SecurityAugust 4, 20269 min read

What to Do After the McLaren Health Care Data Breach

PT

By PrivacyOn Team

Privacy Research & Removal Operations

What to Do After the McLaren Health Care Data Breach

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

McLaren Health Care confirmed that a 2024 ransomware attack — disclosed in mid-2025 and finalized through a $14 million class action settlement in 2026 — exposed the personal and medical information of 743,131 patients. Names, Social Security numbers, medical records, and health insurance details were compromised. If you have ever been a McLaren patient, take action now to protect your identity and finances.

What Happened in the McLaren Breach?

The INC ransomware group attacked McLaren Health Care between July 17 and August 3, 2024. McLaren discovered the intrusion on August 5, 2024, after suspicious activity was flagged on systems belonging to McLaren and its Karmanos Cancer Institute. The forensic review took nearly a year — McLaren completed victim identification on May 5, 2025, and began mailing notifications to 743,131 individuals.

This was McLaren's second major ransomware breach in as many years. In November 2023, the Alphv/BlackCat ransomware gang breached the same network, affecting 2.2 million people. In 2026, a federal court granted final approval to a $14 million class-action settlement covering both incidents.

What Information Was Exposed?

According to McLaren's disclosures, the breached files may have contained:

  • Full names
  • Social Security numbers
  • Dates of birth
  • Medical record numbers and diagnostic information
  • Health insurance and billing details
  • Prescription and treatment information

Because the breach includes both financial identifiers (SSNs, insurance data) and Protected Health Information (PHI), the potential downstream damage is more severe than a typical email-only breach. Medical identity theft is harder to detect and can take years to unwind.

Two Breaches, Same Network

If you were a McLaren patient before or during 2023-2024, your data may have been exposed in both the 2023 BlackCat attack (2.2 million people) and the 2024 INC ransomware attack (743,131 people). Assume all identifiers were compromised and act accordingly.

How to Check if You Were Affected

  1. Check your mail: McLaren mailed breach notifications throughout mid-to-late 2025. Check your paper mail — including anything you might have set aside as junk — for a letter from McLaren Health Care about the incident.
  2. Confirm with McLaren: McLaren set up a dedicated call center to answer patient questions. If you believe you were a patient but never received a letter, call McLaren's breach response line to confirm your status.
  3. Activate the free credit monitoring: Notification letters include an activation code for 12 months of complimentary credit monitoring. Enroll immediately — the code expires.
  4. Check Have I Been Pwned: Enter every email address you use at haveibeenpwned.com to see if it appears in any related breach dumps.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Steps to Protect Yourself Right Now

1. Place a Free Credit Freeze

Because Social Security numbers were exposed, freeze your credit at all three bureaus — Equifax, Experian, and TransUnion. A freeze prevents anyone from opening new credit accounts in your name. It is free, takes about 15 minutes online, and can be temporarily lifted anytime you legitimately need credit.

2. Enroll in the 12-Month Free Credit Monitoring

McLaren is providing 12 months of complimentary credit monitoring through the notification letter. Activate it — but treat it as a baseline, not full protection. It only covers 12 months, and stolen data has an indefinite shelf life on the dark web.

3. Watch for Medical Identity Theft

Unlike financial identity theft, medical identity theft can take years to detect. Review your Explanation of Benefits (EOB) statements from your health insurer for services or prescriptions you did not receive. Request an itemized statement of medical services from your insurer at least once a year. Report anomalies to both your insurer and the provider immediately.

4. Enable Two-Factor Authentication

Turn on 2FA — using an authenticator app rather than SMS — on your email, bank, patient portal, and any other sensitive accounts. This adds a critical layer of protection even if a password gets compromised.

5. Beware of Targeted Phishing

Attackers exploiting healthcare breaches often send fake "free credit monitoring" or "lawsuit settlement" emails and texts. Never click links in unexpected messages. To sign up for the real monitoring, use the code and URL printed in your paper notification letter, or go directly to McLaren's official website.

