Reproductive Medicine Associates of Michigan (RMA of Michigan), a fertility clinic, discovered unauthorized access to its network files on October 22, 2025. This incident involved protected health information (PHI) and personally identifiable information (PII). The company confirmed the unauthorized access and copying of files, securing its network and initiating an investigation with cybersecurity experts. RMA of Michigan notified the U.S. Department of Health and Human Services (HHS) on December 19, 2025, and federal law enforcement.
The confirmed data types involved protected health information and personally identifiable information. While electronic medical record systems were not compromised, the involved data included sensitive health data typical for a fertility clinic, such as IVF and egg donation records. A provisional count of 501 individuals was reported as affected. Specific details on whether SSN or financial data were exposed have not been publicly confirmed.
Reviews are ongoing as of early 2026, and the company plans to mail notification letters to affected individuals once the review is complete. Data breach details can emerge later, and notices may be delayed.