California Cancer Associates for Research and Excellence Data Breach

California Cancer Associates for Research and Excellence-San Diego has notified patients that an email phishing attack led to unauthorized access to a small number of the practice’s email and SharePoint accounts. The organization says it learned of the incident on June 13, 2025, and that its investigation traced the unauthorized access back to a window between December 13, 2024 and December 16, 2024. While the practice believes the intruders’ main goal was to run a phishing scheme rather than steal data outright, it confirmed that certain emails, email attachments, and SharePoint files were accessed during that time, and some of those files contained patient information.

The notice is addressed to patients whose names and other personal information appeared in the specific emails, attachments, or SharePoint files that were accessed. The letter does not state how many people in total were affected, and it does not spell out, in the version we reviewed, every specific data element exposed for each patient — the letter’s own language notes that files may have contained your information, including your name, with additional details filled in individually per recipient. If your letter lists specific data types beyond your name, treat those as accurate for your situation, since the template varies from patient to patient.

What information was exposed?
  • Full name
  • Other personal or patient information contained in the specific email, attachment, or SharePoint file that was accessed — the exact additional data elements are personalized per recipient and not spelled out in the general template we reviewed

The practice is offering affected patients free enrollment in Epiq Privacy Solutions ID credit monitoring, which includes credit monitoring through Equifax, a credit report and score, Social Security number monitoring, dark web monitoring, identity restoration services, and up to $1 million in identity theft insurance. To enroll, visit www.privacysolutionsid.com and click Activate Account, then enter the personal activation code included in your letter and complete the enrollment form and identity verification steps. The enrollment deadline is listed individually in each recipient’s letter, so check your copy for the exact date. If you need help enrolling, you can call 866.675.2006.

What should you do now?
  • Enroll in the free Epiq Privacy Solutions ID credit monitoring using the activation code and deadline printed on your individual letter, since this benefit typically expires if not activated in time
  • Review your credit card and bank statements, as well as any Explanation of Benefits notices from your health insurer, for charges or claims you don’t recognize
  • Consider placing a free fraud alert or a security freeze on your credit files with Equifax, Experian, and TransUnion, since this makes it harder for someone to open new accounts in your name
  • Request your free annual credit report from each of the three bureaus at annualcreditreport.com to check for accounts you didn’t open
  • Watch for follow-up phishing emails or phone calls that reference this incident or try to get you to click links or share personal details — scammers sometimes exploit breach notices themselves
  • Since this incident involved a healthcare provider, it can also be worth signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere and help you respond quickly if it does
  • If you notice signs of identity theft, file a report with the Federal Trade Commission at ftc.gov/idtheft and with your local police department, and keep a copy of the report for your records

If you have questions, California Cancer Associates for Research and Excellence-San Diego can be reached at 855-361-0308, Monday through Friday between 8:00 a.m. and 8:00 p.m. Central Time.

Leave a Comment