Shelby Dermatology Breach Analysis – March 2025

June 12, 2025
A doctor is sitting at a desk using a laptop computer.

In March 2025, a small Alabama-based dermatology clinic became the latest cautionary tale in a growing wave of healthcare cyberattacks. Shelby Dermatology, a practice with approximately 24 employees, disclosed a significant data breach that ultimately compromised the personal and health information of over 86,000 individuals.

While major hospitals and health systems tend to dominate headlines when breached, this incident underscores a hard truth: small practices are no less vulnerable—and often less prepared—when it comes to cybersecurity threats.


What Happened?

On or around March 7, 2025, Shelby Dermatology—operating under the larger brand name Dermatologists of Birmingham—identified suspicious activity on its network. A forensic investigation was immediately launched and concluded in mid-May, confirming that unauthorized access had occurred.

The breach exposed a wide range of sensitive data, including:
- Names
- Dates of birth
- Social Security numbers
- Contact information (phone, email, addresses)
- Health insurance details
- Medical diagnoses and treatment information

In total, 86,414 individuals were affected. Notification letters were sent beginning in early June, and impacted individuals were offered 12 months of free credit monitoring and identity theft protection through TransUnion.


What This Could Cost Shelby Dermatology

While the full financial fallout from the breach is still unfolding, industry benchmarks allow us to estimate its potential impact. According to IBM’s Cost of a Data Breach Report 2023, the average cost per healthcare record breached is $429. At 86,414 records, that would suggest a theoretical cost exceeding $37 million. However, such estimates reflect large-scale enterprises.

While the following represents a practical cost estimate for smaller practices, it's important to consider that 2025 has marked a trend toward higher settlements due to escalating class-action activity:

Category Estimated Cost
Investigation & Compliance $175,000-$225,000
Credit Monitoring (1yr) $3-$5 per person = $260,000 - $430,000
IT Security Upgrades $50,000-$150,000
Class-Action & Legal Costs $500,000-$1,000,000+
*Estimated Total* $1.075M-$1.725M

How Class Actions Influence the Cost

The earlier estimate for Shelby Dermatology included a general allowance of $100K–$500K+ for legal fees, defense costs, and potential settlements. However, given the surge in litigation and precedent-setting payouts, that estimate may lean toward the low end unless a multi-state class is triggered.

Real-world settlement examples:
- Columbus Regional Healthcare faced a $1.1 million settlement for ~100K impacted individuals, including cash payouts and credit monitoring.¹
- Enzo Biochem agreed to a $7.5 million settlement after a healthcare breach, offering up to $10K per person plus credit monitoring.²

While Shelby Dermatology is much smaller, the litigation environment is now more aggressive, especially for breaches involving SSNs and health info.

Conclusion

Shelby Dermatology’s breach highlights the disproportionate risks faced by smaller healthcare providers operating in an increasingly hostile digital environment. With over 86,000 patients impacted, and potential costs exceeding $1.7 million, this incident should motivate every practice to reevaluate their cybersecurity posture—before they find themselves in a similar situation.


References

1. The Sun. Columbus Regional Healthcare data breach settlement. https://www.the-sun.com/news/columbus-breach-settlement
2. Honigman. Enzo Biochem breach class action details. https://www.honigman.com/media/enzo-breach-settlement-2024.pdf
3. IBM Cost of a Data Breach Report 2023. https://www.ibm.com/reports/data-breach
4. U.S. Department of Health and Human Services Breach Portal. https://ocrportal.hhs.gov/ocr/breach
5. Class action notices from Edelson Lechtzin LLP and Shamis & Gentile P.A. https://www.claimdepot.com/investigations/shelby-dermatology-data-breach-2025


A doctor is sitting at a desk using a laptop computer.
May 12, 2025
As healthcare and dental providers increasingly rely on digital records, cloud applications, and connected devices, the responsibility to protect sensitive patient data has never been greater.
A man is sitting at a desk reading a piece of paper.
May 9, 2025
Section 179 of the IRS tax code is one of the most powerful, business-friendly provisions available to small and mid-sized companies.
May 2, 2025
If your business relies on Google Workspace (formerly G Suite) to send emails through third-party applications—such as scanners, CRM systems, helpdesk tools, or website contact forms—then there’s an important security update you need to know about.
A woman is sitting at a desk using a laptop computer.
April 22, 2025
Creating a Hyper-V instance running Amazon Machine Image (AMI) 2023 involves several detailed steps.
A woman is sitting at a desk in a warehouse using a cell phone.
February 28, 2025
Cyberattacks are a growing concern, and small to mid-sized businesses – especially dental, medical, accounting, and construction offices – are increasingly targeted. To help organizations respond effectively to security incidents, a free Security Incident Response Toolkit is now available.
A man in a suit and tie is holding a globe with the words cyber security written on it.
February 26, 2025
As cyber threats continue to grow, the FBI is warning businesses—particularly small and mid-sized dental, medical, accounting, and construction offices—to back up their data immediately. This alert comes in response to a surge in attacks specifically targeting these industries.
February 7, 2025
As of October 14, 2025, Microsoft will officially end support for Windows 10. After this date, the operating system will no longer receive security updates, technical assistance, or software updates from Microsoft. While your Windows 10 PC will continue to function, using an unsupported operating system poses significant risks.
A man is using a laptop computer with a loading bar on the screen.
February 5, 2025
Microsoft’s ESU program provides critical security updates for Windows 10 devices beyond the official end-of-support date. This is a paid service designed for individuals and businesses that need extra time to transition to a supported operating system.
A judge 's gavel is sitting on top of a black table.
January 8, 2025
In December 2024, Westend Dental, an Indianapolis-based dental practice, agreed to pay a $350,000 penalty to the Indiana Attorney General's Office to resolve multiple alleged violations of federal and state laws, including the Health Insurance Portability and Accountability Act (HIPAA)
A woman is sitting in a dental chair and giving a thumbs up.
November 4, 2024
The cloud has the ability to change the game for your dental practice, especially if you're have or are interested in branching out to multiple locations.
More Posts