Hampton Regional Medical Center
Disclosed Sep 12, 20251 year ago501 affectedConfirmed
The covered entity (CE), Hampton Regional Medical Center, reported that it was the target of a cybersecurity incident that affected the protected health information (PHI) 37,591 individuals. The PHI involved included clinical and demographic information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.
What is known
| People affected | 501 (as reported to HHS) |
|---|---|
| Disclosed | Sep 12, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Vermont Attorney General: 2026-03-04 Hampton Regional Medical Center Data Breach Notice to Consumersago.vermont.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Hampton Regional Medical Center (Healthcare Provider, SC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 12, 2025 | 501 |
| Vermont AGresidents of VT | Mar 4 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 501 · backfill source
- 2026-09-25 · disclosed: 2026-03-04 to 2025-09-12 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Hampton Regional Medical Center, reported that it was the target of a cybersecurity incident that affected the protected health information (PHI) 37,591 individuals. The PHI involved included clinical and demographi · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Vermont AG), confirmed by Vermont AG. Record counts are as reported. Not legal advice.