Parexel International Reports Data Breach Exposing Sensitive Clinical Data
Parexel International, a global clinical research organization, reported a data security incident to Montana authorities on December 17, 2025. The breach, which occurred on October 4, 2025, involved the exposure of sensitive personal and health information, including Full Name, Social Security Number, and Clinical Trial Participation Records. Individuals whose data was compromised may face risks of identity theft and privacy violations.
- State
- Montana
- Breach date
- October 4, 2025
- Reported
- December 17, 2025
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Clinical Trial Participation Records
- Diagnosis and Treatment Information
- Contact Information
Parexel International, LLC, a major clinical research organization, filed notice of a data breach with the state of Montana on December 17, 2025. The company stated the incident took place on October 4, 2025. The specific nature of the breach was not detailed in public records, but it resulted in the compromise of highly sensitive personal and health-related data.
The exposed data categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Clinical Trial Participation Records, Diagnosis and Treatment Information, and Contact Information. Given Parexel's role in managing complex medical studies, this type of information is central to its operations.
Such breaches can present significant risks to affected individuals. The exposure of Full Name, Date of Birth, and Social Security Number can be leveraged for various forms of identity theft. Additionally, the compromise of Medical Record Number, Health Insurance ID Number, Clinical Trial Participation Records, and Diagnosis and Treatment Information raises concerns about medical identity theft and privacy breaches.
Individuals who receive notification about this incident should remain vigilant. It is recommended to carefully review all financial statements and health-related communications for any unauthorized activity. Monitoring credit reports can help detect early signs of fraudulent accounts or credit inquiries.
To help protect against potential misuse of exposed data, consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus: Equifax, Experian, and TransUnion. Additionally, be cautious of unsolicited communications, especially those requesting personal information, as these could be phishing attempts.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Montana Attorney General filing
Related data breach cases
- MemberSource Credit Union
- MemberSource Credit Union
- GrayRobinson P.A.
- GrayRobinson P.A.
- First Advantage Corporation
- County of Murray dba Murray County Medical Center
- County of Murray dba Murray County Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Brett Robinson Vacation Rentals
- Standard Sales Company, LP
- Clackamas Community College