AngMar Management Services has confirmed that an unauthorized actor got into its IT systems and may have accessed or taken patient files. AngMar is a home health and hospice management company in Mansfield, Texas. A filing with the Texas Attorney General puts the number of affected Texas residents at 35,916, according to HIPAA Journal. Other state filings add small counts: 9 New Hampshire residents (per Edelson Lechtzin LLP) and 3 Massachusetts residents (per Federman & Sherwood). The total number of people affected nationwide has not been disclosed. The Interlock ransomware group listed AngMar on its dark web leak site in August and says it stole 710 GB of data. AngMar's notification letter does not name an attacker or mention ransomware.
What Happened
AngMar's notification letter and HIPAA Journal's reporting agree on the main timeline:
- On or around July 18, 2026: an unauthorized actor may have accessed or acquired information in AngMar's computer environment.
- July 20, 2026: AngMar spotted unusual activity on its network, took steps to secure its systems, and brought in third-party forensic investigators.
- August 2026: Interlock added AngMar to its leak site. Claim Depot dates the post to August 11.
- September 2026: AngMar finished reviewing the affected data, reported to regulators, and began notifying individuals.
The sources disagree on some dates. HIPAA Journal says the data review was completed on September 8. Edelson Lechtzin and Class Action U both say September 10. For notifications, Edelson Lechtzin says AngMar notified individuals and regulators "on or about September 10," while Class Action U says letters started going out on September 22.
One account contradicts the rest. Edelson Lechtzin's press release (republished by NY Business Times) says the breach happened "on or about July 31, 2026" and that "an employee accidentally emailed documents to an unauthorized actor." Both claims conflict with AngMar's own letter, which gives July 18 as the access date and July 20 as the detection date and describes unusual network activity, not a misdirected email. The same release also lists "financial details" among the exposed data, which the letter does not include. The details look like they may have come from a different incident. We treat them as unverified.
AngMar was founded in 2000 and handles back-office work, clinical compliance, and business development for home health and hospice agencies. Class Action U reports that it manages close to 100 locations in eleven states under brands including Angels Care Home Health. The breach therefore likely reaches beyond Texas, and the 35,916 figure should be read as a floor, not a total.
What Was Taken
According to AngMar's notification letter, the affected data may have included a person's first and last name plus any of the following:
- Address and date of birth
- Social Security number
- Patient ID and medical record number
- Health insurance information
- Dates of service
- Diagnosis and condition information
- Provider names
- Prescription information
- Medical history
Claim Depot adds "medical records" to the list. Edelson Lechtzin adds "financial details." Neither item appears in the company's letter.
Interlock claims it took 710 GB of data. That figure comes from the attackers and has not been independently verified. AngMar has not confirmed that anything was exfiltrated. It says only that data "may have been accessed or acquired," and that there is "no evidence to suggest" misuse so far. The letter came via Cyberscout, which suggests that is the provider of the free credit monitoring AngMar is offering.
Why It Matters
This is a third-party risk problem. AngMar is a management company, not a care provider. It runs back-office and compliance work for many agencies, so one intrusion exposed patient data from agencies across several states. Healthcare organizations that hand off administration to management service organizations are also handing off their exposure.
The stolen data lasts. Diagnoses, prescriptions, and medical histories can't be reissued the way a credit card can. Combined with Social Security numbers, they enable medical identity theft, insurance fraud, and targeted extortion. Hospice and home health patients are mostly elderly or seriously ill, and their families are already stretched, which makes them easier targets for follow-up scams.
The disclosure pattern is typical. The Texas filing gives a precise count, while filings in other states show only single digits. A company operating in eleven states has not published one national total. Defenders and affected people should expect the reported numbers to grow as more state and federal (HHS OCR) filings come in.
Interlock keeps going after healthcare. Interlock is a double-extortion group that has hit healthcare organizations repeatedly. Its leak site works as a pressure tool, and listing a victim usually means negotiations failed or never began.
The Attack Technique
None of the sources say how the attacker got in. AngMar's letter does not describe the entry point. The two-day gap between access and detection (July 18 to July 20) tells us little without knowing when the attacker first got a foothold, since July 18 may mark when data was taken rather than when the intrusion began.
The following is background from earlier public reporting on Interlock, not confirmed for this incident. A joint CISA/FBI advisory published in 2025 and vendor research describe how the group usually operates:
- Initial access: drive-by downloads from compromised legitimate websites, fake browser and software update prompts, and "ClickFix"-style lures that trick users into pasting and running malicious commands.
- Tooling: custom remote access trojans, credential stealers, and keyloggers, followed by movement across the network using RDP and stolen credentials.
- Exfiltration and impact: bulk data theft through cloud storage tools, then encryption of Windows and Linux systems including virtual machines, followed by leak-site extortion.
Edelson Lechtzin's claim that the breach started with an employee mistakenly emailing documents does not match AngMar's account, and no other source supports it.
What Organizations Should Do
- Audit management service and back-office vendors. List every outside party that holds PHI for your organization. Require proof of EDR coverage, MFA, segmentation, and incident notification deadlines in business associate agreements, and limit vendors to the data they actually need.
- Defend against social engineering in the browser. Block fake-update and ClickFix lures: restrict the Run dialog and PowerShell for standard users, filter newly registered and uncategorized domains, and train staff that no real website will ask them to paste commands.
- Watch for large outbound transfers. Taking 710 GB requires sustained outbound traffic. Alert on unusual volumes to cloud storage, file-sharing services, and rclone-style tools, especially at night.
- Restrict RDP and admin credentials. Remove direct RDP exposure, require MFA for all remote and privileged access, use tiered admin accounts, and watch for new local admin accounts or credential dumping.
- Segment and encrypt clinical data stores. Keep EHR exports, billing archives, and file shares holding SSNs and diagnoses off flat networks, and encrypt them at rest so that stolen bulk files are less useful.
- Prepare for multi-state notification. Set up a process to produce a single affected count across all states, so that regulators and patients don't have to assemble the scope from separate state filings.
Sources: Texas Hospice Management Company Data Breach Affects ... | PDF AngMar Management Services c/o Cyberscout PO Box 1286 ... | Angmar Management Services Data Breach Lawsuit Investigation | AngMar Management Service Data Breach Investigation | AngMar Management Services Data Breach - Class Action U | AngMar: 35,916 Texans Hit by Major Data Breach | AngMar Management Services Data Breach – Investigated by Federman &... | Edelson Lechtzin LLP Probes Class Action Claims After Customer Data...