Docs Medical Group, Inc. dba Pulse Urgent Care Data Breach
Pulse Urgent Care Network Server Breach Affects 4,035 Patients
What happened in the Docs Medical Group, Inc. dba Pulse Urgent Care data breach?
The Docs Medical Group, Inc. dba Pulse Urgent Care data breach was reported on December 28, 2025 and affected 4,035 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in California. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Docs Medical Group, Inc. dba Pulse Urgent Care Breach Details
Pulse Urgent Care Network Server Breach Report
Incident Overview
Docs Medical Group, Inc., operating as Pulse Urgent Care, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was reported to the California Attorney General on December 28, 2025, affecting 4,035 individuals across the organization's patient population. This incident represents a hacking or IT-related compromise of the urgent care provider's networked systems, where patient protected health information (PHI) may have been accessed by unauthorized threat actors. The breach occurred at the network server level, indicating that attackers gained entry to centralized systems where patient records and associated data are typically stored and processed.
Discovery and Response Timeline
While specific details regarding the initial discovery date are not provided in the breach submission, Pulse Urgent Care's notification to the California Attorney General on December 28, 2025, indicates that the organization completed its investigation and determined notification was necessary within the timeframe required by California law and HIPAA regulations. The entity's response protocol likely included forensic investigation of the compromised network infrastructure, identification of affected individuals, and preparation of notification materials required under California's data breach notification law (CA Civil Code § 1798.82) and the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414). The organization would have been required to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach, as mandated by HIPAA.
Technical Breach Details
Network server breaches typically occur through one or more attack vectors, including exploitation of unpatched software vulnerabilities, weak authentication credentials, phishing attacks targeting employee credentials, or misconfigured access controls. The fact that this breach occurred at the network server level—rather than at individual workstations or through physical theft—suggests that attackers gained unauthorized access to centralized systems that house patient records, appointment information, billing data, and clinical documentation. This type of compromise is particularly concerning because a single successful intrusion can expose data for numerous patients simultaneously. Network server breaches in healthcare settings often involve sophisticated threat actors who may use techniques such as lateral movement within the network, privilege escalation, and data exfiltration tools to access and remove sensitive information. The breach may have persisted for an unknown duration before detection, potentially allowing extended unauthorized access to patient information.
Organizational Context
Pulse Urgent Care, operating under the parent entity Docs Medical Group, Inc., is an urgent care provider based in California. Urgent care facilities typically serve patients requiring immediate medical attention for non-life-threatening conditions, offering services such as minor injury treatment, acute illness management, diagnostic testing, and basic preventive care. These organizations maintain comprehensive electronic health records (EHRs) containing detailed patient information necessary for clinical care delivery. As a healthcare provider subject to HIPAA regulations, Pulse Urgent Care is required to implement administrative, physical, and technical safeguards to protect patient PHI. The breach indicates that despite these regulatory requirements, the organization's network security infrastructure was compromised, allowing unauthorized access to patient data. The organization's service area encompasses California, with the breach affecting patients across its operational footprint.
Patient Impact and Affected Population
Approximately 4,035 individuals were affected by this breach, representing patients who received care at Pulse Urgent Care facilities and whose information was stored on the compromised network servers. The affected population likely includes both current and former patients whose records remained accessible within the organization's systems. These individuals would have been notified of the breach through written notification letters sent by Pulse Urgent Care, as required by HIPAA and California law. The notification would have included details about the breach, the types of information potentially exposed, steps the organization is taking to address the incident, and recommended actions patients should take to protect themselves. Patients affected by this breach should have received information about complimentary credit monitoring or identity theft protection services, which are typically offered by healthcare organizations following data breaches involving sensitive personal information.
Protected Health Information Exposed
Given the nature of a network server breach at an urgent care facility, the compromised data likely includes multiple categories of PHI. This typically encompasses patient names, dates of birth, Social Security numbers, medical record numbers, insurance information including policy numbers and group numbers, clinical information from patient visits, diagnoses and treatment records, medication lists, and potentially financial account information used for billing purposes. Depending on the scope of the network compromise, the breach may have also exposed contact information such as addresses and telephone numbers, emergency contact details, and employment information. The specific data elements exposed would depend on what information was stored on the compromised server and what access the attackers obtained during their unauthorized access period.
HIPAA Compliance and Regulatory Context
Under the HIPAA Breach Notification Rule, a breach is defined as the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of such information. Healthcare providers must conduct a risk assessment to determine whether a breach has occurred and, if so, must notify affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of Health and Human Services. Network server breaches represent a significant category of healthcare data breaches, accounting for a substantial portion of reported incidents in recent years. According to HHS Office for Civil Rights data, hacking and IT incidents remain among the most common causes of healthcare data breaches, often affecting larger numbers of individuals than other breach types due to the centralized nature of network systems. The healthcare industry continues to experience increasing sophistication in cyber attacks, with threat actors targeting healthcare providers specifically due to the high value of medical records and the critical nature of healthcare operations.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Docs Medical Group, Inc. dba Pulse Urgent Care Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized services or claims. Contact your insurance provider and healthcare providers immediately if you identify suspicious activity.
Change passwords for any online accounts associated with Pulse Urgent Care or your insurance provider, using strong, unique passwords that are not reused across multiple accounts.
Enroll in complimentary credit monitoring and identity theft protection services offered by Pulse Urgent Care following the breach. Monitor these services actively for alerts indicating suspicious activity.
Consider placing a security freeze with credit bureaus to prevent unauthorized access to your credit file, and monitor your Social Security number usage through the Social Security Administration's online account.
Be vigilant against phishing emails and suspicious communications claiming to be from Pulse Urgent Care, your insurance provider, or financial institutions. Do not click links or provide information in response to unsolicited communications.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and consider filing a police report for documentation purposes.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More California Breaches
Search all breaches reported in California