type: incident ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ยท confidence: high ยท severity: high ยท affected_sectors: ยท au_impact: false
HIPAA breach notifications published this week confirm ransomware-led compromises at five US healthcare providers, three of which are attributed to named ransomware groups.
Assessment
The breaches illustrate the continued targeting of healthcare providers of varying sizes across the US, with exposed data in most cases including names, dates of birth, Social Security numbers and health or insurance information. At Alta Orthopaedics the exposure extended to financial account and biometric data. Three of the five incidents are attributed to ransomware groups, while Cornerstone Behavioral Healthcare is notable for a detailed disclosure describing rapid containment and a decision not to pay.
Details
- Alta Orthopaedics (California): 24,496 individuals affected; INC Ransom claimed 26 GB exfiltrated and leaked; exposed data included financial account and biometric data.
- Cornerstone Behavioral Healthcare (Maine): 14,830 patients affected; ransom was declined and less than 10% of data was encrypted following rapid containment.
- Cameron Regional Medical Center (Missouri): a 60-bed acute care hospital; Anubis ransomware claimed around 500 GB.
- Suntree Internal Medicine (Florida): 9,810 individuals affected; attributed to INC Ransom.
- Associated Endocrinologists (Michigan): 4,979 patients affected; attributed to RansomHouse.
- Three of the five providers are attributed to named groups (INC Ransom, Anubis, RansomHouse).
- These are confirmed data breaches.