Interim HealthCare, a franchised home health, hospice and medical staffing network operating across roughly 40 U.S. states, has been named on the dark-web leak sites of two unrelated ransomware operations inside an eleven-day window. The HIPAA Journal, which broke the story on September 9, 2026, reports that the newer GENESIS crew posted first, claiming 1TB of exfiltrated data tied to Interim HealthCare of Oklahoma and Tulsa, and that Anubis followed with a claim of 530GB taken from what it describes as the corporate head office. Critically, there is no primary-source confirmation in this story: Interim HealthCare has not publicly validated either claim, and the only regulator-facing datapoint is a July 31, 2026 filing by a single franchise entity, Interim HealthCare of Oklahoma City, Inc., to the HHS Office for Civil Rights. Treat everything below the filing as claims by extortion actors, not established fact.
What Happened
The sequence, as reconstructed from the reporting, starts with the regulator. HIPAA Journal (S2) and the syndicated copy of the same report (S4) state that Interim HealthCare of Oklahoma City, Inc. reported a network server hacking incident to HHS OCR on July 31, 2026, using the placeholder estimate of 500 affected individuals that organizations commonly file when the forensic count is not yet known. Tech-Insider (S1, OTHER) goes further and says the Oklahoma City breach notice enumerates names, addresses and Social Security numbers; no other source corroborates that data-element list, so treat it as single-source.
Roughly ten days later, GENESIS listed the company. HIPAA Journal, Tech-Insider and Shattered.io all date that listing to August 10, 2026; the Darkfield victim record for the GENESIS post (S7) timestamps it August 11, 2026. That one-day spread is typical of leak-site scraping versus reporting and is not itself significant. GENESIS threatened to publish within five days absent payment, according to Tech-Insider, and posted a file tree, but as of the September 9 reporting the data itself had not been published.
Anubis listed the company second. Five sources (S2, S3, S4, S5, S6) put the Anubis listing on August 21, 2026. CyberThreatIntelligence.net (S8, OTHER) instead dates the Anubis disclosure to August 15, 2026, which is six days earlier and inconsistent with the rest of the record; the August 21 date is better supported. Unlike GENESIS, Anubis has already published, which HIPAA Journal reads as an indication that no ransom was paid.
Accounts diverge on whether the regulator filing and the leak-site posts describe the same event. HIPAA Journal presents the OCR filing alongside the GENESIS claim without asserting causation. Shattered.io (S3) states flatly that no OCR filing tied specifically to either group's allegations had appeared as of its writing, and that it is unclear whether the Oklahoma City filing connects to either claim or to an unrelated incident. Both readings are defensible from the public record. The honest position is that one franchise-level breach is documented with a regulator, two extortion claims exist, and the link between them is inferred rather than proven.
What Was Taken
The two groups describe materially different hauls, which is itself the most analytically interesting feature of this incident.
GENESIS claims approximately 1TB scoped to the Oklahoma and Tulsa operations, described across S2 and S4 as medical records, healthcare data, personal data, patient lists, clinical data and company data. Darkfield's record of the GENESIS post (S7) is thinner, listing only patient records, healthcare information and organizational data, and explicitly notes that no proof files were disclosed at the time of listing. That gap matters: a file tree is cheap to fabricate or recycle.
Anubis claims roughly 530GB and, per its own post quoted in S2 and S4, frames the material as corporate rather than clinical: financial information about franchisees, internal and external audit documents, discussions of operational issues, and day-to-day business memoranda. Darkfield's Anubis dossier (S5) extends that list to HR records including employee salary information, medical records, background checks, termination documents and identity documents from multiple locations, and grades the incident critical on the basis of confirmed exfiltration. That expanded inventory comes from an automated dossier over the leak post, so the specificity should be weighted accordingly. Anubis did attach samples to its listing and has since published, which puts it on firmer evidentiary ground than the GENESIS claim.
Neither figure has been independently verified, and neither maps to a victim count. The 500-person figure in the OCR filing is a placeholder, not a finding. For scale context, Darkfield's public-source profile of the company describes a network of 300-plus locations serving roughly 200,000 people annually. Class Action U (S6), a plaintiff-side firm already soliciting claimants, states the scope of exposed data remains unconfirmed.
