The Genesis extortion gang has added a Texas freestanding emergency room chain to its leak site, posting Hospitality Health ER (Longview) on August 23 alongside a claim that it stole internal data.
Threat trackers logged the listing at ransomware.live, which estimates the intrusion began around August 20. The tracker’s profile for the chain shows infostealer activity tied to the domain, with 394 compromised user accounts recorded in Hudson Rock logs, though that exposure predates and may be unrelated to the extortion claim.
Hospitality Health ER operates freestanding emergency departments across Texas, including the Longview location named in the post. Freestanding ERs have become a recurring target for extortion groups because they hold the same protected health information as full hospitals while often running leaner security teams.
The claim is unconfirmed. Genesis has spent the summer cycling through healthcare victims, including a Memphis physician group and an Oklahoma home care provider in August. The gang typically posts sample data to pressure victims into paying.
For Texas ER operators, the listing is a reminder to verify that business associate agreements cover offsite imaging, billing, and transcription vendors, since patient data frequently flows through third parties before attackers are detected. Monitoring credential exposure in infostealer logs and enforcing multi-factor authentication on remote access remain the most effective controls.
Ransomware.live lists the incident among recent healthcare victims, and GalaxyWarden’s breach index independently logged the same listing with a high severity rating on the same day.