All Breaches
May 28, 2025 Verified Sensitive Record Healthcare

Waveny LifeCare Network 2025 Data Breach

The Waveny LifeCare Network 2025 data breach occurred when an unauthorized party accessed certain data during a disruption to the network systems of the Connecticut nonprofit healthcare and senior-care organization around May 28, 2025. Waveny confirmed the event in an official security notice on its own website, notified law enforcement, and engaged outside cybersecurity specialists.

The U.S. Department of Health and Human Services OCR breach portal reports 27,113 affected people. Publicly identified fields extend across identity, contact, medical-record, laboratory and imaging results, health-insurance, payment, and financial-account information. No person rows were imported into LeakData; importedRecordCount is zero, and only verified incident metadata is published.

How Was the Waveny LifeCare Network Breach Confirmed?

The primary source is Waveny's “Notification of Data Security Event” on its own domain. In that document, the organization directly describes the network disruption around May 28, the finding that an unauthorized party accessed certain data, the categories under review, its assistance line, and security enhancements made after the incident.

The HHS OCR public portal provides the healthcare-breach entry for Waveny LifeCare Network with 27,113 affected individuals. A Massachusetts consumer-notification file supports the complimentary monitoring assistance, while Claim Depot connects the official organization and state sources and summarizes the timeline and scope. The sources align on the entity, incident date, data types, and affected-person total.

What Happened on May 28, 2025?

Waveny experienced a disruption to its network systems on or around May 28. The organization immediately took internal response measures, notified law enforcement, and engaged leading cybersecurity specialists to examine the nature of the event. Its official notice says the investigation determined that an unauthorized party accessed certain data during the incident.

A secondary source associates the event with ransomware activity and a responsibility claim by a group called Qilin. Waveny's primary notice does not name an actor, identify the initial entry method or malware, or confirm that data was actually published on the dark web. LeakData records the verified unauthorized access without presenting the group's claim as a conclusive technical attribution.

What Identity and Contact Information Was Involved?

Information that may have been affected includes first and last names with addresses, dates of birth, telephone numbers, email addresses, Social security numbers, and driver's-license numbers. Facial photographic images may also have been present. Because the elements differed by person, the list is a union of possible fields rather than a complete profile held for every individual.

A combination of name, birth date, and SSN creates substantial risk of new-account fraud and tax-identity misuse. Email, telephone, and address data may enable convincing phishing attempts that impersonate Waveny or another healthcare organization. A facial photograph is not necessarily a biometric template, and the official text does not separately confirm that facial-recognition templates were involved.

What Medical and Insurance Data Was In Scope?

The official notice lists admission dates, discharge dates, date of death, medical-record numbers, patient-account numbers, laboratory-test results, medical-imaging results, and electronic health records. Health-insurance account or policy numbers and Medicare or medicaid information were also within the possible scope. These data directly connect a person to a treatment history.

Medical and insurance identifiers can be abused for fraudulent services, medical-identity misuse, and targeted scams. Patients should review healthcare portals, billing summaries, and insurance explanation-of-benefits statements for unexplained services, unfamiliar providers, or unknown claims. Unexpected changes to clinical records should be reported directly to the relevant provider.

What Financial Data and How Many People Were Affected?

The possible fields also include payment information and financial-account numbers. The official text does not explain whether payment information means a card number, transaction record, or another financial field, and it does not publish a bank name or account-access code. LeakData therefore retains the broad financial categories and does not add undisclosed subfields.

The HHS OCR entry reports 27,113 affected people, the figure used for pwnCount and totalRecords. Claim Depot gives state examples of 174 Massachusetts, 19 Maine, and nine Vermont residents. Those subsets are not added on top of the nationwide total. Because LeakData did not import any individual patient records, importedRecordCount remains zero.

How Did Waveny Respond and How Can People Protect Themselves?

Waveny initiated internal response measures, notified law enforcement, investigated with cybersecurity specialists, and took additional steps to enhance system security. State notification materials offered eligible recipients 24 months of credit monitoring and identity protection through Cyberscout. A dedicated line at 833-353-3395 was established from 9:00 a.m. to 9:00 p.m. Eastern on weekdays.

Recipients should regularly review credit reports, financial accounts, healthcare bills, and insurance explanation-of-benefits statements. When an SSN or financial information was involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate. Passwords, SSNs, insurance numbers, or verification codes should not be shared in unexpected messages claiming to represent Waveny. LeakData does not host leaked files or provide person data.

27.1 Thousand
Affected Accounts
21
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

21
Personal information
Protected health information
Names
Physical addresses
Dates of birth
Telephone numbers
Email addresses
Social security numbers
Driver's license numbers
Facial photographic images
Admission and discharge dates
Dates of death
Medical record numbers
Patient account numbers
Laboratory test results
Medical imaging results
Electronic health records
Health insurance account or policy numbers
Medicare or medicaid information
Payment information
Financial account numbers

Additional Information

Added DateJuly 27, 2026
Breach DateMay 28, 2025
Domainwaveny.org
SourceOfficial Waveny LifeCare Network notice and HHS OCR filing confirming unauthorized access affecting 27,113 people
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information