Healthcare Services Company · Healthcare facility development and specialty care services · Healthcare infrastructure and renal services company · USA
Dialysis and renal (nephrology) telemedicine care provider.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Sanderling Renal Services (listed by the actor as "Sanderling Healthcare"), a Nashville-based dialysis and nephrology provider, was hit by a ransomware attack around July 3, 2025 attributed to the Sarcoma group, which claimed to have exfiltrated roughly 587 GB including a full Oracle database backup spanning 25 years of patient and business data. DataBreach.com’s parse confirmed circulating identifiers including names, addresses, phone numbers, emails, and Social Security numbers (about 40,453 records). Sarcoma additionally claims exposure of dates of birth, driver’s license/state ID numbers, medical records, health insurance, and payment information, which were not independently confirmed in circulation. Sanderling had not confirmed the incident or notified individuals as of the latest reporting.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
40K records analyzed
Sanderling Renal Services (SRS), operating as Sanderling Healthcare, is a Nashville, Tennessee-based provider of dialysis and renal (nephrology) care founded in 2012, offering in-center and home dialysis and renal telemedicine with a focus on rural communities. It maintains patient identity, clinical, insurance, and billing records along with employee and business data.
Healthcare facility and specialty-care companies collect employee, patient, operational, project, and financial records across healthcare development and service-delivery workflows.
Sanderling had not publicly confirmed the incident or notified individuals as of the latest reporting; details emerged through security trackers and law firms, several of which opened class-action investigations. The Sarcoma group listed Sanderling on its leak site and claimed a full Oracle database backup spanning 25 years of patient and business data.
Confirmed circulating identifiers (names, addresses, phones, Social Security numbers) for tens of thousands of dialysis patients and staff create identity-theft and chronic-illness/elder scam risk. Sarcoma additionally claims a 25-year Oracle backup containing driver’s licenses, medical records, health insurance, and payment data; if published, that would sharply raise medical- and financial-fraud risk for a chronically ill patient population.
• Identity theft and synthetic identity construction using SSN | • Targeted phishing, smishing, and vishing using exposed contact data | • Doxxing and physical targeting from exposed home addresses | • Chronic-illness/elder-targeted scams exploiting dialysis-patient status | • Potential medical- and financial-fraud if the claimed medical/DL/insurance/payment data is published
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
Emerged October 2024 and rapidly reached high global ransomware volume; focuses on industrial, manufacturing and tech firms with double extortion.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation