Healthcare IT Ransomware HIPAA Patient Data Cybersecurity

Five Healthcare Ransomware Breaches in One Report: What They Have in Common

Five healthcare providers reported ransomware breaches in one HIPAA Journal roundup. Here is what they share and what your practice can do now.

centrexIT Team
8 min read

On September 3, 2026, HIPAA Journal published a single roundup covering five separate healthcare providers, in five different states, all reporting ransomware-related data breaches at roughly the same time. An orthopaedic group in California. A behavioral health provider in Maine. A 60-bed hospital in Missouri. An internal medicine practice in Florida. An endocrinology group in Michigan. Different sizes, different specialties, different parts of the country. Same story.

If you run IT or operations for a medical practice, that clustering is the part worth sitting with. This is not one dramatic attack against one big hospital system. This is the ordinary background rate of what is happening to ordinary healthcare organizations, and most of these are not household names.

What the report actually says

Let’s stay close to what HIPAA Journal documented, because the details matter more than the headline.

According to HIPAA Journal, Alta Orthopaedics Medical Group, a specialty practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, confirmed that the protected health information of 24,496 individuals was exposed and potentially stolen. The report says unusual network activity was identified on March 10, 2026, and the investigation determined an unauthorized third party had access to the network between February 3 and February 6, 2026. HIPAA Journal reports the INC Ransom ransomware group claimed responsibility, said 26 GB of data was exfiltrated, and that the data was subsequently leaked. The compromised information, per the report, included Social Security numbers, driver’s license numbers, passport numbers, financial account information, diagnoses, treatment information, and biometric data.

According to HIPAA Journal, Cornerstone Behavioral Healthcare, a mental health and substance use disorder treatment provider in Worcester, Maine, identified a ransomware attack on May 26, 2026, the same day the attackers gained access. The report says access was blocked within an hour of discovery and affected computers were powered down quickly, and Cornerstone believes less than 10 percent of the data on affected systems was encrypted. HIPAA Journal reports the protected health information of 14,830 patients was ultimately determined to have been potentially compromised, including substance use disorder treatment information. Per the report, Cornerstone received a ransom demand and did not pay, wiped all affected computers, purchased new ones, and provided ransomware training to its workforce.

According to HIPAA Journal, Cameron Regional Medical Center, a 60-bed acute care hospital in Cameron, Missouri, detected a ransomware attack on June 18, 2026, when files on its network were encrypted. The report says the investigation is ongoing, that patient protected health information was subject to unauthorized access and may have been exfiltrated, and that the Anubis ransomware group claimed responsibility and leaked some stolen data as proof.

The HIPAA Journal roundup also names Suntree Internal Medicine in Florida and Associated Endocrinologists in Michigan as reporting ransomware-related breaches, with ransomware groups claiming responsibility. The portion of the article available to us did not include the specifics for those two providers, so we won’t invent them.

Why five different practices tell one story

Look past the individual names and a pattern shows up.

These are not five identical organizations. One is a small behavioral health provider. One is an acute care hospital. One is a multi-location specialty group. The attackers did not care. Ransomware crews run at scale, and a small specialty practice holds the same thing a large system does: Social Security numbers, driver’s licenses, diagnoses, financial account data, and in some cases biometric and substance use disorder records. That last category is not just sensitive, it is legally and ethically some of the most protected information a provider can hold. When it leaks, the harm to a patient is not abstract.

The timelines in the report are the other thing to notice. At Alta Orthopaedics, per HIPAA Journal, the intruder had access in early February, but the unusual activity was not identified until March 10. That is roughly a month of quiet access before anyone saw it. Compare that to Cornerstone, where the report says the attack was identified the same day access was gained and blocked within an hour, and less than 10 percent of data was encrypted as a result. Same threat, very different outcomes, and the difference is how fast someone noticed and acted.

That is the whole game for a medical practice. You will not stop every attempt to get in. What you can change is how long an intruder gets to sit inside your network before someone catches it, and what they can reach once they are there.

If you are a practice administrator or a physician-owner reading this, none of this is a lecture. These are organizations that look like yours, run by people who were doing their jobs. The point is not that they did something uniquely wrong. The point is that this is the current baseline, and preparing for it is now part of running a healthcare organization.

What to do now

You do not need to overhaul everything this quarter. You need to close the gap between intrusion and detection, and shrink what an attacker can reach. A short list you can actually work through:

  1. Know your detection window. Ask a direct question: if someone were inside your network right now, how long before you’d know? If the honest answer is days or weeks, that is your first project. Cornerstone’s one-hour response, per the report, is what good looks like.

  2. Segment your network. The reason Cornerstone contained the damage is that powering down affected sections limited the spread. If your clinical systems, billing, and administrative machines all live on one flat network, one foothold reaches everything.

  3. Test your backups by restoring from them, not by checking a box that says they ran. A backup you have never restored is a hope, not a recovery plan. Cornerstone was able to wipe and rebuild because it had somewhere to rebuild from.

  4. Turn on multi-factor authentication everywhere it will go, especially remote access. A month of quiet access, like the Alta timeline HIPAA Journal describes, usually starts with a credential that should have had a second factor in front of it.

  5. Train your people on ransomware specifically, the way Cornerstone did afterward. Do it before, not after. The staff at the front desk and in the exam rooms are your earliest warning system.

  6. Have a breach response plan written down and know your HIPAA notification obligations before you need them. When PHI is exfiltrated, the clock and the reporting requirements are not optional.

Ransomware against healthcare is not a wave that is coming. It is the tide that is already in. Five practices in five states in one report is the ordinary weather now, and the organizations that come through it are the ones that decided, ahead of time, to notice fast and contain hard.

centrexIT has been the IT team Healthcare organizations across the West have trusted since 2002. If you are not sure how long an intruder could sit inside your network before you’d catch it, that is exactly the gap worth measuring first. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/assessment/cybersecurity/

Common Questions

How long did the attackers have access before being detected in these breaches? It varied widely. According to HIPAA Journal, at Alta Orthopaedics an unauthorized party had network access in early February 2026 but the unusual activity was not identified until March 10, 2026. At Cornerstone Behavioral Healthcare, the report says the attack was identified the same day access was gained and blocked within an hour.

Does paying the ransom make the breach go away? No. Per HIPAA Journal, Cornerstone received a ransom demand and did not pay, then wiped and rebuilt its systems. In other cases in the report, groups leaked stolen data regardless. Paying does not guarantee data is returned or deleted, and exfiltrated data may still be published.

Are small practices really targets, or is this a big-hospital problem? The five providers in this report range from a small behavioral health provider to a 60-bed hospital to a multi-location specialty group. Ransomware crews operate at scale and target the data, not the org chart. A small practice holds Social Security numbers, diagnoses, and financial data that attackers can monetize.

What is the single most important thing a practice can do? Shorten the time between intrusion and detection. You cannot prevent every attempt, but the difference between a month of quiet access and a one-hour response, both documented in this report, is the difference between a catastrophic breach and a contained incident.

Sources

Found this helpful? Share it with your network.
Written by
centrexIT Team

The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.

Meet Our Team