\u002Fp>\n\u003Cp>The HHS OCR public record lists the organization as a Healthcare Provider, the event as a Hacking\u002FIT Incident, and the information location as Network Server; 97,217 people were affected. This entry is separate from Survival Flight's May 2024 employee-email incident affecting 12,342 people. LeakData imported no patient rows, and importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the Survival Flight 2025 Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the Notice of Data Security Incident published on Survival Flight's official domain. Dated August 12, 2025, it says the organization discovered an event affecting its information technology systems on July 17, engaged outside cybersecurity specialists, and identified likely exposure of certain patient information during its investigation.\u003C\u002Fp>\n\u003Cp>The second source is the HHS Office for Civil Rights breach portal. Its federal row, dated September 15, 2025, confirms 97,217 people, a Hacking\u002FIT Incident, and Network Server as the location. The organization, year, system type, and health-data categories align across the two channels, and no existing database entry matched the same event.\u003C\u002Fp>\n\u003Ch2>What Happened on July 17, 2025?\u003C\u002Fh2>\n\u003Cp>Survival Flight identified a cybersecurity incident affecting its information technology systems on July 17. It immediately engaged third-party experts to assess, contain, and remediate the event and also notified law enforcement. The breachDate field uses July 17, the publicly disclosed discovery date.\u003C\u002Fp>\n\u003Cp>The official notice does not provide the start or end of actor access, the technique used, or a named threat actor. The entry therefore does not construct an estimated intrusion window before discovery and does not label the event as ransomware. The confirmed findings are impact to the systems and likely exposure of patient information.\u003C\u002Fp>\n\u003Ch2>What Patient Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The investigation identified names, addresses, medical treatment information, and health insurance information as likely exposed for certain patients. dataClasses contains those four specific fields and their broader personal-information and protected-health-information categories. It does not assume that every field appeared for all 97,217 people.\u003C\u002Fp>\n\u003Cp>The notice does not identify Social Security numbers, dates of birth, payment cards, financial accounts, passwords, email addresses, or driver's-license information. LeakData does not add undisclosed fields merely because they are common in healthcare incidents. The document also does not confirm that files were publicly released, sold, or downloaded by a named actor.\u003C\u002Fp>\n\u003Ch2>What Does the 97,217-Person Scope Mean?\u003C\u002Fh2>\n\u003Cp>The pwnCount and totalRecords fields use the exact 97,217-person total in the current HHS OCR public row. The company's August notice said work to determine the full extent was ongoing; the September federal record supplies the later notification population. The entry relies on that regulatory total instead of estimating a number from the earlier uncertainty.\u003C\u002Fp>\n\u003Cp>The value counts affected individuals, not files, medical flights, insurance claims, or data elements. One patient may have both treatment and insurance information, while another may have a narrower combination. Because subgroup sizes were not disclosed, LeakData does not calculate a new scope by adding data classes.\u003C\u002Fp>\n\u003Ch2>What Measures Did the Organization Take?\u003C\u002Fh2>\n\u003Cp>Survival Flight immediately engaged third-party cybersecurity experts for assessment, containment, and remediation and notified law enforcement. The organization said it took steps intended to reduce the likelihood of a similar event, but its public notice does not disclose the technical details of those controls.\u003C\u002Fp>\n\u003Cp>As of the August notice, the investigation had identified no fraud or identity theft resulting from the incident. The company said it would notify affected people and provide protective resources after completing its review. A lack of known misuse does not guarantee that health and insurance information cannot later be used in medical-identity fraud.\u003C\u002Fp>\n\u003Ch2>What Should Affected Patients Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should regularly review health-insurance explanations of benefits, annual service histories, and provider records for unfamiliar flights, treatments, doctors, or claims. If an unknown service appears, contact the insurer and healthcare organization through previously known official channels.\u003C\u002Fp>\n\u003Cp>Links in unexpected payment, policy-verification, or record-update messages using the name of Survival Flight or an insurer should not be opened directly. Start contact through the organization's official website and the number printed on the insurance card. LeakData does not host likely exposed patient data; it provides verified incident metadata and practical follow-up guidance.\u003C\u002Fp>","Official company notice confirming likely exposure of patient information",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fsurvivalflightinc_com.svg"]