Data breach
Kentfield Hospital
- Records
- 10,174
- Breach date
- 15 July 2025Estimated
- Added
- 24 June 2026
What was exposed
9 types of data · 3 more reported · 2 put you at serious risk
- Names10,174
- Phone numbers3,412
- Email addresses1,885
- Street addresses775
- Social security numbers601
- Passport numbers232
- Dates of birth177
- Licence plates2
- Home addresses1
- Medical recordsReported, not counted
- Medical diagnosesReported, not counted
- Insurance detailsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Kentfield Hospital, a critical access hospital in Marin County, California, appears to have been the victim of a data theft and extortion attack in mid-2025. According to DataBreaches.net, a group calling itself World Leaks added the hospital to its leak site on July 5, 2025, claiming to have exfiltrated 146.4 gigabytes of data across 140,683 files. DataBreaches.net reviewed a sample of the tranche and confirmed it contained detailed patient files, including admissions, treatment, and discharge records for named patients, plus more than 28,000 photographs taken to document wound care. World Leaks is described by HIPAA Journal as a data theft and extortion group believed to include former members of the Hunters International ransomware operation. The investigation team estimates the attack occurred on July 15, 2025, and has not confirmed a claiming actor, though external reporting attributes the incident to World Leaks. Neither Kentfield Hospital nor its operator, Vibra Healthcare, had confirmed a breach in the coverage reviewed, and our team found no confirmation of a company notice as of September 25, 2026.
Breach Timeline
July 5, 2025: The World Leaks group lists Kentfield Hospital on its leak site, claiming 146.4 GB of stolen data. DataBreaches.net previews the files and confirms patient information is present.
July 9, 2025: The law firms Schubert Jonckheer & Kolbe and Strauss Borrelli PLLC announce investigations into the incident.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (10,174 records), phone numbers (3,412), email addresses (1,885), street addresses (775), Social Security numbers (601), passport numbers (232), dates of birth (177), and vehicle license plates (2). The number of home addresses present could not be determined.
Not every individual is affected by every type of data listed here.
The stolen files reviewed by DataBreaches.net reportedly went further, containing medical record numbers, financial record numbers, diagnoses, medications, care information, and test results. That review also noted hundreds of health insurance and billing files, admissions folders covering 2020 through early 2022, and patient-related files from 2023 and 2024, including complaint investigations and quality reviews initiated by the Centers for Medicare & Medicaid Services. Some employee records, including a new-hire file with names, roles, and birth dates, were also spotted, though DataBreaches.net reported finding no Social Security numbers or W-2 data in that tranche.
What Are the Potential Risks for Affected Individuals?
Medical records are hard to change. A Social Security number, birth date, and address can be used to open fraudulent accounts, file fake tax returns, or commit medical identity theft, where someone receives care under your identity and corrupts your medical file. Photographs of patients tied to their names carry a separate, personal privacy harm if published. The combination of diagnoses with contact details also creates openings for convincing phishing scams that reference real treatment information. Because the data had not been publicly leaked in the reporting reviewed, the practical risk depends heavily on what the group does with it next.
What Should You Do If You Were Affected?
Check whether you have any connection to Kentfield Hospital or Vibra Healthcare facilities and whether you received any notice. If you may have been a patient, take these steps:
Place a free fraud alert or credit freeze with the three major credit bureaus: Equifax, Experian, and TransUnion.
Review your medical and insurance statements for care you did not receive, and dispute anything unfamiliar with the provider and your insurer.
Order your free credit reports and watch for new accounts or inquiries you did not initiate.
Be cautious with unexpected calls, texts, or emails that reference your health care. Do not share personal details in response.
If you believe your information was misused, you can file a complaint with the federal Office for Civil Rights and report identity theft at IdentityTheft.gov.
In the news
- DataBreaches.net: Kentfield Hospital victim of cyberattack by World Leaksdatabreaches.net (opens in a new tab)
- HIPAA Journal: Surmodics & Kentfield Hospital Fall Victim to Cyberattackshipaajournal.com (opens in a new tab)
- PR Newswire: Kentfield Hospital Under Investigation for Data Breach of Patient Recordsprnewswire.com (opens in a new tab)
- Strauss Borrelli PLLC: Kentfield Hospital Data Security Investigationstraussborrelli.com (opens in a new tab)
