The Center for Hearing and Speech, a Houston nonprofit operating as Texas Hearing Institute (THI), has notified roughly 30,000 current and former patients that their protected health information was exposed in a March 2026 network intrusion. Published counts differ by source: HIPAA Journal reports 29,744 individuals notified in total, while the figure filed with the Texas Attorney General and repeated by Paubox, ClaimDepot and HEAL Security is 29,498 Texas residents. The Interlock ransomware group claimed the attack on its dark web leak site and says it took 540 GB of data. No primary victim statement, regulator filing or CERT advisory was available for this brief; every source below is security press or secondary reporting, and THI's own notification letters do not use the word ransomware.
What Happened
The timeline is consistent across all eight sources. On or about March 20, 2026, THI detected suspicious activity on its computer systems and moved to lock down and secure its environment. A third-party cybersecurity firm was engaged to investigate.
On or about April 22, 2026, that investigation confirmed that an unauthorized third party had accessed parts of the network, including files containing patient information, and that the access predated the March 20 discovery. Emery Reddy, summarizing the Notice of Data Event, states the forensic review determined unauthorized access occurred prior to discovery, but no source gives a dwell time or an initial intrusion date.
Because of the volume and complexity of the data involved, identifying affected individuals took another two months. THI finalized the notification list on June 19, 2026, and mailed letters on June 26, 2026. Paubox notes the incident was reported to the U.S. Department of Health and Human Services later than the June 26 public notice date.
Interlock did not wait for the notification cycle. ClaimDepot dates the leak site posting to April 2, 2026; HIPAA Journal and HEAL Security place it more loosely in "early April." Either way, the extortion posting went up roughly three weeks before THI's own forensic confirmation and nearly three months before patients were told.
The victim profile matters here. THI was founded in 1947 and provides audiology, speech-language therapy and spoken-language education for children with hearing loss, from infancy through young adulthood, across dozens of Texas counties and parts of Louisiana. This is a pediatric patient population.
What Was Taken
Reported data categories are broadly consistent, with some variation in granularity:
- Names and personal identifiers (HIPAA Journal)
- Social Security numbers (all sources)
- Financial account information, specified by ClaimDepot as credit and debit card numbers and account numbers
- Medical records, described by HIPAA Journal as diagnosis and treatment information
ClassAction.org adds that a filing with the Massachusetts Office of Consumer Affairs and Business Regulation identified Social Security numbers and medical information as compromised, which indicates the affected population extends beyond Texas residents. Both HIPAA Journal and HEAL Security state explicitly that the total number of individuals affected nationwide is unclear.
On volume, Interlock claims 540 GB of data copied from the environment. That figure comes from the threat actor's own leak site and is repeated by six of the eight sources, but it has not been independently verified or confirmed by THI.
Remediation offers are also reported inconsistently. HIPAA Journal describes complimentary single-bureau credit score, credit record and credit monitoring services without stating a duration. HEAL Security and a separate HIPAA Journal round-up both describe 24 months of complimentary credit monitoring and identity theft protection. Affected individuals should read their own letter rather than rely on press summaries.
Where Accounts Differ
Three points of genuine divergence are worth flagging rather than smoothing over.
First, the headcount. 29,744 versus 29,498 is not a contradiction so much as two different denominators, one apparently a total notification count and the other a state regulator figure, but no source reconciles them and neither should be presented as the definitive number.
Second, whether the data was published. HIPAA Journal states that Interlock proceeded to leak the stolen data, which would indicate no ransom was paid. No other source corroborates that the leak was completed rather than merely threatened. Treat it as single-source reporting from an established outlet, not settled fact.
Third, the ransomware attribution itself. THI has issued no statement confirming ransomware or naming Interlock. Every source that calls this a ransomware incident is inferring it from the leak site posting. That inference is well supported, but the distinction between a claimed attack and an acknowledged one is the kind of thing that matters in litigation and in regulatory filings.
