Healthcare provider · Outpatient surgical services · Ambulatory surgery center · USA
Outpatient surgery center.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Waterford Surgical Center, a physician-owned ambulatory surgery center in Waterford, Michigan, was hit by the SafePay ransomware group, which claimed the attack on September 1, 2025; the center detected unauthorized access on September 3, 2025. Approximately 9,000 current and former patients and employees were affected per HHS disclosure. Exposed data may include names, addresses, dates of birth, phone numbers, emails, Social Security numbers, driver’s license/state ID copies, health insurance information, medical records, and payment information. The breach is catalogued by DataBreach.com and reported to HHS.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
9K records analyzed
Waterford Surgical Center is a physician-owned ambulatory (outpatient) surgery center in Waterford, Michigan, providing same-day surgical procedures across specialties. It maintains patient identity, insurance, billing, scheduling, and surgical-treatment records, along with employee records.
Ambulatory surgery centers collect highly sensitive patient identity, contact, insurance, billing, appointment, and surgical treatment records across outpatient care workflows.
The SafePay ransomware group claimed an attack on Waterford Surgical Center on September 1, 2025; the center discovered unauthorized access on September 3, 2025. Approximately 9,000 patients and employees were affected per HHS disclosure. Class-action investigations followed.
The exposure combined identity, government-ID, financial, and clinical data (SSNs, driver’s licenses, payment information, health insurance, and medical records) for roughly 9,000 patients and staff, an unusually complete bundle for a small surgery center that enables identity theft, payment fraud, and medical fraud. The surgical-care context also supports credible treatment- and billing-themed scams.
• Full identity theft and synthetic identity construction using SSN, DOB, and driver’s license | • Payment fraud using exposed payment information | • Medical identity fraud and insurance abuse using medical records and insurance data | • Targeted phishing and vishing referencing surgical care or billing | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware group identified in late 2024 that became highly active in 2025. Reporting describes it as a double-extortion group using LockBit 3.0-derived tooling, with a strong victim concentration in North America.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation