---
title: "QualDerm Partners network data incident"
description: "Evidence-backed account of QualDerm Partners network data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/qualderm-partners-network-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/qualderm-partners-network-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/qualderm-partners-network-data-incident-2025/stix.json"
---

# QualDerm Partners network data incident

Unauthorized access to a limited number of QualDerm network systems and removal of information stored in those systems. Potential exposure of current and former patient demographic, medical, and health-insurance information.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Reporting healthcare organization whose network systems and patient information were involved.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to a limited number of [QualDerm](https://www.qualderm.com/) network systems and removal of information stored in those systems. [1](#source-1)

## Impact

Potential exposure of current and former patient demographic, medical, and health-insurance information. [2](#source-2)

Documented data types include:

- Names [2](#source-2)
- Dates of birth [2](#source-2)
- Contact information — Texas's report lists addresses among the affected personal-information types. [2](#source-2)
- Clinical information — Texas's report lists medical information among the affected personal-information types. [2](#source-2)
- Health insurance information [2](#source-2)

A cited record reports 174,837 individuals (Texas residents affected according to report BR-0004855; not a national total; as of 2026-02-24). [2](#source-2) [3](#source-3)

A cited record reports 3,117,874 individuals (Total individuals in both the HHS OCR incident report and Texas Attorney General report BR-0004855; regulator-reported and not independently verified; as of 2026-08-08). [2](#source-2) [3](#source-3)

QualDerm said an unauthorized actor accessed a limited number of systems and removed information; the notices reviewed do not identify the actor or access method. [1](#source-1)

The California sample notice says the addressed population's Social Security numbers, driver's-license numbers, and financial-account information were not impacted; this does not establish the same negative fact for every affected individual. [1](#source-1)

## Timeline

### December 23, 2025 — Activity began

Start of the access-and-removal interval identified by QualDerm. [1](#source-1)

### December 24, 2025 — Discovery

Date QualDerm says it detected unauthorized network activity. [1](#source-1)

### December 24, 2025 — Documented activity ended

End of the access-and-removal interval identified by QualDerm. [1](#source-1)

### February 20, 2026 — Documented event

Date printed on the California sample individual notice; it is not asserted as the mailing date for every affected individual. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

QualDerm said it contained the activity, engaged a third-party forensic firm, assessed system security, notified federal law enforcement and regulators, and reviewed information-security policies and procedures. QualDerm offered the sample-notice recipient 12 months of complimentary credit-monitoring and identity-protection services through Cyberscout. At the time of the California sample notice, QualDerm said it was unaware of attempted or actual misuse of the recipient's information. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/qualderm-partners-network-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### QualDerm Partners notice of data event — California sample

official · QualDerm Partners, LLC

<https://oag.ca.gov/system/files/QualDerm%20Partners%20LLC%20-%20Sample%20Notice.pdf>

<a id="source-2"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-3"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   December 2025 QualDerm network incident: QualDerm said an unauthorized actor accessed a limited number of systems and removed information; the notices reviewed do not identify the actor or access method.
2. **Resulted In · 100% confidence · current**  
   December 2025 QualDerm network incident: QualDerm said it contained the activity, engaged a third-party forensic firm, assessed system security, notified federal law enforcement and regulators, and reviewed information-security policies and procedures.
3. **Exposed Data Category · 100% confidence · current**  
   QualDerm patient-information exposure: Names
4. **Resulted In · 100% confidence · current**  
   QualDerm affected-individual notification: QualDerm offered the sample-notice recipient 12 months of complimentary credit-monitoring and identity-protection services through Cyberscout.
5. **Began At · 100% confidence · current**  
   December 2025 QualDerm network incident: 2025-12-23
6. **Affected Organization · 100% confidence · current**  
   December 2025 QualDerm network incident: QualDerm Partners, LLC
7. **Resulted In · 100% confidence · current**  
   December 2025 QualDerm network incident: QualDerm affected-individual notification
8. **Affected Individual Count · 100% confidence · current**  
   QualDerm patient-information exposure: 174,837 individual
9. **Affected Individual Count · 100% confidence · current**  
   QualDerm patient-information exposure: 3,117,874 individual
10. **Resulted In · 100% confidence · current**  
   QualDerm affected-individual notification: At the time of the California sample notice, QualDerm said it was unaware of attempted or actual misuse of the recipient's information.
11. **Exposed Data Category · 100% confidence · current**  
   QualDerm patient-information exposure: Dates of birth
12. **Exposed Data Category · 100% confidence · current**  
   QualDerm patient-information exposure: Contact information
13. **Discovered At · 100% confidence · current**  
   December 2025 QualDerm network incident: 2025-12-24
14. **Exposed Data Category · 100% confidence · current**  
   QualDerm patient-information exposure: Clinical information
15. **Exposed Data Category · 100% confidence · current**  
   QualDerm patient-information exposure: Health insurance information
16. **Resulted In · 100% confidence · current**  
   QualDerm patient-information exposure: The California sample notice says the addressed population's Social Security numbers, driver's-license numbers, and financial-account information were not impacted; this does not establish the same negative fact for every affected individual.
17. **Resulted In · 100% confidence · current**  
   December 2025 QualDerm network incident: QualDerm patient-information exposure
18. **Ended At · 100% confidence · current**  
   December 2025 QualDerm network incident: 2025-12-24
19. **Occurred At · 100% confidence · current**  
   QualDerm affected-individual notification: 2026-02-20

</details>
