Uncategorized

HMG Healthcare Says Data Breach Impacts 40 Facilities

The compromised information includes names, contact information, dates of birth, health information, medical treatment details, Social Security numbers, and employee records.

The compromised information includes names, contact information, dates of birth, health information, medical treatment details, Social Security numbers, and employee records.

Healthcare services provider HMG Healthcare has disclosed a data breach impacting the personal health information of employees and residents at 40 affiliated nursing facilities.

According to a notice from the organization, the incident was identified in November 2023 but an investigation determined that the data breach occurred in August 2023.

“The incident involved hackers gaining access to our server and stealing unencrypted files. Files on the server likely contained medical records and personal information,” HMG Healthcare notes in an incident notification on its website.

The compromised information includes names, contact information, dates of birth, health information, medical treatment details, Social Security numbers, and employee records.

“We are notifying affected individuals and/or their responsible parties that during August 2023, a server containing your or a loved one’s information was accessed without authorization and the records were potentially compromised,” HMG Healthcare said.

While it did not provide specific details on the type of cyberattack it fell victim to, HMG might have been targeted by an extortion gang, likely a ransomware group, and appears to have been in contact with the attackers, to prevent the public release of the stolen data.

Advertisement. Scroll to continue reading.

“HMG worked diligently to ensure that the stolen files were not further shared by the hackers to other sources. HMG attempted to identify the specific data that was compromised but we have now determined that such identification is not feasible,” it said.

The potentially impacted individuals are advised to monitor their account statements and credit reports to identify any suspicious activity.

The organization has named a total of 40 facilities in Texas and Kansas that were affected by the incident, some of which may not be known by an “HMG” name, but did not say how many individuals might have been impacted.

Related: Ransomware Gang Claims Attack on Capital Health

Related: 4.5 Million Individuals Affected by Data Breach at HealthEC

Related: Over 900k Impacted by Breach at Defunct Boston Ambulance Service

Related Content

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Data Breaches

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version