Medical Group Ransomware Attack

Medical Practice Ransomware Attack Exposes 934,000 Patient Records
A multi-location medical group in Maryland had patient data for 934,326 individuals stolen in a January 2025 ransomware attack, leading to multiple class-action lawsuits over its cybersecurity practices and delayed notification.
What happened in this medical practice ransomware case?
On January 27, 2025, an unauthorized party gained access to the medical group's network and copied files from a shared file server. The organization, which operates more than 25 locations and employs nearly 4,000 staff, detected the unauthorized activity and took its IT systems offline to contain the threat.
The electronic medical records system itself was reportedly not the entry point. The attackers reached patient data through a shared drive — a far more common and far less defended target than the EHR platform most practices assume is their main point of exposure.
What patient information was exposed?
Stolen data included patient names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, health insurance details, and clinical information related to patient care. No ransomware group publicly claimed the attack and no stolen data surfaced publicly afterward, which security researchers say often indicates a ransom was paid quietly rather than negotiated in public.
Why did patients sue over this breach?
At least five class-action lawsuits were filed against the medical group. The suits allege the organization failed to implement reasonable cybersecurity safeguards, didn't follow industry-standard practices, and didn't disclose adequate detail in its breach notification letters — including what specific steps were being taken to prevent a repeat incident.
The lawsuits illustrate a pattern that extends well past large health systems: a breach notification that reads as vague or incomplete can generate legal exposure on its own, separate from the underlying security failure.
What would a managed IT provider have done differently?
- A shared file server held highly sensitive data with apparently limited monitoring or access restriction. Network segmentation and least-privilege access mean files containing Social Security numbers and clinical data aren't sitting on a general-access shared drive in the first place — and if they must be, access is scoped and logged.
- The intrusion wasn't detected until the attackers had already copied the data out. Continuous monitoring is built to catch unusual file access and large data transfers in progress, not after the fact, narrowing the window between intrusion and detection from weeks to minutes.
- Breach notification letters were criticized as vague and incomplete, which became part of the basis for litigation. A documented incident response plan defines exactly what gets communicated, when, and in what level of detail — so notification meets both the legal requirement and the standard a reasonable patient would expect.
- The practice had no way to quickly confirm what was actually impacted versus merely accessible. Clear documentation of where sensitive data lives and who can reach it means a practice can scope an incident accurately and quickly, instead of guessing under pressure while lawyers and regulators wait for an answer.
The bottom line
This wasn't an attack on a hardened core system — it was an attack on a shared drive that nobody had gotten around to locking down. That's a gap nearly every practice has somewhere, and it's the exact kind of gap proactive, documented IT management is built to close before it becomes a headline and a lawsuit.






