
QualDerm, a U.S.-based dermatology management services provider supporting more than 150 medical practices across 17 states, is notifying more than 3.1 million individuals after a cyber intrusion exposed sensitive medical and health insurance information. The company identified unauthorized access to its systems in late December 2025 and began notifying affected patients this week.
The organization said it first became aware of the breach on Dec. 24, 2025. An investigation conducted with external cybersecurity specialists determined that an unauthorized actor accessed a limited number of systems between Dec. 23 and Dec. 24 and removed certain stored data.
The incident was reported to the U.S. Department of Health and Human Services Office for Civil Rights on Feb. 22 in accordance with federal healthcare data breach reporting requirements. Federal records show that 3,117,874 individuals were affected.
QualDerm operates alongside Pinnacle Dermatology, a national skin care and aesthetics brand, collectively supporting more than 158 practices and 350 dermatology providers. The network serves an average of 120,000 patients each month across locations in the Northeast, South, and Midwest, including states such as Illinois, Ohio, Tennessee, North Carolina, Pennsylvania, Michigan, and New Jersey.
The company said the compromised data varies by individual but may include patient names, email addresses, dates of birth or death, physician names, medical record numbers, diagnostic and treatment details, health insurance information, and government-issued identification such as driver’s license numbers.
QualDerm has not disclosed how the attackers gained access to its systems or whether information belonging to medical staff or providers was affected.
The breach involves electronic protected health information, placing it on the federal health department’s public breach reporting portal, which tracks healthcare incidents affecting 500 or more individuals under HIPAA regulations.
The company stated it has no evidence of misuse of the exposed information at this time. However, it is advising affected individuals to monitor financial accounts, credit reports, and explanation of benefits statements for any suspicious activity. QualDerm is also offering credit monitoring and identity protection services.
The company said it has taken steps to strengthen its security posture and is reviewing its data protection policies and procedures following the incident.
Industry observers note that healthcare data breaches often carry heightened risks due to the depth of personal and medical information involved. Such records can be used in identity theft, phishing campaigns, and medical fraud.
QualDerm emphasized that it is treating the incident seriously and urged patients to remain vigilant by reviewing account statements and reporting any irregularities to the appropriate institutions.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543