Protect Family Members Who Were Patients

If your children, elderly parents, or spouse were McLaren patients, their data was also exposed. Place credit freezes for adult family members, and consider a credit freeze on minor children — Experian, Equifax, and TransUnion all allow you to freeze a minor's credit file by mail.

6. File Your Taxes Early

SSN theft is often used for tax refund fraud. File your federal and state tax returns as early as possible each year and consider requesting an IRS Identity Protection PIN (IP PIN) — a six-digit code that must be included on your return.

7. Remove Your Information From Data Brokers

Attackers combine breach data with information from data broker sites — home addresses, phone numbers, relatives, employment history — to build convincing social engineering attacks. Reducing your exposure across 100+ people-search sites makes it harder to target you.

The Bigger Picture: Healthcare Ransomware Is a Long-Term Threat

Healthcare organizations remain the most-targeted sector for ransomware in 2026. INC, BlackCat, and other groups specifically target hospitals because the sensitivity of patient data and the operational urgency of medical care create pressure to pay ransoms. McLaren's back-to-back breaches — and $14 million settlement — are the pattern, not the exception.

Consumers cannot prevent healthcare providers from being breached, but you can limit the downstream damage. Credit freezes, 2FA, EOB review, and reducing your public data footprint all shrink the attack surface criminals use once your information leaks.

How PrivacyOn Can Help

PrivacyOn helps limit the fallout from healthcare breaches like McLaren's:

  • Dark web monitoring alerts you when your SSN, email, phone, or other identifiers appear in breach dumps or dark web marketplaces
  • Data broker removal from 100+ people-search sites that criminals cross-reference with breach data to target victims
  • 24/7 continuous monitoring with automatic re-removal when your data reappears
  • Family plans covering up to 5 people — critical when multiple family members were McLaren patients

Protect Yourself After the McLaren Breach

PrivacyOn's dark web monitoring and data broker removal help contain the long-tail damage from healthcare breaches. Plans start at $8.33/month with family coverage available. Get protected today.

Frequently Asked Questions

How many people were affected by the McLaren Health Care data breach?

McLaren notified 743,131 individuals about the 2024 ransomware attack. A separate 2023 ransomware attack on the same network affected 2.2 million people. Combined, more than 2.9 million patient records have been compromised across the two incidents.

What data was exposed in the McLaren breach?

Compromised information may include full names, Social Security numbers, dates of birth, medical record numbers, diagnostic and treatment information, health insurance details, and billing information. The combination of financial identifiers and Protected Health Information makes this breach unusually severe.

Am I eligible for the McLaren data breach settlement?

A $14 million class-action settlement received final approval in 2026 covering the 2023 and 2024 McLaren breaches. Eligibility, claim deadlines, and payout tiers are outlined in the official settlement notice. Only file claims through the court-approved settlement administrator — scammers frequently impersonate settlement sites.

Is the free credit monitoring from McLaren enough?

No. Twelve months of credit monitoring only alerts you to changes on your credit file for one year, while stolen SSNs and health data can be exploited for a decade or more. Combine McLaren's free monitoring with a permanent credit freeze at all three bureaus, an IRS IP PIN, dark web monitoring, and data broker removal for stronger long-term protection.

What is medical identity theft and how do I detect it?

Medical identity theft happens when someone uses your name and insurance to obtain medical services, prescriptions, or file fraudulent claims. Signs include unfamiliar entries on your Explanation of Benefits, denials of coverage for care you didn't receive, and collection notices for unfamiliar medical bills. Review every EOB and request an annual itemized statement from your insurer.

How can I remove my personal information from data brokers?

You can manually opt out site-by-site, or use a service like PrivacyOn that automatically removes your data from 100+ people-search sites and monitors for reappearance. Because breach data is combined with data broker records to target victims, reducing your broker footprint is one of the highest-value defenses after a healthcare breach.

PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families