Massive Breach: Nearly 1 Million Patients Exposed in Frederick Health Ransomware Attack


# Frederick Health Ransomware Attack Exposes Nearly One Million Patient Records

A significant data breach has impacted Frederick Health Medical Group following a January ransomware attack, affecting approximately 934,326 patients. The Maryland healthcare provider, which employs nearly 4,000 staff across more than 25 locations, detected the security incident on January 27, 2025.

Frederick Health promptly notified law enforcement and engaged a forensic investigation team after discovering the breach. According to their March notification to patients, “an unauthorized person gained access to our network and copied certain files from a file share server.”

The stolen data included sensitive personal information such as:
– Patient names and addresses
– Dates of birth
– Social Security numbers
– Driver’s license numbers
– Medical record numbers
– Health insurance details
– Clinical information related to patient care

While Frederick Health has begun mailing notification letters to affected individuals with available contact information, they did not initially disclose the scope of the breach. The U.S. Department of Health and Human Services, where the incident was reported on March 28, later confirmed the nearly one million patients affected.

Notably, no ransomware group has publicly claimed responsibility for the attack, suggesting Frederick Health may have paid the ransom demand.

This incident joins other recent major healthcare data breaches, including Blue Shield of California’s exposure of 4.7 million members’ protected health information to Google’s platforms and Yale New Haven Health’s data theft affecting 5.5 million patients.

Share This Article