Kettering Health 2025 Data Breach

Kettering Health Faith-Based Hospital System Breach (2025): 1.7M Patient & Employee Records Including Medical, SSN & Financial Data Exposed

Healthcare provider · Hospital and clinical care services · Integrated health system · USA

Kettering Health Faith-Based Hospital System Breach (2025): 1.7M Patient & Employee Records Including Medical, SSN & Financial Data Exposed

Faith-based healthcare system operating hospitals and outpatient facilities.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
82/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
1.7MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
Gov IDGovernment ID
PHI / MedicalMedical Diagnosis; Medical Record Number; Medication
AddressPhysical address
Classification Tags
InterlockRansomware / ExtortionHealthcareMedical2025

Breach Summary

Interlock gained access to Kettering Health on April 9, 2025 and, after 41 days, deployed ransomware on May 20, 2025, triggering a system-wide outage that forced paper charting and some ambulance diversions. Interlock claimed exfiltration of about 941 GB (roughly 732,000 files) and published stolen data after Kettering declined to pay. Leaked samples reviewed by researchers included patient names, medical record numbers, clinical summaries, medication lists, mental-health notes, insurance and pharmacy documents, and scans of identity documents and payroll files for employees; reported PII also includes DOB, SSN, and payment-card/banking data. Kettering confirmed 1,695,382 individuals affected on the HHS OCR portal and began notifications in early 2026, noting a file-by-file review and that only a subset of patients had the most sensitive data exposed.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.7M records analyzed

About Kettering Health

Kettering Health is a not-for-profit, faith-based (Adventist) integrated health system in western Ohio, operating roughly 14 hospitals and more than 120 outpatient sites. It provides emergency, surgical, imaging, pharmacy, and outpatient care using the Epic electronic health record, maintaining extensive patient clinical, insurance, and billing records as well as employee HR and payroll data.

Why They Hold Your Data

Integrated health systems collect patient identity, contact, insurance, billing, appointment, and clinical records across hospitals, specialty care, and administrative operations.

Recent Developments

A May 20, 2025 ransomware attack caused a system-wide outage; Kettering restored core Epic functions by early June and declared normal operations on June 13, 2025. It initially reported a placeholder of 501 affected individuals to HHS in July 2025, then confirmed the total at 1,695,382 and began mailing patient notifications in early 2026. A class-action lawsuit was filed in Montgomery County in June 2025.

Data Points Exposed

14 verified field types
Clinical Notes
Date of Birth High
Email Address
Financial Account
Full Name
Government ID Critical
Health Insurance
Medical Diagnosis Critical
Medical Record Number High
Medication High
Mental Health Notes Critical
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

The breach compromised a broad set of clinical, identity, and financial data (medical records, mental-health notes, medication lists, Social Security numbers, insurance, and payment/banking data) for roughly 1.7 million patients, plus HR/payroll and ID-document data for employees. The scale and sensitivity create severe medical-fraud, identity-theft, financial-fraud, and extortion risk, compounded operational disruption to patient care, and generated significant litigation and reputational exposure.

Exploitation & Downstream Threats

• Medical identity fraud and insurance abuse using clinical, medication, and insurance data | • Identity theft and synthetic identity construction using SSN, DOB, and ID documents | • Financial fraud using exposed payment-card/banking data | • Extortion using mental-health notes and sensitive diagnoses | • Employee-directed HR/payroll fraud and social engineering | • Targeted phishing/vishing and fraudulent medical-bill scams | • Doxxing and physical targeting from exposed home addresses

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
I
Threat Actor: InterlockConfidence: High
Ransomware group

Motivation: Financial extortion
A ransomware and data-extortion operation active since around September 2024, impacting businesses and critical infrastructure across North America and Europe via a double-extortion model (encrypt plus steal).

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation