Insomnia gang claims Tulsa foot and ankle clinic chain breach

The newer Insomnia ransomware operation claims it breached a five-location Tulsa foot and ankle clinic.

MedRisk Staff
By
1 Min Read

An extortion group called Insomnia has claimed a breach of a Tulsa-area foot and ankle clinic chain, with the victim named on the gang’s leak site on August 31, 2026, according to ransomware trackers.

Metro Tulsa Foot operates five locations in the Tulsa metro area, treating common foot pain, deformities, and injuries and offering same-day appointments for urgent cases. Podiatry clinics maintain patient charts, imaging, and insurance records that qualify as protected health information under HIPAA.

Insomnia is a newer ransomware operation, and its claim comes with the usual caveats: no evidence files, no volume figure, and no statement from the practice. Trackers treat emerging groups as higher-uncertainty sources until a claim is independently verified.

If the clinic confirms a compromise, patient notification duties under HIPAA would apply. In the meantime, the posting is a useful prompt for other ambulatory providers to confirm backups, patching, and multifactor authentication are in place.

Share This Article