Excelas, a national provider of medical record organization and analysis services, experienced a data breach between November 27, 2025, and December 3, 2025. The company discovered the unauthorized access on December 3, 2025. The Cl0p ransomware group claimed to have obtained data from Excelas on January 23, 2026. Excelas posted a notice on its website and began notifying affected individuals on or about May 12, 2026. The Massachusetts and New Hampshire Attorneys General were also notified on May 12, 2026.
The potentially impacted data may have included names, dates of birth, Social Security numbers, government-issued identification, diagnosis information, medical history, mental and physical treatment records, prescription information, treating/referring physician details, medical record images, health insurance policy numbers, medical record numbers, subscriber numbers, health insurance group/plan numbers, health insurance information, and payment information. The total number of affected individuals has not been publicly disclosed by Excelas. The actual notice letter text is not available in the provided sources, however, the content of its summary is.
Details about data breaches can emerge over time, and consumer notification processes may experience delays. Additional information about this incident may become available as investigations continue.