On April 29, 2025, Heartland Regional Medical Center, known locally as Mosaic Life Care, discovered a major data breach that impacted the security of sensitive patient information. The breach, which began as early as January 22, 2025, affected a reported 145,269 individuals across the United States. The incident involved unauthorized access to both personally identifiable information (PII) and protected health information (PHI).
The types of information exposed in this breach were extensive and included names, Social Security numbers, dates of birth, driver’s license numbers, insurance information, dates of service, treating physicians, treatment and diagnostic information, as well as medication information.
The breach was disclosed to the U.S. Department of Health and Human Services on June 27, 2025, as documented in the official HHS breach report.
The breach is considered severe due to the breadth of sensitive data involved and the large number of individuals affected. However, the specific method of unauthorized access and the party responsible have not been publicly disclosed.
Following the discovery of the breach, Mosaic Life Care took immediate steps to secure its systems and investigate the extent of the incident. The organization has notified affected individuals and regulatory authorities, as required by law. A comprehensive notice has been posted on the Mosaic Life Care website, providing guidance and resources for those impacted.
Given the nature of the exposed information, individuals affected by the breach are encouraged to:
Because both PII and PHI were involved, it is especially important for affected individuals to remain vigilant in protecting their identities and personal medical information.
Additional information about the organization and its services can be found on the Mosaic Life Care website.