Trinity Caring Data Breach Exposes Sensitive Patient and Employee Information

Published: 16 September 2026 · Last Updated: 16 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

Trinity Caring, a senior services organization tied to Guardian Angels Senior Services and Cassia, suffered a ransomware attack by the Safepay group that may have exposed patient and employee data, including Social Security numbers and medical records. The number of people affected has not been publicly disclosed. Affected individuals should monitor credit reports and consider a credit freeze immediately.

Companytriniticaring.org
IndustryHealthcare
Data Types ExposedFull Names and Contact Information, Social Security Numbers, Dates of Birth, Medical and Health Records, Insurance Information, Employment Records, Financial Account Details
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Trinity Caring Data Breach?

Trinity Caring, a senior services organization formed through a joint ownership arrangement between Guardian Angels Senior Services of Elk River and Cassia, an Augustana and Elim affiliation, has confirmed a ransomware attack on its network. A group known as Safepay has claimed responsibility for the intrusion. This group is known for both locking down systems and stealing data before deploying ransomware payloads.

The exact discovery date for the breach has not been publicly disclosed. However, the attack fits a pattern common among healthcare-adjacent organizations targeted by ransomware crews. Attackers typically gain a foothold through phishing emails, stolen credentials, or unpatched software. From there, they move through internal systems to locate valuable files before triggering encryption.

Because Safepay is associated with data theft alongside encryption, the exposure of files appears to have happened before any ransomware payload was activated. As a result, the organization likely faced a two-part crisis: recovering locked systems while also confronting the reality that sensitive data had already left its network. This dual threat is now common across ransomware incidents in the healthcare sector.

Following discovery, Trinity Caring reportedly began an internal investigation to determine what happened and which records were affected. Forensic specialists were likely brought in to trace the intrusion path and assess the scope of stolen data. This kind of investigation often takes weeks or months to complete fully, which is why exact notification timelines have not yet been made public.

Who was affected?

The breach may affect a range of people connected to Trinity Caring’s operations. This can include current and former patients, residents of affiliated senior living communities, and employees whose personal records were stored on the compromised network. Because the organization serves senior populations, older adults are especially likely to be represented among those affected.

The exact number of individuals affected has not been publicly disclosed. In addition, the geographic scope of the breach has not been detailed in available information. Given that Trinity Caring operates through Guardian Angels Senior Services and Cassia affiliates, the impact could extend across multiple facilities and communities rather than a single location.

It also remains unclear whether family members or emergency contacts listed in resident files were affected. Senior care organizations often store this kind of secondary contact information alongside medical and financial records. Therefore, the pool of potentially impacted individuals could be broader than patients and staff alone.

What Information Was Potentially Exposed?

While a complete, itemized list of exposed data has not been made public, ransomware attacks against healthcare and senior care organizations commonly involve highly sensitive categories of information. Based on the nature of Trinity Caring’s operations, the following types of data may have been included in the exposure.

  • Full names and contact information
  • Social Security numbers
  • Dates of birth
  • Medical and health records
  • Insurance information
  • Employment records for staff
  • Financial account details

If Social Security numbers and financial information were indeed part of the stolen data, affected individuals face a real risk of identity theft. Criminals can use this information to open new credit lines, file fraudulent tax returns, or apply for loans in someone else’s name. Because senior residents may be less likely to monitor their credit regularly, this risk is particularly serious for that population.

Medical record exposure carries its own set of dangers. Stolen health information can be used to commit medical identity theft, where a criminal seeks treatment or prescriptions under someone else’s insurance. This can lead to incorrect medical histories, billing disputes, and complications with future care. In addition, exposed health data is often used in targeted phishing scams that reference real diagnoses or treatments to appear credible.

What is the company doing?

In response to the attack, Trinity Caring has reportedly taken steps to contain the breach and secure its network. This typically involves isolating affected systems, resetting credentials, and working with cybersecurity professionals to close the entry point used by attackers. These immediate containment measures are standard practice following a confirmed ransomware event.

Beyond containment, the organization is likely continuing its forensic investigation to fully determine which records were accessed or stolen. Once this process concludes, affected individuals should expect formal notification letters explaining what happened and what protections, if any, are being offered. Many organizations in this situation provide free credit monitoring or identity theft protection services to those impacted, though specific offerings from Trinity Caring have not been publicly detailed.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request copies of their credit reports from all three major credit bureaus. Reviewing these reports carefully can help identify any unfamiliar accounts or inquiries. Because ransomware breaches often involve stolen personal identifiers, early detection of misuse is critical.

You can access free credit reports through AnnualCreditReport.com. In addition, many financial institutions now offer free credit monitoring tools through their banking apps. Checking reports every few months, rather than just once, gives you a better chance of catching suspicious activity quickly.

Consider a Fraud Alert or Credit Freeze

Because Social Security numbers and financial information may have been exposed, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires creditors to verify your identity before opening new accounts. A credit freeze goes further by blocking access to your credit file entirely.

To set up a freeze, you must contact each of the three credit bureaus individually: Equifax, Experian, and TransUnion. This process is free and can be reversed later if you need to apply for credit. As a result, many security experts recommend a freeze over an alert for stronger protection.

Watch for Phishing and Scam Attempts

Following a healthcare-related data breach, scammers often send emails or texts pretending to be from the breached organization. These messages may reference real details from stolen files to appear legitimate. Because of this, affected individuals should be cautious with any unexpected communication asking for personal information.

Never click links or provide details in response to unsolicited messages. Instead, contact Trinity Caring directly using a verified phone number or website. This simple habit can prevent a secondary scam from compounding the damage already done by the original breach.

Protect Against Medical Identity Theft

Because medical records may have been included in the exposure, affected individuals should review recent insurance statements and medical bills closely. Look for treatments, prescriptions, or provider visits that you do not recognize. This can be an early sign of medical identity theft.

If you notice any discrepancies, contact your insurance provider and the healthcare facility immediately. Requesting a copy of your medical records can also help you verify accuracy. Correcting fraudulent entries early prevents larger complications with future medical care or insurance claims.

Seek Legal Guidance if You Were Affected

If you believe your information was compromised in this breach, consulting a data breach attorney can help clarify your rights. Many attorneys offer free case evaluations to determine whether you qualify for compensation. This is especially relevant if you experience financial losses or identity theft linked to the incident.

Legal action following data breaches has become increasingly common, particularly in the healthcare sector. Because deadlines for filing claims can vary by state, speaking with an attorney sooner rather than later is generally advisable. This ensures you do not miss any applicable filing windows.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →