Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Major Addiction Treatment Firm BayMark Confirms Ransomware Attack Caused Data Breach

Substance abuse treatment provider BayMark Health Services says patient personal information was compromised in a data breach.

Healthcare and substance abuse treatment provider BayMark Health Services has started notifying patients that their personal information was stolen in a data breach resulting from a ransomware attack.

The Texas-based company runs one of the largest addiction treatment services in the US, operating roughly 200 facilities and over 380 programs in 35 states, and treating more than 70,000 patients every day.

This week, BayMark submitted data breach notices to Attorney General’s Offices in several states, including California and Vermont, revealing that it has started notifying patients of a data breach affecting their personal information.

“On January 8, 2025, we began mailing notification letters to certain patients whose information related to some of the services they received from the facilities was involved in an incident,” BayMark says in an incident notice on its website.

The data breach, the company says, was the result of a security incident “that disrupted the operations of some of our IT systems”.

BayMark’s investigation determined that, between September 24 and October 14, the attackers accessed some files on its systems, including files containing patient information such as names, dates of birth, driver’s license numbers, Social Security numbers, insurance information, and diagnosis and treatment information.

Advertisement. Scroll to continue reading.

The company is providing the impacted individuals with one year of free identity protection and credit monitoring services, but has not shared information on how many people might have been affected.

“We are offering complimentary identity monitoring services to patients whose Social Security numbers or driver’s license numbers may have been involved. Additionally, it is always a good idea for patients to remain vigilant and review their statements for suspicious activity,” the company said.

While BayMark did not provide details on the disruptive attack, the Ransomhub ransomware group added the healthcare provider to its Tor-based leak site in October, claiming the theft of roughly 1.5 terabytes of data from its systems. The group has since made the allegedly stolen data publicly available.

SecurityWeek has emailed BayMark for additional information on the incident and on the number of impacted individuals and will update this article as soon as a reply arrives. 

Related: Ransomware Group Claims Theft of Personal, Financial Data From Krispy Kreme

Related: Cyberattack Disrupts Systems of Gambling Giant IGT

Related: New Mexico Agencies on Edge Amid Rising Ransomware Attacks

Related: Major Auto Parts Firm LKQ Hit by Cyberattack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

Axonius has appointed Moshe Ben Simon as Chief Product Officer.

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.