All Breaches
December 15, 2025 Verified Sensitive Record Healthcare

Wee Care Pediatrics 2025 Data Breach

The Wee Care Pediatrics 2025 data breach involved the pediatric provider identifying suspicious network activity on or about December 15, 2025 and finding that an unauthorized party may have accessed or acquired certain information. Wee Care contained the incident and began a scope review with third-party specialists.

The full HHS Office for Civil Rights report CSV classifies the event as a Hacking/IT Incident involving a Network Server and gives 2,127 people and a February 14, 2026 submission date. Because the organization's data review was ongoing, 2,127 is marked as a published lower bound and retained in numeric fields so the live site does not show zero. No raw person records were imported.

How Was the Wee Care Pediatrics Breach Confirmed?

The primary source is the Notice of Data Event on Wee Care Pediatrics' own domain. It directly confirms the December 15 detection, unauthorized access or acquisition around that date, work with outside specialists, possible data fields, complimentary credit and identity protection, and dedicated assistance line at 1-833-931-5655.

The second official source is the complete 711-row CSV export from the HHS Office for Civil Rights portal. The relevant row identifies a Utah Healthcare Provider and reports 2,127 people. ClaimDepot links to the same provider notice and HHS record. The provider page's “February 13, 2025” heading predates the event and is documented as an apparent date typo.

What Happened on December 15, 2025?

Wee Care identified suspicious activity in its network on or about December 15 and immediately began a comprehensive response and investigation. Work supported by third-party specialists found that certain information maintained by the organization may have been accessed or acquired without authorization around that date. The provider began collecting and reviewing the potentially affected data.

The public notice does not disclose the initial-entry method, account or vulnerability used, actor identity, malware, or a ransom demand. Possible access or acquisition is confirmed, but the organization does not say the information was publicly released. LeakData does not add an unsupported technical cause, attacker, or leak-site attribution.

What Identity Information Was Involved?

Possible personal fields were first and last names, contact information, dates of birth, and Social security numbers. Data types may vary by person, and the list does not mean every field was present for all 2,127 people. A private notice may separately identify fields belonging to a child patient, parent, or person responsible for payment.

An SSN combined with a birth date creates a particularly long-term identity-theft concern for children because a fraudulent credit file in a child's name can remain undetected for years. Contact details can support convincing appointment, results, or billing messages. Payment cards, bank accounts, and passwords are not on the provider's published field list.

What Health and Insurance Information Was Involved?

Possible health fields were treatment or diagnosis information, prescription or medication information, dates of service, provider names, medical record numbers, and patient account numbers. Medicare or medicaid identification numbers and health insurance information were also listed. These fields are sensitive for medical identity, false claims, and targeted health fraud.

A message should not be trusted merely because it knows a real medication, physician, treatment date, or insurance context. Open the patient portal, insurance account, and explanation-of-benefits statements without using an incoming link. Independently verify an unfamiliar provider, service, prescription, or claim with Wee Care and the relevant plan.

How Many People Were Affected and How Did the Organization Respond?

The HHS-published figure is 2,127 people. Because the provider said its file review was continuing, pwnCount and totalRecords carry that published figure while affectedCountStatus “lower_bound” and affectedCountLowerBound 2127 show that scope could increase. importedRecordCount is zero and is not confused with the HHS number.

Wee Care said it contained the incident, enhanced network security, and took additional steps intended to prevent a similar event. It offered potentially affected people complimentary credit monitoring and identity protection, said it had no reason to believe information had been misused, and created a dedicated line for enrollment and questions.

What Should Affected Families Do?

A parent or guardian who receives a notice should check which fields are listed for the adult and child. If an SSN was involved, check whether a credit file exists in the child's name and consider a credit freeze. For health fields, regularly review patient records, explanation-of-benefits statements, prescriptions, and unfamiliar medical claims.

Do not share an SSN, patient number, insurance identifier, password, payment, or one-time code in an unexpected call or message using the Wee Care name. For questions or protection-service enrollment, verify the provider notice by independently opening the official page before calling 1-833-931-5655.

2.1 Thousand
Affected Accounts
12
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

12
First and last names
Contact information
Dates of birth
Social security numbers
Treatment or diagnosis information
Prescription or medication information
Dates of service
Healthcare provider names
Medical record numbers
Patient account numbers
Medicare or medicaid identification numbers
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateDecember 15, 2025
Domainweecarepediatrics.com
SourceOfficial provider notice and HHS report confirming unauthorized network access or acquisition and a published lower bound of 2,127 people
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information