A ransomware group known as Storm has claimed a cyberattack on TheraCare, a healthcare and educational services provider based in New York, potentially affecting children, families, and employees across several states. TheraCare has not publicly confirmed the breach or the data involved. Affected individuals should monitor credit reports, watch for phishing attempts, and consider a credit freeze as a precaution.
| Company | TheraCare |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Dates of Birth, Health and Clinical Treatment Records, Educational and Developmental Records, Contact Information, Social Security Numbers, Insurance and Billing Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the TheraCare Data Breach?
A ransomware group calling itself Storm has claimed responsibility for a cyberattack targeting TheraCare, a healthcare, rehabilitation, and educational services organization based in White Plains, New York. The claim appeared on a dark web leak site used by the group to list victims and pressure them into paying a ransom. As of now, TheraCare has not publicly confirmed the incident.
Because this report stems from a ransomware group’s own claim, many details remain unverified. The exact method the attackers used to breach TheraCare’s network has not been publicly disclosed. Similarly, the breach discovery date has not been made public, and no official notification timeline has been released.
TheraCare serves children, families, and clients across New York, New Jersey, Connecticut, and Maryland. Its services include early intervention, autism support, speech-language therapy, occupational therapy, physical therapy, and school district staffing. Given this role, any confirmed data compromise involving a healthcare provider of this kind would likely involve sensitive personal and clinical information. However, until TheraCare itself issues a statement, the full scope of the TheraCare data breach cannot be independently confirmed.
Ransomware groups like Storm typically steal data before deploying encryption, then threaten to publish stolen files unless paid. This pattern, known as double extortion, often means data was copied off the network. As a result, even without formal confirmation from TheraCare, the claim itself raises real concerns for anyone connected to the organization.
Who was affected?
The individuals potentially affected by this incident may include current and former clients of TheraCare, along with their families. Because TheraCare provides early intervention and educational services to children, it is possible that minors are among those whose information was involved.
TheraCare also employs between 201 and 500 people, according to available business records. This means staff members could also be part of the affected population, in addition to clients and their guardians. The exact number of individuals affected has not been publicly disclosed.
Given TheraCare’s footprint across New York, New Jersey, Connecticut, and Maryland, the potential reach of this incident may extend across multiple states. Families who received services through TheraCare in any of these regions should pay close attention to further updates. In addition, school districts that contracted with TheraCare for staffing could also have relevant ties to this event.
What Information Was Potentially Exposed?
Because TheraCare has not issued a public statement, the specific data categories involved in this claimed breach have not been confirmed. However, given the nature of TheraCare’s business, certain types of information are commonly held by organizations like it. These categories represent the kind of data that could be at risk in a healthcare and education-focused breach.
- Full names of clients, families, and employees
- Dates of birth
- Health and clinical treatment records
- Educational and developmental assessment records
- Contact information, including addresses and phone numbers
- Possible Social Security numbers of employees or clients
- Insurance or billing information related to therapy services
If these categories of data were in fact accessed, the risk to affected individuals could be significant. Health and developmental records are especially sensitive because they relate to children’s long-term medical and educational history. This information cannot simply be changed like a password, which makes any exposure particularly concerning.
In addition, if Social Security numbers or insurance details were part of the stolen data, affected individuals could face a heightened risk of identity theft or insurance fraud. Fraudsters often use stolen health insurance information to file false claims or obtain medical services under someone else’s name. Because children’s identities are rarely monitored closely, pediatric identity theft can go undetected for years.
What is the company doing?
At this time, there is no public statement from TheraCare confirming the breach, launching an investigation, or describing any remediation steps. Because the only available information comes from the ransomware group’s own claim, it would be inaccurate to assume TheraCare has already taken specific action. The organization has not publicly confirmed the incident.
If TheraCare does confirm a breach, affected individuals would typically expect to see a formal notification letter, details about what data was involved, and information about any protective services offered. Until that happens, individuals connected to TheraCare should rely on official communications directly from the organization rather than assuming any particular response has occurred. In the meantime, it is reasonable for concerned clients, families, and employees to reach out to TheraCare directly for updates.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone connected to TheraCare, including clients, parents, and employees, should consider checking their credit reports in the coming months. This is especially important if Social Security numbers were part of the data categories involved. You can request a free credit report from each of the three major credit bureaus through AnnualCreditReport.com.
Because fraud resulting from stolen data can take time to appear, it helps to check reports periodically rather than just once. Look for unfamiliar accounts, inquiries you don’t recognize, or sudden changes to your credit profile. If you notice anything suspicious, report it to the credit bureau immediately.
Consider a Fraud Alert or Credit Freeze
If Social Security numbers or financial details were exposed, placing a fraud alert or credit freeze can add a strong layer of protection. A fraud alert requires lenders to take extra steps to verify your identity before approving new credit. A credit freeze goes further by blocking most access to your credit file entirely.
Both options are free and can be requested directly through each credit bureau. For families with children who may have been affected, it’s worth noting that minors can also have credit files established fraudulently. Parents should consider checking whether a credit file already exists for their child, which could indicate prior misuse.
Watch for Healthcare-Related Fraud
Because TheraCare provides clinical and therapy services, any compromised data could include health or insurance information. This means affected individuals should review insurance statements and explanation-of-benefits notices carefully. Unfamiliar charges or services listed that you don’t recognize could indicate medical identity theft.
If you spot anything unusual, contact your health insurance provider right away. In addition, request a copy of your health records to confirm their accuracy. Catching these issues early can prevent long-term complications with your medical history and insurance coverage.
Stay Alert to Phishing Attempts
Following any data breach claim, affected individuals often become targets of phishing emails, texts, or phone calls. Scammers may pose as TheraCare, a credit bureau, or even a government agency to trick you into giving up personal details. Because this claimed breach involves a healthcare and education provider, scammers could specifically reference therapy services or school programs to appear legitimate.
Always verify the sender before clicking links or sharing any personal information. If you receive a message claiming to be from TheraCare, contact the organization directly using a phone number or website you already trust, rather than one provided in the message itself. This simple step can prevent a secondary fraud attempt tied to this incident.
Consult a Data Breach Attorney
If TheraCare later confirms this breach and discloses that sensitive data was exposed, affected individuals may have legal options worth exploring. A data breach attorney can review your specific circumstances and help determine whether you qualify for compensation. Many offer free initial consultations, so there is little risk in simply asking questions.
Because class action eligibility often depends on confirmed details about the breach, it helps to keep any notification letters or communications from TheraCare. These documents can serve as important evidence if a claim becomes available. Acting early also helps ensure you don’t miss any filing deadlines tied to your state’s laws.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
