HIGH SEVERITYMedical

Neurological Associates of Washington Data Breach

Neurological Associates of Washington Neurology Practice Breach (2026): Patient SSN Exposed

Neurology practice providing diagnostic and treatment services.

Verified by ObscureIQ Intelligence

7.0Severity
85KRecords
3Fields
2026Year

ObscureIQ Breach Intelligence Scores
32.0
Breach Risk Index
22
Data Value
80
Market Recency
69
days
Since Breach

Risk Interpretation

Severe risk of identity theft, medical fraud, and privacy harm. Neurology-related treatment context may be especially sensitive and can support targeted scams or stigma-based abuse.

🎯 Impact & Downstream Threats

The institutional impact on Neurological Associates of Washington is meaningful given the small size of the practice and the sensitivity of neurological diagnostic information. Federal HIPAA notification obligations, an Office for Civil Rights review, Washington attorney-general filings, and active class-action litigation discussions are all underway. As a four-neurologist independent practice, Neurological Associates of Washington has limited resources for remediation, litigation, and credit mo

Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present

🔓 Threat Vectors

Name-based social engineering
SIM swapping, vishing & SMS phishing
Full identity theft & synthetic identity fraud

📋 Breach Intelligence

EntityNeurological Associates of Washington
OrganizationHealthcare Provider • USA
Breach Date2026-01-02
DBC Added2026-02-17
Added Date2026-02-17
Records~85K (85,268 records)
Attack VectorUnknown
Threat ActorDragonForce
SourceDataBreach.com / ObscureIQ
SensitivityStandard
Breach ID964.0
StatusConfirmed

📝 Executive Summary

Neurological Associates of Washington, an independent neurology practice based in Kirkland, Washington, suffered a ransomware attack on December 27, 2025 that encrypted a server containing medical records from 2019 to 2025. The clinic discovered the incident on December 28, 2025. The DragonForce ransomware-as-a-service group claimed responsibility by listing the clinic on its dark-web leak site and asserting it had exfiltrated approximately 1.4 terabytes of data. DragonForce posted sample document images to substantiate its claim. The clinic publicly disclosed the incident to the Washington Attorney General on January 23, 2026 and began mailing notification letters to affected individuals on January 22, 2026.

The breach affected approximately 13,500 Washington state residents per the formal Washington Attorney General notification. Compromised fields included names, addresses, dates of birth, Social Security numbers, health insurance policy or identification numbers, and medical information including diagnoses and disability codes. The DragonForce dataset reportedly contains the full 2019 to 2025 medical records archive, with approximately 1.4 terabytes of data including clinical documents and patient records. New patients added to the practice during 2025 are unlikely to have been affected because the practice had migrated to a cloud-based records system before the attack.

For affected patients, the practical risk profile is unusually severe and durable because of the combination of identity-fraud exposure with neurology-specific sensitivity. The combination of name, date of birth, address, and Social Security number is a strong base for synthetic identity fraud and fraudulent credit applications. Inclusion in the dataset confirms a neurology care relationship and the presence of a neurological diagnosis or disability code, which is itself unusually sensitive health information. Patients with documented disability codes face additional risk of disability-benefits fraud and discrimination-themed scams. Affected patients should accept the twelve months of identity-protection services offered by the practice, freeze credit at all three U.S. bureaus, monitor health-insurance and Social Security disability statements, and treat unsolicited contact referencing neurological care, disability claims, or insurance verification with caution.

🏢 About Neurological Associates of Washington

Neurological Associates of Washington is an independent neurology medical practice based in Kirkland, Washington, in the Seattle metropolitan area. Founded in 1974, the practice provides comprehensive neurological care, expert consultations, advanced diagnostics, and personalized treatment for a wide range of nervous system conditions. The practice operates with a team of four neurologists serving Washington state residents primarily through in-person consultations at its Kirkland location. As a HIPAA-regulated specialty medical practice, Neurological Associates of Washington maintains patient identity, contact, insurance, billing, appointment, diagnostic, and treatment records tied to neurological care, including potentially sensitive diagnoses and disability codes.

Healthcare provider | Neurology and specialty care services | Medical practice | USA
Healthcare ProviderUSAneurologicalassociatesofwashington.com

🗂 Why They Hold Your Data

Neurology practices collect highly sensitive patient identity, contact, insurance, billing, appointment, and treatment records tied to neurological and specialty medical care.

📰 Recent Developments

Neurological Associates of Washington discovered a ransomware attack on December 28, 2025, the day after the intrusion occurred on December 27, 2025. The DragonForce ransomware-as-a-service group, an active threat actor since December 2023, claimed responsibility by listing the clinic on its dark-web leak site and asserting it had exfiltrated approximately 1.4 terabytes of data, posting sample document images as proof. The practice migrated its electronic health records to a cloud-based platform and isolated prior records on a computer with no internet access. Neurological Associates of Washington filed reports with the FBI, HHS, and the Washington Attorney General on January 23, 2026, and began mailing notification letters to affected individuals on January 22, 2026. The practice is offering twelve months of complimentary credit monitoring and identity protection services. Class-action investigations by U.S. plaintiff law firms began in early February 2026.

🔍 Data Points Exposed

3 verified field types:
Social Security Number
Phone Number
Name

Exposure Categories

CredentialsSSN

Canonical Fields

full_name, phone_number, ssn

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~85K records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: neurological-associates-2026

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Neurological Associates of Washington
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MedicalPhone

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom