DermCare Management, a Florida-based company managing dermatology and skincare clinics, experienced a cybersecurity incident between February 14 and February 26, 2025. The company discovered the breach on February 26, 2025. Notifications to affected individuals began on or around April 8, 2026, with a website notice updated on April 14, 2026. The incident was also reported to the Texas Attorney General on April 10, 2026. This incident involved at least 11 of the 70+ clinics managed by DermCare Management.
Exposed data types include names, Social Security numbers, driver's license numbers, government-issued identification, financial account information, medical information, health records, health insurance information, and dates of birth. At least 9,724 Texas residents were affected, though the total number of individuals impacted across all affected states has not been publicly disclosed. It remains unclear if any additional data types were compromised.
Details about data breaches can emerge over time, and notifications may be delayed.