Medstar Health 2025 Data Breach

MedStar Health System Ransomware Breach (2025): 4.6 Million Patient Records Including Medical Diagnoses & SSN Exposed

Healthcare provider · Hospital and healthcare services · Integrated health system · USA

MedStar Health System Ransomware Breach (2025): 4.6 Million Patient Records Including Medical Diagnoses & SSN Exposed

Nonprofit healthcare system operating hospitals and clinics in the Mid-Atlantic.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
88/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
4.6MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
PHI / MedicalMedical Diagnosis
AddressPhysical address
Classification Tags
RhysidaRansomware / ExtortionHealthcareMedicalPatients2025

Breach Summary

Rhysida, a ransomware group known for targeting healthcare organizations, breached MedStar Health's systems between September 12 and September 16, 2025, exfiltrating 3.7 terabytes of data. MedStar, a nonprofit health system serving patients across Maryland, Virginia, and Washington D.C., discovered the intrusion on October 4. Rhysida listed the stolen data for sale on its dark web site at 25 bitcoin and, when MedStar did not pay, published the files publicly. The breach is estimated to affect 4.6 million patients. The exposed data includes names, home addresses, phone numbers, email addresses, Social Security numbers, and medical diagnoses, along with potentially medications, test results, medical images, insurance information, and treatment records. The combination of Social Security numbers and medical diagnoses creates layered risk. Affected individuals face potential identity theft, fraudulent tax filings, medical identity fraud in which someone uses another person's insurance or benefits, and targeted scams that exploit knowledge of a person's health condition or care history. MedStar began notifying affected patients by mail on December 3, 2025, and is offering complimentary credit monitoring and identity theft protection. The organization engaged third-party cybersecurity experts and notified the FBI. A consolidated federal class-action lawsuit was filed in December 2025, alleging negligence and seeking financial damages and court-ordered security improvements. Individuals who received a breach notice should enroll in the offered monitoring services promptly and remain alert to unsolicited contact referencing their medical care, insurance, or personal finances.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

4.6M records analyzed

About Medstar Health

MedStar Health is a nonprofit health system operating 10 hospitals and more than 300 care sites across Maryland, Virginia, and Washington D.C. Its network includes MedStar Georgetown University Hospital, MedStar Washington Hospital Center, and several other major facilities across the Baltimore-Washington metropolitan corridor. MedStar is one of the largest healthcare employers in the Mid-Atlantic region.

Why They Hold Your Data

Integrated health systems collect patient identity, contact, insurance, billing, appointment, and clinical records across hospitals, clinics, and administrative operations.

Recent Developments

MedStar has been managing sequential cybersecurity incidents. A prior breach involving compromised employee email accounts led to a $1.35 million class-action settlement finalized in 2024. The 2025 Rhysida ransomware attack occurred against that backdrop. This is also not MedStar's first ransomware encounter — a March 2016 attack forced the system to shut down multiple systems for approximately a week. The pattern of repeated incidents has sustained regulatory and litigation attention on the organization's security posture.

Data Points Exposed

6 verified field types
Email Address
Full Name
Medical Diagnosis Critical
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

Rhysida ransomware attackers gained unauthorized access to MedStar systems between September 12 and September 16, 2025, exfiltrating 3.7 terabytes of data claimed to include over 7 million pieces of patient information. MedStar discovered the intrusion on October 4 and began patient notifications by mail on December 3. Confirmed exposed data includes names, dates of birth, Social Security numbers, and potentially diagnoses, medications, test results, medical images, health insurance information, and treatment records. Rhysida listed the data for sale on its dark web site at 25 bitcoin, then published all files publicly when the ransom was not paid. MedStar engaged third-party cybersecurity experts, notified the FBI, and offered complimentary credit monitoring and identity theft protection. A consolidated federal class-action complaint was filed in December 2025 alleging negligence and seeking financial damages and enhanced security measures.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
R
Threat Actor: RhysidaConfidence: High
Ransomware-as-a-service group

Motivation: Financial extortion
A ransomware-as-a-service group using double extortion. CISA reporting notes targeting across education, manufacturing, IT, government, and healthcare.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation