Data Breach Watch logoDBW
    Healthcare
    High
    investigation open
    Updated 29 days ago

    Healthcare Services Group, Inc Data Breach

    Key takeaways

    • Reports suggest a potential breach involving Healthcare Services Group, Inc.
    • Discovered on September 1, 2024.
    • Possible data exposed: Names, Social Security numbers, Driver’s license numbers, State ID numbers, Financial account information, Full access credentials, Dates of birth, Health insurance records, Medical/PHI information, Employee payroll/tax records, Stockholder data.
    • Affects individuals in: Maine, Texas, Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, Wyoming.
    • Confirmation level: Confirmed by regulators.

    Breach confirmed

    The Healthcare Services Group, Inc breach is confirmed. If you may be affected, add your details below and we will take it from there.

    Detailed summary

    Healthcare Services Group, Inc. (HSGI) experienced a data breach that began on September 27, 2024, and continued until October 3, 2024. The company discovered the unauthorized access on October 7, 2024, and confirmed sensitive data was stolen on June 3, 2025. HSGI filed a FORM 8-K with the SEC on October 16, 2024, and notified the Maine Attorney General’s Office and the Texas Attorney General.

    The breach impacted 624,496 individuals across 48 U.S. states. The compromised data types include names, Social Security numbers (SSN), driver’s license numbers, state ID numbers, financial account information, full access credentials, dates of birth, health insurance records, medical/PHI information, employee payroll/tax records, and stockholder data. HSGI states there is no evidence of fraud or identity theft resulting from the breach, but urges vigilance. Notification letters were mailed to affected individuals starting August 25, 2025. HSGI offered 12 months of free Experian credit monitoring and identity restoration services.

    This incident is a vendor breach, as HSGI provides laundry, dining, and environmental support to healthcare facilities and acts as a business associate under HIPAA. Despite initial allegations, no ransomware group has officially claimed responsibility for this incident. Details regarding the full scope and impact of the breach may continue to emerge.

    Data possibly involved

    • Names
    • Social Security numbers
      Can be used to open fraudulent accounts and file false tax returns
    • Driver’s license numbers
    • State ID numbers
    • Financial account information
    • Full access credentials
    • Dates of birth
    • Health insurance records
      Could be used for insurance fraud
    • Medical/PHI information
    • Employee payroll/tax records
    • Stockholder data

    Company Response Timeline

    Response Grade
    F

    Took over 180 days or has not yet notified consumers

    Breach Occurred

    Sep 27, 2024

    Company Discovered

    Oct 7, 2024

    Regulator Notified

    Sep 27, 2024

    Consumers Notified

    Aug 25, 2025

    10 days to discover
    322 days to notify consumers

    Breach Verification Status

    Reports Only

    Complete

    Initial dark web reports of potential breach

    Company Confirmed

    Complete

    Company has acknowledged the breach

    Regulator Confirmed

    Current

    Confirmed by regulatory authorities

    Note: Breach verification can take time. Information may evolve as more details become available from companies and regulators.

    Case Status:
    Investigation Open

    We're actively investigating this case and seeking affected individuals.

    Were you affected? Submit your information below.

    Were You Affected By This Breach?

    If you are a customer or have received a data breach notification, you may submit your information as part of our ongoing investigation. Submitting your information is free and does not obligate you.

    Were you in the Healthcare Services Group, Inc breach? Check your email

    Free scan against known breach datasets. Then remove your info from data-broker sites with Data Shield.

    No signup required. 30-second scan. Your email is only stored if you opt into alerts.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Check Your Risk Level

    Answer a few questions to understand how this breach might affect you

    What should I do?

    Change your passwords

    Update passwords for the affected service and any accounts using the same password

    Enable two-factor authentication

    Add an extra layer of security to your accounts

    Monitor your accounts

    Watch for suspicious activity on your financial and online accounts

    Watch for phishing attempts

    Be cautious of emails or messages claiming to be from the affected company

    Consider a credit freeze

    Prevent unauthorized access to your credit report

    Scan your email for other exposures

    Check whether this address shows up in other known breaches. Free, no account.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Got a notice about this breach?

    Paste it into BreachBrief to see exactly what data was exposed, how serious it is, and what to do next.

    Protect yourself

    Share This Breach Alert

    Help friends and family who might be affected by sharing this breach information

    Sources

    Are you a law firm investigating this breach?

    Get qualified claimant leads delivered directly to your CRM.

    Related breaches

    Stay informed about breaches like this one

    We'll notify you when new data breaches are reported. Free, no spam. Unsubscribe anytime.

    Free, no spam. Unsubscribe anytime.