RansomHub-era vendor breach resurfaces in spine clinic letters

Midwest Spine and Brain Institute and four other organizations are notifying patients about intrusions tied to vendors, email accounts, and cloud systems.

MedRisk Staff
By
2 Min Read

Breach notices from five US health organizations surfaced this week, including a Minnesota and Wisconsin spine clinic whose patient data may have been caught up in an attack on a healthcare IT vendor, and a Canadian-owned digital health firm whose actual exposure turned out far smaller than a hacker group claimed.

Midwest Spine and Brain Institute said an intruder accessed files it had entrusted to 3C Care Systems, a vendor specializing in workflow automation and cloud-hosted platforms for healthcare. The clinic’s own network was not touched, and its review closed June 18. The episode traces to a ransomware attack by the now-disbanded RansomHub group around November 21, 2024, which claimed 100 GB of stolen data. Notifications are going out, though no victim count has been posted yet.

Bakersfield, California surgical center Silver Summit Medical Corporation, which operates as the Digestive Disease Center and Heart Vascular and Leg Center, is warning patients after an unnamed vendor’s systems were hit between November 27 and 30, 2025. Files included names, Social Security numbers, financial and payment card data, and government identifiers.

Premier Medical Group of the Hudson Valley, a multispecialty practice in Poughkeepsie, New York, found unauthorized file access on June 14, 2026, exposing names, contact details, insurance information, and clinical data.

Risk Program Administrators, a California insurance program administrator, is notifying 8,309 people after an employee mailbox was accessed between May 27, 2025 and June 16, 2026, exposing Social Security numbers, treatment details, and mental health condition information.

TELUS Health (US), a Canton, Massachusetts digital health firm, reported 2,641 people to the HHS Office for Civil Rights, a fraction of the 1 petabyte haul that the ShinyHunters group claimed in March after breaching its Google Cloud environment.

Share This Article