Nonprofit · Community healthcare services · Regional health organization · USA
Community health center providing primary and preventive care.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Sandhills Medical Foundation, a South Carolina federally qualified health center, suffered a ransomware attack by the INC Ransom group with network access from about May 2-8, 2025 (detected May 8 when files were encrypted). INC Ransom listed Sandhills on May 30, 2025 and leaked all stolen data on June 15, 2026 after no ransom was paid. Sandhills notified 169,017 individuals around April 28, 2026. Exposed data included names, dates of birth, and health information, and (per the notice) may also have included Social Security numbers, ITINs, driver's license/government ID numbers, passport numbers, and financial information. (NOTE: prior record count was 63,150; official figure is 169,017.)
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
169K records analyzed
Sandhills Medical Foundation is a nonprofit federally qualified health center (FQHC) providing primary and preventive care across Chesterfield, Kershaw, Lancaster, and Sumter Counties in South Carolina, largely serving rural and underserved populations. It maintains patient identity, insurance, billing, and clinical records.
Regional healthcare organizations collect patient identity, insurance, billing, treatment, and administrative records across community care operations.
A ransomware attack by the INC Ransom group compromised Sandhills’ network in early May 2025 (access ~May 2-8, detected May 8 when files were encrypted). INC Ransom listed Sandhills on May 30, 2025 and leaked the stolen data on June 15, 2026 after the ransom went unpaid. Sandhills notified 169,017 individuals around April 28, 2026; class-action investigations followed.
The exposure of Social Security numbers, dates of birth, driver's license/government IDs, and health information for over 169,000 patients, later fully leaked by INC Ransom, creates severe identity-theft, medical-fraud, and insurance-abuse risk. As an FQHC serving rural, underserved communities, affected patients may have fewer resources to detect and recover from fraud, and the delayed notification widened the exposure window.
• Identity theft and synthetic identity construction using SSN, DOB, and driver's license | • Medical identity fraud and insurance abuse using health data | • Targeted phishing and vishing referencing clinic care or billing | • Doxxing and physical targeting from exposed home addresses | • Heightened harm to rural/underserved patients with fewer recovery resources
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware and data extortion group active since at least July 2023. MITRE describes it as targeting industrial, healthcare, and education sectors in the United States and Europe.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation