Avala Data Breach Exposes Social Security Numbers: Over 22k Affected

Published
July 29, 2025
Updated
August 6, 2025
Avala Data Breach Exposes Social Security Numbers: Over 22k Affected
Avala Holdings
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Avala Holdings

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On May 30, 2025, Avala, a physician-led and physician-owned hospital and health care provider based in Covington, Louisiana, discovered a cybersecurity incident within its IT systems. Immediately after identifying the breach, Avala engaged third-party cybersecurity experts to assess, contain and remediate the situation.

The investigation concluded on or around July 23, 2025, and revealed that patient data. both personally identifiable information (PII) and protected health information (PHI), was exposed as a result of the incident.

The exposed information includes names, addresses, dates of birth, medical treatment information, health insurance information and Social Security numbers.

Avala has stated that they are notifying individuals whose personal information was involved and are providing resources to help protect their information. For more information, Avala has posted a data security incident notice on their website.

In a disclosure to the Department of Health and Human Services, the company reported at least 22,732 people have been affected,.

Avala's response

For affected individuals, Avala is providing resources and guidance to help protect their information. They recommend the following steps to monitor for signs of medical identity theft:

  • Only share health insurance cards with healthcare providers and trusted family members involved in medical care
  • Review explanation of benefits statements from health insurance companies and follow up on any unfamiliar items with the insurer or care provider
  • Request a current year-to-date report of all services paid for by the insurance company and confirm the accuracy of any unfamiliar items

Individuals who believe they may be affected are encouraged to remain vigilant and to monitor their medical and insurance records for any suspicious activity. If any discrepancies or unauthorized activities are found, they should contact their insurance provider and care provider promptly.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image