Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

The Everest ransomware group has taken credit for a hacker attack on Vikor Scientific, now called Vanta Diagnostics.

Healthcare data breach

Nearly 140,000 people are affected by a data breach disclosed by healthcare diagnostic company Vikor Scientific.

The number of affected individuals came to light in recent days on the healthcare data breach tracker maintained by the US Department of Health and Human Services (HHS). 

However, the narrative is not straightforward.

HHS’s tracker lists the South Carolina-based molecular diagnostics company Vikor Scientific (recently rebranded as Vanta Diagnostics) as the victim of a data breach that compromised the information of 139,964 individuals.

The incident came to light in November 2025, when the Everest ransomware group listed Vikor Scientific, along with affiliated diagnostic laboratory companies KorPath and Korgene, on its leak website. The cybercriminals later published data allegedly stolen from the companies.

However, the cybercriminals did not target Vikor and its affiliates directly. The data breach appears to stem from Catalyst RCM, a provider of revenue cycle management solutions.

Advertisement. Scroll to continue reading.

Catalyst published a data breach notice on its website earlier this month, revealing that it detected suspicious activity within its secure file management system in mid-November 2025. An investigation showed that compromised credentials had been used to access data. 

The company’s probe showed that the files stolen by the hackers stored names, dates of birth, payment card details, medical information, and health insurance information.

The Everest ransomware group claimed to have stolen roughly 12GB worth of documents from Vikor, Korgene, and KorPath.

According to Catalyst’s notification to impacted individuals, the compromised data was in its possession as a result of the medical coding and billing services it provides to Vikor Scientific, KorPath, and Korgene. 

Catalyst, KorPath, and Korgene have yet to share the number of impacted individuals with the HHS. It’s unclear whether 139,964 is the total number of affected people or if it’s higher.

SecurityWeek has reached out to Catalyst RCM for clarification.

Related: Mississippi Hospital System Closes All Clinics After Ransomware Attack

Related: ApolloMD Data Breach Impacts 626,000 Individuals

Related: Central Maine Healthcare Data Breach Impacts 145,000 Individuals

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.