Major hospital cyberattack sees 6m Social Security numbers and medical data stolen… see if you're affected

A major data breach has compromised the personal information of 5.5 million patients 

Yale New Haven Health (YNHHS), which runs five hospitals in Connecticut, disclosed that hackers managed to access sensitive data such as names, Social Security numbers, patient type, and medical record numbers.

The breach occurred on March 8, when YNHHS first detected unusual activity within its IT systems. 

However, it was not until April 11 that the organization confirmed patient data had indeed been stolen. 

YNHHS clarified that electronic medical records and treatment details were not compromised, and no financial account or payment information was included in the security breach.

The healthcare provider initiated the process of sending letters to affected patients on April 14, assuring them that there is no indication of any patient data being misused for identity theft or fraudulent activities.

The US Department of Health and Human Services breach portal confirmed that the data breach impacted 5,556,702 patients. 

That makes it the largest healthcare breach reported to federal regulators so far in 2025.

Yale New Haven Health (YNHHS), which operates five hospitals in Connecticut , reported hackers accessed sensitive information like name, Social Security number, patient type and medical record number

Yale New Haven Health (YNHHS), which operates five hospitals in Connecticut , reported hackers accessed sensitive information like name, Social Security number, patient type and medical record number 

YNHHS publicly reported the suspicious activity on March 11, noting that it did not impact patient care, and opened an investigation.

‘Our investigation has now determined that an unauthorized third-party gained access to our network and, on March 8, 2025, obtained copies of certain data,’ the healthcare system shared on April 11.

‘The information involved varies by patient, but may include demographic information (such as name, date of birth, address, telephone number, email address, race or ethnicity), Social Security number, patient type, and/or medical record number.’

While YNHHS said payment information was not access, it has urged patients to ‘review statements they receive from their healthcare providers and immediately report any inaccuracies to the provider.’

‘We have begun the process of mailing letters to patients whose information was involved in this incident and providing appropriate resources, including offering complimentary credit monitoring and identity protection services to individuals whose Social Security number was involved,’ YNHHS said.

While this is the largest healthcare system breach this year, an attack on UnitedHealth Group last year was the biggest in history.

Change Healthcare, owned by UnitedHealth Group, fell victim to a cyberattack in February, but revealed in October that 100 million people had been impacted.

That surpassed the previous record holder for worst breach of US patient data: a 2015 episode at Anthem Inc. that compromised 78.8 million individuals.

Another healthcare attack was reported this past February, which saw more than one million Americans’ medical records stolen.

Community Health Center (CHC), based in Connecticut, reported it ‘found that a skilled criminal hacker got into our system and took some data, which might include your personal information.’

The data may have included the patient’s name, date of birth, address, phone number, email, diagnoses, treatment details, test results, Social Security number, and health insurance information.

The breach, which occurred on October 14, 2024, impacted current and former patients, ‘and all individuals who received a COVID test or vaccine at a CHC clinic.’

CHC determined the hacker infiltrated ‘its inadequately secured computer environment,’ gaining access to its data files.

The company said it ‘added special software to watch for suspicious activity.’

The law firm investigating claims on behalf of patients said: ‘These individuals’ personal and highly sensitive information may be in the hands of cybercriminals who can place the information for sale on the dark web or use the information to perpetrate identity theft.’

Murphy Law Firm is currently investigating the breach to determine if a class action lawsuit can be filed against CHC.

You May Also Like
The subtle clues that suggest Prince Harry is the 'spare' in his marriage with Meghan Markle

Indicators that Prince Harry may be considered the ‘spare’ in his relationship with Meghan Markle

According to a body language expert, Meghan Markle was in the spotlight…
Gavin Newsom performs political U-turn after shameful plan for migrant's release was revealed

“Gavin Newsom reverses course after controversial migrant release plan exposed”

California Governor Gavin Newsom has made a surprising decision to cooperate with…
Scammers using new enhanced phishing emails with malicious links to hack victims, security experts tell ABC7 I-Team

Security experts inform ABC7 I-Team about scammers employing improved phishing emails with harmful links to compromise targets.

Scammers are becoming more sophisticated in their approach by sending out increasingly…
Dominican Republic nightclub roof collapse: Owner of Jet Set speaks for first time since tragedy that killed 232 people

Owner of Jet Set in Dominican Republic addresses the public for the first time following a tragic roof collapse that claimed the lives of 232 individuals

SAN JUAN, Puerto Rico — The owner of a popular nightclub in…
Time100 Gala 2025 red carpet: See all the celebrity looks

View the celebrity fashion at the 2025 Time100 Gala red carpet

The 2025 TIME100 gala celebrates 100 people who are shaping the future…
Pope Francis' doctor says pontiff died 'without suffering, at home'

Pope Francis’ physician confirms pontiff passed away ‘peacefully, at home’

ROME — The doctor of Pope Francis shared details of the pontiff’s…
Austin mortuary employee arrested for allegedly ‘experimenting’ on corpses

An Austin funeral home worker arrested for reportedly conducting unauthorized procedures on deceased bodies

A North Austin mortuary employee is facing felony charges after allegedly experimenting…
Illinois US Sen. Dick Durbin to speak amid announcement to not run for reelection; Lt. Gov. Juliana Stratton announces senate run

Senator Dick Durbin of Illinois to speak following decision not to seek reelection; Lieutenant Governor Juliana Stratton declares candidacy for Senate

Longtime Democratic Senator Dick Durbin of Illinois is expected to speak for…
Miley Cyrus wears 8 understated and chic looks in half as many days

Miley Cyrus flaunts 8 simple and stylish outfits in just a few days

Miley Cyrus has been making a splash in New York City this…
Super-woke Ben & Jerry's gets a nasty threat that will end its left-wing activism

Ben & Jerry’s, known for its progressive values, receives a serious threat that could halt its social justice efforts

The bitter feud between Ben & Jerry’s and parent company Unilever has…
'Sleazebag' reporter who exposed Signal scandal gets Trump White House invite for 'curious' reason

Reporter Involved in Signal Scandal Receives Invitation to Trump White House for Unexpected Cause

Atlantic editor Jeffrey Goldberg is set to get a top White House…
Love of Subarus is what makes this man's car collection so unique

“The Unique Car Collection of a Subaru Enthusiast”

NEW YORK — The New York International Auto Show is packed with…