QualDerm Partners network data incident

Unauthorized access to a limited number of QualDerm network systems and removal of information stored in those systems. Potential exposure of current and former patient demographic, medical, and health-insurance information.

Last modified

Summary

  • Environment: Reporting healthcare organization whose network systems and patient information were involved.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to a limited number of QualDerm network systems and removal of information stored in those systems. [1]

Impact

Potential exposure of current and former patient demographic, medical, and health-insurance information. [2]

Documented data types include:

  • Names [2]
  • Dates of birth [2]
  • Contact information — Texas’s report lists addresses among the affected personal-information types. [2]
  • Clinical information — Texas’s report lists medical information among the affected personal-information types. [2]
  • Health insurance information [2]

A cited record reports 174,837 individuals (Texas residents affected according to report BR-0004855; not a national total; as of 2026-02-24). [2][3]

A cited record reports 3,117,874 individuals (Total individuals in both the HHS OCR incident report and Texas Attorney General report BR-0004855; regulator-reported and not independently verified; as of 2026-08-08). [2][3]

QualDerm said an unauthorized actor accessed a limited number of systems and removed information; the notices reviewed do not identify the actor or access method. [1]

The California sample notice says the addressed population’s Social Security numbers, driver’s-license numbers, and financial-account information were not impacted; this does not establish the same negative fact for every affected individual. [1]

Timeline

  1. Activity began

    Start of the access-and-removal interval identified by QualDerm.

    [1]
  2. Discovery

    Date QualDerm says it detected unauthorized network activity.

    [1]
  3. Documented activity ended

    End of the access-and-removal interval identified by QualDerm.

    [1]
  4. Documented event

    Date printed on the California sample individual notice; it is not asserted as the mailing date for every affected individual.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

QualDerm said it contained the activity, engaged a third-party forensic firm, assessed system security, notified federal law enforcement and regulators, and reviewed information-security policies and procedures. QualDerm offered the sample-notice recipient 12 months of complimentary credit-monitoring and identity-protection services through Cyberscout. At the time of the California sample notice, QualDerm said it was unaware of attempted or actual misuse of the recipient’s information. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]