Five Healthcare Providers Report Ransomware-Related Data Breaches
Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.
Alta Orthopaedics Medical Group, California
Alta Orthopaedics, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, has recently confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen in a cybersecurity incident earlier this year. Unusual network activity was identified on March 10, 2026, and the investigation determined that an unauthorized third party had accessed information on its network between February 3, 2026, and February 6, 2026.
The review of the affected data was completed on June 24, 2026. Personally identifiable information potentially compromised in the incident included names, contact information, Social Security numbers, driver’s licence numbers/state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth, and login information. Protected health information compromised in the incident included diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information, and biometric data.
Notification letters have been mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been made available for 24 months. While not mentioned in the notification letters, this appears to have been a ransomware attack. The INC Ransom ransomware group claimed responsibility for the attack and said 26 GB of data was exfiltrated. The data was subsequently leaked.
Cornerstone Behavioral Healthcare, Maine
Cornerstone Behavioral Healthcare, a Worcester, Maine-based mental health and substance use disorder treatment provider, has notified patients that some of their protected health information may have been compromised in a May 2026 ransomware attack. Cornerstone identified the attack on May 26, 2026, the same day that the attackers gained access to its network. The attacker’s access to its network was blocked within an hour of discovery, and computers on the affected parts of the network were powered down rapidly, limiting the extent of file encryption. Cornerstone said it believes that less than 10% of the data on the affected computers and servers was encrypted.
The initial findings of the investigation indicated that the protected health information of approximately 2,830 patients was compromised as a result of the attack, including names, addresses, other contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare information, and Social Security numbers. Further investigation determined on July 22, 2026, that a log of appointment reminders was also compromised, which included the protected health information of approximately 12,000 patients. The log data included names, birth dates, appointment times, and reminders of documentation due.
The investigation has now been completed, and the HHS’ Office for Civil Rights has been informed that, in total, the protected health information of 14,830 patients was potentially compromised in the incident. Cornerstone explained in its refreshingly detailed breach notification letter that it received a ransom demand but did not pay. All affected computers were wiped, new computers were purchased, and all systems, policies, and procedures have been reviewed. Additional security measures have been implemented on its servers, and special training has been provided to the workforce on ransomware.
Cameron Regional Medical Center, Missouri
Cameron Regional Medical Center, a 60-bed acute care hospital in Cameron, Missouri, announced in August 2026 that it recently discovered that it was the victim of a sophisticated ransomware attack. The attack was detected on June 18, 2026, when files on its network were encrypted. In an announcement on August 18, 2026, the hospital explained that the investigation into the attack is ongoing; however, the initial findings indicate that patients’ protected health information was subject to unauthorized access and may have been exfiltrated from its network.
While the specific types of data involved for each patient have yet to be determined, Cameron Regional Medical Center said the information likely compromised includes names plus some or all of the following: home addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient ID numbers, agency-assigned identification numbers, treatment cost information, health insurance information, electronic/digital signatures, and/or employer-assigned identification numbers.
Third-party cybersecurity experts have been engaged to investigate the attack and assist with evaluating and reinforcing its security measures to ensure optimal data security. At the time of issuing the notification, no actual or attempted misuse of patient data had been identified. Individual notification letters will be mailed to the affected individuals when the data review is concluded. While the name of the ransomware group was not disclosed, the Anubis ransomware group claimed responsibility and leaked some of the stolen data as proof of the attack, including patient information. The group claimed to have exfiltrated around 500 GB of data.
Suntree Internal Medicine, Florida
Suntree Internal Medicine, an internal medicine practice in Melbourne, Florida, has notified 9,810 individuals about a cybersecurity incident first identified on September 28, 2025. Unusual activity was identified in certain systems, and immediate action was taken to contain the incident. An investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts.
The investigation confirmed unauthorized network access and the exposure of files containing patient information. Those files may have been copied from its network, although at the time of issuing the breach notice, no misuse of patient information had been identified. The data review confirmed that the following information was exposed: names, addresses, treatment information, and health insurance information. Suntree Internal Medicine has implemented additional security measures to reduce the risk of similar incidents in the future. While the incident was not described as a ransomware attack, a ransomware group called INC Ransom claimed responsibility for the attack on its dark web data leak site. The listing states that data was exfiltrated.
Associated Endocrinologists, Michigan
Associated Endocrinologists, a consultative endocrinology practice with locations in Farmington Hills and Clarkston, Michigan, has started notifying 4,979 patients about a cybersecurity incident earlier this year. There is currently no substitute breach notice on the practice website, and the HIPAA Journal has been unable to find a press release about the incident, which was reported to the HHS’ Office for Civil Rights on July 29, 2026. It is currently unclear exactly what types of information were exposed or stolen in the incident. The RansomHouse ransomware group claimed responsibility for the attack on its data leak site in early February and claimed to have exfiltrated data and encrypted files on January 31, 2025



