Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. 3.1 Million Impacted by QualDerm Partners Data Breach
3.1 Million Impacted by QualDerm Partners Data Breach
NEWS

3.1 Million Impacted by QualDerm Partners Data Breach

QualDerm Partners, a national dermatology network operating 158 practices across 17 states, disclosed a December 2025 data breach that exposed the medical...

Dylan H.

News Desk

March 24, 2026
3 min read

QualDerm Partners, LLC, a Tennessee-based dermatology management company that provides operational, IT, and insurance support to 158 dermatology and skin care practices across 17 states, has disclosed a data breach that exposed the personal and medical information of approximately 3,117,874 individuals. The breach occurred in late December 2025 and notification letters began reaching affected patients in February 2026.

What Happened

On December 24, 2025, QualDerm Partners detected unauthorized activity on certain systems within its network. A third-party cybersecurity firm was engaged to investigate, and the forensic analysis determined that between December 23 and December 24, 2025, an unauthorized actor gained access to a limited number of systems and exfiltrated data.

The Oregon Attorney General was among the state regulators notified of the breach, which affected a total of 3,117,874 individuals nationwide, including at least 174,837 Texas residents. Notification letters were mailed to affected individuals beginning on February 22, 2026 — approximately two months after the breach occurred.

What Data Was Compromised

The type of data exposed varies by individual. QualDerm confirmed the breach may have included:

  • Full names and dates of birth/death
  • Email addresses
  • Doctor names and medical record numbers
  • Diagnoses and treatment information
  • Health insurance information
  • For a small subset of individuals: government-issued identification (e.g., driver's license numbers)

The inclusion of detailed medical information — diagnoses, treatments, and health insurance data — creates a significantly elevated risk beyond typical data breaches. This combination of PHI (protected health information) and personal identifiers enables highly targeted attacks including medical identity theft, fraudulent insurance claims, and sophisticated phishing scams impersonating healthcare providers.

Notification Timeline Concerns

Multiple law firms investigating the breach have noted that although the unauthorized access occurred in December 2025, affected individuals were not notified until approximately two months later, in February 2026. Under HIPAA's Breach Notification Rule, covered entities and business associates are generally required to notify affected individuals within 60 days of discovering a breach. Whether QualDerm met this deadline is a subject of ongoing legal scrutiny.

Company Response

QualDerm Partners stated it is reviewing its data security policies, procedures, and protocols in response to the incident. The company said no misuse of patient data has been identified to date, and has offered complimentary credit monitoring and identity theft protection services to all affected individuals.

Legal Actions

Several law firms have launched investigations into the breach and are exploring potential class action lawsuits on behalf of affected patients. The exposure of medical records and health insurance information from a large, multi-state healthcare network raises significant HIPAA compliance questions and creates a long-term risk window for affected individuals.

Context: Healthcare Sector Under Siege

The QualDerm breach is one of several multi-million-record healthcare incidents confirmed in early 2026. TriZetto Provider Solutions, a healthcare IT business associate, disclosed a comparable breach affecting over 3.4 million individuals around the same period. Healthcare organizations remain among the most targeted sectors for data theft due to the high value of medical records on criminal marketplaces — health records command significantly more than financial records due to the rich combination of PII, PHI, and insurance data they contain.

Patients who received a notification letter from QualDerm Partners should enroll in the offered credit monitoring service, monitor their explanation of benefits (EOB) statements for unfamiliar claims, and be alert for phishing attempts that may reference their dermatology care or health insurance provider.

#Data Breach#Healthcare#HIPAA#Patient Records#Identity Theft

Related Articles

Cognizant TriZetto Breach Exposes Health Data of 3.4

TriZetto Provider Solutions, a Cognizant subsidiary serving 875,000 US healthcare providers, has confirmed a 2024 cyberattack went undetected for nearly a...

6 min read

Covenant Health Ransomware Attack Impacts 478,000 Patients

Qilin ransomware group claims responsibility for massive healthcare breach, stealing 850GB of sensitive patient data across multiple states. Initial...

3 min read

Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status

A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...

4 min read
Back to all News