Two regional care providers appeared on the Genesis ransomware gang’s leak site within a minute of each other on August 10, in back-to-back postings logged by leak-site watchers.
HookPhish logged both listings on August 10, with the Interim HealthCare post appearing at 21:57 UTC and the Memphis physician group at 21:58 UTC. Ransomware.live dates both discoveries to the same day.
Consolidated Medical Practices of Memphis, also known as CMPM, is a physician group serving the Memphis area. Interim HealthCare Oklahoma and Tulsa is part of the national home care franchise network, providing elderly care and home health services through interimhealthcare.com. Neither organization has publicly confirmed an intrusion, and the claims remain unverified.
The two targets illustrate how smaller regional care organizations are being swept into the same extortion patterns that have hit large health systems this year. Physician groups and home care franchises hold protected health information, insurance details, and staff records, but often lack the security operations resources of major hospitals.
For organizations in this tier, the practical takeaways are the same as for larger providers: assume unverified leak-site listings could be real, test offline backups, review remote access logs, and map which vendors and business associates hold copies of the same data.
