Four care providers disclose hacking incidents dating back to 2025

Rehab, skilled nursing, and senior living operators in three states plus a California foundation disclosed old intrusions this week.

MedRisk Staff
By
2 Min Read

Four healthcare organizations disclosed hacking incidents this week, each revealing network intrusions that took place months earlier.

An operator of North Carolina rehabilitation practices reported that stolen vendor credentials were used to access files between November 25 and 28, 2025, affecting almost 4,000 patients of Elevate Health and Rehabilitation, Bear Mountain Health and Rehabilitation, and Swannanoa Valley Health and Rehabilitation. Names, Social Security numbers, driver’s license numbers, diagnoses, and other health information sat in the copied files. The operator told the HHS Office for Civil Rights the vendor assured it the data was deleted and never published, suggesting a ransom was paid.

Atrium Centers, a Columbus, Ohio skilled nursing and rehabilitation provider, said a Medusa ransomware attack accessed its systems between October 8 and 12, 2025, viewing or copying files with patient and employee data including SSNs, medical information, and financial account data. The affected count has not been disclosed.

Rockwood Retirement Communities in Spokane, Washington disclosed a February 16, 2026 intrusion with file exfiltration. Compromised data included SSNs, passport numbers, financial account information, and Medicaid and Medicare numbers. Notification letters went out July 27, and the breach is not yet listed on the OCR portal.

The Health Trust, a San Jose nonprofit foundation, and its subsidiary FASS reported unauthorized access before March 26, 2025 and again June 8-11, 2025. The Qilin gang claimed responsibility, saying it exfiltrated 408 GB.

Share This Article