QualDerm Partners Data Breach Affects 3.1 Million Patients

QualDerm Partners, a provider of healthcare management services to almost 160 dermatology practices, has reported a data breach to the Oregon Attorney General that has affected more than 3.1 million patients.

QualDerm Partners works with dermatology and skin care practices in 17 U.S. states. On December 24, 2025, anomalous activity was identified within its computer network. Steps were taken to secure its systems to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the activity. The forensic investigation confirmed that a threat actor had access to its network from December 23, 2025, to December 24, 2025.

QualDerm Partners has been reviewing the exposed data and has confirmed that, for the majority of affected individuals, the compromised data included their name, date of birth or date of death, email address, diagnosis, treatment information, medical record number, and health insurance information. A small number of individuals may also have had their driver’s license number or another government identification number compromised in the incident.

QualDerm Partners said it was unaware of any misuse of the affected data at the time of issuing notification letters on February 22, 2026; however, as a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. The data breach is not yet shown on the HHS’ office for Civil Rights breach portal, so it has yet to be confirmed how many individuals’ protected health information was compromised.

The QualDerm Partners data breach is one of several million-record-plus data breaches to be confirmed this year. TriZetto Provider Solutions, a business associate of many HIPAA-covered entities, has experienced a similarly-sized data breach, affecting more than 3.4 million individuals. The University of Hawai’i Cancer Center has experienced a breach affecting up to 1.15 million individuals, and a massive data breach has affected the business associate Conduent Business Services. The latter has affected more than 25 million individuals.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/