Midwest Spine and Brain Institute
Incident posture
Linked entities
- Victim
- Midwest Spine and Brain Institute
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Midwest Spine and Brain Institute reported that a breach at its service provider 3C Care Systems resulted in unauthorized access to patient data including names combined with dates of birth, medical details, record numbers, provider information, prescriptions, service dates, and health insurance information. The organization's investigation found its own network was not compromised, only the data shared with the vendor, and it has begun notifying affected individuals while offering identity monitoring for those whose Social Security numbers were involved. Although the exact number of impacted patients is not publicly posted, the incident is linked to a ransomware claim by the disbanded RansomHub group alleging exfiltration of about 100 gigabytes from the vendor, though those claims remain unverified.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Midwest Spine and Brain Institute learned that patient data had been accessed or obtained from its service provider 3C Care Systems after the provider disclosed a security incident. The institute launched an internal investigation that concluded on June 18, 2026, determining that its own network remained unaffected and that only the data shared with 3C Care Systems was involved. According to the investigation, the breach originated from a ransomware attack attributed to the now‑disbanded RansomHub operation that occurred on or around November 21, 2024. RansomHub claimed to have exfiltrated approximately 100 gigabytes of data from 3C Care Systems, although the provider did not issue a separate breach notice and the claim remains unverified.
The review of the compromised data indicated that personally identifiable information and protected health information could have been exposed, including first and last names combined with one or more of the following: date of birth, medical treatment, procedure, diagnosis, medical record number, medical provider information, prescription information, dates of service, and health insurance claim or policy information. For individuals whose Social Security numbers were part of the exposed data, the institute offered complimentary identity monitoring and protection services. The types of data described align with the categories typically targeted in ransomware exfiltration events.
In response, Midwest Spine and Brain Institute began mailing notification letters to all affected individuals. The institute has not disclosed the total number of patients impacted, and the incident does not yet appear on the HHS Office for Civil Rights breach portal. The investigation concluded on June 18, 2026, after which the notification efforts commenced. The notification process and the offered services constitute the primary actions taken by the institute following the conclusion of its investigation.
Sources
Sources available to members: 1 source.