Why It Matters
Small specialty and pediatric providers are now a first-tier target, not collateral damage. THI is a mid-sized nonprofit clinic, not a hospital system, and the attackers still walked away with a claimed half-terabyte of data. Groups running data-theft extortion do not need the victim to be large; they need the data to be sensitive and the victim to be under-resourced.
The dataset is close to worst-case for downstream harm. Social Security numbers belonging to children are an unusually durable fraud asset, because a minor's credit file is typically unmonitored for a decade or more before anyone checks it. Standard adult-oriented credit monitoring is a poor fit for that exposure, and a 24-month offer covers a fraction of the risk window.
The 98-day gap between detection and patient notification is also the pattern to watch. Interlock published its claim in early April. Patients did not receive letters until late June. For most of that window, the people whose data was on a leak site had no idea, while the criminals and anyone browsing the leak site did.
Interlock's target history reinforces the sector focus. Paubox notes prior claimed victims including Kettering Health and DaVita, both healthcare organizations, plus other Texas entities.
The Attack Technique
The initial access vector for this specific intrusion has not been disclosed by THI or reported by any source. What is known is generic to the incident class: unauthorized network access, lateral movement to file shares containing patient records, and bulk exfiltration prior to detection.
On the actor, Paubox reports that Interlock emerged in September 2024 and operates as a ransomware-as-a-service platform, taking a cut of affiliate proceeds that it puts at up to 20 percent. It further reports that the FBI has characterized Interlock's tradecraft as uncommon for its reliance on drive-by download, delivering malicious payloads disguised as ordinary software downloads or triggered without user intent. HIPAA Journal describes the group as running the standard double-extortion model: steal data, encrypt files, demand payment both for decryption keys and to suppress publication.
That drive-by-download detail comes from a single OTHER-tier source citing the FBI secondhand, and no source links it to this particular intrusion. Defenders should treat it as a plausible actor-level TTP worth hunting for, not as the confirmed entry point at THI.
What Organizations Should Do
- Hunt for drive-by download staging. If Interlock's reported preference for fake installers and browser-delivered payloads holds, application allowlisting and blocking execution from user-writable paths (Downloads, %TEMP%, %APPDATA%) removes the most common landing zone. Pair with proxy logging of executable and archive downloads from uncategorized domains.
- Instrument for exfiltration, not just encryption. THI detected suspicious activity on March 20 but confirmed the scope only on April 22, and the actor was on a leak site before that. Alert on anomalous outbound volume, first-time use of cloud storage and file transfer utilities, and unusual access patterns against clinical file shares. A 540 GB egress event should be a detection, not a discovery.
- Shorten the data review cycle in advance. The two-month gap between forensic confirmation and notification came from having to determine what was in the files after the fact. Data inventory, classification and retention discipline done now is what converts a multi-month review into a multi-week one, and reduces the exposed record count in the first place.
- Purge stale PHI and financial data. Financial account information including card numbers sat alongside pediatric clinical records. Ask whether that data needed to be retained at all, and whether records for patients who aged out of services years ago needed to remain online.
- Prepare pediatric-specific breach response. If your patient population includes minors, plan for credit freezes on children's files rather than monitoring alone, and budget for coverage that extends well past a 24-month window.
- Assume claims-then-notification sequencing. Monitor leak sites for your own organization and your vendors. In this case, public attribution preceded the victim's own confirmation by roughly three weeks. Learning about your breach from a security reporter is a preventable failure mode.
Sources: Texas Hearing Institute Ransomware Attack Affects 30,000 Patients | Almost 30,000 Texas Residents Affected by Data Breach at The Texas... | Texas Hearing Institute notifies public of 30k breach claimed by In... | Texas Hearing Institute Data Breach Investigation | Almost 30,000 Texas Residents Affected by Data Breach at The Texas... | Interlock Ransomware Group Claims 540 GB from Texas Hearing Institu... | Texas Hearing Institute Data Breach Emery Reddy | Texas Hearing Institute Data Breach Reported, Lawsuit Possible