A Florida-based technology firm, OutcomesOne, which provides medication therapy management and related services to health plans, experienced a significant data breach due to a targeted phishing attack. The incident was discovered on July 1, 2025, when an employee noticed unusual activity in their work email account and promptly reported it to the company's security team. The breach was contained to a single employee's email account, which was accessed by an unauthorized party for approximately one hour. During this brief window, the attacker was able to access files and emails containing sensitive information. The compromised data included names, demographic details, medical provider names, health insurance information, and medication information of nearly 150,000 individuals. Importantly, Social Security numbers were not affected by this breach. OutcomesOne responded quickly by securing the affected email account and confirmed that no other accounts were impacted. The company reported the incident to several state regulators and began notifying affected individuals about the potential exposure of their protected health information (PHI). The breach highlights the ongoing risk posed by phishing attacks, which remain a leading cause of health data breaches. OutcomesOne's swift detection and containment efforts limited the scope of the incident, but the exposure of PHI underscores the need for robust email security and employee awareness. The company has not disclosed whether any of the compromised information has been misused. Regulatory authorities are monitoring the situation, and OutcomesOne is likely to face scrutiny regarding its security practices and breach notification procedures. The incident serves as a reminder that even short-lived compromises can have far-reaching consequences when sensitive health data is involved. The breach also raises questions about the effectiveness of current anti-phishing measures and the importance of rapid incident response. OutcomesOne is expected to review and strengthen its security protocols to prevent similar incidents in the future. The notification process for affected individuals is ongoing, and the company is offering support to those whose information was exposed. This event adds to the growing list of healthcare sector breaches driven by phishing, emphasizing the sector's vulnerability to such attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The company reported the incident to multiple state regulators, including California and Oregon, as part of its breach notification process. At the time of reporting, the incident had not yet appeared on the HHS OCR HIPAA Breach Reporting Tool.
OutcomesOne disclosed that the incident potentially exposed PHI for nearly 150,000 individuals, including names, demographic details, provider name, health insurance information, and medication information, but not Social Security numbers. The affected individuals were identified as patients with Aetna health plans for which OutcomesOne provides medication therapy services.
On July 1, OutcomesOne detected the unauthorized access after the employee noticed unusual activity, and its security team quickly secured the affected account. The company said it found no evidence that any other email accounts were impacted.
A single OutcomesOne employee email account was accessed without authorization for about one hour in a phishing-related compromise. During the exposure window, the attacker accessed emails and files containing protected health information.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.