SYS::ONLINE
Wasteland.
Briefs2308
Issues25
SinceFeb 2026
LIVE
█ Ransomware CENTRAL-OHIO-HEALT 2026-08-28

Central Ohio Primary Care Physicians: Chaos Ransomware Data Theft Claim

"The ransomware group Chaos has named Central Ohio Primary Care Physicians (COPCP), a physician-owned primary care group serving more than 500,000 patients across Ohio, on its leak site. The listing appeared on August…"

The ransomware group Chaos has named Central Ohio Primary Care Physicians (COPCP), a physician-owned primary care group serving more than 500,000 patients across Ohio, on its leak site. The listing appeared on August 25, 2026 and was picked up by security press on or about August 26. Monitoring site Breachsense puts the volume of stolen data at roughly 362 GB, while earlier reporting referenced roughly 263 GB, per the Edelson Lechtzin LLP release (PRNewswire, Aug. 27). One important caveat up front: as of this writing there is no COPCP statement, no HHS Office for Civil Rights portal entry, and no state attorney general filing in the available sourcing. Breach House records the victim's disclosure status as "Not disclosed yet." Everything below the leak-site claim is unconfirmed by the victim.

What Happened

According to a dark web blog post reported by HookPhish and corroborated by Breachsense, Chaos claimed an attack on COPCP estimated to have occurred on or about August 25, 2026. Breach House, which indexes leak-site postings, logs the victim record as published August 25 with a zero-day "window zero," meaning the leak-site listing itself was the first public signal.

The extortion posture is the standard double-extortion playbook. The Chaos post, as summarized by Breach House and Undercode News, complains that COPCP leadership "has chosen to completely ignore all attempts to establish a constructive dialogue" and threatens publication of the stolen files. That framing is the attacker's, not the victim's, and it should be read as leverage rather than fact. Refusing to negotiate with a criminal group is a defensible incident response decision, not evidence of negligence.

Two accuracy notes on the Breach House record: it lists the victim's country as China, its business category as IT, and its headcount as 51 to 100 employees. None of that matches a Westerville, Ohio physician group serving half a million patients. Leak-site metadata is frequently wrong or auto-tagged, and this entry should not be cited for anything beyond the timestamp and the claim itself.

There is also a separate Ohio healthcare incident circulating in the same coverage cycle that is easy to conflate with this one, and readers should keep the two apart. Unlimited Technology Systems (UTS), a revenue cycle management and practice management software vendor based in Montgomery or Cincinnati, Ohio depending on the source, disclosed a ransomware intrusion in which an actor had access between October 5 and October 10, 2025. Reported victim counts for UTS range from "at least 442,000" patients in state attorney general filings (MedRisk, Aug. 2) to 3,803,750 individuals on the HHS OCR portal (HIPAA Journal and CyberInsider). The higher HHS figure is the authoritative national total; the lower figure reflects partial state-level filings. UTS notifications began July 21, 2026. The COPCP incident is a distinct event with a different actor, a different timeline, and no confirmed notification program yet.

What Was Taken

For COPCP, the only quantitative claim comes from the attackers and the monitoring services indexing them. Reported volumes range from roughly 263 GB in earlier reporting to approximately 362 GB per Breachsense, as stated in the Edelson Lechtzin release. Breach House published redacted proof-of-breach previews including a file tree listing, a spreadsheet named finance_2024.xlsx, a passport scan, and a signed contract. That sample set suggests a mix of corporate finance, HR, and identity documentation rather than a clean electronic health record dump, though a sample is not an inventory.

The Tech Edvocate reports that exposed data may include medical history, Social Security numbers, addresses, and employment records. That characterization is not sourced to COPCP or any regulator and should be treated as informed speculation about what an organization of this type holds. The class action firm's release is explicit that "the full scope and nature of the incident remain unconfirmed."

By contrast, the UTS incident has a documented data inventory because notification letters exist. Per CyberInsider and MedRisk, exposed elements varied by individual and potentially included names, Social Security numbers, dates of birth, contact and demographic details, scanned driver's licenses and government IDs, insurance cards, patient intake forms, health insurance policy numbers, claims and benefits data, medical record numbers, dates of service, and diagnosis information. UTS stated the incident did not involve full medical records, medical imaging, or credit card and bank account numbers, and that it had no evidence of misuse. That is the level of detail COPCP has not yet provided, and the gap is the story.

