Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatransomware-group-operationbreach-disclosure-notificationmass-credential-exposure

Healthcare Organizations Face Legal and Notification Fallout From Ransomware-Linked Data Theft

Updated 3mo agoFirst seen Feb 19, 20263 sources

Norton Healthcare agreed to pay $11 million to settle a class-action lawsuit tied to a 2023 ALPHV/BlackCat ransomware-related data theft that reportedly involved 4.7 TB of stolen data and impacted nearly 2.5 million people. The preliminary settlement provides for reimbursement claims (up to $2,500 for unreimbursed expenses), compensation for time spent responding to the incident (up to $80), and three years of medical identity monitoring, pending final court approval.

Separately, Ohio-based Kettering Health began notifying current and former patients and affiliates about a May 2025 ransomware and data theft incident claimed by the Interlock cybercrime group. Reporting indicates Interlock publicly listed Kettering Health on its leak site and claimed roughly 941–950 GB of data, and Kettering previously warned patients about scam calls from fraudsters impersonating medical bill collectors seeking credit card payments—activity consistent with post-breach social engineering and fraud attempts.

Share:
Healthcare Organizations Face Legal and Notification Fallout From Ransomware-Linked Data Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 15, 20261mo ago

Final approval hearing set for Norton settlement

A final court approval hearing for Norton Healthcare's preliminary $11 million settlement was scheduled for May 15 in Kentucky state court. The settlement reportedly does not require Norton to implement specific security improvements.

Feb 18, 20264mo ago

Norton Healthcare agrees to $11 million breach settlement

Norton Healthcare agreed to pay $11 million to settle a class action lawsuit over the 2023 BlackCat-related data theft. The preliminary settlement includes reimbursement for certain losses, compensation for time spent responding, and three years of medical identity monitoring, while Norton denied wrongdoing.

Feb 17, 20264mo ago

Kettering Health begins notifying patients and affiliates

By February 2026, Kettering Health was notifying an unspecified number of current and former patients and affiliates about the 2025 Interlock-linked breach. The organization said it worked with federal law enforcement and was reviewing its cybersecurity policies and practices.

Jul 1, 20251y ago

Kettering Health reports breach to federal regulators

In July 2025, Kettering Health reported the incident to federal regulators as a hacking breach affecting 501 individuals, using that figure as a placeholder. The organization did not provide an updated total in the referenced reporting.

Jun 1, 20251y ago

Interlock lists Kettering Health on leak site

In June 2025, the Interlock group publicly listed Kettering Health on its leak site and claimed to have stolen roughly 941 GB of data. As of February 2026, the leak site still listed Kettering with about 950 GB allegedly available.

May 20, 20251y ago

Kettering Health intrusion continues through May 20

Kettering Health said unauthorized access to its environment lasted until May 20, 2025. The incident disrupted its IT environment for weeks, affecting patient care, canceling elective procedures, and causing emergency room diversions.

Apr 9, 20251y ago

Unauthorized access begins in Kettering Health environment

Kettering Health said unauthorized actors first accessed its environment on April 9, 2025, in an intrusion later tied to the Interlock cybercrime group. The attackers potentially viewed and acquired files containing personal, health, and financial data.

May 9, 20233y ago

BlackCat data theft at Norton affects nearly 2.5 million people

The May 2023 Norton Healthcare incident was attributed to the ALPHV/BlackCat ransomware group and ultimately affected nearly 2.5 million people. BlackCat claimed to have stolen about 4.7 TB of data, including sensitive personal, health, insurance, and financial information.

May 7, 20233y ago

Attackers access Norton Healthcare network storage devices

Norton Healthcare said attackers accessed certain network storage devices between May 7 and May 9, 2023, in a ransomware-related data theft incident later attributed to ALPHV/BlackCat. Norton said its medical record system and MyChart portal were not accessed.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Threat actors
1 linked
Organizations
2 linked
Information Security Media GroupNorton Healthcare
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Healthcare Organizations Face Legal and Notification Fallout From Ransomware-Linked Data Theft | Mallory