Central Ohio Primary Care Physicians
Incident posture
Linked entities
- Victim
- Central Ohio Primary Care Physicians
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Central Ohio Primary Care Physicians, a physician-owned primary care group serving over 500,000 patients, experienced a ransomware attack claimed by the group Chaos. The incident reportedly involved the exfiltration of between roughly 260 and 360 gigabytes of data containing patient and employee information, and a law firm has launched an investigation into potential data privacy claims.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Central Ohio Primary Care Physicians (COPCP), a physician‑owned primary care group that serves more than 500,000 patients across Ohio, experienced a ransomware attack that was reported on or about August 26, 2026. According to postings on the dark web security blog HookPhish and the cybersecurity monitoring site Breachsense, the ransomware group Chaos claimed responsibility for the intrusion, which is estimated to have begun on or about August 25, 2026. Breachsense reported that the attackers exfiltrated approximately 362 gigabytes of data from COPCP’s systems, while earlier references cited a figure of roughly 263 gigabytes; the exact volume and contents of the taken data have not been confirmed. The incident was disclosed publicly on August 27, 2026, in a press release issued by the law firm Edelson Lechtzin LLP.
The breach potentially affects current and former patients and employees of COPCP, given that the organization routinely stores sensitive personal and protected health information. As of the press release, the specific categories of data exposed had not been verified, and the full scope and nature of the incident remained unconfirmed. Individuals who receive a breach notification from COPCP may face an increased risk of identity theft and fraud, according to the law firm’s statement. Edelson Lechtzin LLP indicated that it is investigating whether a class action could be pursued on behalf of those whose sensitive personal data may have been compromised, noting that a successful action could seek compensation for harms such as loss of privacy, lost time, and out‑of‑pocket costs, and could encourage COPCP to strengthen its data protection measures.
Edelson Lechtzin LLP, a national class action law firm with offices in Pennsylvania and California, is conducting a free, confidential case evaluation for anyone who believes their information may have been involved in the COPCP breach, and is collecting statements from current and former patients and employees to assess potential claims. The firm’s attorneys, including Marc Edelson, Esq., are available via phone and email to discuss possible legal remedies, and they state that there is no cost to speak with them. The press release notes that, aside from the law firm’s investigation, no further details about attacker tactics, detection, containment, or remediation by COPCP have been made public.
Sources
Sources available to members: 1 source.