Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by Crystal Coast Pain Management, Golden State Orthopedics & Spine, Gardiner Family Chiropractic, and BestCare Treatment Services.
Interim HealthCare of Oklahoma City
Interim HealthCare, a home healthcare provider operating in 40 U.S. states, has been added to the data leak sites of two ransomware groups. The first listing was added to the Genesis ransomware group’s data leak site on August 10, 2026. Genesis claimed to have exfiltrated data in the incident and threatened to publish it if the ransom was not paid. Genesis claims the stolen data relates to Interim Healthcare of Oklahoma and Tulsa, and that 1TB of data was exfiltrated, including medical records, healthcare data, personal data, patient lists, clinical data, and company data. While a list of the compromised files was added to the data leak site, the data allegedly stolen has yet to be published.
Then on August 21, 2026, a second ransomware group listed Interim HealthCare as one of its victims. Anubis claims to have exfiltrated 530 GB of data in the attack, including “financial information about franchisees, details of internal and external audits, discussions of operational issues, as well as memoranda covering all kinds of day-to-day business matters.” Samples of the stolen data were added to the listing, and the stolen data has been published, indicating the ransom was not paid.
While Interim HealthCare has yet to confirm the validity of either claim, Interim HealthCare of Oklahoma City, Inc. reported a network server hacking incident to the HHS’ Office for Civil Rights on July 31, 2026, using a placeholder estimate of 500 affected individuals.
Crystal Coast Pain Management
Crystal Coast Pain Management in North Carolina, a division of East Carolina Anesthesia Associates ECAA), has started notifying patients that some of their personal and protected health information was obtained by an unauthorized third party in a cybersecurity incident earlier this year.
Suspicious network activity was identified on or around January 11, 2026, and third-party digital forensics and cybersecurity experts were engaged to investigate the activity. On April 20, 2026, it was determined that files containing patient information had been copied by the attackers. The file review was completed on June 24, 2026, when it was confirmed that the stolen data included first and last names, dates of birth, medical information, and Social Security numbers.
The cybersecurity experts confirmed the security of its network; however, as a precaution, all affected systems were wiped and rebuilt, and additional security measures have been implemented. No evidence has been found to indicate any misuse of the affected data, but as a precaution, the affected individuals have been offered single-bureau credit monitoring, credit report, and credit score services. A ransomware group called Devman 2.0 claimed it was behind the attack.
Golden State Orthopedics & Spine
Golden State Orthopedics & Spine (GSOS), an orthopedics practice with 13 locations in the San Francisco Bay Area in California, has announced a recent cybersecurity incident. Suspicious network activity was identified on July 2, 2026, and a third-party team of forensics experts was engaged to assist with the investigation and determine the nature and scope of the activity.
GSOS confirmed that its network had been accessed by an unauthorized third party, who may have viewed or obtained files containing patient information. The data review confirmed that the exposed data included first and last names, addresses, dates of birth, Social Security numbers, health insurance information, and medical diagnosis information.
The review of the affected data is ongoing, and the number of affected individuals has yet to be disclosed. GSOS is reviewing its data security policies, procedures, and practices and is taking steps to prevent similar incidents in the future. This appears to have been a ransomware or data theft and extortion incident. A ransomware group called Brain Cipher claimed responsibility for the attack, in which it alleged that 150 GB of data was stolen.
Gardiner Family Chiropractic
Gardiner Family Chiropractic, a chiropractic clinic in Gardiner, Maine, has notified the HHS’ Office for Civil Rights about a network server hacking incident that has affected up to 5,000 patients. Suspicious activity was identified within its computer network on July 17, 2026. An investigation was launched, which confirmed unauthorized network access and the exposure of patient data. Data potentially compromised in the incident includes names, contact information, birth dates, health information, and health insurance/Medicaid information.
According to the substitute breach notice, this was a ransomware attack involving file encryption and data theft. A ransom demand was received; however, the attack was blocked, and the ransom was not paid. The Interlock ransomware group claimed responsibility for the attack. Gardiner Family Chiropractic has taken several steps in response to the attack to strengthen security. In addition to wiping the affected devices and purchasing new computers for its employees, security policies, procedures, and practices have been reviewed, additional security measures have been implemented, and special training has been provided to its workforce on ransomware.
BestCare Treatment Services
BestCare Treatment Services, Inc., an Oregon-based behavioral healthcare provider, has experienced a data security incident involving unauthorized access to parts of its network containing patient information. Unauthorized network activity was identified on June 15, 2026, and a third-party cybersecurity firm was engaged to assist with the investigation and confirm the security of its network.
The investigation confirmed that files had been exposed containing names, dates of birth, contact information, demographic information, medical information, and other patient identifying information. Notification letters were mailed to the affected individuals on August 10, 2026. The data breach was recently reported to the HHS Office for Civil Rights as affecting 4,216 individuals.
