Heart of America Medical Center 2025 Data Breach

Heart of America Medical Center Breach (2025): 2.1 Million Patient Records Including Medical Diagnoses & SSN

Healthcare provider · Hospital and clinical services · Regional medical center · USA

Heart of America Medical Center Breach (2025): 2.1 Million Patient Records Including Medical Diagnoses & SSN

Community hospital and healthcare provider in North Dakota.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
88/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
2.1MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
PHI / MedicalMedical Diagnosis
AddressPhysical address
Classification Tags
Ransomware / ExtortionHealthcareMedicalPatients2025

Breach Summary

Heart of America Medical Center, a rural community hospital in Rugby, North Dakota, suffered a data breach that compromised the personal and medical information of 2,136,993 individuals. The breach was reported in September 2025. The attack vector has not been publicly disclosed. The scale of the breach far exceeds the hospital's local patient population, suggesting the exposed data extended to historical records or regional data holdings beyond current active patients. The breach exposed a combination of names, home addresses, email addresses, phone numbers, Social Security numbers, and medical diagnosis information. This is among the most sensitive categories of personal data. Social Security numbers enable identity theft and fraudulent credit applications. Medical diagnosis records can be used to target individuals with health-related scams, manipulate insurance claims, or cause personal harm if disclosed. Affected individuals face compounding risks because both financial and medical fraud are possible from a single breach event. No major class-action settlement has been documented as of early 2026. The hospital notified affected individuals and reported the breach to relevant regulators, as required under federal health privacy law (HIPAA). Anyone who has received care at or affiliated with Heart of America Medical Center should monitor their credit reports, review their health insurance statements for unfamiliar claims, and consider placing a fraud alert or credit freeze with the major credit bureaus.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

2.1M records analyzed

About Heart of America Medical Center

Heart of America Medical Center is a community hospital and healthcare provider located in Rugby, North Dakota, serving a rural patient population in the north-central part of the state. The facility provides inpatient and outpatient services including emergency care, surgical services, and primary care for communities across a broad geographic area where access to alternative healthcare facilities is limited.

Why They Hold Your Data

Regional medical centers collect patient identity, insurance, financial, and clinical data across hospital, outpatient, and administrative systems.

Recent Developments

Heart of America Medical Center operates as an independent rural community hospital. No major organizational changes have been publicly reported beyond the 2025 breach and its aftermath.

Data Points Exposed

6 verified field types
Email Address
Full Name
Medical Diagnosis Critical
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

In September 2025 reports confirmed a data breach at Heart of America Medical Center had compromised the personal and medical information of more than 2.1 million individuals. The exposed data included names, email addresses, phone numbers, home addresses, Social Security numbers, and medical diagnoses — a scope that far exceeds the local patient population and suggests the breach extended to historical or regional data holdings beyond active patients. The hospital notified affected individuals and reported the incident to relevant regulators. No major class-action settlement has been documented as of early 2026.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation