In March 2025, College Hospital Costa Mesa revealed that a forensic investigation into a 2024 data breach uncovered that additional patients were impacted.
College Hospital Costa Mesa (CHCM) recently revealed they are investigating a breach. The breach occurred between August 14 and September 17, 2024, when a threat actor accessed hospital files containing sensitive patient information, including names, diagnoses, dates of birth, Social Security numbers, driver’s license numbers, and appointment details.
The hospital, a privately owned psychiatric and medical facility in California, has enlisted the Chicago-based law firm Strauss Borrelli PLLC to assess the extent of the breach and identify affected individuals. On March 10, 2025, College Hospital Costa Mesa began sending notification letters to impacted patients, offering complimentary identity monitoring services to those whose Social Security numbers were compromised.
The breach was first detected on September 17, 2024, when hospital officials noticed a security incident disrupting their operations. In response, CHCM immediately launched an investigation with the help of third-party cybersecurity experts to determine the nature and extent of the breach. The forensic review revealed that hackers had infiltrated hospital files containing sensitive patient data.
The hospital conducted a comprehensive assessment to identify the individuals affected, and by January 31, 2025, it confirmed the specific data types compromised. The breach prompted legal scrutiny, leading to investigations by Strauss Borrelli PLLC and Levi & Korsinsky, LLP, both of which are evaluating whether affected individuals may be entitled to compensation.
According to the notice, CHCM says they “remain committed to protecting the confidentiality and security of patient information, and apologize for the concern this may cause. We are offering complimentary identity monitoring services to patients whose Social Security numbers were involved. Additionally, it is always a good idea for patients to review statements they receive related to their healthcare provider or health insurer.”
Related: HIPAA Compliant Email: The Definitive Guide (2025 Update)
Data breaches in hospitals can occur due to various reasons such as:
Commonly compromised data includes:
Data breaches can divert resources away from patient care, impacting hospital productivity.