If you are a current or former patient of QualDerm Partners, your medical records may have been stolen. This was not a system glitch. Between December 23 and 24, 2025, cybercriminals deliberately infiltrated QualDerm's network and removed patient data from a company that manages 158 dermatology practices across 17 states and serves more than 15 million patients annually. The U.S. Department of Health and Human Services has confirmed 3,117,874 individuals were affected nationwide. Tennessee patients are squarely among them.
If you received a breach notification letter or suspect you were affected, the data breach lawyers at Cory Watson Attorneys are actively reviewing claims from Tennessee patients right now.
What Happened in the 2026 QualDerm Partners Cybersecurity Incident?
QualDerm detected the intrusion on December 24, 2025, but did not begin mailing notification letters until February 22, 2026, approximately 60 days later. That gap matters legally. It may have given bad actors weeks to exploit stolen data while patients had no idea their information was in criminals' hands.
Key Takeaways
- The breach occurred on December 23–24, 2025, and exposed the health and personal data of 3,117,874 Americans.
- Exposed data includes diagnoses, treatment records, insurance details, and government-issued IDs.
- QualDerm's ~60-day notification delay raises potential compliance questions under T.C.A. 47-18-2107 and HIPAA.
- Tennessee law requires breach notification within 45 days of discovery; violations give rise to independent legal claims.
- Medical identity theft causes lasting harm: altered records, denied claims, and credit damage that does not self-correct.
- Tennessee patients may be entitled to compensation for loss of privacy, out-of-pocket costs, and emotional distress.
- There is no cost to consult with a Tennessee data breach attorney, and the clock is already running.

Identifying If Your Personal Health Information Was Exposed
QualDerm's official breach notice confirms the following categories of data were removed from its systems:
- Full legal names and dates of birth
- Medical record numbers and treating provider names
- Diagnosis and treatment information
- Health insurance details and policy information
- Email addresses
- Government-issued ID numbers, including driver's license numbers for some patients
This is what security professionals call a "complete profile." A stolen credit card gets canceled in minutes. Stolen diagnosis records and insurance histories follow a victim indefinitely, and on the dark web, a complete medical record commands significantly more value than a credit card number precisely because medical fraud is harder to detect and the data never expires.
Tennessee Data Privacy Laws and Your Right to Compensation
Tennessee law does not leave breach victims without recourse. When a company stores personal information on Tennessee residents and fails to protect it, state statute creates a direct path to financial accountability.
The Tennessee Identity Theft Deterrence Act Explained
The Tennessee Identity Theft Deterrence Act, codified at T.C.A. Section 47-18-2101 and enforced through the breach notification mandate at Section 47-18-2107, is the controlling state law here. It requires any organization that stores computerized personal information about Tennessee residents to notify affected individuals no later than 45 days after discovery. When a breach affects more than 1,000 individuals, the law also requires notification to all major consumer reporting agencies.
QualDerm discovered the breach on December 24, 2025. Letters went out February 22, 2026, roughly 60 days later. Whether that timeline satisfies the statutory 45-day window or constitutes a violation giving rise to additional claims is a fact-specific legal question that requires immediate review by counsel.
T.C.A. 47-18-2107 operates alongside HIPAA's federal 60-day notification requirement. Together, they create a dual compliance obligation. A failure under either framework can independently support a claim on behalf of affected Tennessee patients.
Steps to Take if You Received a Breach Notification Letter:
- Keep the letter. It is a legal document establishing what data was exposed and when.
- Enroll in QualDerm's free monitoring. Call their dedicated line at 1-855-522-4707 to activate all credit and identity protection services offered.
- Audit your Explanation of Benefits (EOB) statements. Look for medical services billed under the name that you never received.
- Freeze your credit. Contact Equifax, Experian, and TransUnion directly to place a fraud alert or full credit freeze.
- Contact a Tennessee data breach attorney. The statute of limitations is not unlimited. Every day without action narrows your legal window.
Why Tennessee Patients Must Act Now
The QualDerm breach was a foreseeable failure by a well-resourced company with a legal obligation to protect the data it collected. Healthcare breaches now average $7.42 million in organizational costs per incident, and those costs cascade onto patients through higher premiums and denied claims. But the individual cost is measured in something harder to quantify: years spent disputing fraudulent medical bills, correcting a record that was never supposed to be touched.
Tennessee law gives you a path to hold QualDerm accountable. That path has a deadline.
Contact us today for a free, no-obligation consultation. To learn more about us and our track record representing Tennessee victims of data breaches and corporate negligence, visit our firm overview page.
Frequently Asked Questions
How do I know if I'm affected? If you are a current or former patient at any QualDerm-managed dermatology practice, you may be affected even without a letter. Call 1-855-522-4707 to confirm your status.
Can I sue QualDerm Partners? Potentially yes. Claims can allege negligence and violations of T.C.A. Section 47-18-2107, which mandates disclosure within 45 days of discovery. QualDerm's February 2026 notifications arrived roughly 60 days after detection. A Tennessee attorney must evaluate whether that gap supports your claim.
What damages are recoverable? Loss of privacy, remediation time, out-of-pocket losses from fraud, and emotional distress. Specific amounts depend on individual circumstances.
What does this cost me? Nothing. Cory Watson Attorneys works on contingency. You pay no fee unless we recover compensation for you.
Is there a deadline? Yes. The HIPAA Breach Notification Rule sets a 60-day federal notification floor; Tennessee imposes a 45-day floor. Tennessee's statutes of limitations on your right to sue are separate and shorter. Waiting permanently bars recovery. Do not delay.