All Breaches
December 6, 2025 Verified Sensitive Record Healthcare

Woundtech 2025 Data Breach

The Woundtech 2025 data breach resulted from unauthorized activity in the Wound Technology Network environment from December 6 through December 9, 2025. The organization's official notice confirms that certain information may have been copied by an unauthorized individual during the incident. The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows a reported scope of 139,830 people.

Potentially affected data includes first and last names, birth dates, telephone numbers, gender, clinical notes, medical and treatment information, diagnosis information, health-insurance information, treatment images, and a very limited amount of Social Security numbers. The combination varies by person. LeakData imported no patient rows or medical images, and importedRecordCount is zero.

How Was the Woundtech Data Breach Confirmed?

The primary evidence is Woundtech's Notice of Data Breach, published on its own domain on March 16, 2026. The organization says it detected unusual network activity on December 6, retained a third-party cybersecurity firm, and learned from the forensic investigation on December 31 that certain information may have been copied. This is a company-confirmed event rather than an entry based only on an actor's claim.

The HHS OCR row classifies Wound Technology Network, Inc. as a Healthcare Provider and the event as a Hacking/IT Incident affecting a Network Server. Its total of 139,830 people supplies the regulatory scope not stated in the company notice. The two sources align on the event type, affected environment, and involvement of sensitive health information.

What Was the Incident and Review Timeline?

Woundtech noticed unusual network activity on or around December 6, 2025 and promptly opened an investigation. The official notice says the unauthorized activity occurred between December 6 and December 9. The breachDate field therefore uses December 6, the first day of the known window, rather than substituting the announcement date or completion of the later file review.

The forensic investigation concluded on December 31 that certain information may have been copied. Woundtech then conducted a comprehensive review to determine whose information and which data types were present; the work to identify the potential notice population finished on March 2, 2026. The public notice followed on March 16, and letters were mailed where a valid address was available.

What Information May Have Been Affected?

Identity and contact fields include first names, last names, dates of birth, telephone numbers, and gender. The clinical categories are clinical notes, medical health information, medical treatment information, medical diagnosis information, and medical treatment images. Health-insurance information is also in scope, while Social Security numbers were involved only in what the organization described as a very limited amount.

The list does not mean that every person had all of those fields. The official notice states that the information differs by individual and directs recipients to their personal letter for the exact categories. dataClasses therefore records the supported categories without assigning Social Security numbers or treatment images to all 139,830 people and without inventing subgroup counts.

How Is the 139,830-Person Scope Used?

The pwnCount and totalRecords fields use the current HHS OCR total of 139,830 people. It is the affected-person count reported by Woundtech to the federal regulator, not the number of files, images, or distinct data fields that may have been copied. Separate categories are not added together to produce a new victim total.

A threat actor posted a larger claim involving more than 160,000 patients and multiple terabytes of data. The company notice does not validate that actor-supplied count, and the HHS record provides a different regulatory total. LeakData uses the official 139,830 value and does not transfer the actor's volume or person claims into pwnCount, totalRecords, or dataClasses.

Why Are Health and Treatment Records Sensitive?

Woundtech provides chronic-wound management and advanced wound-care services. Clinical notes, diagnoses, treatment information, and treatment images can reveal private context about a person's condition and course of care, not merely identity details. When combined with health-insurance information, the data may increase the risk of false claims, provider impersonation, or targeted fraud.

Files containing Social Security numbers, even for a very limited subset, can create longer-term identity-theft risk. The public notice does not disclose which fields applied to which people in aggregate. This entry reflects the sensitivity without claiming that clinical contents were publicly released or that actual misuse has been established.

What Should Affected People Do?

Woundtech mailed notice letters to people identified in the affected files for whom a valid mailing address was available. It recommended monitoring account statements, health-insurance explanations of benefits, and free credit reports for suspicious activity. Recipients should rely on the individual data scope and official assistance line shown in their notice letter.

An unfamiliar medical service, insurance claim, or payment should be checked with the provider and insurer through a known official channel. Unexpected links, image requests, or identity-verification messages presented in Woundtech's name deserve scrutiny because incident context can support phishing. LeakData does not host copied patient data; it documents only verified incident metadata, sources, and practical follow-up steps.

139.8 Thousand
Affected Accounts
12
Data Types
High
Severity
Yes
Verification

Exposed Data Types

12
First names
Last names
Dates of birth
Telephone numbers
Gender
Clinical notes
Medical health information
Medical treatment information
Medical diagnosis information
Health insurance information
Medical treatment images
Social security numbers (very limited subset)

Additional Information

Added DateJuly 27, 2026
Breach DateDecember 6, 2025
Domainwoundtech.net
SourceCompany-confirmed network incident; certain information may have been copied
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information