Millions possibly affected by data breach at dermatology giant QualDerm
- QualDerm cyberattack exposed sensitive healthcare and personal data of 3.1 million people
- Breach included names, medical records, insurance info, and government IDs
- No evidence of misuse yet; company reported incident to HHS and is notifying affected individuals
Dermatology management services giant QualDerm suffered a cyberattack in late 2025 which saw it lose sensitive personal and healthcare data on more than three million people.
The company is now notifying affected individuals by mail, noting in a breach notification letter that between December 23 and 24, 2025, a threat actor managed to access “a limited number of systems” and pull “certain information” stored within.
That data includes a combination of people’s names, email addresses, dates of birth, their doctor’s name, medical record numbers, diagnosis and treatment information, health insurance information, and government-issued ID numbers or driver’s license numbers. Not every individual lost all this information, though.
Article continues below
No attribution yet
This information is highly sensitive and can be used for devastating effect. For example, a threat actor can identify contact information of a CEO in a large company, and use a convincing phishing lure to gain access, drop ransomware, and demand payment. They can also extort people who are trying to keep their medical conditions private.
QualDerm also reported the breach to the US Department of Health and Human Services (HHS) Office for Civil Rights, whom it told that exactly 3,117,874 individuals were affected.
At the moment of writing, there is no evidence of the data being abused in real-life attacks, and no threat actors have claimed responsibility for the breach just yet. We also don’t know if the attackers reached out to QualDerm asking for ransom in exchange for deleting the files. The company also did not say how the crooks broke in.
QualDerm provides administrative, financial, and IT services to affiliated skin care practices, serving dermatologists and clinics across 17 states, supporting over 150 practices and treating more than 120,000 patients monthly.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via Cybernews

The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
QualDerm cyberattack exposed sensitive healthcare and personal data of 3.1 million people Breach included names, medical records, insurance info, and government IDs No evidence of misuse yet; company reported incident to HHS and is notifying affected individuals Dermatology management services giant QualDerm suffered a cyberattack in late 2025 which saw…
Recent Posts
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023