Why It Matters

A physician group with a 500,000-patient panel is a high-consequence target for reasons that have nothing to do with its security maturity. Primary care is the front door to the health system: it holds longitudinal records, insurance identifiers, dependent and family linkage, and employment data for staff. Note that the 500,000 figure describes COPCP's patient population, not a confirmed count of affected records. Those are different numbers, and conflating them is the most common error in early breach coverage.

The broader pattern worth tracking is where healthcare data is actually being lost. HIPAA Journal reports that six of the top ten breaches disclosed this year occurred at business associates rather than providers, and that business associates account for 50 percent of the largest healthcare breaches of all time. The UTS case is the archetype: a software vendor most affected patients had never heard of, holding records for patients of dozens of unrelated practices. HIPAA Journal also notes the proposed HIPAA Security Rule update includes tighter business associate requirements and stronger vendor oversight obligations, but that the final rule has slipped, with OCR now expecting release by July 2027. Defenders should not plan around regulatory pressure arriving on schedule.

Meanwhile the legal machinery moves faster than the forensics. Edelson Lechtzin LLP opened an investigation and began soliciting current and former COPCP patients and employees within roughly 48 hours of the leak-site post, before any victim statement existed. Organizations should expect the class action clock to start at leak-site publication, not at notification.

The Attack Technique

Initial access, dwell time, and the specific Chaos payload variant are all unreported for COPCP. No source in this set describes the intrusion vector, whether encryption occurred alongside exfiltration, or whether clinical operations were disrupted. Anyone stating otherwise is inferring.

What the sources do support is the extortion model. Undercode News and The Tech Edvocate both describe Chaos operating the now standard exfiltrate-then-pressure pattern, where the threat of publication is the primary leverage and encryption is secondary or optional. The naming and shaming post, the countdown framing, and the redacted proof screenshots are all consistent with that model.

The UTS incident, where more forensic detail is public, offers a useful contrast in shape. A five-day access window from October 5 to October 10, 2025, was not detected until October 19, 2025 per CyberInsider, with public confirmation arriving in July 2026 and the full scale only becoming clear when the HHS portal entry appeared. Roughly nine months elapsed between intrusion and notification, and around ten between intrusion and an accurate victim count. Notably, CyberInsider reports no threat group claimed responsibility for the UTS attack. The two cases bracket the range: one where the attacker announces immediately and the victim is silent, one where nobody announces and the disclosure grinds through regulators.

What Organizations Should Do

  1. Monitor leak sites as a detection source, not just a PR problem. In this case the leak-site post was the first public indicator, with a zero-day gap between attacker publication and press pickup. If your first notice of a vendor compromise comes from a journalist, you are already behind.
  2. Inventory downstream business associates and their subprocessors. MedRisk's guidance on the UTS case applies broadly: know which vendors host or process your patient data, review their incident response and notification obligations contractually, and pressure-test whether their hosted platforms meet your own control standards.
  3. Assume exfiltration precedes encryption and instrument for it. Alert on large outbound transfers, anomalous archive creation, and cloud storage or file-transfer utilities appearing on clinical and finance file servers. A 362 GB egress should not be a silent event.
  4. Shorten the detection gap on the network segments holding scanned identity documents. The proof screenshots in this case featured passport scans and signed contracts, and the UTS inventory included driver's licenses and intake forms. Unstructured document shares are frequently outside EHR-focused monitoring and are exactly what extortion crews screenshot first.
  5. Pre-stage your disclosure posture before you need it. Decide in advance who authorizes public statements, what the holding statement says, and how fast you can file with OCR and state AGs. Silence during an active extortion campaign is a legitimate choice, but it must be a deliberate one, because the attacker will narrate the gap for you.
  6. Offer and operationalize identity monitoring early. UTS provided 24 months of free identity monitoring. Have the vendor contract and the call center capacity pre-negotiated so enrollment is not the bottleneck when notifications go out.
  7. Track the numbers you publish. Distinguish patient panel size from confirmed affected records, and cite the source for each. Early figures in this case already span 263 GB to 362 GB, and the UTS parallel spans 442,000 to 3.8 million depending on whether you read state filings or the federal portal.

Sources: Catastrophic: Central Ohio Data Breach Exposes Half a Million Patie... | Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycl... | copcp.com — CHAOS Ransomware Attack Breach House | Edelson Lechtzin Investigates Data Breach at Central Ohio Primary C... | Ransomware at Ohio vendor triggers notices for 442,000 patients – M... | Unlimited Technology Systems data breach impacts 3.8 million people | Central Ohio Primary Care Physicians Data Breach | Chaos Ransomware Targets Central Ohio Primary Care as Healthcare Da...