A ransomware group called incransom claims to have breached Rimrock Foundation, a regional addiction treatment center, potentially exposing patient treatment records, contact details, and possibly Social Security numbers. Rimrock has not publicly confirmed the incident or the number of people affected. Anyone who received care there should monitor their credit reports and watch for official notification from Rimrock.
| Company | Rimrock Foundation |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Contact Information, Dates of Birth, Substance Abuse Treatment Records, Mental Health Treatment Information, Insurance or Billing Details, Social Security Numbers |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Rimrock Foundation Data Breach?
A ransomware group calling itself incransom has claimed responsibility for a cyberattack on Rimrock Foundation. Rimrock is a large addiction treatment center that provides inpatient and outpatient care for adults facing substance use and co-occurring mental health disorders. The group posted its claim on a dark web leak site, stating it accessed the organization’s systems and data.
As of now, Rimrock Foundation has not publicly confirmed this incident. This means the exact method of intrusion, along with the precise timeline of the alleged attack, has not been publicly disclosed. Ransomware groups like incransom typically gain access through phishing emails, stolen credentials, or unpatched software vulnerabilities, though it is not yet known which method, if any, applies here.
Because this claim currently comes only from the threat actor’s own listing, there is no confirmed detail yet about when unauthorized access may have occurred. In addition, no forensic findings or investigation updates have been made public. As a result, affected individuals and the public are relying solely on the attacker’s statement until Rimrock Foundation issues its own confirmation.
Who was affected?
The population potentially affected by this incident likely includes current and former patients of Rimrock Foundation. Because the organization provides addiction and mental health treatment, this raises particular privacy concerns. Individuals receiving substance abuse treatment often face heightened stigma, so any exposure of their treatment history could carry unique personal and professional risks.
The exact number of affected individuals has not been publicly disclosed. It also remains unclear whether employee records, in addition to patient records, were involved. Since Rimrock serves as a regional treatment hub, the geographic scope of affected individuals may extend beyond a single city or county, though this has not been confirmed.
What Information Was Potentially Exposed?
Because Rimrock Foundation has not released an official statement, the specific data categories involved in this incident have not been confirmed by the organization. However, given that incransom claims to have accessed data from a treatment facility, the types of information typically held by such an organization would likely include medical and personal details.
- Full names
- Contact information
- Dates of birth
- Substance abuse treatment records
- Mental health treatment information
- Insurance or billing details
- Possible Social Security numbers
If this information was indeed accessed, the risks to affected individuals could be significant. Exposed treatment records could lead to discrimination, stigma, or embarrassment if disclosed to employers, family members, or the public. In addition, insurance information could be used to commit medical billing fraud, resulting in incorrect charges or denied future claims.
Furthermore, if Social Security numbers or other identifying details were part of the exposure, affected individuals could face a higher risk of identity theft. Criminals could use this data to open new credit accounts, file fraudulent tax returns, or access other financial resources. Because recovery records are especially sensitive, individuals should treat any notification from Rimrock with urgency.
What is the company doing?
Because this incident has only been claimed by the incransom ransomware group, there is no public record of an official response from Rimrock Foundation at this time. The organization has not publicly confirmed the breach, launched an investigation, or announced notification plans. Therefore, affected individuals should watch for official communication directly from Rimrock in the coming weeks.
Until Rimrock Foundation releases a statement, it remains unknown whether credit monitoring, identity protection services, or other remediation steps will be offered. If the organization confirms the incident, healthcare entities are generally required to notify affected patients and regulators under federal law. For now, individuals should rely only on verified communications from Rimrock rather than third-party claims.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. You can request free copies from all three major credit bureaus. Reviewing these reports often helps catch fraudulent activity early, before it causes lasting financial damage.
In addition, consider setting up ongoing credit monitoring if it becomes available through Rimrock or a third-party service. This type of monitoring can alert you quickly to new account openings or suspicious credit inquiries. Because fraud can take months to surface, consistent review over time is important.
Consider a Fraud Alert or Credit Freeze
If Social Security numbers or financial details were part of this incident, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to verify your identity before approving new credit in your name. This step is free and can be renewed periodically.
For even stronger protection, you may want to freeze your credit entirely. A credit freeze blocks new creditors from accessing your credit file altogether. As a result, it becomes much harder for identity thieves to open accounts using your information.
Protect Your Healthcare Privacy
Because this breach may involve sensitive treatment records, it is worth requesting an accounting of disclosures from Rimrock Foundation. This document shows who has accessed your medical records and when. If you notice unfamiliar access, you can raise concerns directly with the provider.
You should also review any insurance statements or explanation-of-benefits documents closely. Unexpected charges could indicate someone used your information to receive treatment fraudulently. Reporting discrepancies quickly to your insurer can limit further misuse.
Stay Alert for Phishing Attempts
Following any data exposure, scammers often send phishing emails or texts posing as the breached organization. Be cautious of unexpected messages asking you to click links or provide personal details. Legitimate notifications from Rimrock Foundation will not request sensitive information through unsolicited messages.
Instead, verify any communication by contacting Rimrock directly through a known, official phone number or website. This simple step can prevent you from falling victim to a secondary scam. Because attackers often target breach victims specifically, staying skeptical is a reasonable long-term habit.
Consult a Data Breach Attorney
If you believe your information was compromised in this incident, speaking with a data breach attorney can help clarify your options. Many offer free consultations to review your situation and explain potential legal remedies. This is especially useful if Rimrock later confirms the breach and notifies you formally.
An attorney can also help you understand whether you may qualify for compensation through a class action lawsuit. Because healthcare data carries special legal protections, cases involving treatment records sometimes lead to significant settlements. Acting early can help preserve your rights as more facts become available.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
