Nationwide Recovery Service reports breach of debt collection records
- Organization
- Nationwide Recovery Service
- Exploit
- Hacking
- Industry
- Debt Collection
Nationwide Recovery Service, a debt collection agency that works for healthcare providers, banks and government bodies, reported a hacking incident to the U.S. Department of Health and Human Services Office for Civil Rights on September 9, 2024. The filing followed the discovery that an unauthorized party had reached confidential consumer information held on the company's network.
Forensic investigators placed the intrusion between July 5 and July 11, 2024, during which files and folders were copied from NRS systems. The data involved names, addresses, dates of birth, Social Security numbers, financial account details, guarantor information, account balances and medical information collected in the course of debt servicing work.
The regulatory filing listed 501 affected individuals, a placeholder figure used when the true count is not yet known. NRS said at the time that it would write to everyone affected once the review of the copied files was complete.
The scale emerged well after the initial report. Client organizations began issuing their own notifications from early 2025, among them Harbin Clinic, which told 210,140 patients their data was involved, along with Select Medical Holdings and UChicago Medicine Medical Group. HIPAA Journal counted more than 560,000 affected individuals across NRS clients by late 2025, and the company faced multiple lawsuits alleging it had failed to protect the records in its care.