Medical Group Ransomware Attack

michael • July 6, 2026

Share this article

Medical Practice Ransomware Attack Exposes 934,000 Patient Records


A multi-location medical group in Maryland had patient data for 934,326 individuals stolen in a January 2025 ransomware attack, leading to multiple class-action lawsuits over its cybersecurity practices and delayed notification.


What happened in this medical practice ransomware case?

On January 27, 2025, an unauthorized party gained access to the medical group's network and copied files from a shared file server. The organization, which operates more than 25 locations and employs nearly 4,000 staff, detected the unauthorized activity and took its IT systems offline to contain the threat.


The electronic medical records system itself was reportedly not the entry point. The attackers reached patient data through a shared drive — a far more common and far less defended target than the EHR platform most practices assume is their main point of exposure.


What patient information was exposed?

Stolen data included patient names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, health insurance details, and clinical information related to patient care. No ransomware group publicly claimed the attack and no stolen data surfaced publicly afterward, which security researchers say often indicates a ransom was paid quietly rather than negotiated in public.


Why did patients sue over this breach?

At least five class-action lawsuits were filed against the medical group. The suits allege the organization failed to implement reasonable cybersecurity safeguards, didn't follow industry-standard practices, and didn't disclose adequate detail in its breach notification letters — including what specific steps were being taken to prevent a repeat incident.


The lawsuits illustrate a pattern that extends well past large health systems: a breach notification that reads as vague or incomplete can generate legal exposure on its own, separate from the underlying security failure.


What would a managed IT provider have done differently?

  • A shared file server held highly sensitive data with apparently limited monitoring or access restriction. Network segmentation and least-privilege access mean files containing Social Security numbers and clinical data aren't sitting on a general-access shared drive in the first place — and if they must be, access is scoped and logged.


  • The intrusion wasn't detected until the attackers had already copied the data out. Continuous monitoring is built to catch unusual file access and large data transfers in progress, not after the fact, narrowing the window between intrusion and detection from weeks to minutes.


  • Breach notification letters were criticized as vague and incomplete, which became part of the basis for litigation. A documented incident response plan defines exactly what gets communicated, when, and in what level of detail — so notification meets both the legal requirement and the standard a reasonable patient would expect.



  • The practice had no way to quickly confirm what was actually impacted versus merely accessible. Clear documentation of where sensitive data lives and who can reach it means a practice can scope an incident accurately and quickly, instead of guessing under pressure while lawyers and regulators wait for an answer.


The bottom line

This wasn't an attack on a hardened core system — it was an attack on a shared drive that nobody had gotten around to locking down. That's a gap nearly every practice has somewhere, and it's the exact kind of gap proactive, documented IT management is built to close before it becomes a headline and a lawsuit.

Recent Posts

Dental ransomware attack case study: $350,000 HIPAA settlement — Vault Technologies
By michael June 29, 2026
A 2020 dental ransomware attack led to a $350,000 HIPAA settlement after a 2-year disclosure delay. See what proactive monitoring and incident response would have changed.
By michael April 16, 2026
Vault Technologies Case Study — Synology 4‑Bay NAS Recovery for GoodGardens
By michael March 12, 2026
This is a subtitle for your new post
By michael March 12, 2026
Case Study: Emergency Data Recovery for a Time‑Sensitive Project
By michael February 24, 2026
Why Vault Technologies Is Becoming Oregon's Trusted IT Partner for Senior Care — and Beyond In a crowded field of MSPs, most companies promise the same things: "fast support," "reliable service," "expert technicians." But the organizations we serve aren't looking for another generic IT provider. They're looking for a partner who understands the stakes of what they do — and shows up with the discipline, documentation, and clarity to match. That's exactly why Vault Technologies was built. As a Service-Disabled Veteran-Owned and Woman-Owned business, we built Vault on the values that shaped our careers: precision, integrity, and accountability. We don't believe in vague promises or confusing pricing. We believe in clear expectations, transparent processes, and IT support that feels like a partnership rather than a gamble. That's what makes Vault different — and it's the thread running through everything we've built since. Built on Discipline, Documentation, and Trust Most MSPs operate behind the curtain. Clients rarely know what's happening, what's included, or what they're paying for. Vault Technologies takes the opposite approach. We document everything. We communicate proactively. We set boundaries clearly. We price transparently — flat, per-seat, per-month, with no hourly billing surprises. Our clients know exactly what we do, how we do it, and what to expect at every step. That clarity builds trust — and trust is the foundation of every long-term partnership we have. A Rare Hybrid: IT Expertise and Clinical Understanding One of the biggest gaps in healthcare IT is the divide between people who understand technology and people who understand care delivery. Most MSPs only know the former. Vault closes that gap. Our co-founder Kristina brings 15 years of nursing experience, including hospice and home care, to every conversation we have with assisted living, home health, and hospice clients. We don't just know what EHR downtime looks like on a dashboard — we know what it means for a med-pass window or a shift change when systems fail. That's a hybrid skillset almost no other MSP in Oregon can offer, and it's why we built our service tiers — Foundation, Continuum, and Vigil — specifically around the realities of shift-based care, not a generic 9-to-5 business clock. A Partner Built for Other MSPs, Too Vault isn't just direct-to-client. We're also structured to support other MSPs who need additional capacity without the overhead of hiring. Through our white-label and subcontracting model, we offer: Overflow ticket capacity when an MSP's queue gets ahead of them Standing capacity partnerships for MSPs ready to free up their senior techs Full-scope backend delivery for MSPs that want to focus on sales and relationships while we run help desk, NOC, security, and M365 administration behind the scenes Every tier comes with clear, published pricing and a transparent application process — because the same documentation-first approach we bring to direct clients applies to our MSP partners too. Certified and Ready for Government and Prime Contracting As a certified SDVOSB, VOSB, WOSB, and EDWOSB small business, Vault is also positioned to support federal, state, and local agencies, as well as prime contractors building out their subcontracting base. We're registered in SAM.gov and eligible for set-aside and sole-source opportunities — backed by the same audit-ready documentation and disciplined execution that defines how we operate everywhere else. Veteran Values, Applied Everywhere We Work Being veteran-owned isn't a marketing slogan for us — it's a mindset. It shows up in how we communicate. It shows up in how we document. It shows up in how we treat clients and partners alike. It shows up in how we build systems that scale — whether that's a single assisted living facility or an MSP partner's entire book of business. Why Organizations Choose Vault Technologies Organizations across Oregon and beyond choose Vault because we offer: Clear, transparent, per-seat pricing Professional, jargon-free communication Documented, audit-ready processes Veteran-level discipline Real clinical understanding for senior care and home health A scalable model for MSP partnerships and government contracting A modern, approachable brand built on substance, not slogans We're not trying to be the biggest MSP in Oregon. We're becoming the most trusted — for the care organizations who depend on us, the MSPs who partner with us, and the agencies who need a certified, capable small business they can rely on. The Future of Vault Technologies  Our mission is simple: become the most trusted IT partner for the organizations that value clarity, reliability, and professionalism — whether that's a senior care facility that can't afford technology failure, an MSP looking for a dependable subcontractor, or an agency seeking a certified small business partner. This is the standard we hold ourselves to, and the standard our clients and partners have come to expect.