QualDerm Partners, a Tennessee-based healthcare management company that supports dermatology practices, disclosed a cyberattack that exposed the personal and protected health information of more than 3.1 million individuals. The company said it detected unusual activity on December 24 and later determined that an unauthorized actor accessed a limited number of internal systems between December 23 and December 24, 2025, and exfiltrated stored data.
The stolen information reportedly included names, dates of birth, medical record numbers, treatment and diagnosis details, health insurance information, and driver’s license numbers, making the incident one of the larger recent healthcare data breaches. QualDerm notified the U.S. Department of Health and Human Services Office for Civil Rights, informed law enforcement and regulators, and began offering affected individuals complimentary identity protection and credit monitoring; the company did not publicly attribute the intrusion, disclose the volume of data taken, or say whether a ransom demand was involved.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By March 25, 2026, QualDerm had publicly disclosed a data breach potentially affecting millions of individuals. The incident involved exposure of sensitive personal and health information tied to the healthcare management company and supported dermatology practices.
By May 21, 2026, QualDerm reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights, notified law enforcement and regulators, and began offering affected individuals complimentary identity protection and credit monitoring. The company said more than 3.1 million individuals were affected.
On December 24, 2025, QualDerm detected unusual activity in its environment. The company said the unauthorized access occurred between December 23 and December 24, 2025, indicating the intrusion ended by that date.
QualDerm Partners determined that an unauthorized actor accessed a limited number of its internal systems beginning on December 23, 2025. During this intrusion window, certain stored information was accessed and later found to have been exfiltrated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.