Highlands Oncology Data Breach Affects 113,000 Patients

Published
August 2, 2025
Updated
August 2, 2025
Highlands Oncology Data Breach Affects 113,000 Patients
Highlands Oncology Group
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Highlands Oncology Group

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On June 2, 2025, Highlands Oncology Group PA, based in Northwest Arkansas, discovered a cyberattack that compromised the personal information of more than 113,000 individuals in the United States, including six in Maine.

An investigation revealed unauthorized access to the company’s computer network between January 21 and June 2, 2025. During this period, a threat actor known as MEDUSA infiltrated Highlands Oncology’s systems, encrypted files, and is believed to have accessed and acquired sensitive data.

The exposed information includes personally identifiable information (PII) and protected health information (PHI): names, Social Security numbers, driver’s license numbers, passport numbers, electronic or digital signatures, employee identification numbers, financial account information, medical information, and health insurance details.

On June 19th, the MEDUSA ransomware group publicly claimed responsibility for the attack, posting sample screenshots and threatening to publish stolen data within days on the dark web.

The incident was reported to the Maine Attorney General’s office on August 1, 2025, and Highlands Oncology Group began notifying affected individuals in writing on the same day.

The company has also published a detailed disclosure for the public on their website.

Highlands Oncology Group's response

Highlands Oncology Group is offering a complimentary one-year membership to Experian IdentityWorks Credit 3B, which provides credit monitoring, identity restoration services, and up to $1 million in identity theft insurance. Affected individuals are encouraged to enroll in this service and remain vigilant by reviewing account statements and monitoring credit reports for suspicious activity.

Given the nature of the breach—specifically, the involvement of ransomware and the theft of sensitive PII and PHI—individuals should consider placing fraud alerts or credit freezes with the major credit bureaus.

Individuals are also advised to file a police report if they experience identity theft or fraud and to consult resources provided by the Federal Trade Commission for additional guidance.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
August 01, 2025
Date of Breach
Breach Discovered Date
June 02, 2025
Total People Affected
Information Types Exposed
  • names
  • Social Security numbers
  • driver’s license numbers
  • passport numbers
  • electronic/digital signatures
  • employee identification numbers
  • financial account information
  • medical information
  • health insurance information
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image