CSIDB logo
Incident

QualDerm Partners

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-17 14:36

Linked entities

Victim
QualDerm Partners
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Dec 2025
Disclosed
Dec 2025
Resolved
Pending

Summary

QualDerm Partners disclosed that unauthorized actors accessed its network for two days and exfiltrated personal, medical and health insurance information from a limited number of systems, affecting approximately 3.1 million individuals. The compromised data includes names, addresses, dates of birth, email addresses, medical record numbers, physician names, treatment and diagnosis details, health insurance information, dates of death and, in some cases, government‑issued identifiers. Upon detection, the company activated its response plan, contained the activity, assessed system security, notified law enforcement and regulators, and began offering affected individuals twelve months of free identity theft and credit monitoring services. Headquartered in Brentwood, Tennessee, QualDerm Partners provides management services to 158 dermatology‑related practices across 17 states.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

QualDerm Partners discovered a data breach on December 24, 2025, after detecting unauthorized access to its network that persisted for two days. During this window, attackers gained entry to a limited number of systems and exfiltrated certain information stored there. The company confirmed that the compromised data included names, addresses, dates of birth, email addresses, medical record numbers, doctor names, treatment and diagnosis details, health insurance information, dates of death, and, in some instances, government‑issued identification numbers. QualDerm stated that the breach affected more than 3.1 million individuals, a figure later specified as 3,117,874 people when reported to the U.S. Department of Health and Human Services. The organization provides healthcare management services to 158 practices across 17 states, specializing in dermatology, cosmetics, pathology, plastic surgery, and skin cancer care.

Upon discovery, QualDerm immediately activated its incident response plans and took steps to contain the unauthorized activity while assessing the security of its affected systems. The company notified law enforcement and relevant regulatory agencies as part of its response protocol. QualDerm also began an ongoing investigation to determine the full scope of the breach and to identify all individuals whose information had been accessed. To date, the firm has notified the patients who have been identified as impacted and is offering them twelve months of free identity theft and credit monitoring services. The breach was initially reported to federal authorities last month and was subsequently added to the HHS breach portal this week.

QualDerm Partners is headquartered in Brentwood, Tennessee. The company indicated that its investigation into the data breach continues and that it has notified the patients identified to date.

Sources

Sources available to members: 1 source.

CSIDB