Sanderling Healthcare Breach: 25 Years of Data Stolen

Published
July 31, 2025
Updated
August 1, 2025
Sanderling Healthcare Breach: 25 Years of Data Stolen
Sanderling Healthcare
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Sanderling Healthcare

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On July 3, 2025, Sanderling Healthcare became the victim of a significant ransomware attack that may have impacted thousands of patients. The data breach was orchestrated by the Sarcoma group disclosed on the dark web, where the attackers claimed to have hacked and accessed sensitive data from the company’s systems.

According to the dark web posting, the breach resulted in the compromise of tens of thousands of personal records. The attackers claimed to have stolen a full Oracle database backup containing 25 years of the company’s work history, which included both patient and business data.

The exposed information reportedly includes both personally identifiable information (PII) and protected health information (PHI). Compromised information could include names, dates of birth, contact information, Social Security numbers, driver's license or state ID numbers, medical records, health insurance information and payment information.

This data breach breach is considered severe, due to the amount of compromised information, and increases the risk of identity theft, fraud, and unauthorized use of medical information. The Sarcoma group's claim to have full database backups and years of company history may suggest that the attackers had deep access to Sanderling Healthcare’s network prior to detection.

Sanderling Healthcare's response

While Sanderling Healthcare has not yet issued a public statement, the organization will work to identify the then notify impacted individuals. Sanderling Healthcare will also be required to make certain state and federal disclosures.

If you believe your personal and protected health information may have been compromised in this breach:

  • Carefully review any notice or communication you receive from Sanderling Healthcare.
  • Monitor financial accounts and credit reports for signs of identity theft.
  • Consider placing fraud alerts or credit freezes with the major credit bureaus.
  • Be cautious of unsolicited emails or phone calls requesting personal information.
-

Sanderling Healthcare offers credit monitoring or identity protection services, individuals should consider enrolling. For more information about the healthcare organization, visit the Sanderling Healthcare website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image