2025 Wildwood Surgical Center — network intrusion; patient PHI notices (Jul 2026)
Data compromised
Names, DOB, SSNs, driver’s license/passport numbers, diagnostic/treatment info, medical billing (bank/debit/credit), health insurance — aggregate count unpublished
Technical writeup
Verified surgical-center disclosure — notifications mailed on or about July 13, 2026. Wildwood Surgical Center (Ohio) identified suspicious activity June 26, 2025; forensics determined unauthorized third-party network access from June 24–26, 2025, involving removal of patient data. After more than a year of data review, notice letters told patients that names, dates of birth, Social Security numbers, driver’s license and passport numbers, diagnostic and treatment information, medical billing information (including bank or debit/credit card numbers), and health insurance information may have been exposed or stolen. The incident was not yet on the HHS OCR portal in the HIPAA Journal coverage reviewed, and no public headcount was disclosed. recordsAffected 0 pending OCR/state AG count.
Root cause
Unauthorized network access June 24–26, 2025; patient data removed from network