Michael R. Schwartz, MD Inc. Data Breach
Michael R. Schwartz, MD Inc. Confirms Desktop Computer Breach
What happened in the Michael R. Schwartz, MD Inc. data breach?
The Michael R. Schwartz, MD Inc. data breach was reported on October 23, 2025 and affected 9,080 individuals. The breach type was Hacking/IT Incident involving Desktop Computer. This breach occurred in California. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Michael R. Schwartz, MD Inc. Breach Details
Healthcare Data Breach Report: Michael R. Schwartz, MD Inc.
Breach Overview
Michael R. Schwartz, MD Inc., a California-based medical practice, discovered and reported a data breach affecting 9,080 individuals on October 23, 2025. The breach resulted from a hacking or IT incident that compromised a desktop computer within the organization's network infrastructure. This incident represents a significant unauthorized access event that exposed protected health information (PHI) and potentially other sensitive patient data maintained by the medical practice. The breach was classified as a hacking/IT incident, indicating that external threat actors or malicious software gained unauthorized access to systems containing patient records.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach submission, though the entity filed notification with state authorities on October 23, 2025, in compliance with California's breach notification law and HIPAA requirements. Upon discovery of the unauthorized access, Michael R. Schwartz, MD Inc. initiated an investigation to determine the scope of the compromise, identify affected individuals, and assess what data had been accessed. The organization was required to notify affected patients without unreasonable delay, and no later than 60 days following discovery of the breach, as mandated by HIPAA's Breach Notification Rule. The fact that notification was submitted in October 2025 indicates the organization moved to comply with these federal and state requirements promptly.
Technical Details of the Incident
Specific Details
The breach involved a desktop computer, which typically represents a single workstation or endpoint device within the medical practice's network. Desktop computers in healthcare settings often contain cached patient data, electronic health records (EHR) accessed through web portals or client applications, and may store local copies of sensitive documents. The hacking or IT incident classification suggests several possible breach vectors: malware infection (such as ransomware, spyware, or trojans), exploitation of unpatched software vulnerabilities, credential compromise through phishing or brute-force attacks, or unauthorized remote access through compromised credentials or exposed remote desktop protocol (RDP) services.
Desktop computers are frequently targeted in healthcare breaches because they may have weaker security controls compared to centralized servers, users may have administrative privileges that expand the scope of accessible data, and endpoint protection may be inconsistently applied across the organization. The fact that this was a single desktop computer suggests the breach may have been limited in scope compared to network-wide compromises, though the number of affected individuals (9,080) indicates the compromised system had access to a substantial patient database or multiple patient records.
Organizational Context
Michael R. Schwartz, MD Inc. operates as a medical practice in California, likely providing direct patient care services. The organization's size, based on the number of affected individuals, suggests it maintains records for thousands of patients, indicating either a multi-provider practice, a practice with significant patient volume, or a practice that has accumulated records over many years of operation. As a California-based entity, the organization is subject to California's strict data breach notification law (California Civil Code Section 1798.82), which requires notification of any breach of unencrypted personal information, in addition to HIPAA requirements applicable to all covered entities and business associates.
The absence of a business associate involvement in this breach indicates that the compromised data was directly accessible through the medical practice's own systems rather than through a third-party vendor or service provider. This suggests the organization bears direct responsibility for the security of the affected systems and the notification obligations to patients.
Patient Impact and Affected Individuals
Number of People Affected
Approximately 9,080 individuals had their protected health information potentially compromised in this incident. This represents a substantial patient population and indicates the desktop computer had access to a significant portion of the practice's patient database. All affected individuals were required to receive breach notification letters detailing the incident, the types of information compromised, steps they should take to protect themselves, and contact information for the organization and credit monitoring resources if applicable.
Personal Information Involved
While the specific data elements exposed were not enumerated in the breach submission, desktop computers in medical practices typically contain or provide access to: patient names, dates of birth, Social Security numbers, medical record numbers, insurance information, addresses and contact information, medical histories and diagnoses, treatment records and clinical notes, medication lists, laboratory and imaging results, and potentially financial or billing information. The actual scope of exposed data depends on what information was stored locally on the compromised desktop, what data was accessible through applications running on that system, and what network resources the compromised system could reach.
HIPAA and Regulatory Context
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities must notify affected individuals of breaches of unsecured PHI. The rule defines a breach as unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Hacking incidents are presumed to be breaches unless the covered entity can demonstrate, through a risk assessment, that there is a low probability that the PHI has been compromised. Given that 9,080 individuals were notified, Michael R. Schwartz, MD Inc. determined that the risk of compromise was sufficient to warrant notification.
California's breach notification law is more stringent than HIPAA in some respects, requiring notification of breaches of "personal information" (a broader category than HIPAA's PHI) and requiring notification without unreasonable delay. The state law also requires notification to the California Attorney General if more than 500 California residents are affected, which appears to apply in this case. Healthcare data breaches involving hacking or IT incidents represent a significant portion of reported breaches nationally, with the U.S. Department of Health and Human Services Office for Civil Rights reporting that hacking incidents consistently account for a substantial percentage of breaches affecting large numbers of individuals.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Michael R. Schwartz, MD Inc. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review medical bills and explanation of benefits (EOB) statements carefully for unauthorized services or charges. Contact your insurance provider and healthcare providers immediately if you identify suspicious activity.
Monitor financial accounts, including bank accounts and credit cards, for unauthorized transactions. Set up account alerts with your financial institutions to notify you of unusual activity.
Consider enrolling in credit monitoring and identity theft protection services if offered by the organization or through your insurance. Many breaches include complimentary monitoring for affected individuals.
Change passwords for any online healthcare portals, insurance accounts, and related services, using strong, unique passwords. Enable multi-factor authentication where available.
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies. Verify any requests for personal information by contacting the organization directly using known contact information.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your identity has been compromised, and consider filing a police report for documentation purposes.
Contact Michael R. Schwartz, MD Inc. directly to confirm what specific information was exposed in your case and to inquire about available remediation services or credit monitoring programs.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More California Breaches
Search all breaches reported in California