The United Medical Doctors 2025 data breach involved an unauthorized user accessing the healthcare organization's systems at varying times between December 12, 2025 and March 31, 2026 and potentially viewing or acquiring certain files. The organization detected suspicious network activity on or about March 31, 2026 and opened an investigation.
The HHS Office for Civil Rights public record classifies the event as a Hacking/IT Incident involving a Network Server and reports 501 people. United Medical Doctors said its file review was ongoing and specific data fields and total scope were not yet known. LeakData therefore stores 501 as a verifiable lower bound rather than an exact total; no person records were imported.
How Was the United Medical Doctors Breach Confirmed?
The primary source is United Medical Doctors' Notice of Data Privacy Event published on its own domain May 20, 2026. It directly states that suspicious activity was detected March 31, identifies the December 12–March 31 access window, says the unauthorized user accessed or may have acquired certain files, and confirms that the data review remained in progress.
The second official source is the HHS Office for Civil Rights breach portal. Its row identifies United Medical Doctors as a California Healthcare Provider, classifies the case as a Hacking/IT Incident involving a Network Server, lists 501 people, and gives a May 29, 2026 submission date. ClaimDepot is a third cross-check linking to the same two sources.
What Happened From December 12, 2025 Through March 31, 2026?
United Medical Doctors detected suspicious activity on its network on or about March 31 that was consistent with a cybersecurity event. Its investigation found that unauthorized system access occurred at varying times from December 12, 2025 through March 31, 2026. The organization said the unauthorized user accessed and may have acquired certain files in its digital environment.
The public sources do not disclose the initial-entry method, account or vulnerability used, actor identity, malware, a ransom demand, or publication of files. The phrase “access to and/or acquisition” confirms access and possible taking, but is not proof of public release. LeakData does not add an unsupported technical cause or threat-actor attribution.
What Information Was Involved?
The organization's direct answer in its May 20 notice is: “The information involved in this event is currently unknown.” Its file review was continuing to determine whether sensitive personal, financial, or medical information was present. Data classes are therefore limited to “personal information under review” and “protected health information under review.”
Names, SSNs, dates of birth, addresses, government IDs, medical data, and financial data displayed as general ClaimDepot categories are not confirmed incident fields; the page itself says the specific types remain undisclosed. Those labels are not copied into the record as exposed data. A person should not assume which information was involved before receiving an individual notice.
What Risks Follow From an Unknown Data Scope?
Because the file fields are unknown, it cannot be said that a particular person definitely faces credit, banking, identity, or medical risk. A relationship with a healthcare organization can still be used in a targeted call, fake patient portal, bill, appointment, or results message. Independently verify even a request that contains a real clinical detail.
The organization recommends reviewing credit reports and account statements for suspicious activity, but that advice does not mean an SSN or financial account was confirmed as involved. If an individual notice identifies a field, protections can be tailored to it; without such detail, refusing to share a password, full SSN, card information, or one-time code remains a core precaution.
How Many People Were Affected and How Did the Organization Respond?
The 501 people in the HHS row are the minimum notification scope verifiable in the official portal. Because the organization did not publish a total and its file review was continuing, pwnCount and totalRecords are null, affectedCountStatus is “lower_bound,” and affectedCountLowerBound is 501. importedRecordCount is zero and is not confused with the HHS figure.
United Medical Doctors said it directly notified potentially affected people and notified appropriate government regulators. It published (951) 290-5182, available weekdays from 9:00 a.m. to 4:00 p.m. Pacific, and the address 28078 Baxter Road, Suite 530, Murrieta, California. The notice also provides guidance on free credit reports, fraud alerts, and credit freezes.
What Should Current and Former Patients Do?
People associated with the organization should watch for mailed and emailed notices and check whether their letter identifies a specific data type. Review patient portals, medical bills, insurance explanation-of-benefits statements, and account statements for an unfamiliar provider, service, claim, or transaction.
If an unexpected message using the United Medical Doctors name demands urgent payment, a password, identity document, or verification code, stop the interaction. Independently open the official page, call (951) 290-5182, or write to the published address with questions. A credit-freeze decision should reflect the field disclosed in the personal notice and individual risk.