2025 Bell Ambulance — ~237,830 individuals (unauthorized network access)
Data compromised
Names, DOB, SSNs, driver's licenses, financial/payment data, medical records, health insurance information
Technical writeup
Bell Ambulance, Inc. (Milwaukee-area EMS) disclosed unauthorized access to portions of its network between approximately February 7 and February 14, 2025; activity was discovered February 13, 2025. Subsequent HHS OCR filings and state notices referenced up to roughly 237,830 affected individuals. Data types described in public notices included names, dates of birth, Social Security numbers, driver's license or government ID numbers, financial and payment card information, and medical and health insurance information. The organization engaged forensics, notified regulators, and offered credit monitoring. Some reporting also referenced ransomware-group claims; treat operational details as evolving if new primary sources emerge.
Root cause
Unauthorized access to internal systems (hacking/IT incident per regulatory filing)