Supply chain β›“ Supply Chain

Nationwide Recovery Services Healthcare Billing Vendor Breach (Multiple Hospitals)

πŸ“… 2025-04-01 🏒 Nationwide Recovery Services (medical billing/RCM)
Primary Source β†—

Incident Details

In May 2025, Nationwide Recovery Services (NRS), a healthcare billing and accounts receivable management vendor, disclosed a data breach affecting over a dozen healthcare provider clients. Confirmed affected organizations include: TRG Medical Imaging, Smile Solutions of Goodlettsville, Duncan Regional Hospital, MAK Anesthesia, City of Chattanooga municipal health, Swedish Edmonds Hospital, Erlanger Western Carolina Hospital, Rhea Medical Center, Radiology Chartered, Northeast Georgia Health System, Shore Medical Center, UChicago Medicine Medical Group, Vitruvian Health, and Harbin Clinic. For all affected patients, the breach exposed names, Social Security numbers, dates of birth, financial account information, and detailed medical information. The broad impact across 14+ healthcare organizations from a single vendor breach illustrates the systemic risk of healthcare revenue cycle management outsourcing.

Technical Details

Initial Attack Vector
Nationwide Recovery Services (NRS), a medical billing and revenue cycle management vendor, suffered a breach of its systems, exposing patient data from more than a dozen healthcare provider clients
Vendor / Product
Nationwide Recovery Services (medical billing/RCM)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-04-01 Breach occurred
  2. 2025-05-15 Publicly disclosed
  3. 2025-05-15 Customers notified