Sturgis Hospital Data Breach Affects over 77k: SSNs & Health Info Exposed

Published
September 22, 2025
Updated
September 22, 2025
Sturgis Hospital Data Breach Affects over 77k: SSNs & Health Info Exposed
Sturgis Hospital
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Sturgis Hospital

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

In December 2024, Sturgis Hospital detected unauthorized activity within a portion of its computer network, signaling the existance a data breach. The hospital, located in Sturgis, Michigan, immediately began working with third-party cybersecurity experts to investigate and remediate the incident. However, while that investigation was still ongoing, a second wave of unauthorized activity was discovered in June 2025.

According to the disclosure filed with the Dept. of Health & Human Services, 77,771 people have had their protected health information exposed. The total number of people affected may be higher, including those who had other personally identifiable information (like Social Security numbers) exposed that excluded health information.

This prompted a separate investigation, again involving external cybersecurity specialists, to determine the extent of the breach and secure the hospital’s systems.

Based on the findings from both investigations, Sturgis Hospital determined that an unauthorized third party may have accessed or acquired files containing sensitive information. The first breach is believed to have occurred between Dec. 11 and Dec. 17, 2025. The hospital has since worked diligently to identify the individuals affected and to verify their contact information for notification purposes.

The types of information exposed in this incident are both broad and sensitive. Impacted data includes personally identifiable information (PII) such as name, contact information, government identification number (like a Social Security number), and financial account details (such as a bank account number). In addition, protected health information (PHI) was also compromised, including health insurance details and clinical information like prescriptions, treatment records, and similar medical data.

According to the disclosure filed with the Montana Attorney General’s office, six individuals in Montana were affected. The breach was publicly disclosed on Sept. 18, 2025, and a detailed notice was posted on the Sturgis Hospital website.

Sturgis Hospital's response

In response to the breach, Sturgis Hospital took immediate steps to secure its systems and prevent further unauthorized access. The hospital engaged third-party cybersecurity experts to investigate both incidents, remediate vulnerabilities, and implement additional security measures. Law enforcement was notified and involved in the process, though this did not delay the notification to affected individuals.

To support those impacted, Sturgis Hospital is offering complimentary identity theft protection services through Experian’s IdentityWorks. Affected individuals are encouraged to enroll in these services by the deadline specified in their notification letter. The hospital’s notice also provides detailed instructions on how to monitor financial accounts, obtain free credit reports, place fraud alerts or security freezes, and report suspicious activity to authorities.

Given the nature of the breach—which involved both PII and PHI—individuals should remain vigilant for signs of identity theft or fraud.

It is recommended that those affected:

  • Review account statements and credit reports regularly
  • Consider placing a fraud alert or security freeze on their credit files
  • Report any suspicious activity to law enforcement and the Federal Trade Commission
  • Take advantage of the identity theft protection resources offered by the hospital

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Sturgis Hospital
Consumers Notification date
Date of Breach
June 1, 2025
Breach Discovered Date
December 2024
Total People Affected
77771
Information Types Exposed
  • name
  • contact information
  • government identification number (such as a Social Security number)
  • financial account details (such as a bank account number)
  • health insurance details
  • clinical information
  • prescriptions
  • treatment records
  • similar medical
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image