Heartland Regional Medical Center d/b/a Mosaic Life Care Data Breach
Mosaic Life Care Network Server Breach Affects 145K Patients
What happened in the Heartland Regional Medical Center d/b/a Mosaic Life Care data breach?
The Heartland Regional Medical Center d/b/a Mosaic Life Care data breach was reported on June 27, 2025 and affected 145,269 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Heartland Regional Medical Center d/b/a Mosaic Life Care Breach Details
Heartland Regional Medical Center Data Breach Report
Incident Overview
Heartland Regional Medical Center, operating under the name Mosaic Life Care in Missouri, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was reported to the U.S. Department of Health and Human Services on June 27, 2025, affecting approximately 145,269 individuals. This incident represents a substantial compromise of patient privacy and protected health information (PHI) stored within the organization's networked systems. The breach occurred through hacking or IT-related unauthorized access, indicating that threat actors successfully penetrated the organization's network security perimeter and gained access to sensitive patient data stored on network servers.
Discovery and Response Timeline
The specific discovery date and investigation timeline have not been publicly detailed in available breach notification records, though the June 27, 2025 submission date indicates the organization completed its investigation and notification process by that time. Upon discovery of the unauthorized access, Mosaic Life Care initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what categories of protected health information were compromised. The organization's response included notification to affected patients as required under the HIPAA Breach Notification Rule, which mandates that covered entities notify individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. The involvement of a business associate in this breach suggests that the compromised data may have included information processed or stored by a third-party vendor or service provider, requiring coordinated notification efforts between the primary entity and its business associate.
Technical Breach Details
Network Server Compromise
The breach location identified as "Network Server" indicates that the unauthorized access occurred at the infrastructure level rather than through a single endpoint or application. Network server breaches typically result from one or more of the following vectors: exploitation of unpatched software vulnerabilities, compromise of administrative credentials, misconfigured access controls, or successful phishing attacks targeting employees with network access privileges. Hackers who gain access to network servers can potentially access multiple systems and databases simultaneously, which explains the large number of affected individuals. The fact that this breach affected over 145,000 patients suggests the compromised server(s) contained centralized patient records, billing information, or other consolidated databases rather than isolated departmental systems. Network-level breaches are particularly concerning because they may provide threat actors with access to the organization's entire IT infrastructure, potentially including backup systems, administrative tools, and multiple applications that store or process PHI.
Organizational Context
Mosaic Life Care (operating as Heartland Regional Medical Center) is a healthcare delivery organization based in Missouri providing inpatient and outpatient services to patients across the region. As a regional medical center, the organization likely operates multiple clinical departments, emergency services, surgical facilities, and ancillary services such as laboratory, imaging, and pharmacy operations. The scale of the breach—affecting 145,269 individuals—indicates this is a substantial healthcare system with significant patient volume and extensive electronic health record (EHR) systems. The involvement of a business associate suggests the organization utilizes third-party vendors for services such as billing and claims processing, IT infrastructure management, data analytics, or other healthcare support functions. Regional medical centers of this size typically maintain complex IT environments with multiple interconnected systems, which can create both operational efficiency and security challenges.
Patient Impact and Affected Population
Number of Individuals Affected
Approximately 145,269 patients and individuals had their protected health information potentially compromised in this breach. This substantial number indicates the breach affected a significant portion of the organization's patient population, likely spanning multiple years of patient records. The affected individuals may include current patients, former patients, and potentially individuals who received services at any of the organization's facilities during the period when the compromised server(s) were accessible to unauthorized parties.
Personal Information Involved
While the specific data elements compromised have not been detailed in publicly available breach notification records, network server breaches at regional medical centers typically expose multiple categories of protected health information, potentially including:
- Full names and contact information (addresses, phone numbers, email addresses)
- Social Security numbers and other government-issued identification numbers
- Date of birth and demographic information
- Medical record numbers and patient account numbers
- Insurance information and policy numbers
- Clinical information including diagnoses, treatment plans, and medication records
- Laboratory and imaging results
- Billing and payment information
- Emergency contact information
- Employment information
- Healthcare provider information and clinical notes
The exposure of this combination of data elements creates significant risk for identity theft, medical fraud, and other forms of misuse.
HIPAA Compliance and Regulatory Context
Under the Health Insurance Portability and Accountability Act (HIPAA), covered entities and business associates are required to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). The Security Rule specifically requires organizations to implement access controls, encryption, audit controls, and integrity controls to prevent unauthorized access to networked systems. This breach indicates that one or more of these required safeguards may have been insufficient to prevent the unauthorized access. The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of Health and Human Services. Given that this breach affected 145,269 individuals across Missouri, media notification requirements were likely triggered. The organization may face investigation by the HHS Office for Civil Rights (OCR) to determine whether appropriate safeguards were in place and whether the breach was preventable through reasonable security measures.
Recommended Patient Actions
Patients affected by this breach should take immediate steps to protect their personal information and monitor for signs of misuse. The organization typically provides affected individuals with complimentary credit monitoring and identity theft protection services for a specified period (commonly 12-24 months). Patients should enroll in these services promptly and maintain vigilance for suspicious activity.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Heartland Regional Medical Center d/b/a Mosaic Life Care Breach
Enroll immediately in the complimentary credit monitoring and identity theft protection services offered by Mosaic Life Care. These services typically include credit monitoring, fraud alerts, and identity theft insurance. Follow the enrollment instructions provided in the breach notification letter.
Place a fraud alert with the three major credit bureaus (Equifax, Experian, and TransUnion) by contacting one bureau, which will notify the others. A fraud alert requires creditors to verify your identity before opening new accounts. Consider placing a credit freeze if you prefer to restrict access to your credit report entirely.
Monitor your credit reports regularly for suspicious activity. You are entitled to one free credit report annually from each of the three major bureaus at annualcreditreport.com. Review these reports carefully for accounts or inquiries you do not recognize and report any suspicious activity immediately.
Monitor your medical records and insurance statements for unauthorized charges, fraudulent claims, or incorrect information. Contact your healthcare providers and insurance company immediately if you identify any suspicious activity. Request copies of your medical records to verify their accuracy.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits