CareTracker, Inc. Data Breach Affects Patient PII & PHI

Published
September 2, 2025
Updated
September 2, 2025
CareTracker, Inc. Data Breach Affects Patient PII & PHI
CareTracker
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

CareTracker

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

CareTracker, Inc., an organization that provides practice management software to medical practices and clinics, experienced a major data breach. The cybersecurity incident was disclosed to the U.S. Department of Health and Human Services on Aug. 18, 2025 and compromised both personal and protected health data.

The total number of impacted individuals has not been released, but is believed to include thousands of patients and multiple medical providers. CareTracker is widely used by physician practices and healthcare providers for scheduling, billing, insurance verification, and electronic medical records management.

Exposed information may include names, contact and demographic information, dates of birth, Social Security numbers, driver's license or state ID numbers, health insurance details, medical records and payment information. The breach was reported has a hacking incident and is considered severe, as unauthorized access to such data can lead to risks such as identity theft, insurance fraud, and privacy violations.

CareTracker's response

In addition to required state and federal disclosures, CareTracker will work to notify affected practices and their patients.

If you believe your personal information may have been compromised in this breach:

  • Carefully review any notice or communication you receive from CareTracker or your medical provider.
  • Monitor financial accounts and credit reports for signs of identity theft.
  • Consider placing fraud alerts or credit freezes with the major credit bureaus.
  • Be cautious of unsolicited emails or phone calls requesting personal information.

More information about the company can be found on the CareTracker website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image