HEALTHPRO PEDIATRICS, LLC: Millcreek Pediatrics Data Breach Lawsuit Investigation

HEALTHPRO PEDIATRICS, LLC: Millcreek Pediatrics Data Breach Lawsuit Investigation

Millcreek Pediatrics Data Breach Exposes Sensitive Information of Over 14,000 Individuals

In February 2025, Millcreek Pediatrics, a Wilmington, Delaware-based pediatric practice, suffered a data breach involving unauthorized access to its network. The incident occurred between February 17 and 25, 2025, and was detected after suspicious activity prompted an investigation with cybersecurity experts.

On October 27, 2025, the practice confirmed that files containing personal and protected health information had been accessed or acquired by an unauthorized party. The breach impacted at least 14,095 individuals across the U.S., exposing sensitive data including:

  • Full names
  • Dates of birth
  • Addresses
  • Social Security numbers
  • Driver’s license/state ID numbers
  • Medical and health insurance information

Millcreek Pediatrics reported the breach to the U.S. Department of Health and Human Services, posted a public notice on its website, and began notifying affected individuals on November 21, 2025. The law firm Shamis & Gentile P.A. is investigating potential legal action for those impacted, citing possible compensation for damages.

The breach highlights ongoing risks to healthcare data security, with exposed information posing long-term risks for identity theft and fraud.

Source: https://www.claimdepot.com/investigations/millcreek-pediatrics-data-breach-2025

HEALTHPRO PEDIATRICS, LLC cybersecurity rating report: https://www.rankiteo.com/company/healthpro-pediatrics-llc

"id": "HEA1765310555",
"linkid": "healthpro-pediatrics-llc",
"type": "Breach",
"date": "2/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '14095',
                        'industry': 'Healthcare',
                        'location': 'Wilmington, Delaware, USA',
                        'name': 'Millcreek Pediatrics',
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Unauthorized Access',
 'customer_advisories': 'Notified affected individuals on Nov. 21, 2025, and '
                        'posted a notice on the website',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '14095',
                 'personally_identifiable_information': ['Full name',
                                                         'Dates of birth',
                                                         'Address',
                                                         'Social Security '
                                                         'number',
                                                         'Driver’s license '
                                                         'and/or state '
                                                         'identification '
                                                         'numbers',
                                                         'Medical information',
                                                         'Health insurance '
                                                         'information'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information',
                                              'Protected Health Information']},
 'date_detected': '2025-02-25',
 'date_publicly_disclosed': '2025-11-21',
 'description': 'Millcreek Pediatrics experienced a significant data breach '
                'involving unauthorized access to its network between Feb. 17 '
                'and Feb. 25, 2025. Files containing personal and protected '
                'health information were accessed or acquired by an '
                'unauthorized party, impacting at least 14,095 individuals in '
                'the United States.',
 'impact': {'data_compromised': 'Sensitive personally identifiable information '
                                'and protected health information',
            'identity_theft_risk': 'High',
            'systems_affected': 'Network and files containing personal and '
                                'health information'},
 'investigation_status': 'Ongoing',
 'recommendations': ['Sign up for credit monitoring services if offered',
                     'Monitor financial statements regularly for suspicious '
                     'activity',
                     'Place a fraud alert and request credit reports from '
                     'major credit bureaus',
                     'Seek legal help to understand rights and pursue '
                     'compensation'],
 'references': [{'source': 'Shamis & Gentile P.A.'}],
 'regulatory_compliance': {'regulations_violated': ['HIPAA'],
                           'regulatory_notifications': ['U.S. Department of '
                                                        'Health and Human '
                                                        'Services']},
 'response': {'communication_strategy': 'Posted a notice of data security '
                                        'incident on its website and notified '
                                        'affected individuals',
              'containment_measures': 'Immediate containment of the incident',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Cybersecurity experts'},
 'title': 'Millcreek Pediatrics Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.