[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkkpoA58HGWZueH1eHtwKKrzh-Z-6dnmpsdctOJDqdJs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":34,"source":35,"isVerified":4,"isSpamList":36,"isSensitive":4,"severity":37,"processingStatus":38,"logoUrl":39,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66e82ca4de5db7908e1de1","VITASHospiceServices2025","VITAS Hospice Services 2025 Data Breach","vitas-hospice-services-2025","vitas.com",{"name":12,"sector":13,"country":14,"website":10},"VITAS Hospice Services, LLC","Healthcare","United States","2025-09-21T00:00:00.000Z","2026-07-27T05:10:04.893Z",319177,[19,20,21,22,23,24,25,26,27,28,29,30,31,32,33],"Personal information","Protected health information","Names","Addresses","Phone numbers","Dates of birth","Social Security numbers","Driver's license numbers","Next-of-kin contact information","Diagnosis information","Medications","Laboratory results","Medical conditions","Treatment information","Health insurance information","\u003Cp>\u003Cstrong>The VITAS Hospice Services 2025 data breach\u003C\u002Fstrong> was a cybersecurity incident in which an unauthorized party used a compromised vendor account to access the hospice provider's systems between September 21 and October 27, 2025. VITAS's individual notice confirms that the actor viewed and downloaded personal information belonging to current and former patients.\u003C\u002Fp>\n\u003Cp>The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists the organization as a Healthcare Provider and classifies the event as a Hacking\u002FIT Incident involving a Network Server; 319,177 people were affected. LeakData imported no patient rows, importedRecordCount is zero, and this entry contains verified incident metadata only.\u003C\u002Fp>\n\u003Ch2>How Was the VITAS Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the fourteen-page Notice of Data Breach sent by VITAS Hospice Services to affected people. It directly explains the discovery date, compromised vendor account, access window, download of data, investigation, security improvements, and twenty-four months of protective services.\u003C\u002Fp>\n\u003Cp>The second source is the HHS OCR breach portal, which confirms the federal total of 319,177 people and the incident classifications. The third is SecurityWeek's December 9, 2025 report, which independently describes the scope, access method, and download of patient data based on the VITAS notice and federal record. HIPAA Journal corroborates the same timeline and data categories.\u003C\u002Fp>\n\u003Ch2>What Happened Between September 21 and October 27, 2025?\u003C\u002Fh2>\n\u003Cp>The unauthorized party compromised an account belonging to a VITAS vendor and used it to enter certain VITAS systems. The organization discovered the event on October 24, while the forensic review identified unauthorized access from approximately September 21 through October 27. During that activity, information about some current and former patients was viewed and downloaded.\u003C\u002Fp>\n\u003Cp>After discovery, VITAS acted to secure its systems, opened an internal investigation, and engaged outside experts. The approximate end of access three days after discovery reflects the completed forensic timeline. The breachDate field uses September 21, the confirmed start of access, rather than the detection or notification date.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The fields varied by person and may include names, addresses, phone numbers, dates of birth, Social Security numbers, driver's-license numbers, next-of-kin contact details, diagnoses, medications, laboratory results, conditions, treatment information, health-insurance information, and other personal information. This combination is highly sensitive for identity and medical fraud.\u003C\u002Fp>\n\u003Cp>VITAS did not say that every field appeared for all 319,177 people. This entry therefore creates no subgroup counts and does not add undisclosed passwords, usernames, payment cards, or bank accounts. Download of data is confirmed by the company letter, but the sources do not establish public release, sale, or transfer to a named ransomware group.\u003C\u002Fp>\n\u003Ch2>What Does the 319,177-Person Scope Mean?\u003C\u002Fh2>\n\u003Cp>The pwnCount and totalRecords fields use the 319,177 affected-person count in the current HHS OCR public row. SecurityWeek and other healthcare-security publications report the same federal total. The value counts people in the notification population, not files, hospice visits, prescriptions, laboratory results, or individual data elements.\u003C\u002Fp>\n\u003Cp>VITAS Hospice Services operates within the nationwide VITAS Healthcare hospice and palliative-care network. The incident involved information belonging to current and former patients, but the separate size of those groups and the number affected by each field were not disclosed, so this entry does not create divided totals.\u003C\u002Fp>\n\u003Ch2>What Measures Did VITAS Take?\u003C\u002Fh2>\n\u003Cp>VITAS said it secured its systems, opened an internal investigation, worked with a leading cybersecurity firm, and notified law enforcement. The organization also reviewed and strengthened vendor oversight and data-protection protocols to reduce the risk of a similar incident.\u003C\u002Fp>\n\u003Cp>VITAS was unaware of misuse of personal information when the letter was issued. Even so, affected people received twenty-four months of complimentary credit monitoring, identity protection, and medical monitoring through Epiq. The package includes identity restoration, credit-freeze assistance, and alerts for certain indicators of medical identity exposure.\u003C\u002Fp>\n\u003Ch2>What Should Affected Patients Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should activate the Epiq service within the letter's enrollment period and regularly review credit reports, address changes, health-insurance explanation-of-benefits statements, and medical-service histories for unfamiliar accounts or activity. A suspicious entry should be reported through an official channel for the relevant organization.\u003C\u002Fp>\n\u003Cp>The VITAS letter specifically says the organization will not send electronic communications about the event and asks recipients not to share personal information electronically. Unexpected links claiming to be from VITAS, Epiq, an insurer, or provider should not be opened; contact should begin through a verified number. LeakData does not host, distribute, or provide search access to downloaded patient information.\u003C\u002Fp>","Official VITAS notice confirming vendor-account compromise and download of patient information",false,"High","completed","\u002Fuploads\u002Flogo\u002Fvitas_com.png"]