Sanderling Healthcare 2025 Data Breach

Sanderling Renal Services Dialysis Provider Breach (2025): Patient SSN & Home Address Exposed via Sarcoma Ransomware

Healthcare Services Company · Healthcare facility development and specialty care services · Healthcare infrastructure and renal services company · USA

Sanderling Renal Services Dialysis Provider Breach (2025): Patient SSN & Home Address Exposed via Sarcoma Ransomware

Dialysis and renal (nephrology) telemedicine care provider.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
67/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
40KRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
AddressPhysical address
Classification Tags
SarcomaRansomware / ExtortionHealthcareMedical2025

Breach Summary

Sanderling Renal Services (listed by the actor as "Sanderling Healthcare"), a Nashville-based dialysis and nephrology provider, was hit by a ransomware attack around July 3, 2025 attributed to the Sarcoma group, which claimed to have exfiltrated roughly 587 GB including a full Oracle database backup spanning 25 years of patient and business data. DataBreach.com’s parse confirmed circulating identifiers including names, addresses, phone numbers, emails, and Social Security numbers (about 40,453 records). Sarcoma additionally claims exposure of dates of birth, driver’s license/state ID numbers, medical records, health insurance, and payment information, which were not independently confirmed in circulation. Sanderling had not confirmed the incident or notified individuals as of the latest reporting.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

40K records analyzed

About Sanderling Healthcare

Sanderling Renal Services (SRS), operating as Sanderling Healthcare, is a Nashville, Tennessee-based provider of dialysis and renal (nephrology) care founded in 2012, offering in-center and home dialysis and renal telemedicine with a focus on rural communities. It maintains patient identity, clinical, insurance, and billing records along with employee and business data.

Why They Hold Your Data

Healthcare facility and specialty-care companies collect employee, patient, operational, project, and financial records across healthcare development and service-delivery workflows.

Recent Developments

Sanderling had not publicly confirmed the incident or notified individuals as of the latest reporting; details emerged through security trackers and law firms, several of which opened class-action investigations. The Sarcoma group listed Sanderling on its leak site and claimed a full Oracle database backup spanning 25 years of patient and business data.

Data Points Exposed

4 verified field types
Email Address
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

Confirmed circulating identifiers (names, addresses, phones, Social Security numbers) for tens of thousands of dialysis patients and staff create identity-theft and chronic-illness/elder scam risk. Sarcoma additionally claims a 25-year Oracle backup containing driver’s licenses, medical records, health insurance, and payment data; if published, that would sharply raise medical- and financial-fraud risk for a chronically ill patient population.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using SSN | • Targeted phishing, smishing, and vishing using exposed contact data | • Doxxing and physical targeting from exposed home addresses | • Chronic-illness/elder-targeted scams exploiting dialysis-patient status | • Potential medical- and financial-fraud if the claimed medical/DL/insurance/payment data is published

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
S
Threat Actor: SarcomaConfidence: High
Ransomware group

Motivation: Financial extortion
Emerged October 2024 and rapidly reached high global ransomware volume; focuses on industrial, manufacturing and tech firms with double extortion.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation