Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatransomware-group-operationthird-party-vendor-breach

Healthcare Data Breach Notifications Following Ransomware and EHR Vendor Compromise

Updated 3mo agoFirst seen Jan 27, 20262 sources

MACT Health Board confirmed patient data theft tied to a November 2025 ransomware attack claimed by INC Ransom. The organization reported network access by an unauthorized party from Nov 12–20, 2025, followed by a file review completed Jan 9, 2026; exposed data may include patient names plus clinical information (e.g., diagnoses, test results, treatment details, medical images) and, for some individuals, Social Security numbers. MACT began mailing notification letters Jan 23, 2026 and is offering credit monitoring/identity theft protection where SSNs were involved.

Munson Healthcare separately notified more than 100,000 patients impacted by a Cerner (Oracle Health) compromise involving access to two legacy Cerner servers (unauthorized access beginning as early as Jan 22, 2025, detected Feb 20, 2025) containing data awaiting migration to the Oracle Cloud. Reported exposed data includes names, SSNs, and typical EHR content (medical record numbers, diagnoses, medications, test results, care details, and providers’ names); Cerner/Oracle Health engaged third-party incident response and notified law enforcement, and reporting indicates notification delays were influenced by law-enforcement requests and ongoing investigation, with litigation alleging the incident may have affected up to 80 hospitals.

Share:
Healthcare Data Breach Notifications Following Ransomware and EHR Vendor Compromise
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Jan 26, 20265mo ago

Michigan AG issues alert after Munson disclosure

Michigan Attorney General Dana Nessel issued a consumer alert in response to the Munson Healthcare breach disclosure. She also called for stronger state data-protection laws.

Munson Healthcare discloses 101,891 patients affected

Munson Healthcare notified patients that data in its electronic medical record system was exposed through the Cerner/Oracle Health cyberattack. The health system said 101,891 current and former patients were affected and offered two years of credit monitoring and identity theft protection.

Jan 23, 20265mo ago

MACT Health Board starts notifying affected patients

MACT Health Board began notifying affected individuals on January 23, 2026 about the November 2025 breach. It offered credit monitoring to people whose Social Security numbers were involved.

Nov 20, 20257mo ago

INC Ransom claims MACT Health Board attack

The INC Ransom ransomware group claimed responsibility for the MACT Health Board incident. The same group was also reported to have listed TriCity Family Services on its leak site and claimed to have stolen 22 GB of data there.

MACT Health Board intrusion ends after days of access

MACT Health Board determined the unauthorized access lasted until November 20, 2025. Exposed information included patient and clinical data, and for some individuals Social Security numbers.

Nov 12, 20257mo ago

MACT Health Board network intrusion begins

MACT Health Board said unauthorized access to its network started on November 12, 2025. The intrusion disrupted IT systems and was later tied to theft of patient information.

Oct 24, 20258mo ago

HAP phishing-related credential compromise occurs

Health Alliance Plan said employee credentials were compromised in a phishing incident on October 24, 2025. HAP later notified potentially affected members even though it could not confirm that their data was actually accessed.

May 14, 20251y ago

TriCity Family Services intrusion ends

TriCity Family Services said the unauthorized access to its network continued until May 14, 2025. The organization later linked the incident to data theft and said the EMR environment was not compromised.

Mar 1, 20251y ago

Oracle Health publicly confirms Cerner breach

Oracle Health publicly confirmed the Cerner cyberattack in March 2025. Later reporting indicated as many as 80 hospitals may have been affected.

Feb 20, 20251y ago

Cerner detects cyberattack on legacy servers

Cerner detected the intrusion on February 20, 2025 and said a hacker had accessed two legacy servers. The incident ultimately affected multiple healthcare organizations and patient records.

Jan 22, 20251y ago

Cerner servers first exposed in Oracle Health incident

In the Cerner/Oracle Health breach affecting healthcare providers including Munson Healthcare, unauthorized access may have begun as early as January 22, 2025 on two legacy Cerner servers awaiting migration to Oracle Cloud.

Nov 11, 20242y ago

TriCity Family Services intrusion begins

TriCity Family Services said an unauthorized party gained access to its network beginning on November 11, 2024. The organization later determined files were copied during the intrusion, though its electronic medical record system was not accessed.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Threat actors
1 linked
Organizations
6 linked
ZenflowMACT Health BoardTriCity Family ServicesHealth Alliance PlanOracle HealthMunson Healthcare
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Healthcare Data Breach Notifications Following Ransomware and EHR Vendor Compromise | Mallory