CRITICAL SEVERITYMedical

Heart of America Medical Center Data Breach

Heart of America Medical Center Breach (2025): 2.1 Million Patient Records Including Medical Diagnoses & SSN

Community hospital and healthcare provider in North Dakota.

Verified by ObscureIQ Intelligence

10.0Severity
2.1MRecords
6Fields
2025Year

ObscureIQ Breach Intelligence Scores
0.0
Breach Risk Index
63
Data Value
40
Market Recency
214
days
Since Breach

Risk Interpretation

Severe risk of medical fraud, identity theft, and targeted health-related scams. Hospital data can also expose sensitive diagnoses or treatment relationships.

🎯 Impact & Downstream Threats

In September 2025 reports confirmed a data breach at Heart of America Medical Center had compromised the personal and medical information of more than 2.1 million individuals. The exposed data included names, email addresses, phone numbers, home addresses, Social Security numbers, and medical diagnoses — a scope that far exceeds the local patient population and suggests the breach extended to historical or regional data holdings beyond active patients. The hospital notified affected individuals

Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure
  • Medical identity fraud or insurance abuse using health data

🔓 Threat Vectors

Phishing, credential stuffing & account takeover
Name-based social engineering
Medical extortion, insurance fraud & discrimination
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification
Home targeting, stalking & physical threat
Full identity theft & synthetic identity fraud

📋 Breach Intelligence

EntityHeart of America Medical Center
OrganizationHealthcare Provider • USA
Breach Date2025-07-17
DBC Added2025-09-25
Added Date2025-09-25
Records~2.1M (2,136,993 records)
Attack VectorUnknown
Data SubjectsPatient
Breach PathwayDirect
SourceDataBreach.com / ObscureIQ
SensitivityRestricted
Breach ID625.0
StatusConfirmed

📝 Executive Summary

Heart of America Medical Center, a rural community hospital in Rugby, North Dakota, suffered a data breach that compromised the personal and medical information of 2,136,993 individuals. The breach was reported in September 2025. The attack vector has not been publicly disclosed. The scale of the breach far exceeds the hospital's local patient population, suggesting the exposed data extended to historical records or regional data holdings beyond current active patients. The breach exposed a combination of names, home addresses, email addresses, phone numbers, Social Security numbers, and medical diagnosis information. This is among the most sensitive categories of personal data. Social Security numbers enable identity theft and fraudulent credit applications. Medical diagnosis records can be used to target individuals with health-related scams, manipulate insurance claims, or cause personal harm if disclosed. Affected individuals face compounding risks because both financial and medical fraud are possible from a single breach event. No major class-action settlement has been documented as of early 2026. The hospital notified affected individuals and reported the breach to relevant regulators, as required under federal health privacy law (HIPAA). Anyone who has received care at or affiliated with Heart of America Medical Center should monitor their credit reports, review their health insurance statements for unfamiliar claims, and consider placing a fraud alert or credit freeze with the major credit bureaus.

🏢 About Heart of America Medical Center

Heart of America Medical Center is a community hospital and healthcare provider located in Rugby, North Dakota, serving a rural patient population in the north-central part of the state. The facility provides inpatient and outpatient services including emergency care, surgical services, and primary care for communities across a broad geographic area where access to alternative healthcare facilities is limited.

Healthcare provider | Hospital and clinical services | Regional medical center | USA
Healthcare ProviderUSAhamc.com

🗂 Why They Hold Your Data

Regional medical centers collect patient identity, insurance, financial, and clinical data across hospital, outpatient, and administrative systems.

📰 Recent Developments

Heart of America Medical Center operates as an independent rural community hospital. No major organizational changes have been publicly reported beyond the 2025 breach and its aftermath.

🔍 Data Points Exposed

6 verified field types:
Social Security Number
Email
Phone Number
Name
Home Address
Medical Diagnosis

Exposure Categories

CredentialsSSN
LocationPHYS ADDR
MedicalDIAGNOSIS

Canonical Fields

email_address, full_name, medical_diagnosis, phone_number, physical_address:home, ssn

🌐 Dark Web Verification

Confirmed

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Heart of America Medical Center
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MedicalEmailPhoneAddress

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom