Reynolds Road Surgical Center LLC, doing business as Wildwood Surgical Center, notified members of its healthcare community of a network security incident that exposed personal and health information. The notice was posted more than a year after the breach had occurred.
What happened
Wildwood Surgical Center, an outpatient surgical facility in Toledo, detected suspicious activity on its network on June 26, 2025. The organization secured its network and hired specialists to investigate. The investigation determined that someone accessed and acquired data from the network without authorization between June 24 and June 26, 2025. Wildwood then conducted a detailed review to identify which data and which individuals the incident affected. It completed that review on May 13, 2026, and confirmed the data set contained personal information and protected health information.
Wildwood did not send public notice until July 13, 2026, roughly 13 months after it first detected the suspicious activity, and about two months after it finished reviewing the affected data. The exposed data varies by individual and may include first and last name, Social Security number, driver's license or passport number, date of birth, medical treatment and diagnostic information, health insurance information, medical billing information, bank account number, and payment or credit card number. No information is available on the total number of individuals affected.
What was said
In their public notice, Wildwood stated, “Upon learning of the incident, we took parts of our network offline and implemented additional tools to confirm the security of our environment and restore our operations safely. We also notified federal law enforcement.”
Why it matters
This incident combines Social Security numbers, government ID numbers, and financial account data with clinical details like diagnoses and treatment history, a combination that gives bad actors more than one way to exploit the same person, from opening fraudulent credit lines to submitting false insurance claims using real medical histories.
Wildwood took about 13 months to move from detecting the intrusion to publicly notifying those affected. That gap is not unusual in the ambulatory surgery center space. Waterford Surgical Center, a physician-owned outpatient facility in Michigan, disclosed a similar breach in 2025 after the SAFEPAY ransomware group claimed responsibility for a cyberattack on its network. That incident exposed a similar mix of names, Social Security numbers, driver's license or state ID information, health insurance details, medical records, and payment information, affecting roughly 9,000 patients and employees. The similarities between the two cases point to a pattern that small, single-facility surgical centers handling the same categories of sensitive data face many of the same risks, regardless of location.
The bottom line
Wildwood Surgical Center confirmed that a June 2025 network intrusion exposed a mix of personal, financial, and health data belonging to members of its patient community, and it is mailing notification letters to those affected. The notice arrived more than a year after the incident was first detected, a timeline consistent with other recent breaches at similarly sized surgical centers.
FAQs
What is a data breach?
A breach occurs when an unauthorized party gains access, uses or discloses protected health information (PHI) without permission. Breaches include hacking, losing a device containing PHI, or sharing information with unauthorized individuals.
See also: How to respond to a data breach
What are the long-term consequences of healthcare data breaches?
In the long term, breaches can cause patients to delay or avoid care, increase public distrust in medical institutions, and lead to legal and regulatory penalties for healthcare providers.
Read also: The complete guide to HIPAA violations
Does a data breach automatically mean that a patient’s information was misused?
No, exposure means your information was accessed without authorization, but it doesn't necessarily mean anyone has used or will use it fraudulently.