Why It Matters
Two crews, two different data profiles, one brand. The likeliest explanations are that two affiliates hit different parts of a federated estate independently, that one group acquired access or data from the other or from a shared initial access broker, or that one claim is opportunistic reuse of the other's publicity. Defenders should not assume a single intrusion.
The franchise model is the structural lesson. Interim HealthCare delivers care through locally owned, independently operated offices under a national brand, with shared systems for franchisee finance, audit and staffing. As Shattered.io observes, a leak-site entry reading "Interim HealthCare" could refer to one local office, a regional operator, or the corporate parent, and the outside world usually cannot tell which. That ambiguity cuts both ways: it lets an actor overstate reach, and it lets a parent company understate exposure. Breach notification obligations, meanwhile, land on whichever covered entity actually held the records, which is why the only regulator filing here names an Oklahoma City corporation rather than the national brand.
There is also a target-selection signal. Home health, hospice and personal care agencies hold the same regulated data as hospitals, with SSNs, clinical histories and caregiver HR files, but typically carry a fraction of a hospital's security staffing. Anubis is a ransomware-as-a-service operation active since December 2024 that S8 describes as explicitly focused on healthcare, engineering, construction and professional services, with an optional destructive wipe mode alongside standard encryption. Victim counts in that same source are internally inconsistent, given as 108 total and as 101 since February 2025, so treat the tally as approximate.
The Attack Technique
Initial access is not established by any source. No CVE, no phishing lure, no vendor advisory, no incident response narrative appears in the public record.
The single technical descriptor available is the OCR filing's incident category: network server hacking. In the HHS taxonomy that indicates compromise of a server rather than email, portable media or paper, which is consistent with the usual path of exposed remote access, a vulnerable edge device, or valid credentials, but it does not select among them.
At the tradecraft level, both actors are exfiltration-first. Anubis runs conventional double extortion, per S8: steal, encrypt, then pressure on both restoration and publication. GENESIS ran a short five-day publication countdown and staged a file tree before releasing anything. Neither group's activity here has been tied publicly to a specific tool, loader or access broker, and no source reports care disruption or downtime at any Interim HealthCare location.
What Organizations Should Do
- Treat the franchise boundary as an attack surface, not a liability shield. Inventory every shared system reachable from franchisee networks, including finance, audit, payroll and staffing platforms, and confirm that a compromise at one location cannot pivot into corporate HR or franchisee financial data. The Anubis claim is precisely a corporate-tier data set.
- Audit and harden remote server access now. Given the network server hacking classification, prioritize internet-facing infrastructure: enforce phishing-resistant MFA on all remote access, retire or gateway any exposed RDP or legacy VPN, and patch edge appliances on an emergency cadence.
- Instrument for exfiltration rather than encryption alone. Both claims here are data theft; only one mentions encryption behavior. Alert on anomalous outbound volume, large archive creation, and traffic to cloud storage and file transfer services from clinical and HR systems.
- Pre-build the multi-entity notification decision tree. Decide in advance which legal entity is the covered entity for which record sets, who files with OCR, and how placeholder counts get revised. Filing 500 as a placeholder, as happened here on July 31, is defensible only if a real count follows.
- Monitor leak sites for your brand and your franchisees' names, not just your corporate legal name. Interim HealthCare appeared under at least three variants across these listings: the national brand, the head office, and Oklahoma and Tulsa entities.
- Assume employee data is in scope and extend protection accordingly. The Anubis inventory reported by Darkfield is heavy on staff records including background checks, terminations and identity documents. Credit monitoring and identity protection planning should cover caregivers and administrative staff, not only patients.
- Verify before you brief. Two claims against one brand does not mean two breaches. Validate file trees and samples against your own asset inventory before conceding scope in public statements, and say plainly what remains unconfirmed.
Sources: Interim HealthCare Ransomware Attack: What We Know | Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare P... | Two Ransomware Gangs Claim Interim HealthCare Hack | Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare P... | Interim HealthCare Head office data breach — Anubis ransomware leak... | Interim HealthCare Data Breach Lawsuit - Class Action U | Interim HealthCare data breach — Genesis ransomware leak (2026) · D... | Interim HealthCare Ransomware Attack by Anubis (2026) Cyber Threat...