An extortion group that has spent the summer cycling through healthcare targets has now posted a medical billing services firm on its leak site. The Coinbase Cartel listed Integrated Health Systems on August 22 as part of an ongoing campaign, saying it holds internal data, though the group has disclosed neither a record count nor which files it claims to possess.
Integrated Health Systems provides practice management, medical billing, accounting, and revenue cycle services to solo practitioners, multi-specialty clinics, and hospital systems. The company has not publicly confirmed the claim, and ransomware trackers mark the listing as unverified.
The claim is corroborated by ransomware.live, GalaxyWarden, and RansomLook, which all date the Coinbase Cartel listing to August 22. Medical billing vendors are high-value targets because the files they handle routinely contain patient names, insurance identifiers, and payment data drawn from many client practices at once.
Provider organizations that use Integrated Health Systems for billing or credentialing should review their business associate agreements and watch for a formal notification from the company. Even an unconfirmed listing is a reason to tighten authentication on any shared portals and to brief staff on phishing risks, since extortion groups often weaponize stolen data in follow-on social engineering.
If the claim is confirmed, affected practices could face notification obligations under HIPAA and state law. Until then, the practical step is to monitor the situation and avoid assuming that silence from the vendor means the listing is baseless.