Good Samaritan Health Center
Incident posture
Linked entities
- Victim
- Good Samaritan Health Center
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Good Samaritan Health Center in Georgia experienced a ransomware attack on an internal server in February 2026, affecting approximately 10,000 individuals; data potentially exposed included names, DOB, ZIP codes, and limited clinical data.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In February 2026, Good Samaritan Health Center in Georgia experienced a ransomware attack on an internal server. The organization discovered the incident and moved quickly to contain it, isolating the affected server from the rest of its environment. Following the isolation, the healthcare provider successfully restored the compromised server from backups, allowing operations to continue. As a result of the attack, the organization subsequently issued notification letters to approximately 10,000 individuals whose information had been stored on the compromised server. The compromised information included individuals' names, dates of birth, ZIP codes, and limited clinical data. While the organization worked to restore systems and assess the impact of the incident, it stated that it could not rule out the possibility that the data on the server had been accessed or exfiltrated during the attack, even though no definitive proof of data theft was identified at the time of reporting.
The incident placed Good Samaritan Health Center among the healthcare organizations impacted by ransomware activity, a sector that remained a primary target during the reporting period. The organization's response involved immediate technical containment through server isolation, followed by a successful recovery from backup systems to restore the affected environment. Alongside these technical measures, the healthcare provider began notifying affected individuals about the incident and the types of information that may have been exposed. The notification process specifically reached out to approximately 10,000 people connected to the data stored on the compromised server, providing them with details regarding the nature of the exposed information, which was limited to names, dates of birth, ZIP codes, and limited clinical data. Although the healthcare provider could not rule out the possibility of data access or exfiltration, no confirmation of such activity was reported at the time of disclosure.
Sources
Sources available to members: 1 source.