Five American healthcare providers across five states have confirmed data breaches tied to ransomware activity, with two established extortion brands claiming credit. Alta Orthopaedics Medical Group (California), Cornerstone Behavioral Healthcare (Maine), Cameron Regional Medical Center (Missouri), Suntree Internal Medicine (Florida) and Associated Endocrinologists (Michigan) all confirmed compromises of patient information, according to reporting by the HIPAA Journal on September 3, 2026. The only per-victim record count published so far belongs to Alta Orthopaedics: 24,496 individuals, following an intrusion window of February 3 to February 6, 2026 that went undetected until March 10. INC Ransom claimed that attack and said it exfiltrated 26 GB of data, which was subsequently leaked. Cameron Regional Medical Center was posted to the Anubis leak site on August 3, 2026, per dark web leak-site monitoring. Readers should note that the four remaining victims have not yet had individual figures published in the available sourcing, and the HIPAA Journal article text is truncated in our source set beyond the Alta section, so details for Cornerstone, Suntree, Cameron Regional and Associated Endocrinologists are drawn from the incident confirmation and leak-site monitoring rather than from full victim notifications.
What Happened
The Alta Orthopaedics timeline is the most complete of the five and is worth reading as a template for the rest. Alta, a specialty orthopaedic practice with clinics in Santa Barbara, Solvang, Santa Maria and Oxnard, identified unusual network activity on March 10, 2026. Forensics later placed the actual unauthorised access more than a month earlier, between February 3 and February 6, 2026. That is a roughly 32-day detection gap after the attacker had already left. The data review took until June 24, 2026 to complete, and notification letters followed after that. From first access to notified patients, the elapsed time was close to five months.
Alta's own notification letters did not characterise the incident as ransomware. The HIPAA Journal assesses that it was, on the basis that INC Ransom claimed the attack, advertised 26 GB of stolen data, and then published it. This is a distinction defenders should hold onto: the victim's public language and the extortion crew's leak-site post describe the same event in very different terms.
Cameron Regional Medical Center, a 60-bed acute care hospital at 1600 East Evergreen in Cameron, Missouri, operating satellite clinics across northwest Missouri, appears in a separate strand. Anubis listed it on August 3, 2026 as part of a same-day cluster of three victims. Leak-site tracking by Darkfield records the listing status as "data leaked" with the leak date unknown, and notes the Anubis post claimed patient and employee data without specifying data categories or volumes. Security Arsenal, monitoring the same postings, placed Cameron Regional alongside home healthcare provider BLACKBURN'S and grocery chain Winn-Dixie in that August 3 batch. Both of those sources are OTHER tier and both derive from the same leak-site data, so they corroborate each other only weakly.
One inconsistency is worth flagging plainly. The HIPAA Journal article body places Cornerstone Behavioral Healthcare in Maine, while the article's own URL slug lists the affected states as CA, MA, MO, FL and MI. We follow the article body and the incident confirmation: Maine.
What Was Taken
For Alta Orthopaedics, the disclosed data set is unusually broad, and it is the identity-theft profile rather than the record count that makes this one serious. Personally identifiable information potentially compromised includes names, contact information, Social Security numbers, driver's licence and state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth and login credentials. The protected health information side includes diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information and biometric data.
That combination, government identity documents plus financial instruments plus clinical detail plus biometrics, is close to a complete identity dossier per patient. Biometric data in particular has no reissue path. A Social Security number can be flagged and a passport replaced; a biometric template cannot be rotated.
INC Ransom put the exfiltration volume at 26 GB for Alta and the data has been leaked. For Cameron Regional, Anubis claimed patient records and employee data but published no categories or volume in the leak post itself, according to Darkfield's extraction. No published data inventories or record counts for Cornerstone Behavioral Healthcare, Suntree Internal Medicine or Associated Endocrinologists appear in the available sourcing. We are not going to invent them.
The Cornerstone case deserves separate weight even without a published inventory. Behavioural health records carry disclosure sensitivity that ordinary medical records do not, and re-identification harm from a leaked behavioural health data set is categorically worse than from, say, a billing file.
Why It Matters
The obvious framing is five small-to-mid providers getting hit. The more useful framing is what these five sit inside.
2026 has been a year in which the largest US healthcare data losses have not come from hospitals at all. Per the HIPAA Journal, six of the top ten healthcare breaches reported this year occurred at business associates, as did half of the largest healthcare breaches of all time. Unlimited Technology Systems, a Cincinnati revenue cycle management and practice management software provider, confirmed 3,803,750 affected individuals on the HHS Office for Civil Rights portal, the second-largest healthcare breach of the year to date, behind DentaQuest at 15 million and ahead of Trizetto Provider Solutions at 3.4 million. Notably, no threat group has claimed the UTS intrusion, and the access window (October 5 to 10, 2025) predates its July 2026 confirmation by nine months.
