Family Medical Associates of Raleigh
Incident posture
Linked entities
- Victim
- Family Medical Associates of Raleigh
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Family Medical Associates of Raleigh detected unauthorized access to its systems between April 18-20, 2026, potentially exposing patient data; Genesis ransomware group claimed responsibility.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Family Medical Associates of Raleigh, a multi-provider family medical practice located in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, at which point it activated its incident response protocol. Upon detection, the organization took immediate steps to investigate, contain, and remediate the situation. Law enforcement was notified, and third-party cybersecurity professionals were engaged to assist with the response and forensic analysis. Through the investigation, it was confirmed that certain systems within the practice's environment had been intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026. During that window of unauthorized access, the threat actor potentially downloaded internal data, including files containing patients' protected health information.
The data review was ongoing as of the date of the report, so the precise number of affected individuals had not yet been determined. However, preliminary findings indicated that the types of data exposed in the incident included names, demographic information, contact information, medical and treatment information, health insurance information, financial and payment-related information, government-issued identification numbers, and other data related to the medical services the practice provides. Family Medical Associates of Raleigh stated that it was unaware of any actual or attempted misuse of patient data resulting from the incident. Despite this, patients were advised to remain vigilant against identity theft and fraud by monitoring their accounts, reviewing free credit reports, and examining their explanation of benefits statements. While the organization did not disclose the identity of the threat actor behind the attack, the Genesis ransomware group publicly claimed responsibility for the incident.
Sources
Sources available to members: 1 source.