Two ransomware groups, Genesis and Anubis, claim they stole medical records, patient lists, and business data from Interim HealthCare, a home healthcare provider operating in 40 states. The breach was discovered in August 2026 and reportedly affects patients tied to its Oklahoma City and Tulsa locations. If you received care through Interim HealthCare, watch for official notification and start monitoring your credit reports immediately.
| Company | Interim HealthCare |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Medical Records, Clinical Data, Patient Lists, Personal Identifying Information, Financial Information, Internal Business Records |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the Interim HealthCare Data Breach?
Interim HealthCare, a home healthcare provider with operations across 40 U.S. states, is now facing claims from two separate ransomware groups. Both groups say they broke into the company’s systems and stole sensitive files. This raises serious concerns for patients and families who rely on the company’s home care services nationwide.
According to public reports, unauthorized access to its network occurred in August 2026, when one of the groups first listed the company on its data leak site. A group calling itself Genesis claimed it exfiltrated roughly 1TB of data tied to Interim HealthCare of Oklahoma and Tulsa. The group said the stolen files included medical records, healthcare data, patient lists, clinical data, and general company records. A second group, known as Anubis, then posted its own listing days later, claiming to have taken about 530 GB of data, including financial information about franchisees and internal business communications.
As a result, the company now faces two competing extortion claims tied to what may be related or separate intrusions. Anubis has already published samples of the data it claims to hold, which suggests a ransom was not paid. Genesis has not yet published the files it says it stole, but it has threatened to do so. Interim HealthCare has not publicly confirmed the accuracy of either claim.
Notably, Interim HealthCare of Oklahoma City, Inc. formally reported a network hacking incident to federal regulators in July 2026. That filing used a placeholder estimate of 500 affected individuals while the investigation continued. Because forensic reviews often take weeks or months, the final number of affected patients could end up being much higher than this early estimate.
Who was affected?
The individuals affected by this incident likely include patients who received home healthcare services through Interim HealthCare’s Oklahoma City and Tulsa locations. Given the company’s broad footprint across 40 states, however, the true scope of affected patients and staff has not been fully clarified in public statements so far.
The exact number of affected individuals has not been publicly disclosed beyond the placeholder estimate of 500 individuals used in the regulatory filing. Because home healthcare often involves elderly patients, individuals with chronic conditions, and other vulnerable populations, the sensitivity of this incident is especially high. In addition, the Anubis claim references franchisee financial data, which suggests that business partners and internal staff records may also be involved.
What Information Was Potentially Exposed?
Based on the claims made by both ransomware groups, a wide range of sensitive information may have been exposed in this incident. The alleged stolen data spans clinical, personal, and internal business records. Because neither claim has been independently verified by Interim HealthCare, the full picture remains uncertain.
- Medical records and clinical data
- Patient lists
- Personal identifying information
- Healthcare data related to home care services
- Financial information tied to franchise operations
- Internal and external audit details
- Internal business communications and operational records
For patients, the exposure of medical records and clinical data creates a real risk of medical identity theft. This happens when someone uses a stolen identity to obtain healthcare services, prescriptions, or insurance reimbursements. As a result, victims can end up with inaccurate medical histories that affect future treatment decisions.
In addition, patient lists and personal details could be used for targeted phishing attempts. Scammers often pose as healthcare providers to trick victims into revealing further information. Because franchisee financial records may also be involved, business partners could face fraud attempts as well, including fraudulent invoices or wire transfer scams.
What is the company doing?
Interim HealthCare of Oklahoma City has already taken the step of notifying the HHS Office for Civil Rights about the network hacking incident. This filing indicates the company is treating the matter as a confirmed security event rather than a mere allegation. However, the company has not yet publicly confirmed the specific details claimed by either ransomware group.
Going forward, affected patients should expect additional communication as the investigation continues. Because the regulatory filing used a placeholder estimate, an updated and more accurate count is likely to follow once the forensic review is complete. In the meantime, patients should watch for official notification letters describing exactly what information was involved and what protective steps, if any, are being offered.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone connected to Interim HealthCare’s Oklahoma City or Tulsa operations should begin monitoring their credit reports closely. This is especially important given the reported presence of personal and financial data in the stolen files. Regular monitoring can help you catch unauthorized accounts or inquiries early.
You can request a free credit report from each of the three major credit bureaus once a year. Consider spacing these requests out every four months so you have monitoring coverage throughout the year. If you notice unfamiliar accounts or hard inquiries, dispute them immediately with the relevant bureau.
Consider a Fraud Alert or Credit Freeze
Because Social Security numbers and financial details may be connected to this broader set of incidents involving Interim HealthCare’s network, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before extending new credit. A credit freeze goes further by blocking new credit accounts from being opened in your name entirely.
Both protections are free to set up. You can contact any one of the three credit bureaus to place a fraud alert, since they are required to notify the other two. For a credit freeze, however, you generally need to contact each bureau separately.
Watch for Medical Identity Theft
Because clinical data and patient lists were reportedly stolen, affected patients should watch closely for signs of medical identity theft. This includes checking insurance statements for services you never received. It also means reviewing medical bills carefully for unfamiliar charges.
If you spot anything suspicious, contact your insurance provider immediately to dispute the charges. You should also request a copy of your medical records to check for inaccuracies caused by fraudulent activity. Correcting a corrupted medical history early can prevent future treatment complications.
Stay Alert for Phishing Attempts
Because attackers now may hold personal and clinical details, phishing emails and phone calls could follow this incident. Scammers often use real details from a breach to make fraudulent messages seem legitimate. As a result, patients should be cautious of any unexpected messages referencing their healthcare provider.
Never click links or provide personal information in response to unsolicited messages. Instead, verify any request by contacting Interim HealthCare directly using a phone number you look up independently. If you believe you have been targeted, report the attempt to the Federal Trade Commission.
Consult a Data Breach Attorney
Given the scale and sensitivity of this incident, affected individuals may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation through a class action or individual claim. This is especially relevant if medical or financial harm results from the exposure.
Many data breach attorneys offer free case evaluations, so there is little downside to asking questions early. Acting sooner rather than later can also help ensure you don’t miss any filing deadlines that may apply to your situation.