The vendor pattern repeats. CareCloud, an RCM, practice management and EHR provider serving more than 45,000 US healthcare providers, notified individuals in late July 2026 about a March 2026 intrusion. Reported figures for CareCloud are consistent across the two sources we have but are explicitly a floor rather than a total: ComplianceHub puts the confirmed count at "at least 345,000 individuals" from AG filings in California, New Hampshire, Massachusetts, Texas and Maine and expects it to climb, and TechNewsHub reports the same at-least-345,000 figure. The two differ slightly on the intrusion window: ComplianceHub gives 10 to 16 March 2026, while TechNewsHub gives March 10 to 16 and adds that the breach hit one of six AWS-hosted EHR environments and caused an eight-hour outage. Both are OTHER tier; treat the AWS environment detail as reported, not confirmed. Neither reports any group claiming the attack. Separately, Xsolis, a care-review vendor, disclosed on June 24, 2026 that a January 22, 2026 phishing attack exposed roughly 1.4 million people, reaching patients at Mayo Clinic, UW Medicine and VHC Health.
Set against that, the five providers here are the other half of the problem. They are the direct-compromise tier: individual practices and a 60-bed rural hospital, each holding a full clinical and identity record set, each with a security budget a fraction of what a national vendor commands, and each apparently detected late. Alta's 32-day gap between attacker exit and detection is not an outlier in this sector; it is the norm.
The regulatory backstop that would tighten this is also slipping. The proposed update to the HIPAA Security Rule, which includes measures aimed at business associate security and vendor oversight by covered entities, was planned for a mid-2026 release. OCR now expects to issue the final rule by July 2027, a delay of roughly a year.
The Attack Technique
Initial access vectors for these five specific victims have not been disclosed. Alta's notification does not state one, and no victim statement in our sourcing names a vulnerability, phishing lure or credential compromise.
What is available is a group-level profile of Anubis from Security Arsenal, which is an OTHER-tier analyst assessment based on leak-site monitoring rather than incident response data, and should be read that way. Security Arsenal characterises Anubis as a ransomware-as-a-service operation running double extortion, with initial access described as heavily reliant on perimeter exploits against VPN and firewall appliances and on compromised remote monitoring and management tooling, rather than phishing. The assessment attributes lateral movement to a mix of Cobalt Strike beacons and native tooling such as PsExec and WMI, estimates dwell time at three to seven days, and puts ransom demands in the $500,000 to $5 million range calibrated to victim revenue. Note that despite the report being titled as a CVE exploitation analysis, no specific CVE is identified in the material available to us. Treat the technique profile as directional, not as an indicator set.
On the group itself, Darkfield records Anubis as having begun operations in February 2025 with roughly 65 documented victims accumulated since, and notes that its country of origin, structure and affiliations are not publicly established. Its August 3, 2026 posting cluster skewed toward US healthcare and retail, which fits the general RaaS logic of hitting organisations where downtime is intolerable and PHI raises the pressure.
INC Ransom, which claimed Alta, behaved consistently with its established pattern: claim, advertise a volume figure, then publish when payment does not arrive. The Alta data is out.
What Organizations Should Do
- Close the detection gap on the edge. If the Anubis profile is directionally correct, internet-facing VPN concentrators, firewalls and RMM agents are the entry point. Inventory every one of them, confirm the patch level against vendor advisories, and enforce phishing-resistant MFA on all remote access. An unpatched edge appliance is the single highest-yield item on this list.
- Assume the exfiltration precedes the encryption. Anubis dwell time is estimated at three to seven days; Alta's attacker was in for four. Detection tuned to encryption events is tuned to the wrong stage. Alert on bulk outbound data transfer, unusual archive creation, and access to EHR or billing databases outside normal service accounts and hours.
- Hunt for the lateral movement toolchain specifically. PsExec, WMI-based remote execution and Cobalt Strike beaconing are the named tools. These are detectable with existing telemetry if anyone is actually looking. Baseline legitimate admin use of PsExec and WMI so that anomalous use surfaces rather than drowning.
- Audit your business associates, not just yourself. Six of the top ten healthcare breaches this year hit business associates. Enumerate every RCM, practice management, EHR, coding and utilisation-review vendor holding your patient data, and get written answers on their access windows, logging retention, encryption at rest and breach notification timelines. Do not wait for the delayed HIPAA Security Rule update to force this.
- Fix the notification clock before you need it. Alta ran roughly five months from intrusion to notification; CareCloud ran four months from discovery to mailing, against HIPAA's 60-day requirement. Pre-stage your data review capability, your forensics retainer and your state AG filing process now, while it is a tabletop exercise rather than a regulatory exposure.
- Treat biometric and behavioural health data as a separate risk tier. Biometric templates cannot be reissued and behavioural health records carry disclosure harm that credit monitoring does not address. Segment these stores, restrict access to a named group, and log every read. Alta's 24-month credit monitoring and identity theft protection offer is standard practice, and it is also the ceiling of what remediation can do once this class of data is public.
Sources: Five Healthcare Providers Report Ransomware-Related Data ... | Unlimited Technology Systems Data Breach Affects 3.8 Million Patients | ANUBIS Ransomware: US Healthcare & Retail Targeted — Critical CVE E... | Cameron Regional Medical Center data breach — Anubis ransomware lea... | BLACKBURN'S data breach — Anubis ransomware leak (2026) · Darkfield | CareCloud's Four-Month Notification Gap: 345,000 Patients, 45,000 P... | CareCloud notifies 345,000 patients months after breach exposed ... | Xsolis breach: one healthcare vendor, many hospitals Supplier Shield