Huron Regional Medical Center Data Breach Exposes SSNs

Published
September 10, 2025
Updated
September 10, 2025
Huron Regional Medical Center Data Breach Exposes SSNs
Huron Regional Medical Center
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Huron Regional Medical Center

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On May 31, 2025, Huron Regional Medical Center (HRMC), based in Huron, South Dakota, detected suspicious activity within its computer network.

After an investigation, including the engagement of legal counsel and third-party forensic specialists, HRMC determined that an unauthorized party had gained access to its systems and copied sensitive data. On Aug. 21, 2025, HRMC identified the individuals whose information was included in the compromised data set.

The breach has been linked to the BEAST ransomware group, which claimed responsibility and asserted it had stolen 800GB of HRMC’s data. The group posted about the attack on the dark web on Aug. 21, 2025, indicating a significant and targeted cyberattack. The incident was classified as a ransomware attack, with the threat actor leveraging the Tor network to publicize their access.

The types of information exposed in this breach are extensive and include both personally identifiable information (PII) and protected health information (PHI).

The data accessed includes name, address, phone number, date of birth, Social Security number, Medicare number, Medicaid number, financial account information, health insurance details, date(s) and cost of service, lab results, medical diagnostic images, prescription information, and medical diagnosis and treatment information.

Not all data elements were impacted for every individual, but the scope is broad and includes highly sensitive medical and financial information.

According to the breach notification filed with the Montana Attorney General, 20 Montana residents were affected, though the total number of impacted individuals across all states has not been specified.

The incident was formally disclosed to regulators and the public on Sept. 9, 2025, and in the notice posted on HRMC’s website.pdf).

Huron Regional Medical Center's response

For those affected, HRMC is offering complimentary single-bureau credit monitoring, credit report, and credit score services for twelve months through Cyberscout, a TransUnion company. Impacted individuals have been notified by mail and provided with instructions to enroll in these services.

HRMC has also set up a dedicated assistance line at 833-456-9193, available Monday through Friday from 8 a.m. to 8 p.m. Eastern time, to answer questions and provide support.

Given the nature of the breach, a ransomware attack by a known cybercriminal group, affected individuals are strongly encouraged to remain vigilant. Recommended steps include monitoring credit reports and account statements for suspicious activity, placing fraud alerts or credit freezes with major credit bureaus, and notifying financial institutions of the breach.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
May 31, 2025
Breach Discovered Date
May 31, 2025
Total People Affected
Information Types Exposed
  • address
  • cost of service
  • date of birth
  • date(s) of service
  • financial account information
  • health insurance information
  • lab results
  • medical diagnosis and treatment information
  • medical diagnostic images
  • Medicaid Number
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image