Sierra Vista Hospital & Clinics experienced a major data breach. On Jan. 29, 2025, the healthcare organization discovered suspicious activity within its computer network. An investigation revealed that a cybercriminal may have accessed and obtained sensitive patient files between Jan. 14, 2025 and Jan. 31, 2025.
A review took place and on Aug. 13, 2025, it was determined that the compromised files contained both personally identifiable information (PII) and protected health information (PHI). Exposed information included names, addresses, Social Security, dates of birth, medical records, health insurance details and other medical information.
The cybersecurity incident was disclosed to the Texas and Massachusetts Attorney Generals' offices on Oct. 7, 2025. The hospital also began notifying affected patients by mail on the same date.
The total number of impacted individuals has not been released, but is believed to include thousands of current and former patients. The combination of personal and protected health information puts consumers at risk for fraud and identity theft.
After discovering the breach, Sierra Vista Hospital & Clinics secured their network and launched an investigation with the help of external cybersecurity professionals. In addition to required state and federal disclosures, the healthcare organization is offering impacted individuals free Experian IdentityWorks credit monitoring services.
If you receive a notice from Sierra Vista Hospital and Clinics about this breach, you may want to:
For more information, affected individuals can contact the dedicated call center at 855-291-2594, available Monday through Friday from 9 a.m. to 9 p.m. Eastern time.
More information about the healthcare organization can be found on the Sierra Vista Hospital & Clinics website.