Data breach
Sunflower Medical Group
- Records
- 356,822
- Breach date
- 7 January 2025Estimated
- Added
- 12 March 2025
What was exposed
9 types of data · 3 more reported · 2 put you at serious risk
- Account balances1
- Doctors' names1
- Email addresses1
- Government IDs1
- Home addresses1
- Insurance providers1
- Medical diagnoses1
- Phone numbers1
- Social security numbers1
- Driving licence numbersReported, not counted
- NamesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Sunflower Medical Group, a Kansas-based multi-specialty medical practice with locations in the Kansas City metro area, confirmed a data breach after an intruder accessed its network for roughly three weeks and copied files containing patient information. According to the company's own incident notice, suspicious activity was detected on January 7, 2025, and an investigation found that an unknown third party had gained access to its systems on or about December 15, 2024. Our investigation team's index for this listing contains 356,822 records and estimates the attack date as January 7, 2025. The company reported 220,968 affected individuals to the Maine Attorney General's Office, a figure cited in reporting by The Register. The Rhysida ransomware group claimed responsibility the same day Sunflower detected the intrusion, according to The Register, though our investigation team's listing does not record a confirmed claiming actor for this breach.
December 15, 2024: An unauthorized third party gained access to Sunflower Medical Group's systems, per the company's incident notice.
January 7, 2025: Sunflower detected the suspicious activity and began an investigation. The Register reported that the Rhysida ransomware gang claimed responsibility the same day.
March 7, 2025: Notification letters were mailed to affected individuals, according to reporting by the HIPAA Journal.
2026: The HIPAA Journal reported that Sunflower agreed to pay up to $1.2 million to settle a consolidated class action lawsuit over the breach.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, email addresses, phone numbers, government ID numbers, account balances, doctor names, home addresses, medical diagnoses, and insurance provider information.
Sunflower's own incident notice states that the affected files may have included one or more of the following, varying by individual: names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical information, and health insurance information.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers, dates of birth, and medical information is among the most sensitive data combinations that can leak in a breach. It can enable identity theft, fraudulent credit applications, tax fraud, and medical identity theft, in which someone uses your insurance or medical identity to receive care. Stolen health insurance details can also be used in scam calls and phishing emails that impersonate insurers or medical offices. The Rhysida gang, per The Register, listed a large volume of data for download after ransom demands went unmet, meaning patient files were published online. Sunflower has stated it has no evidence the information has been misused, but absence of confirmed misuse does not mean risk has passed, particularly with medical data that retains value for years.
What Is Sunflower Medical Group Doing in Response?
According to the company's notice, Sunflower engaged a cybersecurity firm, mailed notification letters to individuals with valid addresses, and offered complimentary identity theft protection services to people whose Social Security numbers or driver's license numbers were involved. The company says it has no evidence of misuse and has advised vigilance. The HIPAA Journal reports that class action lawsuits were consolidated in Missouri state court and that Sunflower agreed to a settlement of up to $1.2 million, including two years of medical data monitoring for class members, while denying wrongdoing. The HHS Office for Civil Rights reviewed the incident and closed its inquiry without a financial penalty, per that report.
What Should You Do If You Were Affected?
Review the notification letter you received and enroll in any offered identity protection services before their deadlines. Check your credit reports at annualcreditreport.com and watch bank, insurance, and medical statements for unfamiliar activity. Place a fraud alert or credit freeze with the three credit bureaus if you prefer. Report suspected medical identity theft to your insurer and to the FTC at ftc.gov/idtheft. If you believe you were affected but received no letter, contact Sunflower's inquiry line listed on its incident page.
In the news
- Sunflower Medical Group Data Security Incident Noticesunflowermed.com (opens in a new tab)
- The Register: Two Rhysida healthcare attacks pwned 300K patients' datatheregister.com (opens in a new tab)
- HIPAA Journal: Sunflower Medical Group to Pay Up to $1.2 Million to Settle Class Action Data Breach Lawsuithipaajournal.com (opens in a new tab)
