CSIDB logo
Incident

Family Medical Associates of Raleigh

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 09:46

Linked entities

Victim
Family Medical Associates of Raleigh
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Family Medical Associates of Raleigh detected unauthorized access to its systems between April 18-20, 2026, potentially exposing patient data; Genesis ransomware group claimed responsibility.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Family Medical Associates of Raleigh, a multi-provider family medical practice located in Raleigh, North Carolina, identified a potential cybersecurity incident on May 7, 2026, at which point it activated its incident response protocol. Upon detection, the organization took immediate steps to investigate, contain, and remediate the situation. Law enforcement was notified, and third-party cybersecurity professionals were engaged to assist with the response and forensic analysis. Through the investigation, it was confirmed that certain systems within the practice's environment had been intermittently accessed by an unauthorized third party between April 18, 2026, and April 20, 2026. During that window of unauthorized access, the threat actor potentially downloaded internal data, including files containing patients' protected health information.

The data review was ongoing as of the date of the report, so the precise number of affected individuals had not yet been determined. However, preliminary findings indicated that the types of data exposed in the incident included names, demographic information, contact information, medical and treatment information, health insurance information, financial and payment-related information, government-issued identification numbers, and other data related to the medical services the practice provides. Family Medical Associates of Raleigh stated that it was unaware of any actual or attempted misuse of patient data resulting from the incident. Despite this, patients were advised to remain vigilant against identity theft and fraud by monitoring their accounts, reviewing free credit reports, and examining their explanation of benefits statements. While the organization did not disclose the identity of the threat actor behind the attack, the Genesis ransomware group publicly claimed responsibility for the incident.

Sources

Sources available to members: 1 source.

CSIDB