A nonprofit health center in rural West Virginia has notified the public that an unknown intruder may have copied patient records off its network.
Camden-on-Gauley Medical Center, which does business as Camden Family Health, alerted the U.S. Department of Health and Human Services on September 15, 2026, and posted a notice on its website. Staff noticed something wrong with the center’s computer systems on July 18, 2026. Investigators later concluded that patient information could have been pulled from the network without permission that same day.
Medical records and health insurance details are among the potentially exposed categories. The notice also names Social Security numbers, dates of birth, addresses, government identification numbers, financial information, and names as possible casualties. A headcount has not been released.
Camden is pointing patients toward free monitoring resources and explaining how to set fraud alerts or credit freezes with Equifax, Experian, and TransUnion. It also opened a phone line, 1-833-516-8779, staffed weekdays from 8 a.m. to 8 p.m. Eastern.
Rural and federally qualified health centers make inviting targets: they hold complete medical histories but run on thin IT budgets. Camden’s timeline, trouble spotted in July and patients notified in September, mirrors a familiar pattern across small providers this year.