Cyber Incident Victim: Sandhills Medical Foundation
Date:
May 2025
Location:
United States of America
Summary
Sandhills Medical Foundation experienced a ransomware attack that led to unauthorized access of its servers and the exfiltration of personal information from select patients. The compromised data included names, dates of birth, Social Security numbers, taxpayer identification numbers, driver’s licenses, government‑issued identification, passports, financial details, and personal health information, affecting approximately 170,000 individuals. The Inc Ransom ransomware group later posted the stolen files on its leak site, making them available for download. In response, a national class action law firm began investigating potential data‑privacy claims and offering free case evaluations to those whose information may have been exposed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On May 8, 2025, Sandhills Medical Foundation discovered that it had been the victim of a ransomware attack on its systems. The organization promptly engaged cybersecurity experts and a forensic firm to investigate the intrusion. That investigation determined that an unauthorized third party had gained direct access to Sandhills Medical’s server and obtained personal information belonging to a subset of patients. Sandhills Medical indicated that it became aware of the cybersecurity incident between November 27 and November 29, 2025. The compromised data were reported to include names, dates of birth, Social Security numbers, taxpayer identification numbers, driver’s license numbers, government‑issued identification details, passport information, financial data, and personal health information. The breach was estimated to affect approximately 169,017 individuals, with other sources describing the figure as nearly 170,000 people.

Throughout the investigation, Sandhills Medical collaborated with law enforcement agencies, the cybersecurity experts, and the forensic firm to analyze the intrusion and assess its impact. The Inc Ransom ransomware group placed Sandhills Medical on its leak website in early June 2025 and subsequently made the allegedly stolen files available for download. Nearly one year after the initial discovery, in May 2026, Sandhills Medical publicly disclosed the incident and began notifying the individuals whose information had been compromised. On May 3, 2026, the national class action law firm Edelson Lechtzin LLP announced that it was investigating data privacy claims arising from the Sandhills Medical breach and was offering free case evaluations to potentially affected persons. Sandhills Medical operates as a Federally Qualified Community Health Center located in McBee, South Carolina, providing community‑based primary health care services.
Individuals who received a data breach notification from Sandhills Medical were advised that they may face an increased risk of identity theft and fraud as a result of the exposure. The compromised information included names, dates of birth, Social Security numbers, taxpayer identification numbers, driver’s license numbers, government‑issued identification details, passport information, financial data, and personal health information. Sandhills Medical publicly disclosed the incident and began notifying the affected individuals nearly one year after the initial discovery. The breach contributed to the tally of ransomware‑related incidents affecting healthcare organizations that have been reported in recent years.
