Mid-South Pulmonary Sleep Specialists
Incident posture
Linked entities
- Victim
- Mid-South Pulmonary Sleep Specialists
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A Memphis-based pulmonary and sleep medicine practice identified suspicious activity within its computer network, secured the environment, and engaged third-party cybersecurity experts who confirmed unauthorized access and the potential theft of patient data. The review of the exposed information was completed in mid-2026 and revealed a wide range of personal and protected health information potentially affected, including names, addresses, dates of birth, Social Security numbers, driver's license or state ID numbers, financial account information, health insurance details, medical diagnoses, treatment and prescription records, Medicare/Medicaid numbers, and other patient identifiers. The incident appears to have been a ransomware attack, with the Anubis ransomware group claiming responsibility and posting samples of allegedly stolen data on its leak site shortly after the intrusion. Regulators have been notified, though the total number of affected individuals had not yet been publicly disclosed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Mid-South Pulmonary Sleep Specialists, a pulmonary and sleep medicine practice based in Memphis, Tennessee, experienced a cybersecurity incident that resulted in unauthorized access to its computer network and the potential exposure and theft of patient data. Suspicious activity was first identified within the practice's network on November 2, 2025. The exact nature of the attack is not described in the breach notice published on the practice's website, and it is also not stated how long the threat actors maintained access to the network before the activity was discovered. Upon detecting the suspicious activity, the practice secured its network and engaged third-party cybersecurity experts to assist with the investigation and response.
The third-party cybersecurity experts confirmed that unauthorized actors had gained access to the practice's network environment and that patient data had been exposed and potentially stolen. The practice then undertook a comprehensive review of the affected data to determine what information had been compromised and which individuals were impacted. This data review process was completed on May 18, 2026, more than six months after the initial detection of the incident. The delay between the November 2025 detection and the May 2026 completion of the review reflects the time required to thoroughly analyze the compromised data.
The review revealed that a wide range of data types were exposed in the incident, though the specific data elements varied from individual to individual. The information potentially compromised included names in combination with one or more of the following data elements: address, date of birth, date of service, driver's license or state ID number, financial account information, health insurance information, medical diagnosis information, medical history, medical provider name, medical record number, medical treatment information, Medicare or Medicaid number, mental or physical condition, other patient identifiers, patient account number, prescription information, and Social Security number. This broad range of data types indicates that the breach had the potential to affect many aspects of patients' personal and medical information.
Although the breach notice itself does not specify the nature of the attack, evidence from external sources suggests that ransomware was involved. The Anubis ransomware group claimed responsibility for the attack and added Mid-South Pulmonary Sleep Specialists to its data leak site in late November 2025. The group also posted samples of data allegedly stolen during the attack and claimed that the stolen data included patient information. This claim, combined with the timing of the addition to the data leak site shortly after the initial detection of suspicious activity, strongly indicates that the Anubis ransomware group was responsible for the unauthorized access.
Following the completion of the data review, the practice began notifying certain patients about the cybersecurity incident and the exposure of their personal and protected health information. The practice also reported the incident to relevant regulators. However, as of the publication of the available information, the incident had not yet appeared on the HHS' Office for Civil Rights website, and it was therefore unclear how many individuals were affected by the breach. The practice's website breach notice did not provide additional details about the nature of the attack or the duration of the unauthorized access, leaving some aspects of the incident undisclosed in official communications.
The impact of the incident on patients is significant given the breadth of data types involved, which included sensitive identifiers such as Social Security numbers, driver's license numbers, financial account information, and detailed medical records. The exposure of mental or physical condition information, medical history, diagnosis details, and prescription information further increases the potential risk to affected individuals. The practice's notification process and regulatory reporting represent standard response actions following the discovery of a data breach, though the full scope of the incident, including the total number of affected individuals, remains undisclosed in publicly available sources.
Sources
Sources available to members: 1 source.