Sandhills Medical Ransomware Attack Exposes 170,000 Patient Records
Data Breach Hits Sandhills Medical, Affecting Nearly 170,000 Individuals
A sophisticated ransomware attack compromised the sensitive information of almost 170,000 patients at Sandhills Medical Foundation, a healthcare provider based in South Carolina.
Ransomware Attack Details
The breach, which was first detected on May 8, 2025, resulted in the unauthorized access of personal identifiable information, including names, dates of birth, Social Security numbers, taxpayer identification numbers, driver’s licenses, government-issued IDs, passports, financial information, and personal health records.
Attackers Identified and Investigation Launched
The attackers, identified as the Inc Ransom ransomware group, gained unauthorized access to Sandhills Medical’s network through a targeted attack. They then exfiltrated sensitive data, which they subsequently published on their leak website. The compromised data has since been made available for public viewing, further exacerbating the breach.
Law Enforcement and Forensic Investigation
Law enforcement officials were promptly notified, and a thorough investigation was launched in collaboration with cybersecurity experts and a forensic firm. Sandhills Medical has since taken steps to remediate the breach, restore systems, and implement enhanced security measures to prevent future incidents.
Importance of Robust Cybersecurity Measures
The breach highlights the increasing sophistication of ransomware attacks and the importance of robust cybersecurity measures in protecting sensitive patient information. As the healthcare sector continues to face growing threats, it is essential for organizations to prioritize cybersecurity and invest in robust defenses to safeguard against such attacks.
Key Facts
- Number of affected individuals: Almost 170,000
- Type of breach: Ransomware attack
- Compromised data: Personal identifiable information, including names, dates of birth, Social Security numbers, taxpayer identification numbers, driver’s licenses, government-issued IDs, passports, financial information, and personal health records
- Attack vector: Targeted attack by the Inc Ransom ransomware group
- Date of discovery: May 8, 2025
- Current status: Investigation ongoing, remediation underway