Breach report
HealthcareYale New Haven Health
Yale New Haven Health data breach affects 5.5 million patients
Hackers stole files from Connecticut's largest health system, exposing Social Security numbers and demographic details for about 5.5 million patients and leading to an $18 million class-action settlement.
Reported by BleepingComputer
Records exposed
5.6M
About 5.56 million patients
Scale vs. largest on file
- When
- 2025
- How they got in
- Network intrusion and data exfiltration
- Sector
- Healthcare
On March 8, 2025, Yale New Haven Health, Connecticut's largest health system and an affiliate of Yale University, detected unusual activity on its network. It publicly acknowledged a cybersecurity incident three days later and brought in Mandiant to investigate. By mid-April, the system confirmed that an unauthorized third party had copied patient data, and it began mailing notification letters. The system operates Yale New Haven Hospital along with Bridgeport, Greenwich, Lawrence + Memorial and Westerly hospitals, serving patients across Connecticut and western Rhode Island.
The health system reported to federal regulators that about 5.56 million people were affected, making it one of the largest healthcare breaches of 2025. The stolen files contained names, dates of birth, addresses, phone numbers, email addresses, race and ethnicity, Social Security numbers for some patients, patient type and medical record numbers. Yale New Haven Health said its electronic medical record system was not accessed and that financial and payment information and clinical records were not involved. Patient care continued without major disruption.
The organization did not disclose how the attacker got in, and no ransomware group publicly claimed responsibility at the time of disclosure. The breach nonetheless drew immediate legal action. Lawsuits were filed within weeks, and 18 complaints were consolidated in mid-2025. In late August, the parties reached an agreement through mediation, and in October 2025 a court granted preliminary approval of an $18 million settlement offering reimbursement of documented losses of up to $5,000, alternative cash payments and medical data monitoring.
The incident fits a broader pattern of attackers targeting large regional hospital systems for data they can resell or use for extortion. Even without clinical notes, a combination of Social Security numbers, birthdates and medical record numbers is valuable for identity theft and for convincing phishing attacks that impersonate providers or insurers.
For health systems, the settlement is a reminder that the costs of a breach extend well beyond forensic response, into multiyear litigation and monitoring obligations. For patients, it reinforces standard post-breach steps: freezing credit, watching insurance statements for unfamiliar services, and treating unexpected calls or emails about medical bills with caution.