A vishing call on May 29 gave an attacker a foothold in Quantum Health’s network, and the healthcare navigation company says files were taken over the following three days. An unknown caller persuaded a Quantum Health user to grant access; a network disruption on June 1 affecting internal and external systems set off the investigation that traced the intrusion back to that conversation.
The Dublin, Ohio company confirmed on June 8 that the exfiltrated material included personal and protected health information: contact and demographic details, Social Security numbers, treatment and prescription records, provider names, dates of service, insurance information, and claims or benefits data. No extortion group has claimed the attack, though Quantum Health said the approach mirrors the ShinyHunters vishing playbook highlighted in a recent Health-ISAC alert. The number of people affected has not been disclosed, and the company is offering credit monitoring and identity theft protection.
Two more disclosures surfaced the same week. In North Dakota, the faith-based Heart of America Medical Center in Rugby said an intrusion it traced to June 2025 ended with patient files carrying names, Social Security numbers, and medical records being exfiltrated; the Embargo group has since taken credit and claims roughly 800 GB was taken. In Florida, the imaging practice Precision Imaging Centers, which operates as The Medical Imaging Partnership, told federal regulators it detected suspicious activity on May 7 and filed a placeholder estimate of 501 affected individuals while its data review continues.
For defenders, the pattern is a warning that a single convincing phone call can bypass the email defenses most security awareness programs focus on.