Thursday, September 3

Columbus, Ohio — Cybercriminals have targeted nursing homes and senior care facilities across four states in a recent wave of attacks, compromising sensitive patient and employee data in breaches that highlight the growing vulnerability of long-term care providers to digital threats.

Atrium Centers Inc., a Columbus-based skilled nursing and rehabilitation care provider operating multiple facilities, disclosed that unauthorized actors accessed its computer systems between October 8 and October 12, 2025. The company, which is employee-owned and serves communities across Ohio, said files containing patient and employee data were viewed or copied during the incident.

The compromised information includes names, contact details, dates of birth, Social Security numbers, driver’s license numbers, patient ID numbers, medical record numbers, medical information, health insurance details, and financial account information. Atrium Centers is still reviewing the full scope of the breach and has not yet disclosed how many individuals were affected.

The Medusa ransomware group later claimed responsibility for the attack, adding Atrium to a growing list of healthcare victims. According to federal cybersecurity advisories, Medusa operators have targeted more than 300 victims across critical infrastructure sectors since emerging in 2021.

Multiple Facilities Across States Affected

The breaches extend beyond Ohio. In North Carolina, nearly 4,000 patients of three rehabilitation and long-term care practices—Elevate Health & Rehabilitation, Bear Mountain Health and Rehabilitation, and Swannanoa Valley Health and Rehabilitation—were notified that their information was compromised.

The incident involved a third-party vendor whose systems were accessed using stolen credentials between November 25 and November 28, 2025. The affected data included names, addresses, email addresses, dates of birth, Social Security numbers, driver’s license numbers, patient account numbers, diagnoses, and other health information. The vendor reported receiving assurances that the stolen data was deleted and not published online, suggesting a ransom payment may have been made.

In Washington state, Spokane United Methodist Homes, operating as Rockwood Retirement Communities, disclosed a February 2026 hacking incident that exposed personal and protected health information. The breach affected names, Social Security numbers, dates of birth, driver’s license and state identification numbers, passport numbers, financial account information, Medicaid and Medicare numbers, medical information, and health insurance details. The organization completed notification to affected individuals on July 27, 2026.

Broader Pattern of Healthcare Cyberattacks

The incidents are part of a broader pattern of ransomware groups targeting healthcare providers, including previous cyberattacks that have drawn litigation and regulatory scrutiny. Long-term care facilities have become particularly attractive targets due to their reliance on legacy systems, limited IT budgets, and the high value of the personal and medical data they maintain.

Security experts say nursing homes face unique cybersecurity challenges. Many operate on thin margins that leave little room for expensive security upgrades, while their distributed networks and remote access needs create multiple entry points for attackers. The consequences of a breach extend beyond financial costs to include regulatory penalties, reputational damage, and the potential for disrupted care.

Atrium Centers said it is working with third-party cybersecurity experts to enhance technical safeguards and prevent similar incidents. The company will mail notification letters to affected individuals once the file review process is complete.

For residents and families, the breaches serve as a reminder to monitor credit reports and financial accounts for unusual activity. Healthcare data breaches can lead to identity theft, medical fraud, and other financial crimes that may not surface for months or years after the initial compromise.


Discover more from Skilled Care Journal

Subscribe to get the latest posts sent to your email.

Share.

Leave a Comment

Discover more from Skilled Care Journal

Subscribe now to keep reading and get access to the full archive.

Continue reading