All Breaches
December 5, 2025 Verified Sensitive Record Healthcare Technology

ZenPatient 2025 Data Breach

The ZenPatient 2025 data breach involved unauthorized access to or copying of data in the digital-health and telehealth software company's network from approximately December 5, 2025, through February 12, 2026. ZenPatient identified suspicious activity around February 27, 2026, and began an investigation with third-party cybersecurity and data-privacy specialists.

A data review was completed around July 1, 2026, and affected fields were determined to include names, addresses, dates of birth, and medical information. A Texas regulatory record reports 1,179 residents, while the consumer letter identifies about 52 Rhode Island residents. These are state subsets and no deduplicated nationwide total is known. LeakData keeps pwnCount and totalRecords at zero, and importedRecordCount is zero.

How Was the ZenPatient Breach Confirmed?

The primary evidence is ZenPatient's consumer notice dated July 17, 2026, published through the California Attorney General record. On the company's behalf, the letter directly states discovery of suspicious activity, the unauthorized access or copying period, comprehensive data review, notification process, federal law-enforcement notice, and identity-protection services offered.

A Texas regulatory disclosure supports the 1,179-resident subset and incident data classes. Claim Depot connects the California and Texas records and independently summarizes the dates and scope involving names, addresses, birth dates, and medical information. The sources align on the organization, access period, July 1 review result, and July 17 notification start.

What Happened From December 5, 2025, Through February 12, 2026?

ZenPatient observed suspicious activity in its network around February 27. An investigation with outside cybersecurity and data-privacy specialists determined that one or more unauthorized actors accessed or copied certain ZenPatient data from December 5 through February 12. The official letter uses both alternatives and does not say all data was definitively copied.

The public material does not disclose the initial entry method, actor identity, malware, ransom demand, or why access ended before discovery. LeakData preserves the source's confidence level by saying the data was “accessed or copied.” It does not minimize the event as a mere system alert, but it also does not add an unverified claim of wholesale exfiltration or public release.

What Identity Information Was Affected?

The incident summary based on regulatory records lists names, addresses, and dates of birth among affected personal fields. The official sample letter displays the recipient's name as a fixed element and other fields in a person-specific variable section. The same data combination therefore should not be assumed for every individual.

Names, addresses, and birth dates may enable targeted phishing, fraudulent account verification, and social engineering. Social Security numbers, driver's licenses, and other documents mentioned in the protection appendix are general examples that may be required for a credit freeze, not confirmed incident fields. LeakData does not add an SSN, driver's license, passport, email, phone number, or password as verified data.

What Was the Scope of Medical Information?

Medical information was confirmed within the possible scope of the incident involving a digital-health and telehealth provider. Medical data may link a person to a healthcare relationship and creates risks of medical-identity misuse, targeted scams, or sensitive inferences. Public sources do not say every person's file contained medical information.

The source does not separately identify a diagnosis, treatment, prescription, laboratory result, telehealth encounter, medical-record number, health-insurance information, physician name, or service date. LeakData retains the medical-information category at the specificity published by sources and does not invent examples. Recipients should review health portals and provider statements for unfamiliar services or changes.

How Many People Were Affected and Was the Data Misused?

The Texas record reports 1,179 residents, while the state appendix to the consumer letter identifies approximately 52 Rhode Island residents. These are distinct state subsets, not a deduplicated nationwide person count. LeakData does not add them together and present a national total; pwnCount and totalRecords are zero, and importedRecordCount is zero because no person data was imported.

ZenPatient said that, as of the letter date, it had no evidence of actual or attempted misuse of anyone's information resulting from the event. That time-bound finding does not guarantee that future misuse will not occur. Given possible copying and medical-data scope, recipients should continue monitoring unusual activity in financial, credit, and healthcare accounts.

How Did ZenPatient Respond and How Can People Protect Themselves?

The company secured its environment, conducted a comprehensive investigation and data review with outside specialists, notified federal law enforcement and relevant regulators, reviewed existing policies, and implemented additional cybersecurity measures. Eligible people were offered 12 months of complimentary Experian IdentityWorks credit monitoring and identity-theft protection, with enrollment due by October 31, 2026.

Recipients should enroll only with the code in their letter and review credit reports and healthcare-account activity for unfamiliar transactions, inquiries, or services. A help line at 833-931-4343 is available from 8:00 a.m. to 8:00 p.m. Central on weekdays. Health information, passwords, or verification codes should not be shared in unexpected messages claiming to represent ZenPatient. LeakData does not host incident files or person records.

0
Affected Accounts
6
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

6
Personal information
Protected health information
Names
Physical addresses
Dates of birth
Medical information

Additional Information

Added DateJuly 27, 2026
Breach DateDecember 5, 2025
Domainzenpatient.com
SourceOfficial ZenPatient regulatory notice confirming unauthorized access to or copying of data containing personal and medical information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information