NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Hacking Group Claims Attack on Cedar County Memorial Hospital

A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported by Next Level Medical in Texas and Grafton City Hospital in West Virginia.

Cedar County Memorial Hospital

Cedar County Memorial Hospital in El Dorado Springs, Missouri, disclosed on August 23, 2026, that it was the victim of a cyberattack that disrupted its IT systems. The affected computer systems were taken offline, and network access was paused to ensure the integrity of hospital systems. The measures taken to contain the attack and protect its systems resulted in an outage of its patient portal and electronic health record system, and the latter affected all hospital and Medical Mall Clinic services. To ensure patient safety, the emergency department was placed on partial diversion since medical imaging systems were unable to transmit medical images to radiologists.

An update was issued by Cedar County Memorial Hospital on August 28, 2026, confirming that the hospital had returned to routine operations after internal and external teams had completed all system reviews and safety checks. The EHR system was brought back online after two weeks offline, and manually recorded information is now being transferred to the EHR.

In a September 10, 2026, update, Cedar County Memorial Hospital explained that the investigation and review of exposed data are continuing, and it has yet to be confirmed to what extent patient data had been compromised. When the investigation and data review processes are completed, patients will be notified if their personal and/or protected health information was exposed.

A relatively new cyber extortion and ransomware group called Wallstreet claimed responsibility for the attack. The group added Cedar County Memorial Hospital to its dark web data leak site in late August and threatened to publish data stolen in the attack. The group’s claim has yet to be verified.

Next Level Medical

Next Level Medical, a Texas-based primary and urgent care provider with more than 45 clinics across the state, has recently disclosed a data security incident that was first identified on July 11, 2026. Steps were taken to secure its environment and investigate the activity; however, further suspicious activity was identified on July 29, 2026. Assisted by third-party cybersecurity experts, further steps were taken to secure its environment and bring systems back online safely and securely.

Next Level Medical determined that an unauthorized third party had accessed its network and copied files, some of which contained patient information. The investigation and file review are ongoing to determine the extent to which patient data was involved and the individuals affected. Next Level Medical said that the initial findings of the investigation indicate that data compromised in the incident includes names, dates of birth, demographic information, Social Security numbers, health information, and health insurance information. This appears to have been a data theft and extortion incident by the PEAR threat group. Ransomware Live identified a listing on the PEAR data leak site; however, it appears to have now been removed.

Grafton City Hospital

Grafton City Hospital (now Vandalia Health Grafton Hospital), a critical access hospital in West Virginia, has notified 1,215 individuals that some of their protected health information was exposed in a recent cybersecurity incident. The incident occurred at Monongalia County General Hospital Company, part of the Vandalia Health network, and was due to a phishing attack.

The incident was detected on May 6, 2026, the same day of the attack, and the investigation determined that several email accounts were compromised. The investigation was completed in late June and confirmed that data compromised in the incident included names, birth dates, addresses, phone numbers, Social Security numbers, health information, and health insurance information. Technical safeguards have been enhanced to prevent similar incidents in the future, and the affected individuals have been offered two years of complimentary credit monitoring services.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist