Three ransomware gangs tied to fresh breach notices at five providers

New breach notices at five US medical organizations trace to ransomware, with INC Ransom, Anubis, and RansomHouse claiming the attacks.

MedRisk Staff
By
2 Min Read

Breach notices filed by five US medical organizations this week each trace back to ransomware activity, and three extortion gangs have claimed a role. The disclosures, reported to the HHS Office for Civil Rights, cover clinics, a behavioral health provider, and a rural hospital across five states.

Alta Orthopaedics in California told 24,496 patients that intruders moved through its network between February 3 and February 6 before unusual activity was spotted on March 10. The INC Ransom gang said it pulled 26 GB of data, which was later leaked online. The practice covers Santa Barbara, Solvang, Santa Maria, and Oxnard, and is offering two years of credit monitoring.

Cornerstone Behavioral Healthcare, a mental health and substance use provider, refused a ransom demand after its May 26 attack, wiped affected computers, and kept encryption below 10 percent of files. A second review in July found a log of appointment reminders was also taken, lifting the total to 14,830 people. Cameron Regional Medical Center, a 60-bed Missouri hospital, found files encrypted on June 18; the Anubis gang claimed roughly 500 GB and leaked sample patient data.

Two practices reported smaller disclosures. Suntree Internal Medicine in Melbourne, Florida notified 9,810 patients about an intrusion first spotted on September 28, 2025, which INC Ransom claimed on its leak site. Associated Endocrinologists in Michigan began notifying 4,979 patients after reporting to the OCR on July 29, and the RansomHouse gang claimed that attack in early February.

The notices list Social Security numbers, diagnoses, and insurance details among the exposed data, and follow a familiar pattern of intrusions disclosed months after they occurred.

Share This Article