Horizon Healthcare RCM Data Breach
Horizon Healthcare RCM Network Server Breach Affects 210K+ Patients
What happened in the Horizon Healthcare RCM data breach?
The Horizon Healthcare RCM data breach was reported on June 27, 2025 and affected 210,901 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Indiana. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Horizon Healthcare RCM Breach Details
Horizon Healthcare RCM Data Breach Report
Breach Overview
Horizon Healthcare RCM, a revenue cycle management company operating in Indiana, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was reported to the U.S. Department of Health and Human Services on June 27, 2025, affecting 210,901 individuals. This incident represents a substantial compromise of protected health information (PHI) stored on the organization's networked systems, likely resulting from external threat actors exploiting vulnerabilities in the company's IT infrastructure or security controls.
Discovery and Response Timeline
The specific date of breach discovery was not disclosed in the available submission data, though the June 27, 2025 submission date indicates the organization had completed its investigation and notification process by that time. Standard HIPAA breach notification requirements mandate that covered entities and business associates notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. Horizon Healthcare RCM's submission to HHS suggests the organization initiated its incident response protocol, which typically includes forensic investigation, containment of affected systems, notification preparation, and regulatory reporting. The organization likely engaged cybersecurity forensics specialists to determine the scope of unauthorized access, identify the attack vector, and assess what specific data elements were compromised during the intrusion.
Technical Details of the Incident
The breach occurred on a network server, indicating that threat actors gained unauthorized access to centralized data storage systems rather than isolated endpoints or portable devices. Network server compromises typically result from one or more of the following vectors: exploitation of unpatched software vulnerabilities, credential compromise through phishing or brute-force attacks, misconfigured access controls, or supply chain vulnerabilities. Revenue cycle management companies like Horizon Healthcare RCM maintain extensive databases of patient information including names, dates of birth, medical record numbers, insurance information, and clinical data necessary for billing and claims processing. The fact that this breach affected over 210,000 individuals suggests the unauthorized access was not limited to a single patient record or small subset of data, but rather represented broad access to the organization's core patient database or multiple interconnected systems. Network server breaches of this magnitude typically indicate either a prolonged period of undetected access or a significant security incident that exposed multiple data repositories simultaneously.
Organizational Context and Operations
Horizon Healthcare RCM operates as a revenue cycle management (RCM) service provider, a critical function in the healthcare industry that handles patient billing, insurance claims processing, payment posting, and accounts receivable management. RCM companies serve as business associates to hospitals, physician practices, and other healthcare providers throughout Indiana and potentially across multiple states. These organizations maintain some of the most sensitive patient data in healthcare systems, including complete medical records, insurance information, financial data, and demographic details necessary for claims processing and patient billing. The scale of Horizon Healthcare RCM's operations—serving enough patients to accumulate records on over 210,000 individuals—indicates the company likely processes claims and maintains records for multiple healthcare facilities across the state. This distributed patient base means the breach's impact extends across numerous healthcare provider networks and potentially multiple insurance companies.
Patient Impact and Affected Population
The breach notification affected 210,901 individuals whose protected health information may have been accessed by unauthorized parties. These individuals likely include patients who received care at healthcare facilities that contracted with Horizon Healthcare RCM for revenue cycle management services. The compromised data may include names, dates of birth, medical record numbers, insurance policy numbers, claim information, diagnosis codes, procedure codes, and potentially Social Security numbers or financial account information used for payment processing. Patients affected by this breach may have received notification letters detailing the incident, the types of information compromised, and recommended protective actions. Under HIPAA requirements, Horizon Healthcare RCM was obligated to provide affected individuals with written notice describing the breach, the types of information involved, steps the organization is taking to investigate and mitigate the breach, and recommended actions patients should take to protect themselves. The organization likely also notified relevant media outlets and state health authorities given the large number of affected individuals.
Industry Context and HIPAA Implications
Network server breaches affecting healthcare data represent a persistent threat in the healthcare industry. According to HHS breach notification data, hacking and IT incidents constitute the largest category of healthcare data breaches by volume, accounting for the majority of incidents reported annually. Revenue cycle management companies face particular risk due to the centralized nature of their data repositories and their role as intermediaries between healthcare providers and insurance companies. HIPAA's Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). These safeguards include access controls, encryption, audit controls, and incident response procedures. The occurrence of this breach suggests potential gaps in Horizon Healthcare RCM's security infrastructure, whether through inadequate vulnerability management, insufficient access controls, weak authentication mechanisms, or delayed detection capabilities. Similar network server breaches in the healthcare RCM sector have affected hundreds of thousands of patients, underscoring the critical importance of strong cybersecurity investments in this sector. Patients affected by healthcare data breaches face elevated risks of identity theft, medical fraud, and insurance fraud, making proactive monitoring and protective measures essential.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Horizon Healthcare RCM Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements from your insurance company and medical bills from healthcare providers for unauthorized claims or services you did not receive. Contact your insurance company and healthcare providers immediately if you identify suspicious activity.
Monitor your bank and credit card statements for unauthorized transactions. Consider placing alerts with your financial institutions and reviewing account activity regularly for the next 12-24 months.
Be vigilant against phishing emails and calls claiming to be from healthcare providers, insurance companies, or financial institutions. Do not click links or provide personal information in response to unsolicited communications. Contact organizations directly using phone numbers from official websites.
Consider enrolling in credit monitoring or identity theft protection services, which may be offered free by Horizon Healthcare RCM as part of their breach response. These services can provide early warning of suspicious activity.
Document all communications related to the breach and keep copies of notification letters and any protective measures you implement. Maintain records of any fraudulent activity discovered.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you discover evidence of identity theft or fraud related to this breach.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Indiana Breaches
Search all breaches reported in Indiana
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits