Sharp Community Medical Group (SCMG) was impacted by a data breach in 2025 originating from a ransomware attack on its vendor, Conduent Business Services (also known as Southeast Series of Lockton Companies). The breach, which occurred between January 27 and February 6, 2025, involved a third-party business associate, rather than SCMG directly. The incident's total impact was updated to regulators in mid-2026.
The broader Conduent incident affected approximately 62.2 million individuals. For SCMG and Sharp HealthCare patients specifically, about 6.7 million individuals were affected. The exposed data types included names, addresses, dates of birth, medical diagnoses, medications, test results, insurance IDs, and in some instances, Social Security numbers and financial information. Specific notification dates for SCMG patients are not isolated in the available information, though broader notifications for related incidents began in late July 2024 and April 2025. The states affected are not specified for SCMG patients, but the primary breached entity, Lockton/Conduent, is in Georgia.
Details can emerge later; notices may be delayed.