2026 Atrium Centers — Oct 2025 network intrusion; Medusa ransomware claim; PHI/SSN types (no census yet)
Data compromised
Per website notice (PDF): names, contact/demographic data, SSNs, driver’s licenses, patient IDs, medical record numbers, medical information, health insurance, claim information, financial account information, DOB — potentially for patients, responsible parties, and employees. No attested individual census as of Vermont AG filing (14 August 2026).
Technical writeup
Verified company notice — August 2026 regulatory filing window. Atrium Centers Inc. (Columbus, Ohio skilled nursing operator) identified unusual IT activity about 13 October 2025 and found unauthorized access between 8 and 12 October 2025 with files viewed or copied. A website PDF notice describes potentially exposed identity, medical, insurance, and financial fields for patients, responsible parties, and employees. On 9 November 2025 the Medusa ransomware group claimed responsibility on a Tor forum, per August 2026 summaries. Vermont Attorney General breach notices posted 14 August 2026; no public headcount at indexing — recordsAffected 0 pending state letters or HHS OCR. Assistance line 855-433-1829.
Root cause
Unauthorized network access 8–12 October 2025; Medusa ransomware group claimed the attack on 9 November 2025 (Tor forum) per August 2026 notices